Event details
Join us for an exclusive Ask Me Anything (AMA) session focused on Security and Data Governance for Copilot for Microsoft 365 on Wednesday, June 12th, from 9:00 AM to 10:00 AM PST. This session will focus on pivotal topics such as Data Loss Prevention (DLP), eDiscovery, audit logs, restricted search, information barriers and data residency
This is a unique opportunity to connect directly with our diverse team of product experts, servicing specialists, and engineers who specialize in security and data governance aspects of Copilot for Microsoft 365.
Event Details:
This chat-based session offers a direct line to the experts behind the secure and compliant operations of Copilot for Microsoft 365. Our team will be ready to discuss and answer your questions on:
- Data Loss Prevention (DLP): Learn how to protect sensitive information automatically.
- eDiscovery: Understand tools that help in identifying and delivering electronic information useful for evidence.
- Audit Logs: Get insights on tracking user activities and critical system changes.
- Preparing your data for Copilot: options for getting started even while staying in control
- Data Residency: Discuss the importance of storing data in specific locations.
- Communication Compliance: Discover how advanced machine learning helps detect and mitigate risks in communications, ensuring adherence to regulatory standards and organizational policies.
**Please note, we will not be covering privacy or other unrelated topics during this session.
How does it work?
During this live, chat-based event, our experts will be available to offer personalized advice and discuss the security and governance capabilities of Copilot for Microsoft 365. Whether you're interested in exploring its advanced security features, seeking strategies for maintaining compliance, or have particular questions about the service, our team is ready to assist you.
To participate, simply post your questions in the comments section. We encourage you to submit your questions early and continue to engage throughout the one-hour session. Remember, this is a chat-only event, so all interactions will take place in the Comments section without any video or live meeting components. Each question should be posted as a new comment to facilitate a smooth and organized discussion.
Don't miss this chance to interact directly with the minds behind Microsoft 365 Copilot and gain valuable insights to elevate your experience with this revolutionary tool. Mark your calendars and join us for an informative and engaging session!
| Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below. Please post each question as a new comment. | 
183 Comments
- JennSCopper ContributorAnother contributor mentioned "In an ideal world, zero trust is always best." Do you have any guides or resources for how to start with zero trust for cloud services, like SharePoint and gradually open it up for documents stored in a shared environment?- HenryTeaMicrosoft Great question Jennifer! In addition to the link that Rajesh kindly shared, please also check out https://learn.microsoft.com/en-us/security/zero-trust/copilots/zero-trust-microsoft-365-copilot.
 
 
- For sensitivity labels that include permissions that are set by the label/policy rather than by the end user - what's the best route for maintaining ownership/author rights internally, but only read rights externally to the specific guest? We want to share specific files with our accountant - we have owner rights, the single external accountant only has read rights. Is this a single label or multiple?- Samson_ChanFormer EmployeeThere are 2 ways to configure a label to ensure certain users have author and certain users can only view. The admin can define a label and assign permissions to user based on their email address. Alternatively, a label can be defined with user assign permissions. this label will allow the author to apply the label and set specific users with read permissions. See https://learn.microsoft.com/purview/encryption-sensitivity-labels#configure-encryption-settings for more information on encryption.- Does that mean within a single label, I can assign two separate sets of permissions?
 
 
- RichardSojkaBrass ContributorGiven Microsoft and Open AI have scored poorly on the Foundation Model Transparency Index https://crfm.stanford.edu/fmti/May-2024/index.html in the past, will Copilot be publishing transparency reports with voluntary codes of conduct from the White House and the G7. Specifically, how do we know what the data practices of security and governance within Copilot are being carried out with customer enterprise data given a current 40% reporting transparency and 20% risk transparency. Are such researchers' findings at Stanford and Princeton University of no credit?
- RichardSojkaBrass ContributorEmergent abilities in LLM are being debated, with Microsoft publishing a controversial paper on the subject: https://arxiv.org/pdf/2303.12712 and their own researchers making statements at talks such as https://www.microsoft.com/en-us/research/video/physics-of-ai/. What security and governance steps do Microsoft Co-pilot have in place should emergence be real, is our only option to switch off co-pilot? - RichardSojkaBrass ContributorWhen Sébastien Bubeck states from Microsoft Research in the Physics of AI that Intelligence Emergence of LLM at a critical input level of data generates answers not intended and "The Truth is that nobody has a clue what's going on", what are the business risks for those in the governance of Copilot?
 
