Data access: the main problem with Copilot for Microsoft 365
Many of the potentially serious security issues with Copilot start with the type of access the genAI tool is given to corporate data and how that access can be misused by hackers or even people inside a company.
Ivan Fioravanti, co-founder and CTO of CoreView, which focuses on security and configuration management for Microsoft 365, notes in a blog post that when a company installs Copilot for Microsoft 365, it gets the same permissions model for data access that is already in place for Microsoft 365. That model, he says, is designed to ensure that “only authorized users can interact with sensitive information.”
However, there are security gaps that businesses could easily overlook. Fioravanti warns that Copilot settings could be enabled by default that could be risky. These settings can give Copilot “access to sensitive data without the proper protections in place. Default settings could allow Copilot to interact with external plugins and access web content, which presents new attack surfaces.”