<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-fasttrack/ct-p/FastTrack</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Thu, 30 Jul 2026 01:05:23 GMT</pubDate>
    <dc:creator>FastTrack</dc:creator>
    <dc:date>2026-07-30T01:05:23Z</dc:date>
    <item>
      <title>Why identity is the Copilot unlock</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/why-identity-is-the-copilot-unlock/ba-p/4537445</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="Member: Charles_Wallace | Microsoft Community Hub" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0yMDE4MTgteTNoRWFa?image-coordinates=0%2C0%2C1500%2C1500&amp;amp;image-dimensions=120x120" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;Charles_Wallace&lt;/SPAN&gt;&amp;nbsp;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;
&lt;P&gt;&lt;EM&gt;This is Part 2 of a three-part series. &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/who-actually-blocks-ai-in-healthcare-and-why/4535044" target="_blank" rel="noopener" data-lia-auto-title="Part 1" data-lia-auto-title-active="0"&gt;Part 1&lt;/A&gt; mapped the people who decide whether your AI program ships. This one is for the Microsoft 365 admins and CIOs whose Copilot is paid for but not “on.” Part 3 will cover agent governance.&lt;/EM&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;
&lt;P&gt;&lt;STRONG&gt;“We bought Copilot. Why can’t we turn it on?”&lt;/STRONG&gt;&lt;BR /&gt;Maybe you’ve said this yourself. You have the licenses. You’re ready to assign them. Months later, Copilot still isn’t in front of a single clinician. The budget cleared. Leadership is asking for the productivity story they were promised, but the deployment is stuck.&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The answer is not a license problem or a Copilot problem, but an identity problem. The identity foundation underneath isn’t ready. In healthcare, that foundation is harder to move than anywhere else I’ve worked. Get it right and two things turn on: a Copilot the clinician trusts at the bedside and the control plane for every agent that comes after.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;Why identity is the gate, not a checkbox&lt;/H3&gt;
&lt;/DIV&gt;
&lt;P&gt;Microsoft 365 Copilot authenticates users through &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/" target="_blank" rel="noopener"&gt;Microsoft Entra ID&lt;/A&gt;. Every Copilot interaction honors the permissions of the signed-in user through &lt;A class="lia-external-url" href="https://learn.microsoft.com/graph/overview" target="_blank" rel="noopener"&gt;Microsoft Graph&lt;/A&gt;, so the question “What can this person see?” is answered by your identity layer, not by Copilot. One of the great things about Copilot is it has access to everything you have access to —&lt;STRONG&gt; &lt;/STRONG&gt;this is also one of the concerning things about Copilot.&lt;/P&gt;
&lt;P&gt;Two different controls play a role here. Identity decides who is at the door and how far you trust the sign-in. Data governance decides what they can reach once inside. Copilot leans on both, and Entra is the first of the two. It is the one that decides whether you can safely turn Copilot on at all. That is why a responsible admin won’t flip Copilot on until the identity foundation holds. They need multifactor authentication everywhere, Conditional Access that actually evaluates risk, and a least-privilege model they trust. All three live in Entra.&lt;/P&gt;
&lt;P&gt;Plenty of the health systems I work with authenticate through 3rd-party identity providers. Microsoft 365 still sits on Entra underneath, the directory it’s built on, but the front door is brokered elsewhere. When the primary authentication layer is 3rd-party, Entra still authorizes Microsoft 365 access.&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;What changes is &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;the signal&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Entra gets to see:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:260,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;
&lt;P&gt;&lt;STRONG&gt;MFA&lt;/STRONG&gt; may be satisfied by a federated claim from elsewhere rather than evaluated by Entra.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:260,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;
&lt;P&gt;&lt;STRONG&gt;Sign-in risk telemetry &lt;/STRONG&gt;gets thinner on the Entra side, because Entra never sees the credential go in. The 3rd-party identity provider is evaluating risk at its own front door, but those signals do not become Entra risk that Conditional Access and Entra ID Protection can act on. Some detections still fire offline. Atypical travel is one example, though the IP Entra logs can be a 3rd-party egress rather than the clinician’s. Leaked-credential detection still works, but it is the one Entra ID Protection signal that depends on password hash sync.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:260,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;
&lt;P&gt;&lt;STRONG&gt;Device-compliance signals&lt;/STRONG&gt; reach Conditional Access only if your devices are registered in Entra. Federated, non-Entra-joined devices also never get an Entra device-bound Primary Refresh Token, so token protection stays dark.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&lt;SPAN data-contrast="auto"&gt;Risk-based Conditional Access and Entra ID Protection then miss the full picture. You are running the front door of your AI program on one system and governing Copilot’s data access on another. That gap is the gate.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;Two ways to close the gap, on two different timetables&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;The “fast” option&lt;/STRONG&gt; keeps the 3rd-party identity provider but moves the Microsoft 365 sign-in to Entra. You defederate the Microsoft 365 domain to managed authentication and register the 3rd party as an external authentication method for MFA. Entra now runs primary sign-in and Conditional Access, so it evaluates device state and risk directly, while the 3rd party still handles the MFA challenge and remains the portal your users know for everything else. You are not ripping out other MFA providers. You are moving one domain’s sign-in to Entra so the signals reach it.&lt;/P&gt;
&lt;P&gt;This is the correct path when leadership wants the Copilot productivity story &lt;EM&gt;this quarter&lt;/EM&gt; and a full identity migration is a multi-year mountain you cannot climb first. External authentication methods are generally available as the supported successor to Custom Controls (requiring Entra ID P1). Custom Controls is on a deprecation path, with new configuration blocked and full retirement staged across 2026 into 2027, so confirm the current dates in Microsoft’s documentation before you plan around them.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The “strategic” option&lt;/STRONG&gt; consolidates identity on Entra outright. It is the harder path but the one that closes the gap completely. Full consolidation is also what lights up device-bound token protection everywhere, because federated, non-Entra-joined devices never get an Entra Primary Refresh Token. Consolidate when 3rd-party identity providers are mostly doing single sign-on. Keep them as the identity provider for other apps when they are load-bearing across the estate and pulling them out buys you a second migration you don't need.&lt;/P&gt;
&lt;P&gt;Either way, the signals must reach Entra before Copilot goes on. If you take the fast path, that managed cutover still runs through the readiness gate and the downtime discipline below. You just skip the full-consolidation mechanics. And if any Microsoft 365 sign-in stays truly federated to a 3rd party, treat it as interim: the thinner Entra telemetry and the absent token protection above stay in force until you close them, so pair it with compensating controls.&lt;/P&gt;
&lt;H3&gt;Healthcare’s identity constraints are not like other industries&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In a normal enterprise, an identity migration is a weekend of change windows and a week of help-desk tickets. In a hospital, the same project touches patient safety. Four constraints make it different:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Electronic health record (EHR) single sign-on dependencies. &lt;/STRONG&gt;The EHR is the center of gravity. It integrates with your identity provider, often through a tap-and-go layer, so a clinician can badge into a shared workstation in a second or two. Change the identity provider and you may change badge tap, workstation sign-in, EHR launch, e-prescribing, medication administration, and chart access. You cannot do that blindly.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Round-the-clock, 24/7 care-continuity.&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;There is no maintenance window. The health system runs every hour of every day. An identity change that would be a minor outage at a bank is, in an emergency department, a clinician who cannot open a chart during a trauma intake. The tolerance for downtime is not low. It is &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;zero &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;for anything on the critical path.&lt;/SPAN&gt; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Clinician friction tolerance.&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Clinicians will accept a badge tap and a biometric. They will not accept a multi-step login at the bedside. Add ten seconds to a workflow they run eighty times a shift and they will route around it. Now your security control is theater. This is where the stakeholders from &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/who-actually-blocks-ai-in-healthcare-and-why/4535044" target="_blank" rel="noopener" data-lia-auto-title="Part 1" data-lia-auto-title-active="0"&gt;Part 1&lt;/A&gt; hold their veto as the clinical leaders who own care-continuity risk.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;The regulatory audit trail.&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;HIPAA expects access controls and a record of who reached protected health records and when. Whatever you build has to keep that trail intact through the migration, not reconstruct it afterward.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;SPAN data-contrast="auto"&gt;None of these are reasons to stay on a fragmented identity model. They are the reasons to migrate carefully rather than quickly.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;The Electronic Health Record (EHR) coordination problem&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Of the four constraints, EHR integration is the one most likely to stall your migration. The single most common mistake I see is treating it as a pure IT project and looping in the EHR vendor late. The EHR is not a bystander here. It authenticates against your identity provider. The vendor has a say in how that integration changes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;I watched one system set a hard cutover date before it talked to its EHR vendor. Three weeks out, it learned the tap-and-go integration had to be re-certified against the new identity provider. The date slipped by a month, and the fix was not technical. It was a conversation that should have happened at the start.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Coordination effort varies by platform. Use this table to start the vendor conversation. Do not use it to set a cutover date.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 99.0093%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 18.1171%" /&gt;&lt;col style="width: 31.8675%" /&gt;&lt;col style="width: 15.7015%" /&gt;&lt;col style="width: 34.2831%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;EHR platform&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Entra integration path&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Coordination load&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Watch for&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Epic&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Federation to Entra supported; SAML / OIDC, SMART on FHIR for app-to-EHR authorization&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Moderate&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Hyperdrive SSO behavior; SMART on FHIR app registrations; Imprivata or tap-and-go path; test real clinical workstation flows in non-prod&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Oracle Health (Cerner)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;SSO via SAML; tap-and-go middleware (Imprivata) common&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Moderate to high&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Middleware re-point is its own workstream; validate proximity-badge flows&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Meditech&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Vendor-assisted SSO; middleware common&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Higher&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Plan added lead time for vendor coordination; confirm supported Entra patterns early&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;SPAN data-contrast="auto"&gt;The pattern across all three: the identity team cannot set the cutover date alone. The EHR vendor and the tap-and-go middleware owner are on the critical path with you. Bring them in while the plan is still a draft, not when you have a date to defend.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The readiness gate: &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;don’t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; start until these are true&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:260,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:260,&amp;quot;335559739&amp;quot;:120}"&gt;&lt;SPAN data-contrast="auto"&gt;If the left column is true, do not put Copilot in front of clinicians until the right column is done. Hand this to your identity and access lead and ask for your system’s version. It turns “Are we ready?” into a list someone owns.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100.031%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 41.628%" /&gt;&lt;col style="width: 58.3411%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;If this is true&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Do not enable Copilot for clinical users until&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;3rd-party identity provider enforces MFA but Entra risk policies are not active&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You have an Entra-led Conditional Access plan or a documented compensating control&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;EHR SSO depends on tap-and-go middleware&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The EHR vendor and the middleware owner have tested the flow in non-prod&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Shared clinical workstations are in scope&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Badge tap, biometric, EHR launch, and chart access are validated by role&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Rollback needs daytime engineering support&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The wave is not approved&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Overshared or unlabeled sensitive sites remain&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Copilot pilot scope is constrained to clean data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The phased migration playbook&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You do not migrate a hospital’s identity in one cutover. You move in stages, prove each one, and keep a way back at every step. Once those readiness gates are owned, the work becomes a migration sequence. &lt;/SPAN&gt;The first five steps are identity work. The sixth is where identity readiness becomes Copilot readiness. &lt;SPAN data-contrast="auto"&gt;These steps hold up across most migrations to Entra I have seen:&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Pilot a low-risk department.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Pick a non-clinical or low-acuity group first — finance or a back-office function, not the ED. Prove the end-to-end flow where a failure is an inconvenience, not a safety event.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:100}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:300,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Coordinate with the EHR vendor before you touch clinical users&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;.&lt;/STRONG&gt; Validate the EHR SSO and the tap-and-go path in a test environment with the vendor in the room. This is the step teams skip and regret.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:300,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;Cut over in waves, by care setting.&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt; Move ambulatory before inpatient and scheduled before emergent, though infusion and urgent care are ambulatory in name only. Sequence by real acuity, not by building. In practice, the first clinical wave is a low-acuity outpatient clinic of twenty or thirty providers, then med-surg, then the ED and ICU last. Each wave is small enough to roll back inside one shift.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:300,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;Validate against the real workflow, not a checklist.&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt; Confirm badge tap, biometric, EHR launch, and chart access for an actual clinician on an actual workstation. A green status page is not validation. A nurse opening a chart is.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:300,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Enforce Conditional Access in report-only first.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; With identity consolidated on Entra, model MFA, device compliance, session controls, and risk-based access before you block anyone. Then enforce by wave once clinical workflows pass. This is the moment the security posture improves.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="4" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:300,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Turn on the Purview controls Copilot will lean on.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Start with sensitivity labels, audit, and an oversharing review, then add Data Loss Prevention. The Microsoft 365 Copilot location in Purview DLP is generally available for sensitivity-label-based blocking. Newer controls, like SIT-based prompt blocking, web-search restrictions, and DLP for Copilot Studio agents, are still rolling out or in preview depending on your tenant, so confirm what you have before the rollout depends on them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Downtime is a patient-safety issue, not an IT metric&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:260,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The framing that changes how this project gets run: in a hospital, identity downtime is a clinical event. Treat it that way and the rest of the plan falls into place. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;A useful test for every mitigation is what I call the 2 a.m. trauma intake. Not “does this pass in a maintenance window,” but “does this hold when a trauma comes through the door at two in the morning and a clinician has to open a chart right now.” If your rollback story only works during business hours with the full team online, it is not a rollback story. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Run the project on the safest assumption: something will go wrong at the worst possible time. Plan for that time. &lt;SPAN data-contrast="auto"&gt;A cutover safety check before any wave goes live:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Failover path tested, not assumed.&lt;/STRONG&gt; Know exactly what happens to authentication if the new path fails. Prove it in test.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:260,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Rollback measured in minutes, not hours.&lt;/STRONG&gt; If you cannot reverse a wave in about fifteen minutes, it is not ready to cut over during a shift when someone is mid-chart. Every wave needs a named owner who can make the call.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:260,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;STRONG&gt;Downtime procedures clinicians already know.&lt;/STRONG&gt; The EHR’s read-only or downtime mode is part of the plan. The floor has practiced it.&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:260,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;STRONG&gt;Validated at the worst hour, not the easy one. &lt;/STRONG&gt;Sign-off includes an off-hours, high-acuity test, because that is when it will actually matter.&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="•" data-font="" data-listid="3" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:540,&amp;quot;335559991&amp;quot;:260,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;•&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;STRONG&gt;Help desk and clinical informatics briefed per wave.&lt;/STRONG&gt; The people who answer the 2 a.m. call know a migration wave is live and what to do.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;H3&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What identity unlocks (and the bridge to agents)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:260,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Here is what turns on: a clinician badges in once and Copilot is right there, scoped to exactly what that person is cleared to see, safe to use in front of a patient. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;That is the payoff.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; The control plane underneath is what makes it safe to leave on.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With Entra as the foundation, the liability ownership and the access controls the CISO need are finally yours to run. Identity secures the perimeter. Most of what &lt;/SPAN&gt;follows is the data-governance work it is now safe to start. Here is what to enable after the migration and where each control lives.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 98.5449%; height: 400px; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 25.0162%" /&gt;&lt;col style="width: 25.0162%" /&gt;&lt;col style="width: 16.7093%" /&gt;&lt;col style="width: 33.2276%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr style="height: 66.6667px;"&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Post-migration control&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What it unlocks for Copilot and agents&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Where it lives&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Healthcare watch-out&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 66.6667px;"&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access, Copilot-scoped&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time access decisions on user risk, device health, and location&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Entra&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Start report-only; enforce by care-setting wave&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 66.6667px;"&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Sensitivity labels&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Label-aware responses; protected content stays protected&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Label ePHI and research data before broad enablement&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 66.6667px;"&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Oversharing review&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Stops Copilot surfacing overshared sites and files&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Purview / SharePoint&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Run clinical and research SharePoint first&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 66.6667px;"&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Audit&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Full trail of Copilot activity for Legal and the CISO&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Keep the HIPAA ePHI access trail intact through cutover&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 66.6667px;"&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;DLP for Microsoft 365 Copilot&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Restricts sensitive content from Copilot grounding and prompts&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 66.6667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Confirm which controls are GA in your tenant&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every agent you build acts as an identity or on behalf of it. You cannot govern what an agent can reach if you cannot govern who the agent is. After this migration, you can.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity is the gate. It is also the most underestimated project in a healthcare AI program, because it looks like plumbing and behaves like patient safety. Get the identity foundation right and Copilot can turn on without the security story degrading. Data hygiene, oversharing, and clinical adoption still matter, but the gate is open. You are ready for the harder question: not whether you can deploy an agent, but which agents should exist, whose identity they run under, what they can reach, and who can shut them off.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:160}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Part 3, “Agent Governance Is Organizational Readiness,” closes the series. Governance is not the brake on agents. It is what allows you to say yes to them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Product names, availability, and timelines reflect Microsoft guidance at the time of writing and can change. Verify current state against official Microsoft documentation for your tenant.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Charles Wallace is a Senior FastTrack Architect at Microsoft. He works on Microsoft 365 Copilot and agent adoption across healthcare and life sciences. His focus is the security, identity, and governance foundations that decide whether AI deployments actually succeed.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 23 Jul 2026 19:58:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/why-identity-is-the-copilot-unlock/ba-p/4537445</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-23T19:58:11Z</dc:date>
