Microsoft Copilot (Microsoft 365) Writing Blocks in M365 Copilot

🚨 The Signal: Microsoft 365 Copilot now allows direct editing of generated content within the chat interface. This streamlines content creation but increases the risk of sensitive data exposure if not properly governed.

The Impact

All users interacting with Copilot are affected, increasing the risk of inadvertent sensitive data exposure and potential data exfiltration.

  • End users: Increased risk of sensitive data exposure through refined content in Copilot chat.
  • Security team: Enhanced need for monitoring and data loss prevention (DLP) policies for Copilot interactions.
  • Compliance team: Potential for non-compliance if sensitive data is processed without appropriate controls.
  • Admins: Requires review of Copilot data handling and retention policies.

The Action

  1. Review and reinforce existing Microsoft Purview Data Loss Prevention (DLP) policies to include Copilot interactions.
  2. Educate users on responsible use of Copilot, emphasizing not to input or refine highly sensitive data.
  3. Implement or review Microsoft Purview Communication Compliance policies for Copilot chat.
  4. Monitor Copilot usage logs for unusual activity or sensitive data patterns.
  5. Ensure appropriate data retention policies are applied to Copilot chat data via Microsoft Purview.

Domain: Agentic-AI · Impact: high · Workload: M365 Apps