<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>FastTrack Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/bg-p/FastTrackBlog</link>
    <description>FastTrack Blog articles</description>
    <pubDate>Thu, 23 Jul 2026 11:18:44 GMT</pubDate>
    <dc:creator>FastTrackBlog</dc:creator>
    <dc:date>2026-07-23T11:18:44Z</dc:date>
    <item>
      <title>Limiting Microsoft 365 Copilot data exposure risk with Zero Trust apps and data controls</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/limiting-microsoft-365-copilot-data-exposure-risk-with-zero/ba-p/4534642</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="
https://techcommunity.microsoft.com/users/atilgurcan/129311" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0xMjkzMTEtMjAxMjgyaTRDRDk1ODBCNDJDQzQ3MjM?image-dimensions=120x120" alt="AtilGurcan" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;AtilGurcan&lt;/SPAN&gt; &lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In&amp;nbsp;previous&amp;nbsp;posts of this series, we mapped &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title=" where exposure can exist " data-lia-auto-title-active="0"&gt;where exposure can exist &lt;/A&gt;when organizations deploy Microsoft 365 Copilot and&amp;nbsp;categorized&amp;nbsp;those&amp;nbsp;risks into two distinct layers. &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title="Layer 1" data-lia-auto-title-active="0"&gt;Layer 1&lt;/A&gt;&amp;nbsp;covers&amp;nbsp;risks associated with people who&amp;nbsp;can&amp;nbsp;access Microsoft 365 Copilot.&amp;nbsp;Layer 2&amp;nbsp;covers&amp;nbsp;risks&amp;nbsp;associated&amp;nbsp;with data Microsoft 365 Copilot can access.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Layer 2 risks are governed primarily by the Apps and Data pillars of Zero Trust, with Identity playing a secondary role in defining the scope of data each user can reach.&amp;nbsp;Organizations can&amp;nbsp;address these risks with Microsoft&amp;nbsp;controls&amp;nbsp;such as&amp;nbsp;Microsoft Purview, SharePoint Advanced Management, Microsoft Entra ID Governance, and Microsoft Sentinel. The work is configuring and scoping them deliberately before Copilot scales across the organization.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to read this post&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:300,&amp;quot;335559739&amp;quot;:100}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each section recaps one risk, describes the mitigation, names the Microsoft control that delivers it, and includes a placeholder for the supporting screenshot. Controls are cumulative—sensitivity&amp;nbsp;labels,&amp;nbsp;DLP policies, and audit logs work together across risks, so several mitigations reinforce one another.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R7&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Overshared SharePoint and OneDrive content&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Content shared with “Everyone,” “Everyone except external users,” or broad security groups becomes part of Copilot’s&amp;nbsp;queryable&amp;nbsp;surface for any licensed user—even if that user would never have manually&amp;nbsp;located&amp;nbsp;those files. Years of SharePoint oversharing, combined with Copilot’s ability to traverse and synthesize content in a single prompt, can turn long-standing governance debt into immediate exposure. Copilot makes&amp;nbsp;data once&amp;nbsp;hidden by volume discoverable by intent.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation starts by understanding what is overshared, then systematically tightening the sharing scope before Copilot scales.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use&amp;nbsp;Restricted SharePoint Search (RSS) during the Copilot pilot&amp;nbsp;as a temporary way&amp;nbsp;to&amp;nbsp;narrow&amp;nbsp;the&amp;nbsp;SharePoint&amp;nbsp;sites Copilot can ground against&amp;nbsp;while you review&amp;nbsp;permissions&amp;nbsp;and governance controls&amp;nbsp;before broad rollout.&amp;nbsp;Then turn it off after validation rather than treating it as a long-term control.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use SharePoint Advanced Management (SAM) to run data access governance reports and identify sites with “Everyone” or “Everyone except external users” sharing links—prioritize sites holding financial, HR, legal, or project data.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Remove or replace broad sharing links with scoped permissions; replace “Anyone” links with site-member access and require expiration dates on sharing links going forward.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Run Microsoft Entra ID Access Reviews scoped to Microsoft 365 groups and SharePoint site members to catch stale memberships that expand Copilot’s grounding surface.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Use Microsoft Purview Content Explorer to inventory which sites and libraries contain sensitive content and cross-reference with sharing scope.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;SharePoint Advanced Management: data access governance report showing sites with broad sharing&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R8&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Sensitivity label gaps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview sensitivity labels help classify content by sensitivity and, together with Purview policy controls, shape how that content can be used in Microsoft 365 Copilot. Unlabeled, mislabeled, or improperly inherited content is harder to govern consistently. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation requires both discovering what is unlabeled and closing the labeling gap at scale through policy, rather than relying on manual user action.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Turn on&amp;nbsp;mandatory labeling in Microsoft Purview so users cannot save or share documents without applying a label—preventing new unlabeled content from accumulating.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Configure auto-labeling policies in Microsoft Purview to classify content at rest and in transit using built-in sensitive information types (SITs) and trainable classifiers—prioritizing SharePoint libraries and OneDrive for Business.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Apply default sensitivity labels to SharePoint document libraries and Teams channels so that content inherits a baseline label even when users do not label manually.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Turn on container-level label inheritance so that SharePoint sites and Teams workspaces propagate sensitivity settings to documents created within them.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Use Microsoft Purview Content Explorer to quantify the volume of unlabeled content across the tenant and track labeling progress over time.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview: auto-labeling policy scoped to SharePoint and OneDrive&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;SharePoint document library: default sensitivity label applied to the library&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Content Explorer: labeled vs. unlabeled content breakdown by location&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R9&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Excessive user permissions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;Apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot follows each user’s existing Microsoft Graph permissions and does not surface content the user cannot access. However,&amp;nbsp;in many enterprise environments, users accumulate access far beyond their current role through leftover project permissions, broad temporary group memberships, and inherited rights from outdated organizational structures. Copilot does not create this overprovisioning, but it makes the full scope of that access&amp;nbsp;immediately&amp;nbsp;visible and usable. What previously required sustained effort to&amp;nbsp;locate&amp;nbsp;and correlate can now be surfaced in a single prompt.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation focuses on continuously right-sizing permissions to reflect actual role requirements, not historical accumulation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Run Microsoft Entra ID&amp;nbsp;access&amp;nbsp;reviews on a recurring schedule for all Microsoft 365 groups, SharePoint sites, and Teams with access to sensitive content. Require reviewers to justify continued membership rather than defaulting to approval.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use SharePoint Advanced Management inactive site policies to identify and deprovision sites no longer in active use whose permissions have never been cleaned up.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Audit group memberships for broad “Edit” or “Full Control” rights and replace with scoped contributor roles aligned to current job function.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Apply the principle of least privilege to new project groups from the start: time-bound membership with expiration dates, and access reviews triggered at project close.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Review service account and application permissions in Microsoft Graph to ensure&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;only humans hold&amp;nbsp;standing access to content&amp;nbsp;that&amp;nbsp;Copilot can query.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;SharePoint Advanced Management: inactive sites report&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Microsoft 365 admin center: group expiration policy configuration&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R10&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;No DLP coverage on Copilot-generated outputs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot outputs—including summaries, drafts, and synthesized answers—can move sensitive information&amp;nbsp;into new&amp;nbsp;contexts, such as&amp;nbsp;chats, emails, pages, and documents.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Mitigation extends DLP coverage explicitly to Copilot interactions, grounding data,&amp;nbsp;and downstream locations where&amp;nbsp;generated content may be stored or shared.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use Microsoft Purview DLP&amp;nbsp;for&amp;nbsp;Microsoft 365 Copilot&amp;nbsp;and Copilot Chat&amp;nbsp;to&amp;nbsp;block or audit&amp;nbsp;sensitive&amp;nbsp;prompts, limit external web search&amp;nbsp;when prompts&amp;nbsp;contain&amp;nbsp;sensitive data, and restrict&amp;nbsp;Copilot&amp;nbsp;from using specified labeled files and emails as grounding data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Configure communication DLP policies for Teams and Exchange so that Copilot-generated content pasted into messages, emails, or chats is evaluated against the same sensitive information type rules as source documents.