Dynamics 365 Customer Service: Service tools, skills and plugins are now available for Code

🚨 The Signal: Dynamics 365 Customer Service tools are now integrated into 'Code,' allowing agents to access service context and actions without switching applications. This streamlines workflows but expands the attack surface for Dynamics 365 data.

The Impact

Customer service agents are affected, with a potential increase in data exposure risk if 'Code' integration is not properly secured.

  • Customer Service Agents: Increased risk of data overexposure if permissions are not meticulously managed.
  • Security Teams: New integration points require validation of existing security controls and data loss prevention policies.
  • Compliance Officers: Need to verify that data handling within 'Code' adheres to regulatory requirements and internal policies.

The Action

  1. Review and validate all user permissions for Dynamics 365 Customer Service within the 'Code' environment to ensure least privilege.
  2. Verify that existing Data Loss Prevention (DLP) policies extend to and are effective within the 'Code' integration.
  3. Conduct a security assessment of the 'Code' integration to identify and mitigate potential vulnerabilities or data exposure risks.
  4. Update security documentation to reflect the new integration and any associated security controls or configurations.

Domain: Other · Impact: medium · Workload: Other