Dynamics 365 Business Central: Copilot and agents - Enable Microsoft Copilot chat experience
🚨 The Signal: Dynamics 365 Business Central Copilot chat interface is updated for consistency with other Microsoft Copilot experiences. This standardisation impacts how users interact with AI agents, potentially increasing adoption and the attack surface for prompt injection.
The Impact
All users interacting with Copilot in Business Central are affected, with a moderate security risk related to prompt injection and data exposure through AI interactions.
- End Users: Increased risk of prompt injection due to more intuitive AI interaction.
- Security Teams: Need to monitor AI usage and potential data exfiltration vectors.
- Admins: Review data access policies for AI agents to prevent unintended exposure.
The Action
- Review existing AI governance policies for Dynamics 365 Business Central.
- Educate users on secure prompt engineering and the risks of sensitive data input into AI chats.
- Verify data loss prevention (DLP) policies are applied to Copilot interactions within Business Central.
- Monitor audit logs for unusual AI agent activity or data access patterns.
Domain: Agentic-AI · Impact: medium · Workload: Other