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Turn on endpoint DLP on managed Windows devices to catch sensitive content that exits by way of clipboard paste, file save, or upload to unmanaged locations after being generated by Copilot.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Review DLP policy coverage for Copilot Pages and other Copilot output surfaces so that synthesized content stored or shared from those surfaces is governed consistently.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Regularly review DLP policy simulation reports to validate that rules fire against realistic Copilot output patterns, not just keyword matches in source files.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview: DLP policy scoped to Microsoft 365 Copilot workload&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Endpoint DLP: activity explorer showing Copilot-related policy matches&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R11&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Plugin and connector data surface expansion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations can extend Microsoft 365 Copilot through plugins and Microsoft Graph connectors that pull external data from CRM systems, ITSM platforms, HR applications, and custom line-of-business tools. Each connector expands the data surface Copilot can query on a user’s behalf and often reaches into systems&amp;nbsp;where&amp;nbsp;access control models do not align natively with Microsoft 365 permissions. As organizations add connectors without reviewing their scope and governance, each connected source introduces risk that scales alongside the broader Copilot data surface.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation requires deliberate governance over which connectors and plugins are&amp;nbsp;turned on, for whom, and under what conditions—before&amp;nbsp;the connected surface grows beyond visibility.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Review and restrict which Copilot plugins and Graph connectors are enabled in the Microsoft 365 admin&amp;nbsp;center,&amp;nbsp;disable connectors not actively&amp;nbsp;required,&amp;nbsp;and require admin approval for new connector deployments.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Scope each approved connector to the minimum data set and user population it needs: not all Copilot users should have access to every connected source.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Audit the permission model of each external system behind a connector. Verify that the connector enforces source-system access control and does not flatten permissions for all Copilot users.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Log and review connector activity in the Microsoft 365 audit log to detect unexpected query patterns or unusually broad data retrieval through connected sources.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft 365 admin center: Copilot plugins and connectors management page&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Graph connector: connection status and scoped user access settings&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R12&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Audit and visibility gap&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations need visibility into Copilot activity so they can investigate suspicious behavior, monitor adoption, and understand which content sources are involved.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Disabling Copilot interaction logging,&amp;nbsp;retaining&amp;nbsp;audit logs for too short a period, or&amp;nbsp;failing to forward&amp;nbsp;logs to a SIEM leaves organizations without the evidence needed to detect anomalous usage patterns, or&amp;nbsp;support incident response.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Mitigation requires&amp;nbsp;turning on&amp;nbsp;the right audit tier,&amp;nbsp;retaining&amp;nbsp;logs long enough to support investigation, and building those&amp;nbsp;signals&amp;nbsp;into security operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Verify that Microsoft Purview Audit (Standard or Premium) is enabled for the&amp;nbsp;tenant&amp;nbsp;and that Copilot interaction events are being captured.&amp;nbsp;Confirm in the Purview compliance portal that Copilot activities appear under the Audit search.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Upgrade to Microsoft Purview Audit Premium for high-risk user populations—including privileged identities and users with access to sensitive sites—to extend log retention up to ten years and gain access to intelligent insights.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Set a minimum audit log retention of 90 days for all users; extend to 180 days or longer for any user group that accesses sensitive or regulated content through Copilot.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Forward Microsoft 365 audit logs to Microsoft Sentinel (or the organization’s existing SIEM) to correlate Copilot activity with endpoint, identity, and network signals and to turn on automated detection rules.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Review Microsoft 365 Copilot usage reports in the admin center regularly to identify unusual query volumes, off-hours activity, or access to unexpected content sources.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview Audit: Copilot interaction events in audit search&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Purview Audit: Copilot interaction events in audit search results&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="1"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="1"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;R13&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Privileged user data amplification&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:400,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity, Apps&amp;nbsp;and&amp;nbsp;Data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:200}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Administrators, senior IT staff, and other privileged users often hold access that spans organizational boundaries—including mailboxes, site collections, security groups, and configuration data that most users never reach. A Copilot-enabled admin account that is compromised or misused gives adversaries—or an inadvertent insider—an organization-wide view of data that far exceeds the exposure associated with a compromised end-user account. Because Copilot amplifies the full scope of a user’s existing access, privileged identities require the strictest governance&amp;nbsp;controls.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation applies Just-In-Time access, dedicated account separation, and elevated monitoring to ensure privileged identities are not simultaneously&amp;nbsp;full&amp;nbsp;administrators and active Copilot users.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use Microsoft Entra Privileged Identity Management (PIM) to enforce Just-In-Time (JIT) elevation for administrative roles. Privileged access should be time-bound, require justification, and expire automatically after the task is complete.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Do not assign Copilot licenses to dedicated admin accounts. Administrators should use separate work accounts for day-to-day productivity and Copilot access, keeping elevated administrative permissions away from Copilot-enabled sessions.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Apply the strictest Conditional Access policies to any identity that holds both a Copilot license and elevated permissions. Require phishing-resistant MFA, compliant devices, and enforce token protection.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Enable Entra ID access reviews specifically scoped to privileged role members to ensure administrative permissions are actively justified and time-limited, not held indefinitely.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Prioritize Microsoft Purview Audit Premium for all privileged identities to capture a complete, long-retention record of Copilot interactions associated with high-privilege accounts and forward those logs to Sentinel for alerting.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Microsoft Entra PIM: active role assignments showing time-bound expiration&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Conditional Access: policy scoped to privileged role members with phishing-resistant MFA&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Layer 2 mitigations &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;at a glance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:300,&amp;quot;335559739&amp;quot;:100}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each Layer 2 risk maps to a primary control and the Microsoft tool that delivers it. Microsoft Purview recurs across multiple risks because it is the central governance layer for data classification, protection, and audit visibility in the Microsoft 365 environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 96.7802%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Primary control&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Microsoft tool&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R7—Overshared content&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Sharing scope reduction + access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;SharePoint Advanced Management, Entra ID Access Reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R8—Sensitivity label gaps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Auto-labeling + mandatory labeling&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Purview sensitivity labels&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R9—Excessive user permissions&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Recurring permission reviews + JIT scoping&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Entra ID Access Reviews, SharePoint Advanced Management&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R10—No DLP on Copilot outputs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;DLP extended to Copilot workloads&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Purview DLP, Endpoint DLP&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R11—Plugin and connector expansion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Connector governance + scoping&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 admin center, Purview DLP&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;R12—Audit and visibility gap&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Full audit coverage + SIEM&amp;nbsp;forwarding&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Purview Audit Premium, Microsoft Sentinel&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;SPAN data-contrast="none"&gt;R13—Privileged user amplification&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/td&gt;&lt;td&gt;&lt;SPAN data-contrast="none"&gt;JIT access + account separation&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/td&gt;&lt;td&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Entra PIM, Conditional Access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Complete your Zero Trust approach to Microsoft 365 Copilot&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:300,&amp;quot;335559739&amp;quot;:100}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 Copilot does not create new permissions or expose data users cannot already access.