Dynamics 365 Business Central: Copilot and agents - Manage agent permissions easier
🚨 The Signal: Dynamics 365 Business Central Copilot agents can now request additional permissions, which administrators can grant. This introduces a new vector for privilege escalation and requires careful permission management for AI agents.
The Impact
Administrators are affected by new AI agent permission management, increasing the risk of over-privileged agents if not carefully controlled.
- Security Teams: Risk of over-privileged AI agents if permissions are not tightly controlled.
- Administrators: New responsibilities for reviewing and approving AI agent permission requests.
- Compliance Teams: Need to update policies for AI agent access control and auditing.
- Business Owners: Potential for data exposure if agents gain unintended access.
The Action
- Review existing Dynamics 365 Business Central agent permissions for least privilege.
- Establish a formal approval process for all new agent permission requests.
- Implement regular audits of AI agent permissions and activities.
- Educate administrators on the risks associated with over-privileged AI agents.
Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898