M365 Co-pilot and security

M365 Co-pilot and security

M365 Co-pilot is appearing to be one of the coolest things after the invention of sliced bread. I don't know how it was eaten before and soon I will not know how to get past daily work without Co-pilot.

By Microsoft studies companies have realized ROI of over 300% from investments in M365 Co-pilot and I truly can believe to those numbers.

I have tried and sometimes succeeded to convince organizations and their users to take new tools like Teams, Sharepoint, Forms etc in to use. In my point of view the coolest thing in Ai tools is the pull from the users, they want these tools! Because of this enthusiasm and pressure many companies have taken M365 co-pilot in to use too fast and disappointed, because security issues or they have not introduced the tool to users properly. Change management effort is still needed even users are willing to take new tool into use.

Security issues are inherited from the surprisingly poor data security, which is caused mainly by couple M365 features like public sites and everyone in the organization links. If you create a everyone in the organization link to folder or file, everyone can access it with tools like co-pilot. Before you basically could find active document with help of Delve search and in traditional file server you needed to know exact file name to search or stumble across to location where you shouldn't have access to.

Luckily we have couple of fast tricks to limit Co-pilot searches:

  1. You can enable curated SharePoint Search and Curate Allowed Sites - This should be temporary measure, since you are limiting all searches, not just Co-pilot
  2. Adjust Site Settings - Site settings can be used to out scope certain sites from searches
  3. Use Sensitivity Labels - This is not and fast fix, but taken into use properly this will solve the data security issues with Co-pilot along with many other data risks in M365 environment. Refer to my earlier articles for more information

By following these steps, you can effectively manage and limit the content that Microsoft 365 Copilot can access and reference, ensuring better control over your organization’s data.


要查看或添加评论,请登录

Tomi Miettunen的更多文章

社区洞察

其他会员也浏览了