&amp;nbsp;What it does do is make existing access more discoverable, bringing years of accumulated oversharing, excessive permissions, unlabeled content, unmanaged connectors, and governance gaps into sharper focus.&amp;nbsp;As a result, reducing Copilot data exposure is not a one-time cleanup effort but&amp;nbsp;a continuous governance practice.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Across this series,&amp;nbsp;we've&amp;nbsp;examined both sides of the Microsoft 365 Copilot risk equation:&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title="who can access Copilot" data-lia-auto-title-active="0"&gt;who can access Copilot&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/mitigating-microsoft-365-copilot-access-risk-identity-and-device-controls-for-ze/4534574" target="_blank" rel="noopener" data-lia-auto-title="what Copilot can access on their behalf" data-lia-auto-title-active="0"&gt;what Copilot can access on their behalf&lt;/A&gt;.&amp;nbsp;Together, the Layer 1 and Layer 2 controls provide a practical, Zero Trust-aligned framework for governing identities, devices, applications, and data throughout your Copilot deployment.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For security, compliance, identity, and IT administrators, the next step is to assess your current environment against the risks discussed throughout this series. Review sharing configurations, sensitivity labeling coverage, data loss prevention policies, access governance practices, connector management, and audit visibility to&amp;nbsp;identify&amp;nbsp;gaps before Copilot adoption scales.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Addressing these gaps now can help reduce risk, strengthen compliance, and build a more secure foundation for AI-powered productivity. Use the controls discussed throughout this series to develop a Microsoft 365 Copilot deployment strategy that aligns with your organization's security, compliance, and business requirements. For&amp;nbsp;additional&amp;nbsp;guidance, see the&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;Zero Trust Overview on Microsoft Learn&lt;/A&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Atil Gurcan is a Senior FastTrack Architect who works with customers to implement secure &amp;amp; compliant AI experiences and accelerate their digital transformation, increasing ROI for their investments with Microsoft.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 21:18:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/limiting-microsoft-365-copilot-data-exposure-risk-with-zero/ba-p/4534642</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-08T21:18:16Z</dc:date>
    </item>
    <item>
      <title>Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/mitigating-microsoft-365-copilot-access-risk-identity-and-device/ba-p/4534574</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="
https://techcommunity.microsoft.com/users/atilgurcan/129311" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0xMjkzMTEtMjAxMjgyaTRDRDk1ODBCNDJDQzQ3MjM?image-dimensions=120x120" alt="AtilGurcan" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;AtilGurcan&lt;/SPAN&gt; &lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/understanding-copilot-risk-mapping-exposure-across-zero-trust-pillars/4534183" target="_blank" rel="noopener" data-lia-auto-title="our&amp;nbsp;previous&amp;nbsp;post" data-lia-auto-title-active="0"&gt;our&amp;nbsp;previous&amp;nbsp;post&lt;/A&gt;, we mapped where exposure can exist when organizations deploy Microsoft 365 Copilot and grouped those risks into two layers. Layer 1&amp;nbsp;focused on&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;who can access Copilot&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;—the identity and device conditions that&amp;nbsp;determine&amp;nbsp;whether a user&amp;nbsp;can&amp;nbsp;reach the service.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If those identity and device conditions are weak, exposure&amp;nbsp;may extend beyond&amp;nbsp;a single workload across the user’s entire Microsoft 365 data surface.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;This post&amp;nbsp;shifts&amp;nbsp;from mapping risk to&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;reducing&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each of the six Layer 1 risks (R1–R6) is governed primarily by the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;identity&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;endpoints&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;pillars&amp;nbsp;of&amp;nbsp;Zero&amp;nbsp;Trust. The good news: customers with Microsoft 365 E5 already own the controls&amp;nbsp;required&amp;nbsp;to&amp;nbsp;address&amp;nbsp;these risks, including&amp;nbsp;Microsoft Entra ID, Conditional Access, Microsoft Intune, and Microsoft Defender.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;next job&amp;nbsp;is configuring and scoping them deliberately before scaling deployment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to read this post&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each section recaps one risk, describes the mitigation, names the Microsoft control that delivers it and indicates where to capture the supporting screenshot.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;These controls are&amp;nbsp;additive.&amp;nbsp;Conditional Access&amp;nbsp;ties&amp;nbsp;identity and device signals together, so several mitigations reinforce one another.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R1—Unmanaged identity access&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Because Copilot operates across the full scope of a user's permissions, a compromised, shared, or orphaned account exposes far more than it would have before.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation starts with disciplined identity lifecycle management so that accounts exist only when&amp;nbsp;they should and&amp;nbsp;belong to&amp;nbsp;real&amp;nbsp;users.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Automate joiner,&amp;nbsp;mover, and&amp;nbsp;leaver&amp;nbsp;processes&amp;nbsp;with&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Entra Lifecycle Workflows&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;so accounts are provisioned, re-scoped, and disabled on schedule rather than manually.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Run recurring &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;access reviews&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;on Copilot-licensed groups to&amp;nbsp;identify&amp;nbsp;stale&amp;nbsp;or unnecessary&amp;nbsp;accounts.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Eliminate shared and generic accounts; require an individual, attributable identity for every Copilot user.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Block or remove dormant accounts and monitor sign-in activity for privileged identities.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&lt;SPAN data-contrast="auto"&gt;The following examples show lifecycle workflows and access review configuration:&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Lifecycle Workflows—leaver workflow showing account-disable tasks&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Access reviews—review scoped to the Copilot users group&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R2—Weak or absent multi-factor authentication&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If MFA is inconsistent—or legacy authentication bypasses modern sign-in controls—an attacker may need only a stolen password to open a Copilot session that synthesizes data across services.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Closing this gap means enforcing strong authentication&amp;nbsp;consistently&amp;nbsp;and shutting down the protocols that route around it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Require MFA for all users with a&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;policy; use Microsoft-managed policies as a baseline, then tighten.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Move to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;phishing-resistant&amp;nbsp;authentication&amp;nbsp;methods&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, such as&amp;nbsp;FIDO2 security keys, Windows Hello for Business, or certificate-based authentication.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Block legacy authentication protocols that don't support modern MFA.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Turn on Microsoft Authenticator number matching and additional context to help resist MFA fatigue attacks.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require multifactor authentication policy&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Authentication methods—phishing-resistant methods enabled&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R3—Unmanaged or noncompliant devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Users can reach Copilot from any device where they can authenticate. Without endpoint protection, encryption, and compliance evaluation, sessions and their outputs can be stored or exfiltrated from untrusted devices.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Mitigation pairs device&amp;nbsp;compliance&amp;nbsp;in&amp;nbsp;Intune with a Conditional Access&amp;nbsp;policy&amp;nbsp;that enforces it.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:120,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Define&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune compliance policies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;that&amp;nbsp;require&amp;nbsp;disk encryption,&amp;nbsp;minimum&amp;nbsp;OS versions,&amp;nbsp;endpoint protection (EDR/Defender), and no jailbreak&amp;nbsp;or&amp;nbsp;root&amp;nbsp;status.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use a&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access grant&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;control that&amp;nbsp;requires&amp;nbsp;devices&amp;nbsp;to be marked compliant,&amp;nbsp;or&amp;nbsp;hybrid&amp;nbsp;Microsoft Entra joined&amp;nbsp;before&amp;nbsp;accessing&amp;nbsp;Microsoft 365&amp;nbsp;and&amp;nbsp;Copilot.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Feed &lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender for Endpoint&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;device&amp;nbsp;risk signals into compliance&amp;nbsp;evaluation,&amp;nbsp;so high-risk&amp;nbsp;devices&amp;nbsp;fall out of compliance automatically.