    </item>
    <item>
      <title>Who actually blocks AI in healthcare (and why)</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/who-actually-blocks-ai-in-healthcare-and-why/ba-p/4535044</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="Member: Charles_Wallace | Microsoft Community Hub" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0yMDE4MTgteTNoRWFa?image-coordinates=0%2C0%2C1500%2C1500&amp;amp;image-dimensions=120x120" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;Charles_Wallace&lt;/SPAN&gt; &lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;This is Part 1 of a three-part series on the organizational readiness work between a Copilot proof-of-concept and AI at scale. Part 2 covers why identity is the technical gate that decides whether Copilot turns on. Part 3 finishes with agent governance as organizational readiness.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Who this is for:&lt;/STRONG&gt; IT leaders, M365 admins, and project sponsors who keep losing AI pilots in committee.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;I've&amp;nbsp;watched a lot of Microsoft 365 Copilot pilots succeed technically and die anyway.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The deployment worked. Licenses were assigned, Conditional Access held, the&amp;nbsp;data&amp;nbsp;didn't&amp;nbsp;leak. Early users loved it. The ambient documentation pilot was&amp;nbsp;reportedly saving&amp;nbsp;clinicians the better part of twenty minutes a visit. Then it sat in a steering-committee queue for two&amp;nbsp;quarters&amp;nbsp;and the funding lapsed.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;That pilot&amp;nbsp;didn't&amp;nbsp;fail on technology. It failed on &lt;STRONG&gt;people&lt;/STRONG&gt;. In healthcare,&amp;nbsp;that's&amp;nbsp;the failure mode nobody puts on the project plan.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you've deployed AI in other industries, you know change management is hard everywhere. Healthcare is a different kind of hard. Not because the people are more resistant—it's that the structure of who can stop you looks nothing like other industries. This post maps the people who decide whether your AI program ships, what they actually worry about versus what they say, and the order to engage them in.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why healthcare's stakeholder map is different&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In most enterprises, an executive sponsor with&amp;nbsp;budget&amp;nbsp;can clear the path. A VP says:&amp;nbsp;"We're&amp;nbsp;doing this,"&amp;nbsp;and the organization moves.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Healthcare&amp;nbsp;doesn't&amp;nbsp;work that&amp;nbsp;way&amp;nbsp;and the reasons are structural. Physicians&amp;nbsp;aren't&amp;nbsp;employees in the ordinary sense. In teaching&amp;nbsp;hospitals,&amp;nbsp;they're&amp;nbsp;often represented by a residents' association or a faculty practice plan. In community systems, admitting privileges&amp;nbsp;give&amp;nbsp;independent physicians real leverage. They can decline to change a&amp;nbsp;workflow&amp;nbsp;and clinical leadership will usually back them.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;On top of that professional autonomy, several European countries, most notably Germany, give works councils legally protected co-determination over technical systems that can monitor staff behavior or performance. How broadly that gets read varies by jurisdiction. Anything that touches care delivery draws scrutiny from patient and family advisory councils and ethics &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;committees. Under all of it runs one constant question: &lt;EM&gt;if this goes wrong, who gets sued?&lt;/EM&gt; Malpractice liability colors every workflow change,&amp;nbsp;whether&amp;nbsp;anyone says so&amp;nbsp;out loud&amp;nbsp;or not.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;None of this shows up in a generic readiness checklist. All of it can stop an AI deployment cold.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The blockers nobody puts on the project plan&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Physicians and clinical staff&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;control whether AI ever touches clinical workflow. The stated concern is usually speed or accuracy:&amp;nbsp;"This will slow me down;&amp;nbsp;the model isn't good enough."&amp;nbsp;The real concern is autonomy and trust in a tool they&amp;nbsp;didn't&amp;nbsp;choose. Union strength sharpens this in teaching hospitals.&amp;nbsp;Independent-physician&amp;nbsp;leverage does the same in community systems.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Works councils&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, especially in European systems, hold co-determination rights. The stated concern is data protection. The real one is&amp;nbsp;surveillance&amp;nbsp;of their members. The behavioral signals a security team can switch on, things like Insider Risk analytics and detailed usage tracking, read as monitoring and can trigger a formal consultation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Patient advocacy groups and ethics committees&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;speak for the people receiving care. The stated concern is privacy. The real one is consent and algorithmic harm: was the consent genuinely informed and voluntary? Do patients understand what algorithmic help means for their care? That gets sharper with anything patient-facing.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Legal and Compliance&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;gets misread more than any other group. The stated concern is&amp;nbsp;almost always&amp;nbsp;HIPAA. The real one is liability and organizational risk aversion. HIPAA usually permits what&amp;nbsp;you're&amp;nbsp;trying to do if you design for minimum-necessary use and get the vendor agreements right. The regulation is rarely the real blocker. Liability and vendor risk are. The vendor terms that matter are the ones on sub-processing, restrictions on model retraining with PHI, and data deletion. You answer that with a named governance owner and an audit trail, not by&amp;nbsp;arguing with&amp;nbsp;the statute.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;The CISO and security team&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;own breach&amp;nbsp;liability&amp;nbsp;and they hold a veto most IT leaders forget to plan for. The stated concern is data loss and audit coverage. The real one is that the&amp;nbsp;needs of&amp;nbsp;logging and&amp;nbsp;monitoring&amp;nbsp;an AI rollout can collide with the access model they already run.&amp;nbsp;They're&amp;nbsp;the ones accountable if it goes wrong. On a security-led program, this is your closest ally or your hardest gate, depending on whether you bring them&amp;nbsp;in to&amp;nbsp;co-design the controls or hand them a finished plan to approve.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;The CMO, CNIO, and CMIO&lt;/STRONG&gt; hold a veto that surprises most IT leaders. Clinical leadership can stop an IT-led initiative if they believe care continuity is at risk. A CIO can fund and deploy a program that either the Chief Medical Officer or the Chief Nursing Information Officer, depending on clinical scope, can still kill. The Chief Medical Information Officer sits between IT and clinical leadership. In practice, they often decide whether that co-sponsorship materializes at all, so engage the CMIO before you assume you have the others. If clinical leadership&amp;nbsp;isn't&amp;nbsp;a co-sponsor, you&amp;nbsp;don't&amp;nbsp;have a sponsor.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Stated concern vs. actual concern&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The most useful habit you can build is separating what a stakeholder says from what they mean and then &lt;STRONG&gt;answering the real objection&lt;/STRONG&gt;.&amp;nbsp;The stated concern is the door you knock on.&amp;nbsp;The actual concern is the room you have to walk into.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;"HIPAA won't allow it" almost never means the regulation forbids it. It means&amp;nbsp;"I don't want to&amp;nbsp;own&amp;nbsp;the risk of this change."&amp;nbsp;Argue the regulation and you lose. Offer a governance owner and an audit&amp;nbsp;trail,&amp;nbsp;and&amp;nbsp;you're&amp;nbsp;past&amp;nbsp;it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When a physician says the model&amp;nbsp;isn't&amp;nbsp;accurate&amp;nbsp;enough,&amp;nbsp;they've&amp;nbsp;usually not benchmarked anything. They mean&amp;nbsp;"I didn't pick&amp;nbsp;this&amp;nbsp;and I don't trust being second-guessed by software."&amp;nbsp;The fix&amp;nbsp;isn't&amp;nbsp;a better accuracy number.&amp;nbsp;It's&amp;nbsp;bringing them into scope and giving them a way out if it&amp;nbsp;isn't&amp;nbsp;working.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When a works council raises data-protection concerns, the subtext is often that their members feel watched. The fix is being precise about what is and&amp;nbsp;isn't&amp;nbsp;logged and involving them before you deploy instead of after.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When a CMO or CNIO raises care-continuity risk,&amp;nbsp;they're&amp;nbsp;often right, but underneath it sits a simpler ask:&amp;nbsp;"I want a vote on this, not a notice."&amp;nbsp;Co-sponsorship, where they review the real architecture and workflow decisions and not just the rollout message, is&amp;nbsp;the key.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;A stakeholder map for healthcare AI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before you write a deployment plan, map the people. For each group, you want four things: their veto power, their stated concern, their actual concern, and your first move. Run this in a sixty-minute working session with your project lead before the kickoff deck exists. Rank by veto power. Anyone in the high rows who isn't engaged yet is a risk on your plan, not a footnote. The actual-concern column tells you what to bring to the first conversation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 94.1796%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Stakeholder&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Veto power&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Stated concern&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Actual concern&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;First move&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Physicians / clinical staff&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;High&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Accuracy, speed&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Autonomy, trust&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Co-scoping; a clinical champion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;CISO / security&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;High&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Data loss, audit coverage&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Breach liability, access-model conflict&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Security co-leads governance; threat-model workshop&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Works council&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;High (EU)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Data protection&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Surveillance of staff&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Early consultation; &lt;BR /&gt;logging transparency&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Patient advocacy / ethics&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Med-High&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Privacy&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Consent, algorithmic harm&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Consent design first&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Legal &amp;amp; Compliance&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;High&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;"HIPAA"&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Liability ownership&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Named governance owner;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;audit trail&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;CMO / CNIO&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;High (veto)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Care continuity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;A real vote and credit&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Co-sponsorship, not sign-off&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;CMIO&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Med-High&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Workflow integration&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Will IT respect clinical workflow&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Scope the workflow with &lt;BR /&gt;them early&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:252}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 20.00%" /&gt;&lt;col style="width: 20.00%" /&gt;&lt;col style="width: 20.00%" /&gt;&lt;col style="width: 20.00%" /&gt;&lt;col style="width: 20.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3&gt;Three example projects&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;A teaching hospital.&lt;/STRONG&gt; A large academic medical center piloted ambient clinical documentation and the clinicians loved it. The residents' association still invoked a workflow-change review because the rollout hadn't been brought to them first. The pilot froze for six weeks and only restarted once the primary stakeholder came on as co-sponsor and the residents had a say in scope. Clinical co-sponsorship wasn't a formality. It meant the stakeholder reviewed the workflow design, not just the rollout message. That was what moved it.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;A works council.&lt;/STRONG&gt; A health system planned to turn on usage analytics and Insider Risk signals alongside Copilot. The works council read the activity logging as surveillance and opened a formal co-determination consultation that took several months. In those jurisdictions, organizations engage the works council before enabling anything that logs clinician behavior, and they are specific about what is and isn’t captured.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;A community hospital.&lt;/STRONG&gt; They wanted a patient-facing scheduling agent. The patient and family advisory council required a consent-and-disclosure design, so patients knew they were talking to an agent and agreed to it before going live. For anything patient-facing, consent design is a gate, not a finishing touch.&lt;/P&gt;
&lt;P&gt;Three systems, three different blockers, one pattern: the technology was never the problem.&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Who to talk to first&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mapping the stakeholders is half the job. Sequencing the conversations is the other half. The order that holds up across most healthcare deployments looks like this:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Clinical leadership first.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Without a clinical co-sponsor, nothing else matters. Get the CMO or CNIO on board and the CMIO in to scope the workflow before you build a deck.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Security and the CISO early, as co-designers.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Bring them the logging and access model while&amp;nbsp;it's&amp;nbsp;still a&amp;nbsp;draft&amp;nbsp;so the controls get built in instead of bolted on.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Legal and Compliance early, for partnership rather than permission.&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;Bring them a governance owner and an audit-trail plan and ask them to help&amp;nbsp;you&amp;nbsp;de-risk, not to bless&amp;nbsp;without oversight.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Frontline champions.&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;Find the physicians and nurses&amp;nbsp;who'll&amp;nbsp;co-scope and advocate and give them real influence over what gets piloted.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Works councils, where they exist, before any logging goes live.&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;Treat the consultation as a prerequisite, not a reaction.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Patient advocacy and ethics for anything patient-facing.&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;Consent and disclosure design before go-live, every time.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:100,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Put these conversations on the calendar before the technical project plan, not after. You&amp;nbsp;won't&amp;nbsp;finish all of them before the kickoff deck, but if any of these people first hear about your plan in a steering-committee meeting,&amp;nbsp;you've&amp;nbsp;already lost ground. If you&amp;nbsp;can't&amp;nbsp;name the person on the other side of each one, your pilot is already at risk, however&amp;nbsp;clean&amp;nbsp;the deployment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;You&amp;nbsp;can't&amp;nbsp;engineer your way around a broken stakeholder map.&lt;/STRONG&gt; The readiness work nobody talks about starts here. Not with licenses or Conditional Access, but with an honest map of who can stop you and why. Get the people right, address their concerns,&amp;nbsp;and the technical deployment turns into the easy part.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Part 2, "Why Identity Is the Copilot Unlock," takes on the first hard technical gate: why so many health systems have bought Copilot and still can't turn it on,&amp;nbsp;and how to work through the Okta-to-Entra migration without breaking 24/7 care.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Charles Wallace is a Senior FastTrack Architect at Microsoft. He works on Microsoft 365 Copilot and&amp;nbsp;agent&amp;nbsp;adoption across healthcare and life sciences and on the security, identity, and governance foundations that decide whether AI deployments actually succeed.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 17:31:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/who-actually-blocks-ai-in-healthcare-and-why/ba-p/4535044</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-28T17:31:17Z</dc:date>
    </item>
    <item>
      <title>Limiting Microsoft 365 Copilot data exposure risk with Zero Trust apps and data controls</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/limiting-microsoft-365-copilot-data-exposure-risk-with-zero/ba-p/4534642</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="
https://techcommunity.microsoft.com/users/atilgurcan/129311" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0xMjkzMTEtMjAxMjgyaTRDRDk1ODBCNDJDQzQ3MjM?image-dimensions=120x120" alt="AtilGurcan" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;AtilGurcan&lt;/SPAN&gt; &lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In&amp;nbsp;previous&amp;nbsp;posts of this series, we mapped &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title=" where exposure can exist " data-lia-auto-title-active="0"&gt;where exposure can exist &lt;/A&gt;when organizations deploy Microsoft 365 Copilot and&amp;nbsp;categorized&amp;nbsp;those&amp;nbsp;risks into two distinct layers. &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title="Layer 1" data-lia-auto-title-active="0"&gt;Layer 1&lt;/A&gt;&amp;nbsp;covers&amp;nbsp;risks associated with people who&amp;nbsp;can&amp;nbsp;access Microsoft 365 Copilot.&amp;nbsp;Layer 2&amp;nbsp;covers&amp;nbsp;risks&amp;nbsp;associated&amp;nbsp;with data Microsoft 365 Copilot can access.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Layer 2 risks are governed primarily by the Apps and Data pillars of Zero Trust, with Identity playing a secondary role in defining the scope of data each user can reach.&amp;nbsp;Organizations can&amp;nbsp;address these risks with Microsoft&amp;nbsp;controls&amp;nbsp;such as&amp;nbsp;Microsoft Purview, SharePoint Advanced Management, Microsoft Entra ID Governance, and Microsoft Sentinel. The work is configuring and scoping them deliberately before Copilot scales across the organization.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to read this post&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:300,&amp;quot;335559739&amp;quot;:100}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each section recaps one risk, describes the mitigation, names the Microsoft control that delivers it, and includes a placeholder for the supporting screenshot. Controls are cumulative—sensitivity&amp;nbsp;labels,&amp;nbsp;DLP policies, and audit logs work together across risks, so several mitigations reinforce one another.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R7&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Overshared SharePoint and OneDrive content&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Content shared with “Everyone,” “Everyone except external users,” or broad security groups becomes part of Copilot’s&amp;nbsp;queryable&amp;nbsp;surface for any licensed user—even if that user would never have manually&amp;nbsp;located&amp;nbsp;those files. Years of SharePoint oversharing, combined with Copilot’s ability to traverse and synthesize content in a single prompt, can turn long-standing governance debt into immediate exposure. Copilot makes&amp;nbsp;data once&amp;nbsp;hidden by volume discoverable by intent.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation starts by understanding what is overshared, then systematically tightening the sharing scope before Copilot scales.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use&amp;nbsp;Restricted SharePoint Search (RSS) during the Copilot pilot&amp;nbsp;as a temporary way&amp;nbsp;to&amp;nbsp;narrow&amp;nbsp;the&amp;nbsp;SharePoint&amp;nbsp;sites Copilot can ground against&amp;nbsp;while you review&amp;nbsp;permissions&amp;nbsp;and governance controls&amp;nbsp;before broad rollout.&amp;nbsp;Then turn it off after validation rather than treating it as a long-term control.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use SharePoint Advanced Management (SAM) to run data access governance reports and identify sites with “Everyone” or “Everyone except external users” sharing links—prioritize sites holding financial, HR, legal, or project data.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Remove or replace broad sharing links with scoped permissions; replace “Anyone” links with site-member access and require expiration dates on sharing links going forward.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Run Microsoft Entra ID Access Reviews scoped to Microsoft 365 groups and SharePoint site members to catch stale memberships that expand Copilot’s grounding surface.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Use Microsoft Purview Content Explorer to inventory which sites and libraries contain sensitive content and cross-reference with sharing scope.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;SharePoint Advanced Management: data access governance report showing sites with broad sharing&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R8&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Sensitivity label gaps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview sensitivity labels help classify content by sensitivity and, together with Purview policy controls, shape how that content can be used in Microsoft 365 Copilot. Unlabeled, mislabeled, or improperly inherited content is harder to govern consistently. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation requires both discovering what is unlabeled and closing the labeling gap at scale through policy, rather than relying on manual user action.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Turn on&amp;nbsp;mandatory labeling in Microsoft Purview so users cannot save or share documents without applying a label—preventing new unlabeled content from accumulating.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Configure auto-labeling policies in Microsoft Purview to classify content at rest and in transit using built-in sensitive information types (SITs) and trainable classifiers—prioritizing SharePoint libraries and OneDrive for Business.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Apply default sensitivity labels to SharePoint document libraries and Teams channels so that content inherits a baseline label even when users do not label manually.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Turn on container-level label inheritance so that SharePoint sites and Teams workspaces propagate sensitivity settings to documents created within them.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Use Microsoft Purview Content Explorer to quantify the volume of unlabeled content across the tenant and track labeling progress over time.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview: auto-labeling policy scoped to SharePoint and OneDrive&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;SharePoint document library: default sensitivity label applied to the library&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Content Explorer: labeled vs. unlabeled content breakdown by location&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R9&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Excessive user permissions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;Apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot follows each user’s existing Microsoft Graph permissions and does not surface content the user cannot access. However,&amp;nbsp;in many enterprise environments, users accumulate access far beyond their current role through leftover project permissions, broad temporary group memberships, and inherited rights from outdated organizational structures. Copilot does not create this overprovisioning, but it makes the full scope of that access&amp;nbsp;immediately&amp;nbsp;visible and usable. What previously required sustained effort to&amp;nbsp;locate&amp;nbsp;and correlate can now be surfaced in a single prompt.