Microsoft Copilot (Microsoft 365): Power BI reports as references in Copilot Notebooks

🚨 The Signal: Copilot Notebooks can now reference Power BI reports, allowing Copilot to use this data for generating content. This expands the data sources Copilot can access, increasing potential for data exposure if not properly governed.

The Impact

All users are affected, with a high risk of sensitive Power BI data being exposed or misused through Copilot if access controls are not rigorously managed.

  • End users: Risk of inadvertently exposing sensitive Power BI data through Copilot-generated content.
  • Security team: Increased surface area for data exfiltration and compliance violations via Copilot.
  • Admins: Need to review and potentially reconfigure data access policies for Power BI and Copilot.
  • Data owners: Risk of their Power BI report data being used in contexts not originally intended.

The Action

  1. Review existing Power BI dataset and report access permissions to ensure least privilege is enforced.
  2. Audit Copilot usage logs for interactions involving Power BI reports to identify potential misuse.
  3. Implement Microsoft Purview Data Loss Prevention (DLP) policies to detect and prevent sensitive Power BI data from being shared inappropriately via Copilot.
  4. Educate users on responsible use of Copilot with sensitive data, emphasizing data classification and sharing policies.
  5. Monitor Microsoft 365 audit logs for unusual access patterns to Power BI reports by Copilot or users.

Domain: Agentic-AI · Impact: high · Workload: Other