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Intune compliance policy—encryption, minimum OS, and Defender requirements&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require device to be marked as compliant&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R4—License sprawl without role-based scoping&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Broad pilot enrollment—licensing whole departments or floors—is itself a risk factor because it&amp;nbsp;grants&amp;nbsp;Copilot&amp;nbsp;access&amp;nbsp;to&amp;nbsp;both&amp;nbsp;well-governed and minimally governed users without an access review. Mitigation makes licensing deliberate: a reviewed group assigned through policy after each member's access is checked.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Assign Copilot through&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;group-based licensing&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;tied to a named, security-reviewed pilot group—not by department or location.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Run an access review on each pilot member's permission posture and role sensitivity&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;before&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;granting the license.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Phase rollout in cohorts and consider Restricted SharePoint Search during the pilot to limit the grounding surface.&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Microsoft 365 admin center—Copilot license assignment count&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R5—Missing real-time risk evaluation at sign-in&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Static controls grant or deny access once; they&amp;nbsp;don't&amp;nbsp;react to a session that turns risky. If Conditional Access&amp;nbsp;doesn’t&amp;nbsp;evaluate sign-in and user&amp;nbsp;risk signals—impossible travel, anomalous tokens, Identity Protection alerts—a high-risk session can still reach Copilot before anyone responds. Mitigation makes access decisions risk-aware in real time.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Turn on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Entra ID Protection&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(included in E5) to generate user&amp;nbsp;risk and sign-in-risk signals.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Create &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;risk-based Conditional Access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;policies: require MFA or a secure password change on elevated risk, and block on&amp;nbsp;high risk.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Add &lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;token protection&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;to bind sign-in sessions to the device and reduce token&amp;nbsp;replay exposure.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—user risk condition set&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Identity Protection—risky sign-ins dashboard&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require token protection session control&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="2"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;R6—App protection gap on mobile devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Pillar&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;On personal phones that&amp;nbsp;aren't&amp;nbsp;enrolled in MDM, organizations still need to govern the app. Without an application protection policy, users can copy Copilot output into unmanaged apps, and&amp;nbsp;data on&amp;nbsp;a&amp;nbsp;lost&amp;nbsp;device&amp;nbsp;can't&amp;nbsp;be wiped. Mobile Application Management (MAM) protects corporate data inside the app without managing the whole device.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What to do:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Deploy&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune App Protection Policies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(MAM) for iOS and Android: require&amp;nbsp;an app PIN, encrypt app data, and allow selective wipe of organizational&amp;nbsp;data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Restrict &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;data egress&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: block copy/paste and 'Save As' to unmanaged locations, and block screen capture where the platform supports it (Android).&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Pair with a &lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;grant requiring an approved client app and an app protection policy for mobile access.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;Figure: Intune app protection policies—iOS and Android policy list&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: App protection policy—data protection, block copy/paste, and “Save As”&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;Figure: Conditional Access—require approved client app and require App Protection Policy&lt;/P&gt;
&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&amp;nbsp;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Layer 1 mitigations&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;at a glance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:320,&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each Layer 1 risk maps to a primary control and the Microsoft tool that delivers it.&amp;nbsp;Conditional Access recurs because it is where identity and device signals are enforced together.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 85.9133%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Primary mitigation&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft control&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R1&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity lifecycle + access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Entra Lifecycle Workflows; Access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R2&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Enforce phishing-resistant MFA; block legacy auth&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Conditional Access; Authentication methods&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R3&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Require compliant/managed devices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune compliance policies; Defender for Endpoint; Conditional Access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R4&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Scoped, reviewed licensing&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Group-based licensing; Access reviews&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R5&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time risk gating at sign-in&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Entra ID Protection; risk-based Conditional Access; token protection&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;R6&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Protect data inside mobile apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune App Protection&amp;nbsp;Policies&amp;nbsp;(MAM);&amp;nbsp;Conditional&amp;nbsp;Access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Securing Copilot access&amp;nbsp;isn't&amp;nbsp;only about who can sign in—it's&amp;nbsp;about&amp;nbsp;validating&amp;nbsp;the devices, conditions, and access patterns behind every session. The six controls above close Layer 1 gaps before risky access patterns scale across the organization.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Governing Microsoft 365 Copilot risk: Next steps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 Copilot security starts before a prompt is ever entered. Identity, device, and session controls help verify that the right people are accessing Copilot from trusted devices under the right conditions. Closing Layer 1&amp;nbsp;gaps&amp;nbsp;reduces the likelihood that compromised identities, risky sign-ins, or unmanaged devices can access organizational data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Controlling&amp;nbsp;who can access Copilot&amp;nbsp;is the first step. The&amp;nbsp;next&amp;nbsp;challenge is governing&amp;nbsp;what Copilot can access&amp;nbsp;once a user is authenticated.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Strong access controls reduce the chances that the wrong person reaches Copilot. Layer 2 focuses on a different question: if the right person signs in, what information can they discover, summarize, and use?&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In&amp;nbsp;the next post of&amp;nbsp;this series,&amp;nbsp;we'll&amp;nbsp;shift from access controls to data controls and explore how organizations can reduce Layer 2 risk through SharePoint and OneDrive permissions management, sensitivity labels, data loss prevention (DLP), connector governance, and auditing capabilities.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before expanding your Copilot deployment, review the six Layer 1 controls covered in this article and&amp;nbsp;identify&amp;nbsp;any gaps in your identity, device, and access policies. You can also use&amp;nbsp;&lt;A class="lia-external-url" href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;the Zero Trust Workshop&lt;/A&gt;&amp;nbsp;to assess your current security posture and prioritize remediation efforts.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When&amp;nbsp;you're&amp;nbsp;ready, continue to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Post 3&amp;nbsp;in&amp;nbsp;this series: Governing Microsoft 365 Copilot data risk&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;to examine how data governance controls help limit exposure after authentication and strengthen secure Copilot adoption.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&lt;EM&gt;Atil Gurcan is a Senior FastTrack Architect who works with customers to implement secure &amp;amp; compliant AI experiences and accelerate their digital transformation, increasing ROI for their investments with Microsoft.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 21:16:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/mitigating-microsoft-365-copilot-access-risk-identity-and-device/ba-p/4534574</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-08T21:16:35Z</dc:date>
    </item>
    <item>
      <title>Understanding Copilot Risk: Mapping Exposure Across Zero Trust Pillars</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/understanding-copilot-risk-mapping-exposure-across-zero-trust/ba-p/4534183</link>
      <description>&lt;DIV style="margin-bottom: 20px; display: flex; flex-wrap: wrap; align-items: center; gap: 20px;"&gt;&lt;!-- Coauthor --&gt; &lt;A style="display: flex; align-items: center; text-decoration: none; color: inherit; gap: 10px;" href="