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation focuses on continuously right-sizing permissions to reflect actual role requirements, not historical accumulation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Run Microsoft Entra ID&amp;nbsp;access&amp;nbsp;reviews on a recurring schedule for all Microsoft 365 groups, SharePoint sites, and Teams with access to sensitive content. Require reviewers to justify continued membership rather than defaulting to approval.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use SharePoint Advanced Management inactive site policies to identify and deprovision sites no longer in active use whose permissions have never been cleaned up.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Audit group memberships for broad “Edit” or “Full Control” rights and replace with scoped contributor roles aligned to current job function.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Apply the principle of least privilege to new project groups from the start: time-bound membership with expiration dates, and access reviews triggered at project close.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Review service account and application permissions in Microsoft Graph to ensure&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;only humans hold&amp;nbsp;standing access to content&amp;nbsp;that&amp;nbsp;Copilot can query.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;SharePoint Advanced Management: inactive sites report&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Microsoft 365 admin center: group expiration policy configuration&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R10&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;No DLP coverage on Copilot-generated outputs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot outputs—including summaries, drafts, and synthesized answers—can move sensitive information&amp;nbsp;into new&amp;nbsp;contexts, such as&amp;nbsp;chats, emails, pages, and documents.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Mitigation extends DLP coverage explicitly to Copilot interactions, grounding data,&amp;nbsp;and downstream locations where&amp;nbsp;generated content may be stored or shared.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use Microsoft Purview DLP&amp;nbsp;for&amp;nbsp;Microsoft 365 Copilot&amp;nbsp;and Copilot Chat&amp;nbsp;to&amp;nbsp;block or audit&amp;nbsp;sensitive&amp;nbsp;prompts, limit external web search&amp;nbsp;when prompts&amp;nbsp;contain&amp;nbsp;sensitive data, and restrict&amp;nbsp;Copilot&amp;nbsp;from using specified labeled files and emails as grounding data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Configure communication DLP policies for Teams and Exchange so that Copilot-generated content pasted into messages, emails, or chats is evaluated against the same sensitive information type rules as source documents.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Turn on endpoint DLP on managed Windows devices to catch sensitive content that exits by way of clipboard paste, file save, or upload to unmanaged locations after being generated by Copilot.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Review DLP policy coverage for Copilot Pages and other Copilot output surfaces so that synthesized content stored or shared from those surfaces is governed consistently.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Regularly review DLP policy simulation reports to validate that rules fire against realistic Copilot output patterns, not just keyword matches in source files.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview: DLP policy scoped to Microsoft 365 Copilot workload&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Endpoint DLP: activity explorer showing Copilot-related policy matches&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R11&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Plugin and connector data surface expansion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations can extend Microsoft 365 Copilot through plugins and Microsoft Graph connectors that pull external data from CRM systems, ITSM platforms, HR applications, and custom line-of-business tools. Each connector expands the data surface Copilot can query on a user’s behalf and often reaches into systems&amp;nbsp;where&amp;nbsp;access control models do not align natively with Microsoft 365 permissions. As organizations add connectors without reviewing their scope and governance, each connected source introduces risk that scales alongside the broader Copilot data surface.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation requires deliberate governance over which connectors and plugins are&amp;nbsp;turned on, for whom, and under what conditions—before&amp;nbsp;the connected surface grows beyond visibility.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Review and restrict which Copilot plugins and Graph connectors are enabled in the Microsoft 365 admin&amp;nbsp;center,&amp;nbsp;disable connectors not actively&amp;nbsp;required,&amp;nbsp;and require admin approval for new connector deployments.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Scope each approved connector to the minimum data set and user population it needs: not all Copilot users should have access to every connected source.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Audit the permission model of each external system behind a connector. Verify that the connector enforces source-system access control and does not flatten permissions for all Copilot users.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Log and review connector activity in the Microsoft 365 audit log to detect unexpected query patterns or unusually broad data retrieval through connected sources.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft 365 admin center: Copilot plugins and connectors management page&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Graph connector: connection status and scoped user access settings&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R12&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Audit and visibility gap&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations need visibility into Copilot activity so they can investigate suspicious behavior, monitor adoption, and understand which content sources are involved.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Disabling Copilot interaction logging,&amp;nbsp;retaining&amp;nbsp;audit logs for too short a period, or&amp;nbsp;failing to forward&amp;nbsp;logs to a SIEM leaves organizations without the evidence needed to detect anomalous usage patterns, or&amp;nbsp;support incident response.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Mitigation requires&amp;nbsp;turning on&amp;nbsp;the right audit tier,&amp;nbsp;retaining&amp;nbsp;logs long enough to support investigation, and building those&amp;nbsp;signals&amp;nbsp;into security operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Verify that Microsoft Purview Audit (Standard or Premium) is enabled for the&amp;nbsp;tenant&amp;nbsp;and that Copilot interaction events are being captured.&amp;nbsp;Confirm in the Purview compliance portal that Copilot activities appear under the Audit search.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Upgrade to Microsoft Purview Audit Premium for high-risk user populations—including privileged identities and users with access to sensitive sites—to extend log retention up to ten years and gain access to intelligent insights.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Set a minimum audit log retention of 90 days for all users; extend to 180 days or longer for any user group that accesses sensitive or regulated content through Copilot.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Forward Microsoft 365 audit logs to Microsoft Sentinel (or the organization’s existing SIEM) to correlate Copilot activity with endpoint, identity, and network signals and to turn on automated detection rules.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Review Microsoft 365 Copilot usage reports in the admin center regularly to identify unusual query volumes, off-hours activity, or access to unexpected content sources.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview Audit: Copilot interaction events in audit search&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview Audit: Copilot interaction events in audit search results&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="1"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R13&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Privileged user data amplification&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity, Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Administrators, senior IT staff, and other privileged users often hold access that spans organizational boundaries—including mailboxes, site collections, security groups, and configuration data that most users never reach. A Copilot-enabled admin account that is compromised or misused gives adversaries—or an inadvertent insider—an organization-wide view of data that far exceeds the exposure associated with a compromised end-user account. Because Copilot amplifies the full scope of a user’s existing access, privileged identities require the strictest governance&amp;nbsp;controls.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation applies Just-In-Time access, dedicated account separation, and elevated monitoring to ensure privileged identities are not simultaneously&amp;nbsp;full&amp;nbsp;administrators and active Copilot users.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use Microsoft Entra Privileged Identity Management (PIM) to enforce Just-In-Time (JIT) elevation for administrative roles. Privileged access should be time-bound, require justification, and expire automatically after the task is complete.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Do not assign Copilot licenses to dedicated admin accounts. Administrators should use separate work accounts for day-to-day productivity and Copilot access, keeping elevated administrative permissions away from Copilot-enabled sessions.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Apply the strictest Conditional Access policies to any identity that holds both a Copilot license and elevated permissions. Require phishing-resistant MFA, compliant devices, and enforce token protection.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Enable Entra ID access reviews specifically scoped to privileged role members to ensure administrative permissions are actively justified and time-limited, not held indefinitely.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Prioritize Microsoft Purview Audit Premium for all privileged identities to capture a complete, long-retention record of Copilot interactions associated with high-privilege accounts and forward those logs to Sentinel for alerting.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Entra PIM: active role assignments showing time-bound expiration&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Conditional Access: policy scoped to privileged role members with phishing-resistant MFA&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Layer 2 mitigations &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;at a glance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:300,&amp;quot;335559739&amp;quot;:100}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each Layer 2 risk maps to a primary control and the Microsoft tool that delivers it. Microsoft Purview recurs across multiple risks because it is the central governance layer for data classification, protection, and audit visibility in the Microsoft 365 environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 96.7802%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Primary control&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Microsoft tool&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R7—Overshared content&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Sharing scope reduction + access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;SharePoint Advanced Management, Entra ID Access Reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R8—Sensitivity label gaps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Auto-labeling + mandatory labeling&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Purview sensitivity labels&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R9—Excessive user permissions&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Recurring permission reviews + JIT scoping&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Entra ID Access Reviews, SharePoint Advanced Management&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R10—No DLP on Copilot outputs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;DLP extended to Copilot workloads&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Purview DLP, Endpoint DLP&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R11—Plugin and connector expansion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Connector governance + scoping&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 admin center, Purview DLP&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R12—Audit and visibility gap&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Full audit coverage + SIEM&amp;nbsp;forwarding&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Purview Audit Premium, Microsoft Sentinel&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;SPAN data-contrast="none"&gt;R13—Privileged user amplification&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/td&gt;&lt;td&gt;&lt;SPAN data-contrast="none"&gt;JIT access + account separation&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/td&gt;&lt;td&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Entra PIM, Conditional Access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Complete your Zero Trust approach to Microsoft 365 Copilot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:300,&amp;quot;335559739&amp;quot;:100}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 Copilot does not create new permissions or expose data users cannot already access.&amp;nbsp;What it does do is make existing access more discoverable, bringing years of accumulated oversharing, excessive permissions, unlabeled content, unmanaged connectors, and governance gaps into sharper focus.&amp;nbsp;As a result, reducing Copilot data exposure is not a one-time cleanup effort but&amp;nbsp;a continuous governance practice.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Across this series,&amp;nbsp;we've&amp;nbsp;examined both sides of the Microsoft 365 Copilot risk equation:&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title="who can access Copilot" data-lia-auto-title-active="0"&gt;who can access Copilot&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/mitigating-microsoft-365-copilot-access-risk-identity-and-device-controls-for-ze/4534574" target="_blank" rel="noopener" data-lia-auto-title="what Copilot can access on their behalf" data-lia-auto-title-active="0"&gt;what Copilot can access on their behalf&lt;/A&gt;.&amp;nbsp;Together, the Layer 1 and Layer 2 controls provide a practical, Zero Trust-aligned framework for governing identities, devices, applications, and data throughout your Copilot deployment.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For security, compliance, identity, and IT administrators, the next step is to assess your current environment against the risks discussed throughout this series. Review sharing configurations, sensitivity labeling coverage, data loss prevention policies, access governance practices, connector management, and audit visibility to&amp;nbsp;identify&amp;nbsp;gaps before Copilot adoption scales.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Addressing these gaps now can help reduce risk, strengthen compliance, and build a more secure foundation for AI-powered productivity. Use the controls discussed throughout this series to develop a Microsoft 365 Copilot deployment strategy that aligns with your organization's security, compliance, and business requirements. For&amp;nbsp;additional&amp;nbsp;guidance, see the&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;Zero Trust Overview on Microsoft Learn&lt;/A&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Atil Gurcan is a Senior FastTrack Architect who works with customers to implement secure &amp;amp; compliant AI experiences and accelerate their digital transformation, increasing ROI for their investments with Microsoft.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 21:18:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/limiting-microsoft-365-copilot-data-exposure-risk-with-zero/ba-p/4534642</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-08T21:18:16Z</dc:date>
    </item>
    <item>
      <title>Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/mitigating-microsoft-365-copilot-access-risk-identity-and-device/ba-p/4534574</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="
https://techcommunity.microsoft.com/users/atilgurcan/129311" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0xMjkzMTEtMjAxMjgyaTRDRDk1ODBCNDJDQzQ3MjM?image-dimensions=120x120" alt="AtilGurcan" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;AtilGurcan&lt;/SPAN&gt; &lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title="our&amp;nbsp;previous&amp;nbsp;post" data-lia-auto-title-active="0"&gt;our&amp;nbsp;previous&amp;nbsp;post&lt;/A&gt;, we mapped where exposure can exist when organizations deploy Microsoft 365 Copilot and grouped those risks into two layers. Layer 1&amp;nbsp;focused on&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;who can access Copilot&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;—the identity and device conditions that&amp;nbsp;determine&amp;nbsp;whether a user&amp;nbsp;can&amp;nbsp;reach the service.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If those identity and device conditions are weak, exposure&amp;nbsp;may extend beyond&amp;nbsp;a single workload across the user’s entire Microsoft 365 data surface.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;This post&amp;nbsp;shifts&amp;nbsp;from mapping risk to&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;reducing&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each of the six Layer 1 risks (R1–R6) is governed primarily by the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;identity&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;endpoints&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;pillars&amp;nbsp;of&amp;nbsp;Zero&amp;nbsp;Trust. The good news: customers with Microsoft 365 E5 already own the controls&amp;nbsp;required&amp;nbsp;to&amp;nbsp;address&amp;nbsp;these risks, including&amp;nbsp;Microsoft Entra ID, Conditional Access, Microsoft Intune, and Microsoft Defender.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;next job&amp;nbsp;is configuring and scoping them deliberately before scaling deployment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to read this post&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each section recaps one risk, describes the mitigation, names the Microsoft control that delivers it and indicates where to capture the supporting screenshot.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;These controls are&amp;nbsp;additive.&amp;nbsp;Conditional Access&amp;nbsp;ties&amp;nbsp;identity and device signals together, so several mitigations reinforce one another.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R1—Unmanaged identity access&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Because Copilot operates across the full scope of a user's permissions, a compromised, shared, or orphaned account exposes far more than it would have before.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation starts with disciplined identity lifecycle management so that accounts exist only when&amp;nbsp;they should and&amp;nbsp;belong to&amp;nbsp;real&amp;nbsp;users.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Automate joiner,&amp;nbsp;mover, and&amp;nbsp;leaver&amp;nbsp;processes&amp;nbsp;with&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Entra Lifecycle Workflows&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;so accounts are provisioned, re-scoped, and disabled on schedule rather than manually.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Run recurring &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;access reviews&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;on Copilot-licensed groups to&amp;nbsp;identify&amp;nbsp;stale&amp;nbsp;or unnecessary&amp;nbsp;accounts.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Eliminate shared and generic accounts; require an individual, attributable identity for every Copilot user.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Block or remove dormant accounts and monitor sign-in activity for privileged identities.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&lt;SPAN data-contrast="auto"&gt;The following examples show lifecycle workflows and access review configuration:&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Lifecycle Workflows—leaver workflow showing account-disable tasks&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Access reviews—review scoped to the Copilot users group&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R2—Weak or absent multi-factor authentication&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If MFA is inconsistent—or legacy authentication bypasses modern sign-in controls—an attacker may need only a stolen password to open a Copilot session that synthesizes data across services.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Closing this gap means enforcing strong authentication&amp;nbsp;consistently&amp;nbsp;and shutting down the protocols that route around it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Require MFA for all users with a&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;policy; use Microsoft-managed policies as a baseline, then tighten.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Move to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;phishing-resistant&amp;nbsp;authentication&amp;nbsp;methods&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, such as&amp;nbsp;FIDO2 security keys, Windows Hello for Business, or certificate-based authentication.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Block legacy authentication protocols that don't support modern MFA.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Turn on Microsoft Authenticator number matching and additional context to help resist MFA fatigue attacks.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require multifactor authentication policy&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Authentication methods—phishing-resistant methods enabled&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R3—Unmanaged or noncompliant devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Users can reach Copilot from any device where they can authenticate. Without endpoint protection, encryption, and compliance evaluation, sessions and their outputs can be stored or exfiltrated from untrusted devices.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation pairs device&amp;nbsp;compliance&amp;nbsp;in&amp;nbsp;Intune with a Conditional Access&amp;nbsp;policy&amp;nbsp;that enforces it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Define&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune compliance policies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;that&amp;nbsp;require&amp;nbsp;disk encryption,&amp;nbsp;minimum&amp;nbsp;OS versions,&amp;nbsp;endpoint protection (EDR/Defender), and no jailbreak&amp;nbsp;or&amp;nbsp;root&amp;nbsp;status.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use a&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access grant&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;control that&amp;nbsp;requires&amp;nbsp;devices&amp;nbsp;to be marked compliant,&amp;nbsp;or&amp;nbsp;hybrid&amp;nbsp;Microsoft Entra joined&amp;nbsp;before&amp;nbsp;accessing&amp;nbsp;Microsoft 365&amp;nbsp;and&amp;nbsp;Copilot.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Feed &lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender for Endpoint&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;device&amp;nbsp;risk signals into compliance&amp;nbsp;evaluation,&amp;nbsp;so high-risk&amp;nbsp;devices&amp;nbsp;fall out of compliance automatically.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Intune compliance policy—encryption, minimum OS, and Defender requirements&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require device to be marked as compliant&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R4—License sprawl without role-based scoping&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Broad pilot enrollment—licensing whole departments or floors—is itself a risk factor because it&amp;nbsp;grants&amp;nbsp;Copilot&amp;nbsp;access&amp;nbsp;to&amp;nbsp;both&amp;nbsp;well-governed and minimally governed users without an access review. Mitigation makes licensing deliberate: a reviewed group assigned through policy after each member's access is checked.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Assign Copilot through&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;group-based licensing&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;tied to a named, security-reviewed pilot group—not by department or location.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Run an access review on each pilot member's permission posture and role sensitivity&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;before&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;granting the license.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Phase rollout in cohorts and consider Restricted SharePoint Search during the pilot to limit the grounding surface.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Microsoft 365 admin center—Copilot license assignment count&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R5—Missing real-time risk evaluation at sign-in&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Static controls grant or deny access once; they&amp;nbsp;don't&amp;nbsp;react to a session that turns risky. If Conditional Access&amp;nbsp;doesn’t&amp;nbsp;evaluate sign-in and user&amp;nbsp;risk signals—impossible travel, anomalous tokens, Identity Protection alerts—a high-risk session can still reach Copilot before anyone responds. Mitigation makes access decisions risk-aware in real time.