- RichardSojkaBrass ContributorThe world is seeing different strategy on AI standards being evolved in the EU and USA, with common aspects such as ISO/IEC 25059 and ISO/IEC TR 24028 and ISO 25000 being published. What strategy is Microsoft following? How will they be evolving their systems regionally with all these conversations and initiatives? For example, see: - The National AI Strategy of the UK - GOV.UK (http://www.gov.uk) - AI Safety Summit 2023: The Bletchley Declaration https://www.gov.uk/government/publications/ai-safety-summit-2023-the-bletchley-declaration - Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (USA) https://www.whitehouse.gov/briefing-room/presidential-actions/2023/10/30/executive-order-on-the-safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence/- tannerbriggsMicrosoft Hi Richard, Microsoft works with regulators in Microsoft services regions to understand local laws and regulations. Per the Data Protection Addendum, Microsoft will comply with local laws. Microsoft takes a holistic approach to compliance with regulations, frameworks, and standards, and is currently examining which certifications are pertinent to adopt given the evolving AI space. ISO 42001 is under consideration and we're actively seeking customer feedback to substantiate the adoption of the most important regulations affecting our customers. https://aka.ms/dpa.
 
- RichardSojkaBrass ContributorMicrosoft states "It’s important that you’re using the permission models available in Microsoft 365 services, such as SharePoint, to help ensure the right users or groups have the right access to the right content within your organization.” In an ideal world, zero trust is always best, do you really think M365’s permission models in most business is securely locked down well enough to let Copilot run free?
- RichardSojkaBrass ContributorDoes Copilot results inherit the security labels from the source files? If not isn't that a serious risk for source files containing sensitive data? What happens if you are not an E3 or E5 license holder, will it be up to an employee to double-check the AI’s work and ensure data is classified and assessed for risk properly?- HenryTeaMicrosoft Hi Richard, thank you for the question. All details around sensitivity label inheritance are described here, https://learn.microsoft.com/en-us/purview/ai-microsoft-purview#copilot-protection-with-sensitivity-label-inheritance. It is applicable to the following licenses as listed here: Microsoft 365 guidance for security & compliance - Service Descriptions | Microsoft Learn. 
 
- Martin_KrasBrass ContributorHow helps has Data Loss Prevention to protect data in relation to Copilot for M365. Can you create DLP policies so Copilot cannot access / use content under control of DLP?- Samson_ChanFormer EmployeeDLP policies can govern the Copilot results, by monitoring egress activities such as pasting the result to emails or browsers to other Gen AI tools and prevent sensitive content from being leaked. Feel free to provide your feedback or product requests to your Microsoft representative.- Martin_KrasBrass ContributorHi Samson. You mean Endpoint data loss prevention (Endpoint DLP) to prevent pasting sensitive information into a prompt? I do understand that. That is also a part of Purview AI Hub. I'm on DLP in SharePoint and Exchange. Has DLP a relation with Copilot on that side?
 
 
- Martin_KrasBrass ContributorRegarding "Preparing your data for Copilot: options for getting started even while staying in control". Can you explain if using content types and metadata for SharePoint content will help Copilot for Microsoft 365 for better understand what relevant content is, based on a prompt. So, in other words will for example using SharePoint Premium Content recognition and extracting information from a document in metadata columns help in getting better answers from Copilot. Or doesn't Copilot for M365 do anything with that metadata. and content type information.
- Martin_KrasBrass ContributorRegarding "Preparing your data for Copilot: options for getting started even while staying in control", beside Restricted SharePoint Search and disable search on a site or library, will it be possible in the future to exclude (blacklist) of include (whitelist) Copilot for M365 using certain data locations, without disabling search. So, like how you can include or exclude SharePoint sites for using information by Viva Topics.- tannerbriggsMicrosoft Hi Martin, We're working on a roadmap item that will allow you to set a parameter on a SharePoint site that will exclude the documents in that site from Copilot. Stay tuned on the Microsoft roadmap site for additional detail (we can't release more information about this at this time): https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=Microsoft%20Copilot%20(Microsoft%20365). - Martin_KrasBrass ContributorHi Tanner. Thanks for your answer. Will it be possible to set that parameter based on a Microsoft Purview Site & Group Label. If that is not what's on your mind, maybe you can add this setting to the Site & Group labels.