https://techcommunity.microsoft.com/users/atilgurcan/129311" target="_blank" rel="noopener"&gt;Co-authored by&lt;BR /&gt;&lt;IMG style="border-radius: 50%; object-fit: cover;" src="https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0xMjkzMTEtMjAxMjgyaTRDRDk1ODBCNDJDQzQ3MjM?image-dimensions=120x120" alt="AtilGurcan" width="40" height="40" /&gt; &lt;SPAN style="font-weight: 500;"&gt;AtilGurcan&lt;/SPAN&gt; &lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;AI&amp;nbsp;represents&amp;nbsp;a major&amp;nbsp;shift&amp;nbsp;in how users interact&amp;nbsp;with organizational data.&amp;nbsp;Instead of&amp;nbsp;finding&amp;nbsp;information&amp;nbsp;one file, email, or chat at a time,&amp;nbsp;users&lt;SPAN data-ccp-charstyle="Normal 1 Char" data-ccp-charstyle-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;424ef91a-e132-5625-abdb-2cccf359c7bb|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,469777841,&amp;quot;Aptos&amp;quot;,469777842,&amp;quot;Times New Roman&amp;quot;,469777843,&amp;quot;Times New Roman&amp;quot;,469777844,&amp;quot;Aptos&amp;quot;,201341986,&amp;quot;1&amp;quot;,469769226,&amp;quot;Aptos,Arial&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;Normal 1 Char&amp;quot;,201340122,&amp;quot;1&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;Normal1Char&amp;quot;,335572020,&amp;quot;1&amp;quot;,134231262,&amp;quot;true&amp;quot;,469777929,&amp;quot;Normal 1&amp;quot;,469778324,&amp;quot;Default Paragraph Font&amp;quot;]}" data-ccp-charstyle-linked-defn="{&amp;quot;ObjectId&amp;quot;:&amp;quot;bd921492-1112-5b48-ab34-dc4d2156f455|1&amp;quot;,&amp;quot;ClassId&amp;quot;:1073872969,&amp;quot;Properties&amp;quot;:[469777841,&amp;quot;Aptos&amp;quot;,469777842,&amp;quot;Times New Roman&amp;quot;,469777843,&amp;quot;Times New Roman&amp;quot;,469777844,&amp;quot;Aptos&amp;quot;,469769226,&amp;quot;Aptos&amp;quot;,335559740,&amp;quot;240&amp;quot;,201341983,&amp;quot;0&amp;quot;,335559739,&amp;quot;0&amp;quot;,201342446,&amp;quot;1&amp;quot;,201342447,&amp;quot;5&amp;quot;,201342448,&amp;quot;1&amp;quot;,201342449,&amp;quot;1&amp;quot;,201341986,&amp;quot;1&amp;quot;,268442635,&amp;quot;24&amp;quot;,469775450,&amp;quot;Normal 1&amp;quot;,201340122,&amp;quot;2&amp;quot;,134234082,&amp;quot;true&amp;quot;,134233614,&amp;quot;true&amp;quot;,469778129,&amp;quot;Normal1&amp;quot;,335572020,&amp;quot;1&amp;quot;,335551550,&amp;quot;6&amp;quot;,335551620,&amp;quot;6&amp;quot;,469777929,&amp;quot;Normal 1 Char&amp;quot;,469778324,&amp;quot;Normal&amp;quot;]}"&gt;&amp;nbsp;can&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;ask natural language questions&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;get&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;synthesize&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;answers&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;drawn&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;from&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;content&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Normal 1 Char"&gt;they already have permission to access&lt;/SPAN&gt;.&amp;nbsp;That can improve productivity, but&amp;nbsp;it can&amp;nbsp;also amplify the&amp;nbsp;impact of broad access, oversharing, and weak governance.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 Copilot brings this shift into focus. It&amp;nbsp;doesn’t&amp;nbsp;grant new permissions, but it acts as a force multiplier for existing access,&amp;nbsp;making it faster and easier for users to&amp;nbsp;discover, aggregate, and act on data across Microsoft 365. That makes it critical to understand both who can access Copilot and what data it can surface on a user’s behalf.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;A second&amp;nbsp;layer of risk&amp;nbsp;follows&amp;nbsp;from&amp;nbsp;how organizational data is structured, shared, and governed.&amp;nbsp;In environments with overshared content, excessive permissions, or inconsistent governance,&amp;nbsp;this acceleration can&amp;nbsp;lead&amp;nbsp;to&amp;nbsp;faster&amp;nbsp;and broader&amp;nbsp;access to sensitive information than organizations&amp;nbsp;may expect.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This&amp;nbsp;shift&amp;nbsp;carries important&amp;nbsp;security implications, especially as organizations move from pilots to&amp;nbsp;scaled&amp;nbsp;deployment.&amp;nbsp;While customers with&amp;nbsp;Microsoft 365&amp;nbsp;E5 licensing&amp;nbsp;may&amp;nbsp;already have access to&amp;nbsp;tools&amp;nbsp;that&amp;nbsp;help&amp;nbsp;identify&amp;nbsp;and reduce&amp;nbsp;risk,&amp;nbsp;licensing alone does not&amp;nbsp;reduce&amp;nbsp;exposure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;What’s&amp;nbsp;often missing&amp;nbsp;during early Copilot deployments&amp;nbsp;is a clear&amp;nbsp;view&amp;nbsp;of the risk surface itself:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;w&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;hat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;data&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;is exposed&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;,&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;who can access it,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;thr&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ough which vectors&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;Organizations&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;building&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;their&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;Microsoft 365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;Z&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ero Trus&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;posture&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;can&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;use&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;the&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust Workshop&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;to a&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ss&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ess&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;their cur&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;rent&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;po&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;sture&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ide&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;ntify&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;&amp;nbsp;gaps, and bett&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;er u&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;nderstan&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;d how&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;x&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;isting per&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;missions and g&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;over&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;nance imp&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;act Copilot readiness&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Emphasis"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In this post, we&amp;nbsp;map&amp;nbsp;Copilot-related risk&amp;nbsp;to&amp;nbsp;the&amp;nbsp;key Zero Trust&amp;nbsp;control areas most relevant&amp;nbsp;to deployment: identity, endpoints, apps, and data.&amp;nbsp;Our&amp;nbsp;goal is to help organizations&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;understand where&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;exposure&amp;nbsp;exists&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;which control&amp;nbsp;areas&amp;nbsp;they should&amp;nbsp;focus on&amp;nbsp;before scaling&amp;nbsp;deployment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Use&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Zero Trust to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;assess&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft 365 Copilot&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;risk&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft defines Zero Trust as a security model built on three core principles: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;Verify&amp;nbsp;explicitly&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Use least privileged access&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Assume breach&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Instead of trusting users or devices based solely on network location, Zero Trust requires continuous validation of every user, endpoint, and request, regardless of where the request originates.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft’s Zero Trust adoption model groups security controls across technology pillars such as identities, endpoints, apps, data, network, infrastructure, and security operations.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For this analysis,&amp;nbsp;we’ll&amp;nbsp;focus on the&amp;nbsp;four&amp;nbsp;pillars most directly&amp;nbsp;involved in&amp;nbsp;Microsoft 365&amp;nbsp;Copilot deployments:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;identity,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;endpoints&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;apps,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;data.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1.&amp;nbsp;Four control areas that shape&amp;nbsp;Copilot&amp;nbsp;exposure&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, these&amp;nbsp;pillars&amp;nbsp;help answer&amp;nbsp;three&amp;nbsp;key&amp;nbsp;questions:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Who&amp;nbsp;can&amp;nbsp;access&amp;nbsp;Copilot&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;From which endpoints and applications&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;What data can Copilot surface once access is granted&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more information and details&amp;nbsp;about&amp;nbsp;Microsoft’s Zero Trust&amp;nbsp;framework,&amp;nbsp;visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/zero-trust/deploy/overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust Overview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;at&amp;nbsp;Microsoft Learn.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Why&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Micro&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;soft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Copilot&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;changes the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;risk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;conversation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before assessing specific risks, it helps to understand why Copilot changes the risk conversation compared to traditional Microsoft 365 applications. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Most enterprise apps operate within a bounded context. The time and effort required to manually locate, connect, and synthesize information across systems creates friction and a practical limit on how quickly users can surface and act on data across systems. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Copilot removes much of that friction. At the speed of a prompt, Copilot lets users retrieve and bring together information from across a user’s existing access—spanning emails, files, meetings, chats, and other Microsoft 365 services—in a single response.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This exposure is not a result of new permissions. It comes from how quickly and easily existing access can be discovered, aggregated, and used.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;To understand where exposure appears, it helps to break Copilot risk into two interconnected layers: access and data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="none"&gt;Figure: Two-layer model for Microsoft 365 Copilot risk.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;The two-layer Microsoft 365 Copilot risk model&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The foundation of this&amp;nbsp;analysis is simple:&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Copilot&amp;nbsp;acts as&amp;nbsp;a force multiplier&amp;nbsp;for&amp;nbsp;whatever access a user already has&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;.&lt;/EM&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;If that access is governed well, Copilot can improve productivity. If not, it can amplify exposure.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;With&amp;nbsp;that framing&amp;nbsp;in mind,&amp;nbsp;we’ll&amp;nbsp;examine&amp;nbsp;Copilot&amp;nbsp;risk in two distinct layers:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Access to the Copilot service itself&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Access to the data that Copilot can ground on and surface&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The first layer focuses&amp;nbsp;on who can access Copilot and under what conditions. The second focuses on what Copilot can see and surface once access is granted.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Risk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;l&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ayer 1&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;:&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;Who&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;c&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;an&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ccess&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Microsoft 365&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;Copilot?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The first layer of risk begins at the point of entry: the conditions that determine whether a user can access Copilot. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Organizations don’t need to address every potential exposure point at once. Start by using the table below as a map of where exposure can exist across identity and endpoint controls. We’ll explore how to mitigate these risks in the second post of this series.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;risks&amp;nbsp;below&amp;nbsp;are primarily governed by&amp;nbsp;Microsoft’s Zero Trust&amp;nbsp;identity and&amp;nbsp;endpoint&amp;nbsp;pillars.&amp;nbsp;Together, these pillars&amp;nbsp;help&amp;nbsp;determine&amp;nbsp;whether&amp;nbsp;the right user&amp;nbsp;can&amp;nbsp;access&amp;nbsp;Copilot from a trusted&amp;nbsp;endpoint&amp;nbsp;under&amp;nbsp;the right&amp;nbsp;access&amp;nbsp;conditions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="auto"&gt;Table&amp;nbsp;1.&amp;nbsp;Identity and endpoint risks that affect Copilot access&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100.031%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 4.83122%" /&gt;&lt;col style="width: 21.4611%" /&gt;&lt;col style="width: 15.1446%" /&gt;&lt;col style="width: 58.5321%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Pillar&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Description&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R1&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Unmanaged&amp;nbsp;identity&amp;nbsp;access&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A&amp;nbsp;compromised, shared,&amp;nbsp;or former employee&amp;nbsp;account&amp;nbsp;can&amp;nbsp;authenticate&amp;nbsp;Microsoft&amp;nbsp;365 and access&amp;nbsp;Copilot.&amp;nbsp;Because&amp;nbsp;Copilot&amp;nbsp;operates&amp;nbsp;across the&amp;nbsp;full scope of&amp;nbsp;a&amp;nbsp;user’s permissions,&amp;nbsp;compromised accounts&amp;nbsp;can&amp;nbsp;expose&amp;nbsp;a&amp;nbsp;much&amp;nbsp;larger&amp;nbsp;risk surface than before Copilot existed.&amp;nbsp;Strong account&amp;nbsp;hygiene and&amp;nbsp;identity&amp;nbsp;lifecycle management&amp;nbsp;can&amp;nbsp;reduce&amp;nbsp;that&amp;nbsp;exposure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R2&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Weak or&amp;nbsp;absent&amp;nbsp;multi-factor&amp;nbsp;authentication&amp;nbsp;(MFA)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If MFA&amp;nbsp;isn’t&amp;nbsp;enforced, or if legacy authentication bypasses modern sign-in controls, users&amp;nbsp;can start Copilot&amp;nbsp;sessions&amp;nbsp;with&amp;nbsp;only&amp;nbsp;a password. In environments&amp;nbsp;with inconsistent&amp;nbsp;MFA coverage,&amp;nbsp;stolen credentials&amp;nbsp;may be enough&amp;nbsp;to gain access.&amp;nbsp;Because&amp;nbsp;Copilot&amp;nbsp;can&amp;nbsp;synthesize data across services,&amp;nbsp;compromised accounts&amp;nbsp;create&amp;nbsp;more&amp;nbsp;risk&amp;nbsp;than access to a single application.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R3&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Unmanaged or&amp;nbsp;non-compliant&amp;nbsp;devices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Users can access&amp;nbsp;Copilot&amp;nbsp;through&amp;nbsp;browsers&amp;nbsp;and native&amp;nbsp;apps&amp;nbsp;from&amp;nbsp;any device where they&amp;nbsp;can authenticate.&amp;nbsp;Unmanaged&amp;nbsp;or noncompliant&amp;nbsp;endpoints&amp;nbsp;without&amp;nbsp;endpoint&amp;nbsp;protection, encryption,&amp;nbsp;or&amp;nbsp;compliance evaluation can&amp;nbsp;expose&amp;nbsp;Copilot sessions and&amp;nbsp;allow&amp;nbsp;outputs&amp;nbsp;to&amp;nbsp;be&amp;nbsp;stored&amp;nbsp;or exfiltrated&amp;nbsp;locally.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R4&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Broad Copilot licensing&amp;nbsp;without&amp;nbsp;role-based&amp;nbsp;scoping&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Broad&amp;nbsp;Copilot&amp;nbsp;licensing&amp;nbsp;without role-based scoping.&amp;nbsp;Copilot pilots often begin with broad license&amp;nbsp;assignments across departments&amp;nbsp;or business units&amp;nbsp;instead of&amp;nbsp;smaller, security-reviewed&amp;nbsp;user&amp;nbsp;groups. When&amp;nbsp;organizations&amp;nbsp;assign&amp;nbsp;licenses&amp;nbsp;without&amp;nbsp;reviewing&amp;nbsp;access rights,&amp;nbsp;permission&amp;nbsp;posture, and role sensitivity,&amp;nbsp;they can expand&amp;nbsp;exposure&amp;nbsp;across both&amp;nbsp;well-governed and minimally&amp;nbsp;governed users.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R5&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Missing&amp;nbsp;real-time&amp;nbsp;risk&amp;nbsp;evaluation at&amp;nbsp;sign-in&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and endpoints&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If Conditional Access&amp;nbsp;doesn’t&amp;nbsp;evaluate sign-in and user risk signals,&amp;nbsp;such&amp;nbsp;as&amp;nbsp;anomalous activity, or identity protection&amp;nbsp;alerts,&amp;nbsp;high-risk sessions may still&amp;nbsp;reach&amp;nbsp;Copilot. Without real-time risk&amp;nbsp;evaluation,&amp;nbsp;controls&amp;nbsp;may&amp;nbsp;respond only&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;after&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;access is granted.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;R6&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;App&amp;nbsp;protection&amp;nbsp;gap on&amp;nbsp;mobile&amp;nbsp;devices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Endpoints&amp;nbsp;and&amp;nbsp;apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Users can access&amp;nbsp;Copilot&amp;nbsp;from personal&amp;nbsp;mobile&amp;nbsp;devices&amp;nbsp;that are not enrolled in&amp;nbsp;device&amp;nbsp;or&amp;nbsp;app management. Without&amp;nbsp;app protection&amp;nbsp;policies,&amp;nbsp;organizations&amp;nbsp;may not be able to&amp;nbsp;control how&amp;nbsp;Copilot outputs&amp;nbsp;move&amp;nbsp;into unmanaged apps&amp;nbsp;or&amp;nbsp;remove&amp;nbsp;organizational data from lost devices.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335557856&amp;quot;:16513529,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Key observations from Layer 1:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity appears most&amp;nbsp;frequently&amp;nbsp;across Layer 1, reflecting how tightly Copilot access depends on authenticated user permissions and sign-in conditions.&amp;nbsp;Endpoint-related risks also play&amp;nbsp;a major role&amp;nbsp;because unmanaged or noncompliant endpoints can expose Copilot sessions and outputs beyond the organization’s trusted environment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;Together, these risks&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;show that&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;securing Copilot access is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;shaped&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;by two factors:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;who can sign in,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;whether&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;endpoint&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;and session meet the organization’s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;&amp;nbsp;access&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;requirements&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal 1"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Risk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;l&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ayer 2&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ata&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;c&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;an&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Microsoft 365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Copilot&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;each?