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Turn on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Entra ID Protection&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(included in E5) to generate user&amp;nbsp;risk and sign-in-risk signals.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Create &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;risk-based Conditional Access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;policies: require MFA or a secure password change on elevated risk, and block on&amp;nbsp;high risk.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Add &lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;token protection&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;to bind sign-in sessions to the device and reduce token&amp;nbsp;replay exposure.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—user risk condition set&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Identity Protection—risky sign-ins dashboard&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require token protection session control&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R6—App protection gap on mobile devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;On personal phones that&amp;nbsp;aren't&amp;nbsp;enrolled in MDM, organizations still need to govern the app. Without an application protection policy, users can copy Copilot output into unmanaged apps, and&amp;nbsp;data on&amp;nbsp;a&amp;nbsp;lost&amp;nbsp;device&amp;nbsp;can't&amp;nbsp;be wiped. Mobile Application Management (MAM) protects corporate data inside the app without managing the whole device.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Deploy&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune App Protection Policies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(MAM) for iOS and Android: require&amp;nbsp;an app PIN, encrypt app data, and allow selective wipe of organizational&amp;nbsp;data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Restrict &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;data egress&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: block copy/paste and 'Save As' to unmanaged locations, and block screen capture where the platform supports it (Android).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Pair with a &lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;grant requiring an approved client app and an app protection policy for mobile access.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Intune app protection policies—iOS and Android policy list&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: App protection policy—data protection, block copy/paste, and “Save As”&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require approved client app and require App Protection Policy&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&amp;nbsp;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Layer 1 mitigations&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;at a glance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:320,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each Layer 1 risk maps to a primary control and the Microsoft tool that delivers it.&amp;nbsp;Conditional Access recurs because it is where identity and device signals are enforced together.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 85.9133%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Primary mitigation&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft control&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R1&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity lifecycle + access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Entra Lifecycle Workflows; Access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R2&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Enforce phishing-resistant MFA; block legacy auth&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access; Authentication methods&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R3&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Require compliant/managed devices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune compliance policies; Defender for Endpoint; Conditional Access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R4&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Scoped, reviewed licensing&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Group-based licensing; Access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R5&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time risk gating at sign-in&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Entra ID Protection; risk-based Conditional Access; token protection&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R6&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Protect data inside mobile apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune App Protection&amp;nbsp;Policies&amp;nbsp;(MAM);&amp;nbsp;Conditional&amp;nbsp;Access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Securing Copilot access&amp;nbsp;isn't&amp;nbsp;only about who can sign in—it's&amp;nbsp;about&amp;nbsp;validating&amp;nbsp;the devices, conditions, and access patterns behind every session. The six controls above close Layer 1 gaps before risky access patterns scale across the organization.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Governing Microsoft 365 Copilot risk: Next steps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 Copilot security starts before a prompt is ever entered. Identity, device, and session controls help verify that the right people are accessing Copilot from trusted devices under the right conditions. Closing Layer 1&amp;nbsp;gaps&amp;nbsp;reduces the likelihood that compromised identities, risky sign-ins, or unmanaged devices can access organizational data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Controlling&amp;nbsp;who can access Copilot&amp;nbsp;is the first step. The&amp;nbsp;next&amp;nbsp;challenge is governing&amp;nbsp;what Copilot can access&amp;nbsp;once a user is authenticated.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Strong access controls reduce the chances that the wrong person reaches Copilot. Layer 2 focuses on a different question: if the right person signs in, what information can they discover, summarize, and use?&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In&amp;nbsp;the next post of&amp;nbsp;this series,&amp;nbsp;we'll&amp;nbsp;shift from access controls to data controls and explore how organizations can reduce Layer 2 risk through SharePoint and OneDrive permissions management, sensitivity labels, data loss prevention (DLP), connector governance, and auditing capabilities.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before expanding your Copilot deployment, review the six Layer 1 controls covered in this article and&amp;nbsp;identify&amp;nbsp;any gaps in your identity, device, and access policies. You can also use&amp;nbsp;&lt;A class="lia-external-url" href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;the Zero Trust Workshop&lt;/A&gt;&amp;nbsp;to assess your current security posture and prioritize remediation efforts.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When&amp;nbsp;you're&amp;nbsp;ready, continue to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Post 3&amp;nbsp;in&amp;nbsp;this series: Governing Microsoft 365 Copilot data risk&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;to examine how data governance controls help limit exposure after authentication and strengthen secure Copilot adoption.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&lt;EM&gt;Atil Gurcan is a Senior FastTrack Architect who works with customers to implement secure &amp;amp; compliant AI experiences and accelerate their digital transformation, increasing ROI for their investments with Microsoft.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 21:16:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/mitigating-microsoft-365-copilot-access-risk-identity-and-device/ba-p/4534574</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-08T21:16:35Z</dc:date>
    </item>
    <item>
      <title>Understanding Copilot Risk: Mapping Exposure Across Zero Trust Pillars</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/understanding-copilot-risk-mapping-exposure-across-zero-trust/ba-p/4534183</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="
https://techcommunity.microsoft.com/users/atilgurcan/129311" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0xMjkzMTEtMjAxMjgyaTRDRDk1ODBCNDJDQzQ3MjM?image-dimensions=120x120" alt="AtilGurcan" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;AtilGurcan&lt;/SPAN&gt; &lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;AI&amp;nbsp;represents&amp;nbsp;a major&amp;nbsp;shift&amp;nbsp;in how users interact&amp;nbsp;with organizational data.&amp;nbsp;Instead of&amp;nbsp;finding&amp;nbsp;information&amp;nbsp;one file, email, or chat at a time,&amp;nbsp;users&lt;SPAN data-ccp-charstyle="Normal 1 Char" data-ccp-charstyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;424ef91a-e132-5625-abdb-2cccf359c7bb|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,469777841,&amp;quot;Aptos&amp;quot;,469777842,&amp;quot;Times New Roman&amp;quot;,469777843,&amp;quot;Times New Roman&amp;quot;,469777844,&amp;quot;Aptos&amp;quot;,201341986,&amp;quot;1&amp;quot;,469769226,&amp;quot;Aptos,Arial&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;Normal 1 Char&amp;quot;,201340122,&amp;quot;1&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;Normal1Char&amp;quot;,335572020,&amp;quot;1&amp;quot;,134231262,&amp;quot;true&amp;quot;,469777929,&amp;quot;Normal 1&amp;quot;,469778324,&amp;quot;Default Paragraph Font&amp;quot;]}" data-ccp-charstyle-linked-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;bd921492-1112-5b48-ab34-dc4d2156f455|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469777841,&amp;quot;Aptos&amp;quot;,469777842,&amp;quot;Times New Roman&amp;quot;,469777843,&amp;quot;Times New Roman&amp;quot;,469777844,&amp;quot;Aptos&amp;quot;,469769226,&amp;quot;Aptos&amp;quot;,335559740,&amp;quot;240&amp;quot;,201341983,&amp;quot;0&amp;quot;,335559739,&amp;quot;0&amp;quot;,201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,201341986,&amp;quot;1&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;Normal 1&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;Normal1&amp;quot;,335572020,&amp;quot;1&amp;quot;,335551550,&amp;quot;6&amp;quot;,335551620,&amp;quot;6&amp;quot;,469777929,&amp;quot;Normal 1 Char&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}"&gt;&amp;nbsp;can&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;ask natural language questions&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;get&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;synthesize&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;answers&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;drawn&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;from&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;content&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;they already have permission to access&lt;/SPAN&gt;.&amp;nbsp;That can improve productivity, but&amp;nbsp;it can&amp;nbsp;also amplify the&amp;nbsp;impact of broad access, oversharing, and weak governance.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 Copilot brings this shift into focus. It&amp;nbsp;doesn’t&amp;nbsp;grant new permissions, but it acts as a force multiplier for existing access,&amp;nbsp;making it faster and easier for users to&amp;nbsp;discover, aggregate, and act on data across Microsoft 365. That makes it critical to understand both who can access Copilot and what data it can surface on a user’s behalf.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;A second&amp;nbsp;layer of risk&amp;nbsp;follows&amp;nbsp;from&amp;nbsp;how organizational data is structured, shared, and governed.&amp;nbsp;In environments with overshared content, excessive permissions, or inconsistent governance,&amp;nbsp;this acceleration can&amp;nbsp;lead&amp;nbsp;to&amp;nbsp;faster&amp;nbsp;and broader&amp;nbsp;access to sensitive information than organizations&amp;nbsp;may expect.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This&amp;nbsp;shift&amp;nbsp;carries important&amp;nbsp;security implications, especially as organizations move from pilots to&amp;nbsp;scaled&amp;nbsp;deployment.&amp;nbsp;While customers with&amp;nbsp;Microsoft 365&amp;nbsp;E5 licensing&amp;nbsp;may&amp;nbsp;already have access to&amp;nbsp;tools&amp;nbsp;that&amp;nbsp;help&amp;nbsp;identify&amp;nbsp;and reduce&amp;nbsp;risk,&amp;nbsp;licensing alone does not&amp;nbsp;reduce&amp;nbsp;exposure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;What’s&amp;nbsp;often missing&amp;nbsp;during early Copilot deployments&amp;nbsp;is a clear&amp;nbsp;view&amp;nbsp;of the risk surface itself:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;w&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;hat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;data&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;is exposed&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;,&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;who can access it,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;thr&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ough which vectors&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;Organizations&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;building&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;their&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;Microsoft 365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;Z&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ero Trus&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;posture&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;can&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;use&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;the&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust Workshop&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;to a&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ss&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ess&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;their cur&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;rent&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;po&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;sture&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ide&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ntify&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;gaps, and bett&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;er u&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;nderstan&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;d how&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;x&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;isting per&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;missions and g&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;over&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;nance imp&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;act Copilot readiness&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In this post, we&amp;nbsp;map&amp;nbsp;Copilot-related risk&amp;nbsp;to&amp;nbsp;the&amp;nbsp;key Zero Trust&amp;nbsp;control areas most relevant&amp;nbsp;to deployment: identity, endpoints, apps, and data.&amp;nbsp;Our&amp;nbsp;goal is to help organizations&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;understand where&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;exposure&amp;nbsp;exists&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;which control&amp;nbsp;areas&amp;nbsp;they should&amp;nbsp;focus on&amp;nbsp;before scaling&amp;nbsp;deployment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Use&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Zero Trust to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;assess&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft 365 Copilot&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;risk&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft defines Zero Trust as a security model built on three core principles: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Verify&amp;nbsp;explicitly&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Use least privileged access&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Assume breach&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Instead of trusting users or devices based solely on network location, Zero Trust requires continuous validation of every user, endpoint, and request, regardless of where the request originates.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft’s Zero Trust adoption model groups security controls across technology pillars such as identities, endpoints, apps, data, network, infrastructure, and security operations.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For this analysis,&amp;nbsp;we’ll&amp;nbsp;focus on the&amp;nbsp;four&amp;nbsp;pillars most directly&amp;nbsp;involved in&amp;nbsp;Microsoft 365&amp;nbsp;Copilot deployments:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;identity,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;endpoints&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;apps,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;data.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1.&amp;nbsp;Four control areas that shape&amp;nbsp;Copilot&amp;nbsp;exposure&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, these&amp;nbsp;pillars&amp;nbsp;help answer&amp;nbsp;three&amp;nbsp;key&amp;nbsp;questions:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Who&amp;nbsp;can&amp;nbsp;access&amp;nbsp;Copilot&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;From which endpoints and applications&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;What data can Copilot surface once access is granted&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more information and details&amp;nbsp;about&amp;nbsp;Microsoft’s Zero Trust&amp;nbsp;framework,&amp;nbsp;visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/zero-trust/deploy/overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust Overview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;at&amp;nbsp;Microsoft Learn.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Micro&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;soft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Copilot&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;changes the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;risk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;conversation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before assessing specific risks, it helps to understand why Copilot changes the risk conversation compared to traditional Microsoft 365 applications. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Most enterprise apps operate within a bounded context. The time and effort required to manually locate, connect, and synthesize information across systems creates friction and a practical limit on how quickly users can surface and act on data across systems. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Copilot removes much of that friction. At the speed of a prompt, Copilot lets users retrieve and bring together information from across a user’s existing access—spanning emails, files, meetings, chats, and other Microsoft 365 services—in a single response.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This exposure is not a result of new permissions. It comes from how quickly and easily existing access can be discovered, aggregated, and used.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;To understand where exposure appears, it helps to break Copilot risk into two interconnected layers: access and data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="none"&gt;Figure: Two-layer model for Microsoft 365 Copilot risk.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The two-layer Microsoft 365 Copilot risk model&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The foundation of this&amp;nbsp;analysis is simple:&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Copilot&amp;nbsp;acts as&amp;nbsp;a force multiplier&amp;nbsp;for&amp;nbsp;whatever access a user already has&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;.&lt;/EM&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;If that access is governed well, Copilot can improve productivity. If not, it can amplify exposure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;With&amp;nbsp;that framing&amp;nbsp;in mind,&amp;nbsp;we’ll&amp;nbsp;examine&amp;nbsp;Copilot&amp;nbsp;risk in two distinct layers:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Access to the Copilot service itself&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Access to the data that Copilot can ground on and surface&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The first layer focuses&amp;nbsp;on who can access Copilot and under what conditions. The second focuses on what Copilot can see and surface once access is granted.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Risk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;l&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ayer 1&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;:&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;Who&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;c&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;an&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ccess&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Microsoft 365&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;Copilot?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The first layer of risk begins at the point of entry: the conditions that determine whether a user can access Copilot. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Organizations don’t need to address every potential exposure point at once. Start by using the table below as a map of where exposure can exist across identity and endpoint controls. We’ll explore how to mitigate these risks in the second post of this series.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;risks&amp;nbsp;below&amp;nbsp;are primarily governed by&amp;nbsp;Microsoft’s Zero Trust&amp;nbsp;identity and&amp;nbsp;endpoint&amp;nbsp;pillars.&amp;nbsp;Together, these pillars&amp;nbsp;help&amp;nbsp;determine&amp;nbsp;whether&amp;nbsp;the right user&amp;nbsp;can&amp;nbsp;access&amp;nbsp;Copilot from a trusted&amp;nbsp;endpoint&amp;nbsp;under&amp;nbsp;the right&amp;nbsp;access&amp;nbsp;conditions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="auto"&gt;Table&amp;nbsp;1.&amp;nbsp;Identity and endpoint risks that affect Copilot access&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100.031%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 4.83122%" /&gt;&lt;col style="width: 21.4611%" /&gt;&lt;col style="width: 15.1446%" /&gt;&lt;col style="width: 58.5321%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Pillar&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Description&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R1&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Unmanaged&amp;nbsp;identity&amp;nbsp;access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A&amp;nbsp;compromised, shared,&amp;nbsp;or former employee&amp;nbsp;account&amp;nbsp;can&amp;nbsp;authenticate&amp;nbsp;Microsoft&amp;nbsp;365 and access&amp;nbsp;Copilot.&amp;nbsp;Because&amp;nbsp;Copilot&amp;nbsp;operates&amp;nbsp;across the&amp;nbsp;full scope of&amp;nbsp;a&amp;nbsp;user’s permissions,&amp;nbsp;compromised accounts&amp;nbsp;can&amp;nbsp;expose&amp;nbsp;a&amp;nbsp;much&amp;nbsp;larger&amp;nbsp;risk surface than before Copilot existed.&amp;nbsp;Strong account&amp;nbsp;hygiene and&amp;nbsp;identity&amp;nbsp;lifecycle management&amp;nbsp;can&amp;nbsp;reduce&amp;nbsp;that&amp;nbsp;exposure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R2&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Weak or&amp;nbsp;absent&amp;nbsp;multi-factor&amp;nbsp;authentication&amp;nbsp;(MFA)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If MFA&amp;nbsp;isn’t&amp;nbsp;enforced, or if legacy authentication bypasses modern sign-in controls, users&amp;nbsp;can start Copilot&amp;nbsp;sessions&amp;nbsp;with&amp;nbsp;only&amp;nbsp;a password. In environments&amp;nbsp;with inconsistent&amp;nbsp;MFA coverage,&amp;nbsp;stolen credentials&amp;nbsp;may be enough&amp;nbsp;to gain access.&amp;nbsp;Because&amp;nbsp;Copilot&amp;nbsp;can&amp;nbsp;synthesize data across services,&amp;nbsp;compromised accounts&amp;nbsp;create&amp;nbsp;more&amp;nbsp;risk&amp;nbsp;than access to a single application.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R3&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Unmanaged or&amp;nbsp;non-compliant&amp;nbsp;devices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Users can access&amp;nbsp;Copilot&amp;nbsp;through&amp;nbsp;browsers&amp;nbsp;and native&amp;nbsp;apps&amp;nbsp;from&amp;nbsp;any device where they&amp;nbsp;can authenticate.&amp;nbsp;Unmanaged&amp;nbsp;or noncompliant&amp;nbsp;endpoints&amp;nbsp;without&amp;nbsp;endpoint&amp;nbsp;protection, encryption,&amp;nbsp;or&amp;nbsp;compliance evaluation can&amp;nbsp;expose&amp;nbsp;Copilot sessions and&amp;nbsp;allow&amp;nbsp;outputs&amp;nbsp;to&amp;nbsp;be&amp;nbsp;stored&amp;nbsp;or exfiltrated&amp;nbsp;locally.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R4&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Broad Copilot licensing&amp;nbsp;without&amp;nbsp;role-based&amp;nbsp;scoping&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Broad&amp;nbsp;Copilot&amp;nbsp;licensing&amp;nbsp;without role-based scoping.&amp;nbsp;Copilot pilots often begin with broad license&amp;nbsp;assignments across departments&amp;nbsp;or business units&amp;nbsp;instead of&amp;nbsp;smaller, security-reviewed&amp;nbsp;user&amp;nbsp;groups. When&amp;nbsp;organizations&amp;nbsp;assign&amp;nbsp;licenses&amp;nbsp;without&amp;nbsp;reviewing&amp;nbsp;access rights,&amp;nbsp;permission&amp;nbsp;posture, and role sensitivity,&amp;nbsp;they can expand&amp;nbsp;exposure&amp;nbsp;across both&amp;nbsp;well-governed and minimally&amp;nbsp;governed users.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R5&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Missing&amp;nbsp;real-time&amp;nbsp;risk&amp;nbsp;evaluation at&amp;nbsp;sign-in&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If Conditional Access&amp;nbsp;doesn’t&amp;nbsp;evaluate sign-in and user risk signals,&amp;nbsp;such&amp;nbsp;as&amp;nbsp;anomalous activity, or identity protection&amp;nbsp;alerts,&amp;nbsp;high-risk sessions may still&amp;nbsp;reach&amp;nbsp;Copilot. Without real-time risk&amp;nbsp;evaluation,&amp;nbsp;controls&amp;nbsp;may&amp;nbsp;respond only&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;after&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;access is granted.