Microsoft Copilot (Microsoft 365): Federated Copilot Connectors will support write, update and delete actions

🚨 The Signal: Copilot connectors now support write, update, and delete actions in third-party services. This expands Copilot's capabilities but increases the attack surface for data manipulation through compromised user accounts.

The Impact

All users are affected, with a high security risk due to expanded data modification capabilities through Copilot and third-party connectors.

  • End users: Can inadvertently modify sensitive data in third-party services.
  • Security teams: Must monitor and audit Copilot connector actions for data integrity.
  • Admins: Need to review and potentially disable connectors that pose unacceptable risks.
  • Compliance teams: Must assess new data handling risks for regulatory adherence.

The Action

  1. Review existing Copilot connector configurations in Microsoft 365 admin center.
  2. Identify connectors with write/delete capabilities to third-party services.
  3. Disable connectors that do not align with organizational data governance policies.
  4. Implement auditing for Copilot actions involving third-party data modification.
  5. Educate users on the implications of granting Copilot write/delete permissions to third-party services.

Domain: Agentic-AI · Impact: high · Workload: M365 Apps · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898