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The second layer of risk&amp;nbsp;assumes that&amp;nbsp;the user is already authenticated and actively using Copilot.&amp;nbsp;At this&amp;nbsp;stage, the focus shifts from who can access&amp;nbsp;Copilot&amp;nbsp;to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;what&amp;nbsp;data&amp;nbsp;Copilot can surface&amp;nbsp;on the user’s behalf&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;These risks reflect the exposure created by existing permissions, overshared content, connected systems, and governance gaps.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Layer 2&amp;nbsp;risks are governed primarily by the&amp;nbsp;apps&amp;nbsp;and&amp;nbsp;data&amp;nbsp;pillars, with&amp;nbsp;identity playing a secondary role in defining the scope of&amp;nbsp;data&amp;nbsp;each user&amp;nbsp;can access.&amp;nbsp;Much of Copilot’s value&amp;nbsp;and risk&amp;nbsp;comes from how it surfaces information based on user intent.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="none"&gt;Figure:How user intent changes data discovery&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 aria-level="4"&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 aria-level="4"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 4"&gt;Data and application risks that shape Copilot exposure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:40,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These&amp;nbsp;risks highlight how&amp;nbsp;permissions,&amp;nbsp;sharing,&amp;nbsp;labeling, and governance directly shape&amp;nbsp;what&amp;nbsp;Copilot&amp;nbsp;can&amp;nbsp;retrieve, synthesize, and surface&amp;nbsp;across&amp;nbsp;organizational&amp;nbsp;data.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100.031%; height: 1408.34px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 35.667px;"&gt;&lt;td style="height: 35.667px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;td style="height: 35.667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Risk&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 35.667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Zero Trust pillar(s)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 35.667px;"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Description&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:2,&amp;quot;335551620&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 234.667px;"&gt;&lt;td style="height: 234.667px;"&gt;&lt;STRONG&gt;R7&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 234.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Overshared SharePoint and OneDrive&amp;nbsp;content&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 234.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 234.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Content shared with "Everyone," "Everyone except external users," or broad groups&amp;nbsp;can&amp;nbsp;become part of Copilot’s&amp;nbsp;queryable&amp;nbsp;surface&amp;nbsp;for licensed users who already&amp;nbsp;have&amp;nbsp;access&amp;nbsp;to that content. Years of oversharing, combined with Copilot’s ability to&amp;nbsp;retrieve&amp;nbsp;and synthesize content in a single prompt, can turn long-standing governance&amp;nbsp;gaps&amp;nbsp;into immediate exposure.&amp;nbsp;Copilot&amp;nbsp;can&amp;nbsp;make data&amp;nbsp;that was&amp;nbsp;once hidden by volume,&amp;nbsp;discoverable by intent.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 206.667px;"&gt;&lt;td style="height: 206.667px;"&gt;&lt;STRONG&gt;R8&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Sensitivity&amp;nbsp;label&amp;nbsp;gaps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview sensitivity labels&amp;nbsp;and related protections&amp;nbsp;tell Copilot how&amp;nbsp;to handle&amp;nbsp;content, including whether it can summarize, cite, or include&amp;nbsp;that content&amp;nbsp;in responses.&amp;nbsp;Across&amp;nbsp;containers such as SharePoint sites and Teams,&amp;nbsp;unlabeled,&amp;nbsp;incorrect, or inconsistently&amp;nbsp;labeled content may be&amp;nbsp;treated&amp;nbsp;as unclassified and&amp;nbsp;surfaced&amp;nbsp;freely.&amp;nbsp;Large volumes of legacy content&amp;nbsp;can make that gap harder to manage at scale.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 206.667px;"&gt;&lt;td style="height: 206.667px;"&gt;&lt;STRONG&gt;R9&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Excessive&amp;nbsp;user&amp;nbsp;permissions&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity&amp;nbsp;and apps&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot follows each user’s existing&amp;nbsp;Microsoft&amp;nbsp;365&amp;nbsp;permissions and&amp;nbsp;does&amp;nbsp;not surface content&amp;nbsp;users&amp;nbsp;cannot access.&amp;nbsp;However,&amp;nbsp;users&amp;nbsp;often&amp;nbsp;accumulate access beyond their current role through leftover project permissions, temporary group memberships, and inherited&amp;nbsp;access. Copilot&amp;nbsp;doesn’t&amp;nbsp;create this overprovisioning, but it&amp;nbsp;can&amp;nbsp;make the full scope of&amp;nbsp;it easier to discover and use.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 216.667px;"&gt;&lt;td style="height: 216.667px;"&gt;&lt;STRONG&gt;R10&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 216.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;No DLP&amp;nbsp;coverage on Copilot-generated&amp;nbsp;outputs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 216.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 216.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot outputs, such as&amp;nbsp;summaries&amp;nbsp;and&amp;nbsp;drafts&amp;nbsp;can&amp;nbsp;combine&amp;nbsp;sensitive details from multiple sources.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations&amp;nbsp;should review how&amp;nbsp;their DLP labeling and data protection policies apply to generated content, especially when users move Copilot outputs into email, chat, or external documents.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 206.667px;"&gt;&lt;td style="height: 206.667px;"&gt;&lt;STRONG&gt;R11&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Plugin and connector data surface expansion&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps&amp;nbsp;and&amp;nbsp;identity&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 206.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations can extend&amp;nbsp;Copilot through&amp;nbsp;agent and&amp;nbsp;connectors that pull external data from CRM systems, ITSM platforms, and&amp;nbsp;other&amp;nbsp;line-of-business tools. Each connected&amp;nbsp;source&amp;nbsp;expands&amp;nbsp;the&amp;nbsp;set&amp;nbsp;of&amp;nbsp;data users&amp;nbsp;can&amp;nbsp;access through Copilot.&amp;nbsp;Each&amp;nbsp;connected source&amp;nbsp;expands the set of data users can access through Copilot and may&amp;nbsp;introduce governance and&amp;nbsp;access model&amp;nbsp;differences that need to be reviewed.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 150.667px;"&gt;&lt;td style="height: 150.667px;"&gt;&lt;STRONG&gt;R12&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Audit and&amp;nbsp;visibility&amp;nbsp;gap&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps and&amp;nbsp;data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations need&amp;nbsp;enough&amp;nbsp;visibility&amp;nbsp;to understand how&amp;nbsp;users&amp;nbsp;interact with&amp;nbsp;Copilot&amp;nbsp;and which resources&amp;nbsp;Copilot accesses in&amp;nbsp;response&amp;nbsp;to prompts.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Audit logs and monitoring help security teams investigate suspicious&amp;nbsp;activity, understand usage patterns, and reduce risk over time.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 150.667px;"&gt;&lt;td style="height: 150.667px;"&gt;&lt;STRONG&gt;R13&lt;/STRONG&gt;&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Privileged&amp;nbsp;user&amp;nbsp;data&amp;nbsp;amplification&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Identity,&amp;nbsp;apps&amp;nbsp;and&amp;nbsp;data&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 150.667px;"&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Privileged users often hold access&amp;nbsp;across sensitive systems and data. A compromised&amp;nbsp;privileged&amp;nbsp;account&amp;nbsp;with&amp;nbsp;Copilot&amp;nbsp;access&amp;nbsp;can expose a much larger slice of&amp;nbsp;organizational&amp;nbsp;data&amp;nbsp;than&amp;nbsp;a&amp;nbsp;standard&amp;nbsp;user account.&amp;nbsp;Privileged identities&amp;nbsp;therefore&amp;nbsp;need&amp;nbsp;tighter&amp;nbsp;access to&amp;nbsp;governance&amp;nbsp;and review.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Key observations from Layer&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;2&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Apps-related risks appear throughout Layer 2 because Microsoft 365 Copilot depends&amp;nbsp;on connected systems, accessible data sources, and governance over generated outputs. The&amp;nbsp;data pillar&amp;nbsp;reinforces the need to protect&amp;nbsp;both&amp;nbsp;sensitive source content&amp;nbsp;and&amp;nbsp;the&amp;nbsp;AI-generated responses that&amp;nbsp;bring content together.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;The table&amp;nbsp;above&amp;nbsp;maps each&amp;nbsp;risk to its primary and secondary Zero Trust pillars&amp;nbsp;to show where to act.&amp;nbsp;Primary pillars&amp;nbsp;represent&amp;nbsp;control areas&amp;nbsp;that most directly govern&amp;nbsp;a given&amp;nbsp;risk,&amp;nbsp;while&amp;nbsp;secondary&amp;nbsp;pillars&amp;nbsp;represent&amp;nbsp;contributing&amp;nbsp;factors.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:6,&amp;quot;335551620&amp;quot;:6,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;G&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;overning Microsoft 365 Copilot risk&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;N&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ext&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;steps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Copilot&amp;nbsp;typically&amp;nbsp;doesn’t&amp;nbsp;grant broader access than a user already has. Instead,&amp;nbsp;it&amp;nbsp;makes&amp;nbsp;existing&amp;nbsp;access&amp;nbsp;easier to discover, connect, and use&amp;nbsp;across&amp;nbsp;Microsoft 365. Organizations&amp;nbsp;that successfully&amp;nbsp;scale&amp;nbsp;Copilot&amp;nbsp;are the ones that&amp;nbsp;understand and govern that access&amp;nbsp;first.&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Understanding &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;where&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; exposure exists is the first step. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Your next step depends on where your organization is&amp;nbsp;in their Zero Trust journey.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Need&amp;nbsp;to assess your&amp;nbsp;current status?&amp;nbsp;Visit &lt;A class="lia-external-url" href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;the Zero Trust Workshop&lt;/A&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Ready to learn more about reducing risk by strengthening access controls at the point of entry? Check out post 2 of this series: &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/fasttrackblog/mitigating-microsoft-365-copilot-access-risk-identity-and-device-controls-for-ze/4534574" target="_blank" rel="noopener" data-lia-auto-title="Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust" data-lia-auto-title-active="0"&gt;Mitigating Microsoft 365 Copilot access risk: Identity and device controls for Zero Trust&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Atil Gurcan is a Senior FastTrack Architect who works with customers to implement secure &amp;amp; compliant AI experiences and accelerate their digital transformation, increasing ROI for their investments with Microsoft.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 21:16:10 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/understanding-copilot-risk-mapping-exposure-across-zero-trust/ba-p/4534183</guid>