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R6&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;App&amp;nbsp;protection&amp;nbsp;gap on&amp;nbsp;mobile&amp;nbsp;devices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Users can access&amp;nbsp;Copilot&amp;nbsp;from personal&amp;nbsp;mobile&amp;nbsp;devices&amp;nbsp;that are not enrolled in&amp;nbsp;device&amp;nbsp;or&amp;nbsp;app management. Without&amp;nbsp;app protection&amp;nbsp;policies,&amp;nbsp;organizations&amp;nbsp;may not be able to&amp;nbsp;control how&amp;nbsp;Copilot outputs&amp;nbsp;move&amp;nbsp;into unmanaged apps&amp;nbsp;or&amp;nbsp;remove&amp;nbsp;organizational data from lost devices.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Key observations from Layer 1:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity appears most&amp;nbsp;frequently&amp;nbsp;across Layer 1, reflecting how tightly Copilot access depends on authenticated user permissions and sign-in conditions.&amp;nbsp;Endpoint-related risks also play&amp;nbsp;a major role&amp;nbsp;because unmanaged or noncompliant endpoints can expose Copilot sessions and outputs beyond the organization’s trusted environment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;Together, these risks&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;show that&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;securing Copilot access is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;shaped&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;by two factors:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;who can sign in,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;whether&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;endpoint&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;and session meet the organization’s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;access&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;requirements&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Risk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;l&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ayer 2&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ata&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;c&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;an&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Microsoft 365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Copilot&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;each?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The second layer of risk&amp;nbsp;assumes that&amp;nbsp;the user is already authenticated and actively using Copilot.&amp;nbsp;At this&amp;nbsp;stage, the focus shifts from who can access&amp;nbsp;Copilot&amp;nbsp;to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;what&amp;nbsp;data&amp;nbsp;Copilot can surface&amp;nbsp;on the user’s behalf&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;These risks reflect the exposure created by existing permissions, overshared content, connected systems, and governance gaps.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Layer 2&amp;nbsp;risks are governed primarily by the&amp;nbsp;apps&amp;nbsp;and&amp;nbsp;data&amp;nbsp;pillars, with&amp;nbsp;identity playing a secondary role in defining the scope of&amp;nbsp;data&amp;nbsp;each user&amp;nbsp;can access.&amp;nbsp;Much of Copilot’s value&amp;nbsp;and risk&amp;nbsp;comes from how it surfaces information based on user intent.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="none"&gt;Figure:How user intent changes data discovery&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="4"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="4"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 4"&gt;Data and application risks that shape Copilot exposure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:40,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These&amp;nbsp;risks highlight how&amp;nbsp;permissions,&amp;nbsp;sharing,&amp;nbsp;labeling, and governance directly shape&amp;nbsp;what&amp;nbsp;Copilot&amp;nbsp;can&amp;nbsp;retrieve, synthesize, and surface&amp;nbsp;across&amp;nbsp;organizational&amp;nbsp;data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100.031%; height: 1408.34px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 35.667px;"&gt;&lt;td style="height: 35.667px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;td style="height: 35.667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 35.667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Zero Trust pillar(s)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 35.667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Description&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 234.667px;"&gt;&lt;td style="height: 234.667px;"&gt;&lt;STRONG&gt;R7&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 234.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Overshared SharePoint and OneDrive&amp;nbsp;content&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 234.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 234.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Content shared with "Everyone," "Everyone except external users," or broad groups&amp;nbsp;can&amp;nbsp;become part of Copilot’s&amp;nbsp;queryable&amp;nbsp;surface&amp;nbsp;for licensed users who already&amp;nbsp;have&amp;nbsp;access&amp;nbsp;to that content. Years of oversharing, combined with Copilot’s ability to&amp;nbsp;retrieve&amp;nbsp;and synthesize content in a single prompt, can turn long-standing governance&amp;nbsp;gaps&amp;nbsp;into immediate exposure.&amp;nbsp;Copilot&amp;nbsp;can&amp;nbsp;make data&amp;nbsp;that was&amp;nbsp;once hidden by volume,&amp;nbsp;discoverable by intent.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 206.667px;"&gt;&lt;td style="height: 206.667px;"&gt;&lt;STRONG&gt;R8&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Sensitivity&amp;nbsp;label&amp;nbsp;gaps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview sensitivity labels&amp;nbsp;and related protections&amp;nbsp;tell Copilot how&amp;nbsp;to handle&amp;nbsp;content, including whether it can summarize, cite, or include&amp;nbsp;that content&amp;nbsp;in responses.&amp;nbsp;Across&amp;nbsp;containers such as SharePoint sites and Teams,&amp;nbsp;unlabeled,&amp;nbsp;incorrect, or inconsistently&amp;nbsp;labeled content may be&amp;nbsp;treated&amp;nbsp;as unclassified and&amp;nbsp;surfaced&amp;nbsp;freely.&amp;nbsp;Large volumes of legacy content&amp;nbsp;can make that gap harder to manage at scale.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 206.667px;"&gt;&lt;td style="height: 206.667px;"&gt;&lt;STRONG&gt;R9&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Excessive&amp;nbsp;user&amp;nbsp;permissions&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot follows each user’s existing&amp;nbsp;Microsoft&amp;nbsp;365&amp;nbsp;permissions and&amp;nbsp;does&amp;nbsp;not surface content&amp;nbsp;users&amp;nbsp;cannot access.&amp;nbsp;However,&amp;nbsp;users&amp;nbsp;often&amp;nbsp;accumulate access beyond their current role through leftover project permissions, temporary group memberships, and inherited&amp;nbsp;access. Copilot&amp;nbsp;doesn’t&amp;nbsp;create this overprovisioning, but it&amp;nbsp;can&amp;nbsp;make the full scope of&amp;nbsp;it easier to discover and use.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 216.667px;"&gt;&lt;td style="height: 216.667px;"&gt;&lt;STRONG&gt;R10&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 216.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;No DLP&amp;nbsp;coverage on Copilot-generated&amp;nbsp;outputs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 216.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 216.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot outputs, such as&amp;nbsp;summaries&amp;nbsp;and&amp;nbsp;drafts&amp;nbsp;can&amp;nbsp;combine&amp;nbsp;sensitive details from multiple sources.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations&amp;nbsp;should review how&amp;nbsp;their DLP labeling and data protection policies apply to generated content, especially when users move Copilot outputs into email, chat, or external documents.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 206.667px;"&gt;&lt;td style="height: 206.667px;"&gt;&lt;STRONG&gt;R11&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Plugin and connector data surface expansion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations can extend&amp;nbsp;Copilot through&amp;nbsp;agent and&amp;nbsp;connectors that pull external data from CRM systems, ITSM platforms, and&amp;nbsp;other&amp;nbsp;line-of-business tools. Each connected&amp;nbsp;source&amp;nbsp;expands&amp;nbsp;the&amp;nbsp;set&amp;nbsp;of&amp;nbsp;data users&amp;nbsp;can&amp;nbsp;access through Copilot.&amp;nbsp;Each&amp;nbsp;connected source&amp;nbsp;expands the set of data users can access through Copilot and may&amp;nbsp;introduce governance and&amp;nbsp;access model&amp;nbsp;differences that need to be reviewed.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 150.667px;"&gt;&lt;td style="height: 150.667px;"&gt;&lt;STRONG&gt;R12&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Audit and&amp;nbsp;visibility&amp;nbsp;gap&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps and&amp;nbsp;data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations need&amp;nbsp;enough&amp;nbsp;visibility&amp;nbsp;to understand how&amp;nbsp;users&amp;nbsp;interact with&amp;nbsp;Copilot&amp;nbsp;and which resources&amp;nbsp;Copilot accesses in&amp;nbsp;response&amp;nbsp;to prompts.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Audit logs and monitoring help security teams investigate suspicious&amp;nbsp;activity, understand usage patterns, and reduce risk over time.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 150.667px;"&gt;&lt;td style="height: 150.667px;"&gt;&lt;STRONG&gt;R13&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Privileged&amp;nbsp;user&amp;nbsp;data&amp;nbsp;amplification&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity,&amp;nbsp;apps&amp;nbsp;and&amp;nbsp;data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Privileged users often hold access&amp;nbsp;across sensitive systems and data. A compromised&amp;nbsp;privileged&amp;nbsp;account&amp;nbsp;with&amp;nbsp;Copilot&amp;nbsp;access&amp;nbsp;can expose a much larger slice of&amp;nbsp;organizational&amp;nbsp;data&amp;nbsp;than&amp;nbsp;a&amp;nbsp;standard&amp;nbsp;user account.&amp;nbsp;Privileged identities&amp;nbsp;therefore&amp;nbsp;need&amp;nbsp;tighter&amp;nbsp;access to&amp;nbsp;governance&amp;nbsp;and review.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Key observations from Layer&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;2&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps-related risks appear throughout Layer 2 because Microsoft 365 Copilot depends&amp;nbsp;on connected systems, accessible data sources, and governance over generated outputs. The&amp;nbsp;data pillar&amp;nbsp;reinforces the need to protect&amp;nbsp;both&amp;nbsp;sensitive source content&amp;nbsp;and&amp;nbsp;the&amp;nbsp;AI-generated responses that&amp;nbsp;bring content together.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;The table&amp;nbsp;above&amp;nbsp;maps each&amp;nbsp;risk to its primary and secondary Zero Trust pillars&amp;nbsp;to show where to act.&amp;nbsp;Primary pillars&amp;nbsp;represent&amp;nbsp;control areas&amp;nbsp;that most directly govern&amp;nbsp;a given&amp;nbsp;risk,&amp;nbsp;while&amp;nbsp;secondary&amp;nbsp;pillars&amp;nbsp;represent&amp;nbsp;contributing&amp;nbsp;factors.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;G&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;overning Microsoft 365 Copilot risk&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;N&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ext&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;steps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot&amp;nbsp;typically&amp;nbsp;doesn’t&amp;nbsp;grant broader access than a user already has. Instead,&amp;nbsp;it&amp;nbsp;makes&amp;nbsp;existing&amp;nbsp;access&amp;nbsp;easier to discover, connect, and use&amp;nbsp;across&amp;nbsp;Microsoft 365. Organizations&amp;nbsp;that successfully&amp;nbsp;scale&amp;nbsp;Copilot&amp;nbsp;are the ones that&amp;nbsp;understand and govern that access&amp;nbsp;first.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Understanding &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;where&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; exposure exists is the first step. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Your next step depends on where your organization is&amp;nbsp;in their Zero Trust journey.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Need&amp;nbsp;to assess your&amp;nbsp;current status?&amp;nbsp;Visit &lt;A class="lia-external-url" href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;the Zero Trust Workshop&lt;/A&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Ready to learn more about reducing risk by strengthening access controls at the point of entry? Check out post 2 of this series: &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/mitigating-microsoft-365-copilot-access-risk-identity-and-device-controls-for-ze/4534574" target="_blank" rel="noopener" data-lia-auto-title="Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust" data-lia-auto-title-active="0"&gt;Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Atil Gurcan is a Senior FastTrack Architect who works with customers to implement secure &amp;amp; compliant AI experiences and accelerate their digital transformation, increasing ROI for their investments with Microsoft.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 21:16:10 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/understanding-copilot-risk-mapping-exposure-across-zero-trust/ba-p/4534183</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-08T21:16:10Z</dc:date>
    </item>
    <item>
      <title>Azure Availability Zone Mapping and VM Resilience Analysis Guidance using SRE.AZURE.COM Agent</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/azure-availability-zone-mapping-and-vm-resilience-analysis/ba-p/4526548</link>
      <description>&lt;H1&gt;Overview&lt;/H1&gt;
&lt;P&gt;This guidance, supported and tested using &lt;STRONG&gt;SRE.Azure.com&lt;/STRONG&gt;, helps Azure platform engineers understand how Availability Zones are mapped within their subscription and how virtual machines (VMs) are distributed across those zones.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;SRE.Azure.com&lt;/STRONG&gt; enables discovery and analysis of zone mappings, VM placement, and infrastructure resilience.&lt;/P&gt;
&lt;H1&gt;Why This Matters&lt;/H1&gt;
&lt;P&gt;Azure uses logical zones (1, 2, 3), but these map differently to physical datacenter zones (az1, az2, az3) in each subscription. This means workloads in the same logical zone across subscriptions may not be physically co-located.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Understanding this is critical for high availability, disaster recovery, compliance, and resilience planning.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;Example&lt;/H1&gt;
&lt;P&gt;sub-prod-eastus-01 -&amp;gt; Zone 1 → az3&lt;BR /&gt;sub-prod-eastus-01 -&amp;gt; Zone 2 → az1&lt;BR /&gt;sub-prod-eastus-01 -&amp;gt; Zone 3 → az2&lt;BR /&gt;sub-prod-weu-01&amp;nbsp; -&amp;gt; Zone 1 → az1&lt;BR /&gt;sub-prod-weu-01&amp;nbsp; -&amp;gt; Zone 2 → az2&lt;BR /&gt;sub-prod-weu-01&amp;nbsp; -&amp;gt; Zone 3 → az3&lt;BR /&gt;&lt;BR /&gt;Key takeaway: &lt;STRONG&gt;Logical zone numbers do not guarantee physical separation across subscriptions.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;What SRE.Azure.com agent Enables&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;- Discover logical-to-physical zone mappings&lt;BR /&gt;- Analyze VM distribution across zones&lt;BR /&gt;- Identify resilience gaps&lt;BR /&gt;- Generate presentation-ready reports&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;Suggested Prompt&lt;/H1&gt;
&lt;P&gt;“Act as an Azure platform engineer and generate a clean, presentation-ready analysis for availability zone design.&lt;BR /&gt;&lt;BR /&gt;For Azure subscription &amp;lt;subscription-id&amp;gt;, produce two outputs inline in chat.&lt;BR /&gt;&lt;BR /&gt;Output 1 — Zone Mapping Summary&lt;BR /&gt;- Query Azure directly for region availability zone mappings&lt;BR /&gt;- Show how logical zones map to physical zones&lt;BR /&gt;- Include a takeaway and tables&lt;BR /&gt;&lt;BR /&gt;Output 2 — VM Resilience Distribution&lt;BR /&gt;- List VMs with zone, physical mapping, and protection level&lt;BR /&gt;&lt;BR /&gt;Formatting:&lt;BR /&gt;- Use markdown tables&lt;BR /&gt;- No raw JSON&lt;BR /&gt;- Screenshot-friendly layout&lt;BR /&gt;- End with 3 observations”&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And so on ……&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Next Steps:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sre.azure.com/docs/get-started" target="_blank"&gt;Get Started | Azure SRE Agent&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sre.azure.com/docs/overview" target="_blank"&gt;What is SRE Agent? | Azure SRE Agent&lt;/A&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 19:50:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/azure-availability-zone-mapping-and-vm-resilience-analysis/ba-p/4526548</guid>
      <dc:creator>munieswar_avulapalli</dc:creator>
      <dc:date>2026-06-08T19:50:35Z</dc:date>
    </item>
    <item>
      <title>Microsoft 365 Copilot on mobile: What staged rollout plans can miss</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/microsoft-365-copilot-on-mobile-what-staged-rollout-plans-can/ba-p/4524953</link>
      <description>&lt;P&gt;IT teams often design rollout plans in careful stages: the right pilot group, the right prerequisites, the right communications, and the right guardrails. Sequencing matters.&lt;/P&gt;
&lt;P&gt;But when &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2367200" target="_blank"&gt;Microsoft 365 Copilot on mobile&lt;/A&gt; shows up in your environment, the shape of adoption can change.&lt;/P&gt;
&lt;P&gt;Employee behavior doesn’t always follow the same tidy stages as licensing or deployment plans. Once people can use Copilot in the moments where work actually happens—between meetings, on the go, in a hallway conversation, before a customer call—usage can spread faster, more socially, and less linearly than many rollout models assume.&lt;/P&gt;
&lt;P&gt;You can stage the rollout, but you can’t always stage the &lt;EM&gt;real-world usage pattern&lt;/EM&gt; that follows. And mobile is one of the fastest places that gap shows up.&lt;/P&gt;
&lt;H2&gt;What we’re seeing: mobile changes the moments where Copilot shows up&lt;/H2&gt;
&lt;P&gt;Mobile shifts adoption because it changes the context in which Copilot appears day to day:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot shows up more during “in-between” work moments&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Those moments where people look for quick help: summarizing, drafting, finding, checking, and preparing.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Usage spreads through behavior, not just rollout sequence&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;A teammate shares a faster way to prep for a meeting. A leader asks for a quick recap while traveling. A project team starts referencing Copilot outputs in a chat thread. That kind of spread can move ahead of your staged plan.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Desktop assumptions don’t always carry over cleanly&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Governance, communication, and readiness decisions that feel straightforward in a desktop-first mindset can surface earlier when usage starts in mobile-first ways.&lt;/P&gt;
&lt;P&gt;Taken together, mobile introduces a second force into staged rollout planning: behavioral adoption momentum that doesn’t always wait for the next planned phase.&lt;/P&gt;
&lt;H2&gt;Staged Copilot deployment ≠ staged usage&lt;/H2&gt;
&lt;P&gt;Mobile frequently compresses the “pilot → expand → scale timeline,” creating earlier-than-expected issues:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;IT starts fielding questions about “what’s allowed,” “what’s recommended,” or “what’s safe” before the plan anticipated&lt;/LI&gt;
&lt;LI&gt;Governance and communication become tightly linked. If the org hasn’t expressed expectations and guardrails early and clearly, fast-moving usage can create confusion or conflicting local norms&lt;/LI&gt;
&lt;LI&gt;Rollout plans start competing with reality. Mobile can make Copilot feel “present” in daily work. While IT is still staging rollout, parts of the organization behave like they’re already in broader adoption.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In many environments, this doesn’t stay theoretical for long.&lt;/P&gt;
&lt;H2&gt;What to do: four areas that tend to matter most&lt;/H2&gt;
&lt;P&gt;If you’re planning your Copilot rollout, you’ll want to think through these four connected areas:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Rollout sequencing&lt;/STRONG&gt;: how you stage availability and expansion&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;User behavior expectations&lt;/STRONG&gt;: how adoption may spread, and how you’ll message it&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Governance and readiness considerations&lt;/STRONG&gt;: what needs to be clear before usage accelerates&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Communication planning&lt;/STRONG&gt;: how you set expectations so momentum doesn’t create confusion&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you’re hearing early signals that people are experimenting with Copilot in mobile contexts before the rollout has fully caught up or already seeing pockets of usage spreading faster than expected, use these four as levers for regaining clarity and alignment&lt;/P&gt;
&lt;H2&gt;Next step&lt;/H2&gt;
&lt;P&gt;Read &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2367200" target="_blank"&gt;the full blog&lt;/A&gt; for Microsoft 365 Copilot mobile rollout planning guidance, including how to align sequencing, governance, and communication, whether you’re still designing your rollout approach, or already responding to early signs of faster-than-expected adoption.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Read the full Accelerator blog: &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2367200" target="_blank"&gt;Microsoft 365 Copilot on mobile: Planning guidance for IT admins&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 21:50:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/microsoft-365-copilot-on-mobile-what-staged-rollout-plans-can/ba-p/4524953</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-06-02T21:50:56Z</dc:date>
    </item>
    <item>
      <title>Windows 365 for Agents: run AI agents in Cloud PCs across real applications</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/windows-365-for-agents-run-ai-agents-in-cloud-pcs-across-real/ba-p/4523433</link>
      <description>&lt;P&gt;Copilot agents have been talking the talk—summarizing information, drafting content, and answering questions. But soon they’ll be walking the walk—executing workflows across systems in policy-controlled Cloud PCs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Windows 365 for Agents (now in public preview), you can run AI agents in a secure environment and use natural language to direct them to work across software and complete tasks, such as processing invoices or updating CRM data.&lt;/P&gt;
&lt;H2&gt;What’s changing?&lt;/H2&gt;
&lt;P&gt;It may sound like a small shift, but Windows 365 for Agents introduces a fundamentally different runtime model.&lt;/P&gt;
&lt;P&gt;For the first time, you’ll be able to automate workflows that live &lt;EM&gt;outside&lt;/EM&gt; APIs across real applications—including legacy and UI-based systems—without giving up enterprise security or control.&lt;/P&gt;
&lt;P&gt;Much of today’s work still lives in browsers, desktop apps, and legacy systems—environments that assume intentional, human behavior. But agents behave differently:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Humans operate intermittently and with judgment&lt;/LI&gt;
&lt;LI&gt;Agents can operate continuously and at scale&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Agents depend on IT-defined boundaries, such as identity, policy, access, and monitoring, to keep execution aligned with intended workflows.&lt;/P&gt;
&lt;P&gt;Without boundaries, agents can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Access unintended systems&lt;/LI&gt;
&lt;LI&gt;Act beyond their intended scope&lt;/LI&gt;
&lt;LI&gt;Amplify small mistakes across workflows&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Agents need a dedicated execution space designed for autonomous activity but governed by humans by default.&lt;/P&gt;
&lt;H2&gt;Windows 365 for Agents introduces the right execution environment&lt;/H2&gt;
&lt;P&gt;Windows 365 for Agents provides a dedicated Cloud PC environment that lets you define and control agents in various ways:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Independently and continuously, or on demand&lt;/LI&gt;
&lt;LI&gt;Under your existing identity, policy, and management controls, such as Microsoft Entra ID and Intune&lt;/LI&gt;
&lt;LI&gt;As repeatable, multi-step workflows across real applications, including legacy and UI-based systems, within the boundaries you set&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Running agents in this controlled environment helps isolate risk and enforce security boundaries so act autonomously while remaining fully governed by your policies and without negatively impacting production systems.&lt;/P&gt;
&lt;H2&gt;Get started with Windows 365 for Agents&lt;/H2&gt;
&lt;P&gt;Interested in how this works and what Windows 365 for Agents unlocks for your environment? Read full blog, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2365820" target="_blank"&gt;Windows 365 for Agents: run AI agents on secure cloud PCs&lt;/A&gt;, to learn more.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 01:04:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/windows-365-for-agents-run-ai-agents-in-cloud-pcs-across-real/ba-p/4523433</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-05-28T01:04:03Z</dc:date>
