Microsoft Teams: Ask Copilot from Search on Mobile

🚨 The Signal: Copilot is now accessible directly from the Teams mobile search bar, allowing users to query and interact with Copilot without leaving search. This expands the attack surface for data exposure and prompt injection on mobile devices.

The Impact

All Teams mobile users are affected, increasing the risk of sensitive data exposure and prompt injection attacks through mobile Copilot interactions.

  • End Users: Increased risk of inadvertently exposing sensitive data via Copilot prompts on mobile.
  • Security Teams: New vector for prompt injection attacks and data exfiltration to monitor and mitigate.
  • Admins: Need to review and enforce existing Copilot data governance policies for mobile access.
  • Organisations: Potential for non-compliance with data handling policies due to expanded AI access.

The Action

  1. Review and reinforce Microsoft Purview Data Loss Prevention (DLP) policies for Teams and Copilot interactions.
  2. Educate users on secure prompting practices and the risks of sharing sensitive information with Copilot on mobile.
  3. Monitor Microsoft 365 audit logs for unusual Copilot activity or data access patterns from mobile devices.
  4. Ensure existing Copilot access controls and data boundaries are effectively applied to mobile experiences.
  5. Evaluate Microsoft Defender for Cloud Apps policies for Copilot to detect and prevent data exfiltration.

Domain: Agentic-AI · Impact: high · Workload: Teams