Dynamics 365 Field Service: Microsoft Copilot in Field Service Mobile app
🚨 The Signal: Copilot in Dynamics 365 Field Service mobile app provides frontline workers with conversational AI access to organizational data. This introduces new data access vectors and potential for sensitive information exposure via natural language queries.
The Impact
Frontline workers are affected, with a security risk of unauthorized data exposure and potential for prompt injection attacks.
- Frontline workers: Risk of exposing sensitive operational data through conversational AI.
- Security teams: Increased surface area for data exfiltration and prompt injection vulnerabilities.
- Data owners: Need to re-evaluate data classification and access policies for AI-driven queries.
The Action
- Review and classify all Dynamics 365 Field Service data for sensitivity and access restrictions.
- Implement data loss prevention (DLP) policies specific to Copilot interactions within Dynamics 365.
- Educate frontline workers on responsible AI usage and the risks of querying sensitive information.
- Monitor Copilot usage logs for unusual data access patterns or potential prompt injection attempts.
- Configure custom Copilot experiences to restrict data access to only necessary information for specific roles.
Domain: Agentic-AI · Impact: high · Workload: Other