    </item>
    <item>
      <title>Deploying DNS Private Resolvers and Private DNS Zones for Azure AI Supported Services</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/deploying-dns-private-resolvers-and-private-dns-zones-for-azure/ba-p/4515645</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Private Networks:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Private DNS Zones:&lt;/STRONG&gt; Resolves domain names to private IPs within Azure virtual networks without exposing them to the internet. Private DNS Zones are global, you don’t need to create multiple same private DNS Zones, you can reuse the same zones as it’s global&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;DNS Private Resolvers:&lt;/STRONG&gt; Fully managed service that enables DNS resolution between Azure VNets and on-premises networks without custom DNS servers. DNS Private resolvers are regional, which means if you have Azure EAST US and WEST US 2 regions, you need to create DNS Private resolvers in both regions linked to Private DNS Zones, you can adopt centralized or distributed DNS Private resolvers, I will discuss both options later in this article&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Public Networks:&lt;/STRONG&gt; &amp;lt;In this part – not focusing on Public Networks&amp;gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Public DNS Zones:&lt;/STRONG&gt; Resolves internet-facing domain names to publicly accessible IP addresses&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Traffic Managers:&lt;/STRONG&gt; DNS-based traffic load balancer that routes client requests to the best available global endpoint&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;DNS Security Policy:&lt;/STRONG&gt; Controls and protects DNS resolution behavior (e.g., filtering, forwarding, and access rules) to secure name resolution and prevent misuse&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;**Note:&lt;/STRONG&gt; &lt;STRONG&gt;1. Follow Prerequisites to deploy resources. 2. A common misconception is that VNet peering enables DNS resolution. In reality, private DNS zones are only accessible to VNets that are explicitly linked to them, peering provides connectivity, but not name resolution.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In the following snapshot à Azure Portal à Network Foundations à DNS, lets explore individual DNS Services offered and later in this document, we will interconnect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;**Credits to Microsoft Azure Portal Design&lt;/STRONG&gt; &lt;STRONG&gt;team&lt;/STRONG&gt; for creating new grouped views – you can check out for more – like compute infrastructure, Hybrid, Backup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, let’s delve into &lt;STRONG&gt;scenario 01&lt;/STRONG&gt;: I have grabbed the following snapshot from &lt;A href="https://azure.github.io/AI-Landing-Zones/#reference-architectures" target="_blank" rel="noopener"&gt;Azure AI Landing Zones&lt;/A&gt; and removed non-network Azure resources to focus only on private Network components,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;**Credits to AI Landing Zone team for the diagram, Original Version: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Inbound Zoom in view with End-to-End Flow &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Hop&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Summary&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Client initiates request&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;DNS query sent to on-prem DNS&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;3&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;DNS query forwarded to Azure&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;4&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Azure DNS Resolver processes query&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;5&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Private DNS resolves to Private Endpoint IP&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;6&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Traffic routed via VNet peering&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;7&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Traffic hits Private Endpoint&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;8&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Request served by Azure Files&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;*Link Private DNS to DNS resolvers in other regions, Private DNS is GLOBAL and DNS Resolvers are regional&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Example Snapshot of entire flow:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;Nslookup from Client machine, &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Domain – DNS Conditional Forwarder configuration &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Note 1: Make sure you selected “All DNS Servers in this forest” for replication, otherwise users pointed to some other domain will be unable to resolve &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Verifying Connectivity with PsPing &amp;lt;credit to Sysinternals team &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/sysinternals/downloads/psping" target="_blank" rel="noopener"&gt;PsPing &amp;nbsp;&lt;/A&gt;&amp;gt; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;PsPing, a tool from Sysinternals, is highly effective for verifying network connectivity from on-premises environments to Azure resources on specific ports. This is particularly useful when you need to ensure connectivity to ports such as 445, 443, 1433, 1521, or any other port required by Azure services you intend to access from either on-premises locations or other cloud environments.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;By using PsPing, you can test and confirm that the necessary ports are open and accessible, which is crucial for troubleshooting connectivity issues and ensuring smooth communication between your on-premises infrastructure and Azure-hosted resources.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Ensure your firewall is set to allow traffic&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;DNS private resolvers – inbound configuration &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Private DNS Configuration &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Virtual Network links enable to your private dns &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="6"&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Make sure you have peer between hub and spoke &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;Private Endpoint configuration &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="8"&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;SPAN class="lia-text-color-6"&gt;&lt;STRONG&gt;Storage Account configuration &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-8"&gt;&lt;STRONG&gt;“Replace the file share with any supported Azure service that uses Private Endpoints, and follow the same guidance.”&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;STRONG&gt;&amp;nbsp;2. &lt;/STRONG&gt;&lt;STRONG&gt;Outbound &amp;lt;flow and resources colored with blue&amp;gt; part 2 upcoming soon &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 19:24:54 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/deploying-dns-private-resolvers-and-private-dns-zones-for-azure/ba-p/4515645</guid>
      <dc:creator>munieswar_avulapalli</dc:creator>
      <dc:date>2026-04-28T19:24:54Z</dc:date>
    </item>
    <item>
      <title>Copilot agents are scaling faster than most organizations expected</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-agents-are-scaling-faster-than-most-organizations/ba-p/4510366</link>
      <description>&lt;P&gt;Copilot agents are easy to pilot.&lt;/P&gt;
&lt;P&gt;Across organizations, teams are building agents to automate tasks, surface insights, and streamline everyday work. Early results are positive—and encouraging. One agent leads to another. Interest spreads. Adoption grows.&lt;/P&gt;
&lt;P&gt;Then a different question starts to surface:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What happens when Copilot agents move beyond experiments and start to scale across the organization?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;That’s where things are getting more complicated.&lt;/P&gt;
&lt;H2&gt;When success creates a new problem&lt;/H2&gt;
&lt;P&gt;In early stages, conversations about Copilot agents focus on &lt;EM&gt;how &lt;/EM&gt;to build, with questions centering on tools, prompts, and connectors. As usage expands, the challenge shifts away from delivery and toward coordination.&lt;/P&gt;
&lt;P&gt;Organizations see signals like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Multiple teams building agents independently&lt;/LI&gt;
&lt;LI&gt;Overlapping use cases with different risk profiles&lt;/LI&gt;
&lt;LI&gt;Unclear ownership as agents move into shared workflows&lt;/LI&gt;
&lt;LI&gt;Hesitation around approving the next agent&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These aren’t failures. They’re signs that agent usage is becoming meaningful enough to require intent, especially at an enterprise level.&lt;/P&gt;
&lt;H2&gt;Why scale changes the conversation&lt;/H2&gt;
&lt;P&gt;As Copilot agents move from isolated experiments to shared enterprise capability, the conversation shifts. The challenge is no longer just how to deliver agents, but how—and which—agents the organization should operate at scale.&lt;/P&gt;
&lt;P&gt;That shift introduces tradeoffs that rarely appear during pilot phases:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How much autonomy should teams retain?&lt;/LI&gt;
&lt;LI&gt;Where does consistency start to matter?&lt;/LI&gt;
&lt;LI&gt;How should we support experimentation without creating fragmentation?&lt;/LI&gt;
&lt;LI&gt;How can leadership stay aligned as impact grows?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Without a shared way to reason through these decisions, choices begin to outpace clarity.&lt;/P&gt;
&lt;P&gt;This is where many IT and business leaders pause. Not to stop innovation, but to ask a more fundamental question:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What does “scaling well” actually look like for us?&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;A CIO‑level framework for deliberate scale&lt;/H2&gt;
&lt;P&gt;Organizations that recognize themselves at this inflection point will want to read Microsoft’s Accelerator article, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2359369" target="_blank" rel="noopener"&gt;&lt;EM&gt;A CIO framework for scaling Copilot agents&lt;/EM&gt;&lt;/A&gt;—a CIO‑level perspective designed for when agent adoption begins to scale.&lt;/P&gt;
&lt;P&gt;The framework explores:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What changes as agents move from pilots to enterprise capability&lt;/LI&gt;
&lt;LI&gt;How leadership decisions evolve with scale&lt;/LI&gt;
&lt;LI&gt;How to balance flexibility with coherence&lt;/LI&gt;
&lt;LI&gt;How to guide growth before friction sets in&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It’s framed for CIOs and senior IT leaders who are thinking beyond approving the next agent build, who are focusing now on aligning teams, expectations, and operating models at scale.&lt;/P&gt;
&lt;P&gt;👉 Read &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2359369" target="_blank" rel="noopener"&gt;the full framework on Microsoft 365 Accelerator&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Discussion&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What signals tell you it’s time to move from experimenting with agents to planning for scale?&lt;/LI&gt;
&lt;LI&gt;Where does agent growth create the most tension in your organization today?&lt;/LI&gt;
&lt;LI&gt;What’s the one decision you wish had been clearer earlier in your agent journey?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft 365 Accelerator is where planning conversations go deeper.&lt;/STRONG&gt;&lt;BR /&gt;If your organization is moving from &lt;EM&gt;“can we build this?”&lt;/EM&gt; to &lt;EM&gt;“how do we scale this responsibly?”&lt;/EM&gt;, Accelerator is where you want to go next.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 17:53:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-agents-are-scaling-faster-than-most-organizations/ba-p/4510366</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-04-17T17:53:04Z</dc:date>
    </item>
    <item>
      <title>Copilot Chat in financial services: 
Is productivity moving faster than policy?</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-chat-in-financial-services-is-productivity-moving-faster/ba-p/4510910</link>
      <description>&lt;P&gt;In financial services, it's rarely the value of a new technology that slows down adoption.&amp;nbsp;More often, it's when productivity starts to outpace the policies designed to govern it.&lt;/P&gt;
&lt;P&gt;That tension is beginning to surface with Copilot Chat.&lt;/P&gt;
&lt;P&gt;Teams are finding real efficiency gains—faster research, clearer summaries, better preparation—while leaders ask a different question:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;What does responsible, repeatable adoption look like once usage expands across regulated roles?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Those conversations usually appear when Copilot Chat becomes operational enough that ad hoc decisions feel insufficient.&lt;/P&gt;
&lt;P&gt;A new post on&amp;nbsp;&lt;STRONG&gt;Microsoft 365 Accelerator&lt;/STRONG&gt; is designed for that exact moment. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2358982" target="_blank"&gt;How financial leaders are scaling Microsoft 365 Copilot Chat without increasing risk&lt;/A&gt; introduces a planning kit that shows financial services leaders how to scale Copilot Chat usage while keeping governance, audit readiness, and oversight intact.&lt;/P&gt;
&lt;P&gt;Instead of features, the kit is focused on the decisions and guardrails that help organizations move forward and use Copilot Chat with confidence.&lt;/P&gt;
&lt;P&gt;If you’re seeing strong demand from business teams and equally strong questions from risk or compliance teams, this kind of guidance brings those conversations together.&lt;/P&gt;
&lt;P&gt;👉 &lt;STRONG&gt;Read &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2358982" target="_blank"&gt;the full planning guidance and explore the Copilot Chat kit &lt;/A&gt;on Microsoft 365 Accelerator.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;We'd like to know:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;At what point did Copilot Chat usage in your organization start raising governance or policy questions?&lt;/LI&gt;
&lt;LI&gt;Which decisions felt easy during early experimentation but harder once Copilot Chat became more widely used?&lt;/LI&gt;
&lt;LI&gt;How are you thinking about ownership and oversight as Copilot Chat moves beyond individual use cases?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Tell us in the comments below.&lt;/P&gt;
&lt;P&gt;If this discussion feels familiar, you’re not alone. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2359157" target="_blank"&gt;Microsoft 365 Accelerator&lt;/A&gt; is designed for the next phase—when teams start asking not just &lt;EM&gt;can we&lt;/EM&gt;, but &lt;EM&gt;how do we do this well&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 16:49:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-chat-in-financial-services-is-productivity-moving-faster/ba-p/4510910</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-04-13T16:49:44Z</dc:date>
    </item>
    <item>
      <title>Modernizing On‑Prem File Servers: Azure Storage Mover and File Sync</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/modernizing-on-prem-file-servers-azure-storage-mover-and-file/ba-p/4500204</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Azure File Sync&lt;/STRONG&gt; is a hybrid cloud storage service that centralizes on-premises file shares into Azure Files while preserving the experience of a local Windows file server. It installs an agent on Windows Server(s) to cache and sync files to an Azure file share (the cloud backend). Key features include cloud tiering (keeping only hot files on-prem and tiering cold data to Azure) and multi-site synchronization, so changes propagate across servers via the cloud. In essence, Azure File Sync transforms your file server into a cache for Azure, providing continuous two-way sync between on-premises and the Azure file share.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Storage Mover&lt;/STRONG&gt; is a fully managed migration service used to transfer file data into Azure Storage (Azure Blob containers or Azure file shares) with minimal downtime. It works by deploying a migration agent near the source storage, which then copies data directly to Azure. The cloud-based Storage Mover resource orchestrates migrations (including initial bulk transfer and optional delta syncs for changes) across multiple shares from a central interface. Unlike File Sync, Storage Mover is not a continuous sync service but rather a one-directional data mover for scenarios like one-time migrations or periodic updates.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Side-by-Side Technical Comparison&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Aspect&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure File Sync&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Storage Mover&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Primary Purpose&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Hybrid file service&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt; Ongoing two-way sync between on-prem file servers and Azure Files, enabling local caching and multi-site data sharing.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Migration tool&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt; One-way transfers of file data from on-prem (or other storage) to Azure Storage, optimized for lift-and-shift migrations with minimal downtime.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Architecture&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Agent on Windows Server connects local NTFS volumes to an Azure File Share (cloud endpoint). The Azure Storage Sync Service coordinates sync across servers in a sync group. Supports cloud tiering to offload cold files to cloud. Sync is continuous and multi-directional (all endpoints stay in sync).&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Cloud service + on-prem agent: An Azure Storage Mover resource manages migration jobs. Lightweight migration agents (VMs or containers) run near your sources, sending data directly to the Azure target (Blob or File share). The service orchestrates project-based migrations but does not keep sources in sync after completion.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Sources&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Windows file servers (NTFS), accessed via SMB/NFS protocols (the agent needs Windows Server OS). Ideal for Windows-based file shares.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;SMB shares, NFS exports, and similar file systems on any platform (Windows or Linux NAS). Also supports migrating from other clouds’ storage (e.g., S3 buckets) into Azure. Broad support for heterogeneous sources.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Supported Targets&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Azure Files only. (Cloud endpoint is an Azure file share in a Storage Account). Supports SMB (and NFS 4.1 Azure file shares in preview) as target share types.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Azure Storage (Blob containers or Azure file shares). For example, can migrate into an Azure Blob (ADLS Gen2) container or an Azure File share depending on scenario.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Sync vs. Migration&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Continuous Sync: Bi-directional; changes on-prem or in Azure propagate to all endpoints. Designed for long-term hybrid operation, not just a one-time move.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Batch Migration: One-time or repeated transfer; not a live sync. Typically used to move data entirely to Azure (cutover once done). Supports incremental (delta) syncs to capture changes between migration runs.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Performance &amp;amp; Scale&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Scales to large datasets (tested up to 100 million files per sync group). Throughput can reach hundreds of files/sec for upload/download given sufficient resources. Performance depends on server hardware, network, and Azure Files limits.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Built to handle high-volume migrations (100M+ files). Can scale out by deploying multiple agents or using bigger VMs to increase throughput. Performance mainly limited by network bandwidth and source/target IOPS and can be optimized by parallel jobs and delta sync workflows.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Integration&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Deep integration with Azure Files (the back-end store) and Windows Server. Works with Azure Backup for centralized backups or using file share snapshots. Leverages Azure’s redundancy (LRS/ZRS/GRS) for durability; supports Azure AD DS for identity integration to maintain ACLs in cloud.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Integrated with Azure Arc (for agent management) and can combine with Azure Data Box for hybrid migrations (offline + online phases). Managed using Azure Portal and CLI, provides logging/monitoring through Azure Monitor for migration jobs. No ongoing infrastructure after migration completes.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Advantages of Azure File Sync:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Hybrid Cloud Caching:&lt;/STRONG&gt; Retains on-premises low-latency file access (via local Windows servers) while using Azure as central storage. End users and apps continue using a local file server interface.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud Tiering &amp;amp; Storage Efficiency:&lt;/STRONG&gt; Frees up local storage by tiering infrequently used files to Azure. This reduces on-prem disk usage without sacrificing access to full dataset (files are pulled from cloud on demand).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Multi-site Sync &amp;amp; Collaboration:&lt;/STRONG&gt; Enables near-real-time sync across multiple servers/sites via Azure hub. Great for distributed teams sharing a common file set, replacing need for complex DFS-R setups or manual transfers.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Minimal Disruption Migration:&lt;/STRONG&gt; Can be used as a no-downtime migration path to Azure Files – sync in background, then cut over clients to the Azure share with identical structure and ACLs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Advantages of Azure Storage Mover:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Purpose-Built for Migration:&lt;/STRONG&gt; Optimized for transferring data at scale into Azure. Can handle large one-time migrations or scheduled recurrent syncs without continuous agent overhead post-migration. Simplifies multi-terabyte or multi-site migration projects.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Heterogeneous Source Support:&lt;/STRONG&gt; Works with a variety of source types (SMB, NFS shares on any OS) and can migrate into both Azure Files and Azure Blob, providing flexibility that Azure File Sync can’t (e.g., migrating Linux NFS servers or third-party storage to Azure).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Centralized Orchestration:&lt;/STRONG&gt; Cloud architects can manage all migrations via a single Azure Storage Mover resource – with projects &amp;amp; jobs tracking progress per share. Logging, error handling, and coordination are unified, unlike scripting copy operations per server.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Incremental &amp;amp; Low Downtime:&lt;/STRONG&gt; Supports delta synchronization to bring the target up-to-date after an initial bulk copy. This reduces cutover downtime since only last-minute changes need transferring. Also integrates with offline seeding (Data Box) plus online catch-up to minimize network strain and downtime.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Common Use Cases and When to Choose Each&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Azure File Sync – Use Cases:&lt;/STRONG&gt; Ideal when you need to maintain on-premises file server access while leveraging cloud storage. Some common scenarios:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Branch Office File Sharing:&lt;/STRONG&gt; Multiple offices each have a local file server, all synced to a central Azure Files share. Users get fast local access, and the cloud ensures each site’s data stays consistent.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;File Server Augmentation:&lt;/STRONG&gt; You want to extend an existing Windows file server with virtually unlimited cloud capacity (via tiering) rather than fully moving to cloud. Azure File Sync offloads old data and provides cloud backup, but users and apps continue as normal with the local server.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Gradual Migration / Testing:&lt;/STRONG&gt; You plan to eventually migrate to Azure Files but want a seamless, no-downtime transition. Deploy AFS on the server, let it sync all data to cloud, then optionally eliminate the on-prem server later. This way, users never stop accessing their files during the migration process.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Storage Mover – Use Cases:&lt;/STRONG&gt; Best when you have a defined migration project to move file shares to Azure, especially for heterogeneous environments or large volumes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Data Center Exit / Large File Share Migration:&lt;/STRONG&gt; Moving tens or hundreds of TBs of data from on-prem NAS or file servers to Azure Storage as a one-time project. The Storage Mover’s robust scalability and delta-sync capabilities help ensure a smooth transfer with minimal final cutover downtime.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Consolidating Cross-Platform Data to Azure:&lt;/STRONG&gt; If you need to migrate non-Windows file systems (Linux NFS, etc.) or even data from other clouds into Azure, Storage Mover supports those sources out-of-the-box. For example, migrating a Linux file repository into Azure Blob for big data analytics.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Recurring Scheduled Migrations:&lt;/STRONG&gt; In cases where you periodically copy data from on-prem to Azure (e.g., monthly exports from a local system to cloud for archiving), Storage Mover can be run as needed and centrally monitored, without maintaining a constant sync infrastructure in between.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Conclusion&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When to choose which: Use Azure File Sync if your goal is to keep using on-prem servers and need a hybrid solution for the foreseeable future, or if you require distributed caching and continuous sync for collaboration. It’s essentially part of your production architecture for hybrid cloud file storage. Conversely, choose Azure Storage Mover when you want to permanently migrate data into Azure (and possibly decommission on-prem storage), or when dealing with a one-off bulk transfer task. In summary, Azure File Sync is an ongoing hybrid file service, and Azure Storage Mover is a one-time (or scheduled) migration service. Both can complement your cloud strategy, but they address distinct scenarios in a cloud architect’s toolkit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2026 21:46:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/modernizing-on-prem-file-servers-azure-storage-mover-and-file/ba-p/4500204</guid>
