Microsoft Copilot (Microsoft 365): Code Blocks in M365 Copilot
🚨 The Signal: Microsoft 365 Copilot now displays code blocks directly inline within chat, rather than side-by-side. This change alters how users interact with generated code, charts, and diagrams, potentially increasing exposure to malicious content if not properly governed.
The Impact
All Copilot users are affected, with a moderate security risk due to increased inline exposure to potentially malicious code or scripts.
- End-users: Increased risk of inadvertently interacting with malicious code snippets.
- Security Teams: New vector for prompt injection or code execution via inline display.
- Admins: Need to review existing Copilot governance for inline content display risks.
The Action
- Review existing Microsoft 365 Copilot governance policies for content display.
- Educate users on the risks of executing or copying code from untrusted Copilot outputs.
- Monitor Copilot usage logs for unusual activity related to code block interactions.
Domain: Agentic-AI · Impact: medium · Workload: M365 Apps