      <dc:creator>SriniThumala</dc:creator>
      <dc:date>2026-03-08T21:46:02Z</dc:date>
    </item>
    <item>
      <title>Copilot adoption: Move your org from pilot to production with this guide</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-adoption-move-your-org-from-pilot-to-production-with/ba-p/4495997</link>
      <description>&lt;P&gt;Are you an IT admin or Copilot adoption lead ready to safely start or scale your rollout of Microsoft 365 Copilot?&lt;/P&gt;
&lt;P&gt;Piecing together the right guidance can be something of a treasure hunt so we created a trusted, single starting point for you: &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2353614" target="_blank"&gt;8 Copilot &amp;amp; agent hubs every adoption leader should bookmark&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This guide is organized around the typical adoption lifecycle (plan → build → operate) to help you accelerate your Copilot adoption &lt;EM&gt;without&lt;/EM&gt; skipping governance.&lt;/P&gt;
&lt;P&gt;Inside the guide, you’ll learn:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What each resource hub includes&lt;/STRONG&gt;—and how each maps to plan → build → operate for Copilot.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;How to turn guidance into motion&lt;/STRONG&gt;: Practical steps you can reuse for rollout and change management (not just reference links).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Which resources to share with each audience&lt;/STRONG&gt;—admins, champions, and business sponsors—so everyone stays aligned.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;How to scale with confidence&lt;/STRONG&gt;: Starting points. that support a governed, production-ready Copilot program&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To get started, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2353614" target="_blank"&gt;check out the full post&lt;/A&gt; and bookmark each resource hub today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Did you know?&lt;/H2&gt;
&lt;P&gt;FastTrack helps&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2267193" target="_blank"&gt;eligible customers&lt;/A&gt;&amp;nbsp;with Microsoft 365 Copilot adoption by providing expert guidance, self‑service resources, and structured engagements at no additional cost.&lt;/P&gt;
&lt;P&gt;If your adoption program could use a boost, FastTrack can help.&lt;/P&gt;
&lt;P&gt;Visit the&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347901" target="_blank"&gt;Microsoft 365 Accelerator site&lt;/A&gt;&amp;nbsp;for Copilot quickstart guides, governance templates, and adoption kits—or&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347354" target="_blank"&gt;submit a request for personalized deployment and change management assistance (RFA) from FastTrack&amp;nbsp;&lt;/A&gt;today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 20:32:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-adoption-move-your-org-from-pilot-to-production-with/ba-p/4495997</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-02-19T20:32:15Z</dc:date>
    </item>
    <item>
      <title>The Copilot resource guide to share with your employees</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/the-copilot-resource-guide-to-share-with-your-employees/ba-p/4495989</link>
      <description>&lt;P&gt;From customers driving Microsoft Copilot adoption, one request we hear a lot is: “Can you send me to a simple starting place?”&lt;/P&gt;
&lt;P&gt;Now we can. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2353414" target="_blank" rel="noopener"&gt;Essential Copilot resource hubs for employees&lt;/A&gt; is a trusted, easy-to-share guide that rounds up key Microsoft-owned Copilot learning and support hubs. It's designed to help you speed up Copilot onboarding and get your employees building good habits from day one.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;How to use it with end users&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Adoption leaders:&lt;/STRONG&gt; Use the hubs to structure learning paths (new user onboarding, prompting basics, role-based scenarios) and reinforce them in champions and community programs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;IT admins:&lt;/STRONG&gt; Add a link to the guide in your rollout emails, intranet, and helpdesk macros so employees have a consistent “start here” link.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Everyone:&lt;/STRONG&gt; Share this as one source of truth, then keep your internal guidance focused on what’s unique to your organization (policies, approved use cases, and where to get help).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For more information about this simple approach that scales, read the guide: &lt;A href="https://go.microsoft.com/fwlink/?linkid=2353414" target="_blank"&gt;Essential Copilot resource hubs for employees&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Need help?&lt;/H2&gt;
&lt;P&gt;FastTrack helps&amp;nbsp;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267193" target="_blank" rel="noopener"&gt;eligible customers&lt;/A&gt;&amp;nbsp;with Microsoft 365 Copilot adoption by providing expert guidance, self‑service resources, and structured engagements at no additional cost.&lt;/P&gt;
&lt;P&gt;If your adoption program could use a boost, visit the&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347901" target="_blank" rel="noopener"&gt;Microsoft 365 Accelerator site&lt;/A&gt; for Copilot quickstart guides, governance templates, and adoption kits. Or,&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347354" target="_blank" rel="noopener"&gt;submit a request for personalized deployment and change management assistance (RFA) from FastTrack&amp;nbsp;&lt;/A&gt;today.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 20:01:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/the-copilot-resource-guide-to-share-with-your-employees/ba-p/4495989</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-02-19T20:01:33Z</dc:date>
    </item>
    <item>
      <title>Intermittent Delay in Loading Files Tab in Microsoft Teams Channels</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-for-microsoft-365/intermittent-delay-in-loading-files-tab-in-microsoft-teams/m-p/4460354#M420</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Within our municipality, we are experiencing an intermittent issue where the &lt;STRONG&gt;Files tab in Microsoft Teams channels takes &amp;gt;5 seconds to load&lt;/STRONG&gt;. This behavior appears to be random and is not tied to specific users, devices, or locations. We have conducted several internal checks and can confirm the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The issue occurs in both small and large Teams channels, regardless of the number of files or folders.&lt;/LI&gt;&lt;LI&gt;It affects various Surface laptops, so it does not appear to be device-specific.&lt;/LI&gt;&lt;LI&gt;It happens both inside and outside our municipal buildings, ruling out local network dependency.&lt;/LI&gt;&lt;LI&gt;We exclusively use Microsoft products, including Surface devices, Microsoft Defender, and Intune for device management.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;We would like to know:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is this a known issue within Microsoft Teams?&lt;/LI&gt;&lt;LI&gt;Are there specific &lt;STRONG&gt;tenant-level settings&lt;/STRONG&gt; or &lt;STRONG&gt;Intune configurations&lt;/STRONG&gt; that could influence the performance of the Files tab?&lt;/LI&gt;&lt;LI&gt;Are there any recommended diagnostics or optimizations we can apply to improve consistency?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We appreciate any guidance or insights you can provide.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;BR /&gt;&lt;STRONG&gt;Dick Noort&lt;/STRONG&gt;&lt;BR /&gt;Advisor Information Services&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 13:20:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-for-microsoft-365/intermittent-delay-in-loading-files-tab-in-microsoft-teams/m-p/4460354#M420</guid>
      <dc:creator>dicknoort715</dc:creator>
      <dc:date>2025-10-09T13:20:31Z</dc:date>
    </item>
    <item>
      <title>Ready to accelerate your Zero Trust journey? Discover what’s next</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/ready-to-accelerate-your-zero-trust-journey-discover-what-s-next/ba-p/4458866</link>
      <description>&lt;P&gt;&lt;STRONG&gt;For admins | &lt;/STRONG&gt;&lt;STRONG&gt;1-minute read&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Zero Trust isn’t just a security buzzword—it’s the new baseline for protecting your organization in a world where threats are always evolving.&lt;/P&gt;
&lt;P&gt;But what does it &lt;EM&gt;really&lt;/EM&gt; take to move from strategy to action?&lt;/P&gt;
&lt;P&gt;Find out by reading our recent blog, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2337627" target="_blank" rel="noopener"&gt;Accelerate your Zero Trust journey: Using the Microsoft Zero Trust workshop for impact&lt;/A&gt; on the M365 Accelerator site. In it, we break down some of the real-world challenges IT admins face and show how this hands-on workshop can help you build a clear roadmap forward.&lt;/P&gt;
&lt;P&gt;For example, learn how you can use the workshop to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess and improve your security posture by &lt;/STRONG&gt;evaluating your organization’s current security maturity across six critical Zero Trust pillars (Identity, Devices, Data, Network, Infrastructure, Security Operations), identify gaps, and prioritize actions for improvement.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Drive cross-team alignment and executive buy-in&lt;/STRONG&gt; by bringing together stakeholders from security, infrastructure, networking, and compliance for communication, consensus building, and creating a data-driven roadmap that resonates with leadership.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Turn security strategy into actionable results with &lt;/STRONG&gt;practical steps for leveraging the Zero Trust Workshop to transform security from a reactive task into a proactive, strategic advantage for your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Next steps&lt;/H1&gt;
&lt;P&gt;Ready to move beyond theory and see how Microsoft’s approach can help you secure identities, apps, and data?&lt;/P&gt;
&lt;P&gt;Then &lt;STRONG&gt;Accelerate your Zero Trust journey&lt;/STRONG&gt; is your next must-read.&lt;/P&gt;
&lt;P&gt;Get the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2337627" target="_blank" rel="noopener"&gt;full story and workshop details here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 16:40:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/ready-to-accelerate-your-zero-trust-journey-discover-what-s-next/ba-p/4458866</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-10-03T16:40:32Z</dc:date>
    </item>
    <item>
      <title>Governing Copilot agents: Your next step starts here</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/governing-copilot-agents-your-next-step-starts-here/ba-p/4446182</link>
      <description>&lt;P&gt;For those of you navigating this shift, Rob Howard, Microsoft’s VP of Product Management for Microsoft 365 Copilot Extensibility, offers a practical governance framework in his article, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2333222" target="_blank" rel="noopener"&gt;&lt;EM&gt;What IT admins need to know about governing AI agents&lt;/EM&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The article introduces three key governance pillars:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Security controls&lt;/STRONG&gt; using Microsoft Purview.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Management controls&lt;/STRONG&gt; through admin centers and deployment planning.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent reporting&lt;/STRONG&gt; to monitor usage and stay ahead of compliance.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You’ll also get a first look at governance zones—a planning model to help segment Copilot deployment based on your organization’s risk tolerance and data sensitivity. Think sandbox, controlled, and trusted zones, with guidance on how to phase rollout.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What else you’ll find:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;A checklist &lt;/STRONG&gt;to assess your readiness.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Real-world examples &lt;/STRONG&gt;of phased deployment.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Links to tools you already use&lt;/STRONG&gt;, like Purview, Power Platform admin center, and Microsoft 365 admin center.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A preview&lt;/STRONG&gt; of the upcoming white paper and webinar.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Next Steps&lt;/H2&gt;
&lt;P&gt;Ready to securely and strategically lead your organization into the future of AI?&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2333222" target="_blank" rel="noopener" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}"&gt;Read Rob’s blog&lt;/A&gt; today for reliable advice on governing Copilot agents. It’s part of a broader initiative by FastTrack for Microsoft 365 to support IT admins with actionable, admin-relevant content on governing Copilot AI agents—so stay tuned for future articles, webinars, and more on the topic!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 23:42:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/governing-copilot-agents-your-next-step-starts-here/ba-p/4446182</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-08-22T23:42:47Z</dc:date>
    </item>
    <item>
      <title>Bring AI out of the shadows with agents for Microsoft 365 Copilot Chat</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/bring-ai-out-of-the-shadows-with-agents-for-microsoft-365/ba-p/4426846</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For IT admins and Microsoft 365 admins&lt;/STRONG&gt;&lt;BR /&gt;7-minute read&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Shadow AI is almost certainly happening across your organization—whether you can see it or not. Employees are using tools like ChatGPT and Notion AI to get work done, even without organizational knowledge or approval. This creates real risks like data leakage, compliance violations, and a lack of visibility into how employees are using artificial intelligence.&lt;/P&gt;
&lt;P&gt;Fortunately, IT admins are in a unique position to fix the problem at its core.&lt;/P&gt;
&lt;P&gt;Today's article is intended to be a practical playbook for helping IT admins lead the charge toward responsible AI use in their organizations by empowering secure, compliant, and easy-to-manage agents for Microsoft 365 Copilot Chat.&lt;/P&gt;
&lt;H2&gt;What is shadow AI?&lt;/H2&gt;
&lt;P&gt;Like shadow IT, the term ‘shadow AI’ exists for a reason: it refers to unsanctioned, often hidden, use of AI tools.&lt;/P&gt;
&lt;P&gt;In the shadows, artificial intelligence can be hard to detect and even harder to govern. Tools can be browser-based, embedded in SaaS apps, or used on personal devices. Controls that mitigate shadow IT—like app blocking or firewall rules—don’t necessarily translate to AI use.&lt;/P&gt;
&lt;P&gt;Both shadow IT and shadow AI involve technical and behavioral elements, however unauthorized use of AI presents deeper behavioral challenges beyond unauthorized tools. These challenges center around how users make decisions and potentially bypass governance in ways that are harder to detect and control.&lt;/P&gt;
&lt;P&gt;While employees may not &lt;EM&gt;want&lt;/EM&gt; to go rogue or bypass IT—and they generally don’t want to put the organization at risk—they do want to get their work done efficiently. They turn to public AI tools when &lt;EM&gt;they can’t find the capabilities they need inside the tools they have permission to use&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;Agents for Microsoft 365 Copilot Chat give you a way to lead AI use into the light and meet your users’ needs with &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2325458" target="_blank" rel="noopener"&gt;modern AI business tools&lt;/A&gt;. By building and deploying task-specific, data-grounded chat experiences that live inside Microsoft 365, users get fast, relevant answers they’re looking for&amp;nbsp;&lt;EM&gt;without having to step into the shadows and leave the secure environment you manage&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;These agents are part of the broader Microsoft 365 Copilot ecosystem and are designed to automate and execute business processes directly within Copilot Chat.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Should you ignore or even allow shadow AI?&lt;/H2&gt;
&lt;P&gt;When employees use public AI tools without oversight, they create risks that are harder to detect, harder to govern, and harder to reverse.&lt;/P&gt;
&lt;P&gt;For IT admins, the stakes are high for operational, security, and technical risks:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Loss of visibility and control: &lt;/STRONG&gt;You can’t protect what you can’t see.&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Shadow AI obscures oversight.&lt;/STRONG&gt; It’s harder to track usage or enforce policies for tools used outside your environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;No centralized monitoring = no control.&lt;/STRONG&gt;&amp;nbsp;Without a unified view, you can’t troubleshoot issues, optimize usage, or step in when something goes wrong.&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Shadow data silos emerge.&lt;/STRONG&gt; Generative AI content created outside your tenant isn’t retained or governed, which complicates lifecycle management, legal holds, and compliance requests.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt; Security and compliance risks&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Enterprise-grade protections are lacking.&lt;/STRONG&gt; Most public AI tools don’t support conditional access, audit logs, or data loss prevention (DLP) policies, leaving you with blind spots and increased risk of data leaks.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Sensitive data exposure.&lt;/STRONG&gt; Employees may unknowingly input proprietary or regulated data into public models, risking violations of GDPR, HIPAA, or internal policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Compliance gaps.&lt;/STRONG&gt; If tools aren’t tracked or documented, they increase the burden of proving compliance and can become major liabilities during audits or regulatory reviews.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt; IT and governance challenges&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IT is out of the loop.&lt;/STRONG&gt; Adoption of unauthorized AI tools sidelines IT, preventing teams from recommending secure, supported alternatives or aligning tools with organizational standards. When users go rogue with AI tools, they aren't using recommended secure, supported options that align with your environment and policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tool sprawl = more support tickets&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt; Unapproved tools often lack integration with existing systems, creating support burdens and increasing the risk of misconfigurations.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Bottom line&lt;/STRONG&gt;: Allowing or ignoring shadow AI will make it much harder to manage later. That’s why Copilot Chat agents, combined with strong governance and user education, are such a powerful response: they give you a way to meet end user demand without losing control.&lt;/P&gt;
&lt;H3&gt;What IT admins are up against&lt;/H3&gt;
&lt;P&gt;When it comes to eradicating rogue AI, admins have their work cut out for them. Here’s a summary table of how activating Copilot Chat agents at your organization can help stem the tide:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5 lia-border-color-10 lia-border-style-outset" border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Unsanctioned AI use contributes to:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;How to stem the problem:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Loss of visibility and control&lt;/STRONG&gt;&lt;BR /&gt;Employees use unsanctioned AI tools.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Reframe shadow AI as a signal&lt;/STRONG&gt;&lt;BR /&gt;Offer sanctioned tools that meet user needs and bring AI usage into the light.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Data governance gaps&lt;/STRONG&gt;&lt;BR /&gt;Unapproved tools bypass DLP and compliance policies.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Keep data in your tenant&lt;/STRONG&gt;&lt;BR /&gt;Copilot agents respect Microsoft 365 compliance, identity, and data boundaries.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Inconsistent AI use across teams&lt;/STRONG&gt;&lt;BR /&gt;Different tools create fragmented workflows.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Centralize AI access&lt;/STRONG&gt;&lt;BR /&gt;Deploy agents across Teams and Microsoft 365 to unify usage.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Security and compliance risks&lt;/STRONG&gt;&lt;BR /&gt;Shadow tools may not meet regulatory standards.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Use enterprise-grade protection&lt;/STRONG&gt;&lt;BR /&gt;Copilot agents are authenticated with Azure AD and governed by Microsoft Purview.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Lack of deployment clarity&lt;/STRONG&gt;&lt;BR /&gt;Admins may not know where to start.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Follow a clear blueprint&lt;/STRONG&gt;&lt;BR /&gt;This blog outlines steps for setup, governance, and scaling.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Missed innovation opportunities&lt;/STRONG&gt;&lt;BR /&gt;IT is seen as a blocker, not a partner.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Support safe innovation&lt;/STRONG&gt;&lt;BR /&gt;Let business units build AI chat agents with IT guardrails in place.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Copilot Chat agents remove the roadblocks to getting value from AI&lt;/H3&gt;
&lt;P&gt;Microsoft's chat agents aren’t just another AI tool—they’re designed to work the way IT works.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure by design&lt;/STRONG&gt;: Agents run inside your Microsoft 365 tenant and authenticate through Azure AD.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Compliant by default&lt;/STRONG&gt;: They respect DLP and audit policies and retention through Microsoft Purview.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Customizable and governable&lt;/STRONG&gt;: You can define access, data sources, and usage policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Easy to deploy&lt;/STRONG&gt;: Agents live inside Teams and Microsoft apps, so users don’t need to install anything new.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Copilot Chat agents strengthen governance&lt;/H3&gt;
&lt;P&gt;While Copilot for Microsoft 365 helps users work more efficiently inside apps like Word, Excel, and Teams, Copilot's AI agents go a step further. They give IT the ability to create task-specific, role-based, and data-grounded AI experiences that directly replace the kinds of tools employees might otherwise seek out on their own.&lt;/P&gt;
&lt;H3&gt;Key deployment benefits for IT admins&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5 lia-border-color-10 lia-border-style-inset" border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Benefit&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Visibility&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Know who’s using AI, how, and with what data.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Control&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Define and enforce usage policies.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Compliance&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Align AI use with regulatory standards.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Efficiency&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Reduce support tickets with self-service agents.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Innovation&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Empower business units without losing oversight.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Take the next step&lt;/H2&gt;
&lt;P&gt;Like shadow IT, you may not get rid of shadow AI completely or overnight. But you can meet it head-on with tools that work for your users and comply with your policies.&lt;/P&gt;
&lt;P&gt;Start by deploying a few AI Chat agents in high-impact areas. Use the resources in this article to guide your rollout.&lt;/P&gt;
&lt;P&gt;With Copilot Chat agents, you’re not just solving a technical problem. You’re leading your organization toward safer, smarter AI adoption.&lt;/P&gt;
&lt;H3&gt;Tools that make it easier&lt;/H3&gt;
&lt;P&gt;When it comes to Microsoft 365 deployments, you’re never alone. FastTrack for Microsoft 365 offers a full set of resources to help you learn about, build, manage, and instruct end users on Copilot Chat agents:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Credentialed access, sign in required:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2238685" target="_blank" rel="noopener"&gt;Microsoft 365 advanced deployment guides and assistance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 Copilot onboarding hub&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 Copilot: Quickstart, Copilot Chat licensing&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Open access, no sign-in required:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Get started with &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2320131" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot extensibility&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2297292" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot ADG: Streamlining your Copilot journey&lt;/A&gt; (video)&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2325519" target="_blank" rel="noopener"&gt;Copilot Chat Success Kit &lt;/A&gt;– Microsoft Adoption&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://aka.ms/CopilotM365SetupDB" target="_blank" rel="noopener"&gt;Microsoft Copilot AI setup and usage guides&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2325458" target="_blank" rel="noopener"&gt;AI in business: Artificial intelligence tools &amp;amp; solutions&lt;/A&gt; (blog)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://setup.cloud.microsoft/microsoft-365-fasttrack-assistance" target="_blank" rel="noopener"&gt;Request assistance from FastTrack&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Deployment blueprint: Get started today&lt;/H2&gt;
&lt;P&gt;Remember: You don’t need to roll out everything at once. Start small, build momentum, and scale responsibly.&lt;/P&gt;
&lt;P&gt;Here’s a blueprint that will get you to the finish line:&lt;/P&gt;
&lt;H3&gt;Copilot Chat agent deployment checklist&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1: Prepare your environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Set up Copilot Studio and review licensing.&lt;/P&gt;
&lt;P&gt;☐ Create Power Platform environments that reflect your data boundaries and governance needs.&lt;/P&gt;
&lt;P&gt;☐ Identify early declarative agent use cases (e.g., HR FAQs, IT help desk).&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Note: Only declarative agents are currently supported in Copilot Chat. Agents that access tenant data (e.g., SharePoint, Graph) require pay-as-you-go billing.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2: Define governance policies&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Use role-based access control (RBAC) to manage who can create, publish, and use agents.&lt;/P&gt;
&lt;P&gt;☐ Apply naming conventions, approval workflows, and publishing guidelines.&lt;/P&gt;
&lt;P&gt;☐ Set up guardrails for data access, agent behavior, and knowledge sources.&lt;/P&gt;
&lt;P&gt;☐ Assign&amp;nbsp;maker permissions&amp;nbsp;via Microsoft Entra groups or Copilot Studio user licenses.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 3: Deploy and monitor&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Use the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2238685" target="_blank" rel="noopener"&gt;Microsoft admin center &lt;/A&gt;and Power Platform admin center to manage billing and access.&lt;/P&gt;
&lt;P&gt;☐ Monitor usage with audit logs, analytics, and the Copilot Control System.&lt;/P&gt;
&lt;P&gt;☐ Identify which teams are still using unauthorized AI tools and guide them toward approved Copilot agents.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 4: Support and scale&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Offer training, templates, and office hours to support agent creators and users.&lt;/P&gt;
&lt;P&gt;☐ Establish a Center of Excellence (CoE) to share best practices and governance.&lt;/P&gt;
&lt;P&gt;☐ Highlight successful use cases to drive adoption and build momentum.&lt;/P&gt;
&lt;P&gt;☐ Encourage feedback loops to refine agent behavior and expand scenarios.&lt;/P&gt;
&lt;H2&gt;Shadow AI prevention checklist&lt;/H2&gt;
&lt;P&gt;What else should you do to discourage shadow AI? Here's a handy checklist of actions to take:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Data protection&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Apply &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2093022" target="_blank" rel="noopener"&gt;Microsoft Purview DLP policies&lt;/A&gt; to monitor and restrict sensitive data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use sensitivity labels and encryption to protect data at rest and in transit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Set up conditional access policies to limit AI tool usage by role, device, or location.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Acceptable use&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Publish clear guidance on approved AI tools and data usage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Include AI-specific clauses in acceptable use and security policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Reinforce policies through onboarding, training, and regular reminders.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Monitoring and detection&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use Microsoft Defender for Cloud Apps (MCAS) to detect unsanctioned AI usage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Analyze browser traffic and app usage patterns for high-risk behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Set up alerts for uploads to known AI endpoints (e.g., ChatGPT, Claude).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Education and empowerment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Run awareness campaigns about shadow AI risks and approved alternatives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Offer training on how to use Copilot and Copilot Chat agents effectively.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Create a feedback loop for users to request new AI capabilities.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Internal partnerships&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Collaborate with HR, legal, and other teams to understand AI needs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Support business units in building Copilot Chat agents with IT oversight.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use shadow AI behavior as a signal for unmet needs and prioritize accordingly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Governance alignment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Align Copilot deployment with your organization’s responsible AI principles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Document how Copilot Chat agents support ethical and regulatory standards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use audit logs and analytics to support transparency and accountability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 22:17:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/bring-ai-out-of-the-shadows-with-agents-for-microsoft-365/ba-p/4426846</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-06-30T22:17:46Z</dc:date>
    </item>
    <item>
      <title>Driving adoption and measuring impact with the Microsoft 365 Copilot Dashboard</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/driving-adoption-and-measuring-impact-with-the-microsoft-365/ba-p/4414283</link>
      <description>&lt;P&gt;Since 2023, nearly &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2320471" target="_blank" rel="noopener"&gt;70%&lt;/A&gt; of Fortune 500 companies have &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2320471" target="_blank" rel="noopener"&gt;integrated Microsoft 365 Copilot’s advanced AI into their daily workflows&lt;/A&gt;, unlocking new efficiencies and streamlining collaboration—and they’re seeing measurable business impact.&lt;/P&gt;
&lt;P&gt;For example, Vodafone&amp;nbsp;discovered employees who use Copilot save an average of&amp;nbsp;3 hours per week, reclaiming 10% of their workweek. Lumen Technologies estimates that using Copilot will help their sales teams save $50 million per year.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are game-changing outcomes. But how do these companies know their numbers are accurate? And how did they achieve them? The key to maximizing the value of AI-driven productivity tools is more than simply licensing your end users and waiting for them to make the most of it. In fact, the key lies in &lt;STRONG&gt;measuring its impact&lt;/STRONG&gt;. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;To drive meaningful adoption and maximize ROI with Microsoft 365 Copilot, organizational leaders need clear visibility into how their workforces are using it. This means understanding:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Who’s adopting AI with Copilot.&lt;/LI&gt;
&lt;LI&gt;How effectively is Copilot supporting workflows.&lt;/LI&gt;
&lt;LI&gt;What measurable productivity gains are users achieving.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In this article, business leaders and IT can learn more about the Microsoft 365 Copilot dashboard, including its key features and core metrics.&lt;/P&gt;
&lt;P&gt;We'll also go over IT's tasks for configuring the dashboard and granting access to business leaders so they can analyze Copilot usage patterns themselves, refine their Copilot engagement strategies, and help drive productivity gains in their teams and throughout the organization.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What is the Copilot Dashboard?&lt;/H2&gt;
&lt;P&gt;The Microsoft Copilot Dashboard is a tool in Viva Insights that helps IT, business leaders, change managers, and other non-technical stakeholders track usage of Microsoft 365 Copilot with practical insights they can use to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Prepare users to work effectively with AI&lt;/LI&gt;
&lt;LI&gt;Drive Copilot adoption across teams&lt;/LI&gt;
&lt;LI&gt;Measure impact on workplace behavior&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Key features and core metrics of the Copilot Dashboard&lt;/H3&gt;
&lt;P&gt;With a Viva Insights license, your unlock advanced dashboard features, including:&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Comprehensive Metrics &lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;A 28-day aggregated view of Copilot usage, adoption, readiness, and impact, to help you understand engagement and Copilot business value.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Readiness tracking&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Based on Microsoft 365 app usage patterns, these metrics can help you identify which teams are ready to adopt AI into their daily workflows and which may need additional support, training or upskilling.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Adoption insights&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;With adoption insights, dashboard users can track active Copilot usage patterns within each Microsoft 365 app to measure how effectively teams are integrating Copilot into workflows. They can also pinpoint areas where Copilot users may need training or support to maximize productivity. By default, the dashboard’s Adoption trendline shows the prior six-month trend for all users in the organization. You can adjust filters at the top of the page for specific groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG style="color: rgb(30, 30, 30); font-size: 24px;"&gt;Impact analysis&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This insight allows you to analyze how often employees in your organization use Copilot during a specified time period. Leaders can also measure productivity gains through metrics like meeting efficiency, email usage, and document collaboration.&lt;/P&gt;
&lt;P&gt;Advanced tools, such as before-and-after behavioral data and employee surveys, can reveal early and even deeper insights into Copilot’s organizational impact.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Learning opportunities&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Use qualitative feedback data from &lt;STRONG&gt;Copilot impact pulse surveys&lt;/STRONG&gt;&amp;nbsp;to identify Copilot satisfaction levels, challenges, and areas for improvement.&lt;/P&gt;
&lt;P&gt;For example, you can compare high-adoption teams with low-adoption ones to uncover training or awareness gaps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H2&gt;Managing the Copilot Dashboard: Key admin responsibilities&lt;/H2&gt;
&lt;P&gt;Global admins play a critical role in &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267974" target="_blank" rel="noopener"&gt;configuring and managing the Copilot Dashboard&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Their roles include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Setting up and configuring the Copilot Dashboard.&lt;/LI&gt;
&lt;LI&gt;Granting access and supporting business stakeholders.&lt;/LI&gt;
&lt;LI&gt;Integrating data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;1. Setting up and configuring the Microsoft 365 Copilot Dashboard&lt;/H3&gt;
&lt;P&gt;Global IT admins are responsible for setting up and configuring the Copilot Dashboard to align with organizational goals and requirements. This includes managing settings and turning features on and off as needed.&lt;/P&gt;
&lt;H3&gt;2. Granting access and supporting business stakeholders&lt;/H3&gt;
&lt;P&gt;Admins, you'll also need to assign permissions to specific leaders, stakeholders, or groups through the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2070783" target="_blank" rel="noopener"&gt;Microsoft 365 admin center&lt;/A&gt; or PowerShell. Make sure stakeholders in different roles have the correct permissions.&lt;/P&gt;
&lt;P&gt;You'll also play a critical role in supporting and troubleshooting issues that users might encounter, such as technical problems and related assistance.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Who should have access to the Copilot Dashboard?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;H5&gt;&lt;STRONG&gt;Business leaders&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;You can view engagement and adoption metrics directly and make informed decisions about how best to guide users on adopting Copilot.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Department heads&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;You'll want to monitor how your teams are using Copilot and identify areas for improvement.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;IT managers&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;You'll need to oversee the technical aspects of Copilot deployment and ensure smooth operations.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;HR Managers&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Track employee sentiment and impact metrics for workforce planning and development.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;How do admins grant access to the Copilot Dashboard?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;You can delegate and manage access for individuals or groups to the dashboard in two different ways:&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;1. The Microsoft 365 admin center&lt;/STRONG&gt;&lt;/H5&gt;
&lt;OL&gt;
&lt;LI&gt;Access&lt;STRONG&gt; &lt;/STRONG&gt;the&lt;STRONG&gt; &lt;A href="https://go.microsoft.com/fwlink/?linkid=2267974" target="_blank" rel="noopener"&gt;Copilot Dashboard here&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;or&lt;/LI&gt;
&lt;LI&gt;Sign in to &lt;A href="https://go.microsoft.com/fwlink/?linkid=2070783" target="_blank" rel="noopener"&gt;Microsoft 365 admin center&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Navigate to the &lt;STRONG&gt;Settings&lt;/STRONG&gt; tab&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Setup&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Go to the &lt;STRONG&gt;Copilot Dashboard&lt;/STRONG&gt; to &lt;STRONG&gt;Manage access settings&lt;/STRONG&gt;. From there you can search for and select users to grant or revoke access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Manage access for groups by selecting the &lt;STRONG&gt;Groups&lt;/STRONG&gt; option, searching for Entra ID groups, and adding or removing users as needed.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;2. PowerShell&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Viva Insights admins can delegate access to organizational insights and the Copilot Dashboard using PowerShell.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set policies to enable or disable access to the dashboard at the tenant level using PowerShell cmdlets. This method gives you more granular control. Use it to manage access for larger groups or the entire organization.&lt;/P&gt;
&lt;P&gt;Note: You can only delegate access to users with a Viva Insights license. Viva Insights is available as part of the Microsoft Viva Suite or as a standalone add-on to Microsoft 365 enterprise plans.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;How&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;do business stakeholders access the Copilot Dashboard?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Business stakeholders, you can &lt;STRONG&gt;access the Microsoft 365 Copilot Dashboard through your Teams Viva Insights app&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;3. Integrating organizational data into the dashboard&lt;/H3&gt;
&lt;P&gt;Admins will upload organizational data directly through the admin center and configure it for analysis. If both the Viva Insights admin and the Global admin upload data, the dashboard will merge these uploads and display insights based on the most recent data.&lt;/P&gt;
&lt;H2&gt;Empowering business stakeholders with insights they can act on&lt;/H2&gt;
&lt;P&gt;Microsoft 365 Copilot is transforming productivity, and metrics powered by Viva Insights are proving its impact to the world.&lt;/P&gt;
&lt;P&gt;Access the Copilot Dashboard today for yourself and unlock Copilot’s full potential for driving organizational success.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Learn more&lt;/H3&gt;
&lt;P&gt;For more information on connecting to the Copilot Dashboard for Microsoft 365 customers, watch our recent video,&amp;nbsp;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2321702" target="_blank" rel="noopener"&gt;AI Transformation: Maximize the value of Copilot with Copilot Dashboard&lt;/A&gt; and check out our article: &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2321701" target="_blank" rel="noopener"&gt;Connect to the Microsoft Copilot Dashboard for Microsoft 365 customers | Microsoft Learn.&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Need more assistance? FastTrack is here to help!&lt;/H2&gt;
&lt;P&gt;FastTrack is available to support customers with&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267193" target="_blank" rel="noopener"&gt;eligible licenses&lt;/A&gt;. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267262" target="_blank" rel="noopener"&gt;Request assistance from FastTrack&lt;/A&gt; today or contact your assigned FastTrack Architect (FTA).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 18:35:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/driving-adoption-and-measuring-impact-with-the-microsoft-365/ba-p/4414283</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-05-29T18:35:37Z</dc:date>
    </item>
    <item>
      <title>Azure Firewall and Service Endpoints</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/azure-firewall-and-service-endpoints/ba-p/4404021</link>
      <description>&lt;P&gt;In my recent blog series &lt;A href="https://blog.cloudtrooper.net/category/privatelink/privatelinkrealitybites/" target="_blank"&gt;Private Link reality bites&lt;/A&gt; I briefly mentioned the possibility of inspecting Service Endpoints with Azure Firewall, and many have asked for more details on that configuration. Here we go!&lt;/P&gt;
&lt;P&gt;First things first: what the heck am I talking about? Most Azure services such as Azure Storage, Azure SQL and many others can be accessed directly over the public Internet. However, there are two alternatives to access those services over Microsoft's backbone: &lt;A href="https://learn.microsoft.com/azure/private-link/private-link-overview" target="_blank"&gt;Private Link&lt;/A&gt; and &lt;A href="https://learn.microsoft.com/azure/virtual-network/virtual-network-service-endpoints-overview" target="_blank"&gt;VNet Service Endpoints&lt;/A&gt;. Microsoft's overall recommendation is using private link, but some organizations prefer leveraging service endpoints. Feel free to read &lt;A href="https://blog.cloudtrooper.net/2025/02/17/private-link-reality-bites-service-endpoints-vs-private-link/" target="_blank"&gt;this post &lt;/A&gt;on a comparison of the two.&lt;/P&gt;
&lt;P&gt;You might want to inspect traffic to Azure services with network firewalls, even if that traffic is leveraging service endpoints. Before doing so, please consider that sending high-bandwidth traffic through a firewall might have cost implications and impact on the overall application latency. If you still want to go ahead, this post is going to explain how to do it.&lt;/P&gt;
&lt;H1&gt;The Design&lt;/H1&gt;
&lt;P&gt;Service endpoints have two configuration parts:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Source subnet configuration to tunnel traffic to the destination service.&lt;/LI&gt;
&lt;LI&gt;Destination service configuration to accept traffic from the source subnet.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The key concept to understand is that if traffic from the client is going to be inspected by a firewall before going to the Azure service, then the source subnet is actually the Azure Firewall's subnet, not the original client's subnet:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;You can configure service endpoints for a specific Azure service on a subnet using the portal, Terraform, Bicep, PowerShell or the Azure CLI. In the portal this is what it looks like:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;For Azure CLI, enabling service endpoints for Azure Storage accounts in all regions would look like this:&lt;/P&gt;
&lt;PRE&gt;❯ subnet_name=AzureFirewallSubnet&lt;BR /&gt;❯ az network vnet subnet update -n $subnet_name --vnet-name $vnet_name -g $rg --service-endpoints Microsoft.Storage.Global -o none --only-show-errors&lt;/PRE&gt;
&lt;P&gt;You would then configure your Azure services to accept traffic coming from the Azure Firewall subnet. For example, for Azure Storage Accounts this is what you would see in the portal:&lt;/P&gt;
&lt;img /&gt;
&lt;H1&gt;Network Rules or Application Rules?&lt;/H1&gt;
&lt;P&gt;Ideally you should use Application Rules in your firewall to make sure that your workloads are accessing the right Azure services, and not exfiltrating data to rogue data services that might be owned by somebody else and still could have the same IP address.&lt;/P&gt;
&lt;P&gt;This is an example of a star rule granting access to all Azure Storage Accounts, but you should specify your own:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;I tested with two storage accounts, one in the same region and another one in a different region than the client (the client being in this case the Azure Firewall). Access to both storage accounts is working, and as you can see both accesses are logged in the Storage Account as well as in the Azure Firewall (I have removed some characters from the storage account names to obfuscate them):&lt;/P&gt;
&lt;PRE&gt;❯ ssh $vm_pip "curl -s4 $storage_blob_fqdn1"&lt;BR /&gt;Hello world! &lt;BR /&gt;❯ ssh $vm_pip "curl -s4 $storage_blob_fqdn2"&lt;BR /&gt;Hello world!&lt;BR /&gt;❯ query='StorageBlobLogs | where TimeGenerated &amp;gt; ago(15m) | project AccountName, StatusCode, CallerIpAddress'&lt;BR /&gt;❯ az monitor log-analytics query -w $logws_customerid --analytics-query $query -o table&lt;BR /&gt;AccountName              CallerIpAddress     StatusCode  &lt;BR /&gt;----------------------   -----------------   ----------&lt;BR /&gt;storagetest????eastus2   10.13.76.72:10066   200&lt;BR /&gt;storagetest????westus2   10.13.76.72:11880   200&lt;BR /&gt;❯ query='AzureDiagnostics | where TimeGenerated &amp;gt; ago(15m) | where Category == "AZFWApplicationRule" | project SourceIP, Fqdn_s, Protocol_s, Action_s' &lt;BR /&gt;❯ az monitor log-analytics query -w $logws_customerid --analytics-query $query -o table &lt;BR /&gt;Action_s  Fqdn_s                                       Protocol_s SourceIP&lt;BR /&gt;--------- -------------------------------------------- ---------- ----------&lt;BR /&gt;Allow     storagetest????eastus2.blob.core.windows.net HTTPS      10.13.76.4 &lt;BR /&gt;Allow     storagetest????westus2.blob.core.windows.net HTTPS      10.13.76.4&lt;/PRE&gt;
&lt;P&gt;The storage account sees as client IP the Azure Firewall's IP (in the subnet 10.13.76.64/26), and the Azure Firewall logs show the actual client IP (in the workload subnet 10.13.76.0/26).&lt;/P&gt;
&lt;P&gt;If you use network rules you would lose a lot of the flexibility of the Azure Firewall, even if using FQDN-based rules. The reason is that if there were 2 storage accounts with different FQDNs sharing the same IP address, and the same client resolves both FQDNs, when Azure Firewall looks at the packet it will not be able to guess to which storage account each specific packet belongs to. From a routing perspective it would still work though, as long as you have the default SNAT settings of Azure Firewall, which involves translating the IP address when public IP addresses are involved:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Conclusion&lt;/H1&gt;
&lt;P&gt;There are some reasons why you might want to pick VNet service endpoints over private link (cost would probably be one of them). If so, there are advantages and disadvantages of sending traffic to Azure services via a firewall. If you decide to inspect traffic to VNet service endpoints with Azure Firewall, hopefully this post has shown you how to do that.&lt;/P&gt;
&lt;P&gt;What are your thoughts about this?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 11:48:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-for-azure/azure-firewall-and-service-endpoints/ba-p/4404021</guid>
      <dc:creator>cloudtrooper</dc:creator>
      <dc:date>2025-04-14T11:48:33Z</dc:date>
    </item>
  </channel>
</rss>