      <dc:creator>AuzinAhmadi</dc:creator>
      <dc:date>2026-07-08T21:16:10Z</dc:date>
    </item>
    <item>
      <title>Microsoft 365 Copilot on mobile: What staged rollout plans can miss</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/microsoft-365-copilot-on-mobile-what-staged-rollout-plans-can/ba-p/4524953</link>
      <description>&lt;P&gt;IT teams often design rollout plans in careful stages: the right pilot group, the right prerequisites, the right communications, and the right guardrails. Sequencing matters.&lt;/P&gt;
&lt;P&gt;But when &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2367200" target="_blank"&gt;Microsoft 365 Copilot on mobile&lt;/A&gt; shows up in your environment, the shape of adoption can change.&lt;/P&gt;
&lt;P&gt;Employee behavior doesn’t always follow the same tidy stages as licensing or deployment plans. Once people can use Copilot in the moments where work actually happens—between meetings, on the go, in a hallway conversation, before a customer call—usage can spread faster, more socially, and less linearly than many rollout models assume.&lt;/P&gt;
&lt;P&gt;You can stage the rollout, but you can’t always stage the &lt;EM&gt;real-world usage pattern&lt;/EM&gt; that follows. And mobile is one of the fastest places that gap shows up.&lt;/P&gt;
&lt;H2&gt;What we’re seeing: mobile changes the moments where Copilot shows up&lt;/H2&gt;
&lt;P&gt;Mobile shifts adoption because it changes the context in which Copilot appears day to day:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot shows up more during “in-between” work moments&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Those moments where people look for quick help: summarizing, drafting, finding, checking, and preparing.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Usage spreads through behavior, not just rollout sequence&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;A teammate shares a faster way to prep for a meeting. A leader asks for a quick recap while traveling. A project team starts referencing Copilot outputs in a chat thread. That kind of spread can move ahead of your staged plan.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Desktop assumptions don’t always carry over cleanly&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Governance, communication, and readiness decisions that feel straightforward in a desktop-first mindset can surface earlier when usage starts in mobile-first ways.&lt;/P&gt;
&lt;P&gt;Taken together, mobile introduces a second force into staged rollout planning: behavioral adoption momentum that doesn’t always wait for the next planned phase.&lt;/P&gt;
&lt;H2&gt;Staged Copilot deployment ≠ staged usage&lt;/H2&gt;
&lt;P&gt;Mobile frequently compresses the “pilot → expand → scale timeline,” creating earlier-than-expected issues:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;IT starts fielding questions about “what’s allowed,” “what’s recommended,” or “what’s safe” before the plan anticipated&lt;/LI&gt;
&lt;LI&gt;Governance and communication become tightly linked. If the org hasn’t expressed expectations and guardrails early and clearly, fast-moving usage can create confusion or conflicting local norms&lt;/LI&gt;
&lt;LI&gt;Rollout plans start competing with reality. Mobile can make Copilot feel “present” in daily work. While IT is still staging rollout, parts of the organization behave like they’re already in broader adoption.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In many environments, this doesn’t stay theoretical for long.&lt;/P&gt;
&lt;H2&gt;What to do: four areas that tend to matter most&lt;/H2&gt;
&lt;P&gt;If you’re planning your Copilot rollout, you’ll want to think through these four connected areas:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Rollout sequencing&lt;/STRONG&gt;: how you stage availability and expansion&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;User behavior expectations&lt;/STRONG&gt;: how adoption may spread, and how you’ll message it&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Governance and readiness considerations&lt;/STRONG&gt;: what needs to be clear before usage accelerates&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Communication planning&lt;/STRONG&gt;: how you set expectations so momentum doesn’t create confusion&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If you’re hearing early signals that people are experimenting with Copilot in mobile contexts before the rollout has fully caught up or already seeing pockets of usage spreading faster than expected, use these four as levers for regaining clarity and alignment&lt;/P&gt;
&lt;H2&gt;Next step&lt;/H2&gt;
&lt;P&gt;Read &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2367200" target="_blank"&gt;the full blog&lt;/A&gt; for Microsoft 365 Copilot mobile rollout planning guidance, including how to align sequencing, governance, and communication, whether you’re still designing your rollout approach, or already responding to early signs of faster-than-expected adoption.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Read the full Accelerator blog: &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2367200" target="_blank"&gt;Microsoft 365 Copilot on mobile: Planning guidance for IT admins&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 21:50:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/microsoft-365-copilot-on-mobile-what-staged-rollout-plans-can/ba-p/4524953</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-06-02T21:50:56Z</dc:date>
    </item>
    <item>
      <title>Windows 365 for Agents: run AI agents in Cloud PCs across real applications</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/windows-365-for-agents-run-ai-agents-in-cloud-pcs-across-real/ba-p/4523433</link>
      <description>&lt;P&gt;Copilot agents have been talking the talk—summarizing information, drafting content, and answering questions. But soon they’ll be walking the walk—executing workflows across systems in policy-controlled Cloud PCs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Windows 365 for Agents (now in public preview), you can run AI agents in a secure environment and use natural language to direct them to work across software and complete tasks, such as processing invoices or updating CRM data.&lt;/P&gt;
&lt;H2&gt;What’s changing?&lt;/H2&gt;
&lt;P&gt;It may sound like a small shift, but Windows 365 for Agents introduces a fundamentally different runtime model.&lt;/P&gt;
&lt;P&gt;For the first time, you’ll be able to automate workflows that live &lt;EM&gt;outside&lt;/EM&gt; APIs across real applications—including legacy and UI-based systems—without giving up enterprise security or control.&lt;/P&gt;
&lt;P&gt;Much of today’s work still lives in browsers, desktop apps, and legacy systems—environments that assume intentional, human behavior. But agents behave differently:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Humans operate intermittently and with judgment&lt;/LI&gt;
&lt;LI&gt;Agents can operate continuously and at scale&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Agents depend on IT-defined boundaries, such as identity, policy, access, and monitoring, to keep execution aligned with intended workflows.&lt;/P&gt;
&lt;P&gt;Without boundaries, agents can:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Access unintended systems&lt;/LI&gt;
&lt;LI&gt;Act beyond their intended scope&lt;/LI&gt;
&lt;LI&gt;Amplify small mistakes across workflows&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Agents need a dedicated execution space designed for autonomous activity but governed by humans by default.&lt;/P&gt;
&lt;H2&gt;Windows 365 for Agents introduces the right execution environment&lt;/H2&gt;
&lt;P&gt;Windows 365 for Agents provides a dedicated Cloud PC environment that lets you define and control agents in various ways:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Independently and continuously, or on demand&lt;/LI&gt;
&lt;LI&gt;Under your existing identity, policy, and management controls, such as Microsoft Entra ID and Intune&lt;/LI&gt;
&lt;LI&gt;As repeatable, multi-step workflows across real applications, including legacy and UI-based systems, within the boundaries you set&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Running agents in this controlled environment helps isolate risk and enforce security boundaries so act autonomously while remaining fully governed by your policies and without negatively impacting production systems.&lt;/P&gt;
&lt;H2&gt;Get started with Windows 365 for Agents&lt;/H2&gt;
&lt;P&gt;Interested in how this works and what Windows 365 for Agents unlocks for your environment? Read full blog, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2365820" target="_blank"&gt;Windows 365 for Agents: run AI agents on secure cloud PCs&lt;/A&gt;, to learn more.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 01:04:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/windows-365-for-agents-run-ai-agents-in-cloud-pcs-across-real/ba-p/4523433</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-05-28T01:04:03Z</dc:date>
    </item>
    <item>
      <title>Copilot agents are scaling faster than most organizations expected</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-agents-are-scaling-faster-than-most-organizations/ba-p/4510366</link>
      <description>&lt;P&gt;Copilot agents are easy to pilot.&lt;/P&gt;
&lt;P&gt;Across organizations, teams are building agents to automate tasks, surface insights, and streamline everyday work. Early results are positive—and encouraging. One agent leads to another. Interest spreads. Adoption grows.&lt;/P&gt;
&lt;P&gt;Then a different question starts to surface:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What happens when Copilot agents move beyond experiments and start to scale across the organization?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;That’s where things are getting more complicated.&lt;/P&gt;
&lt;H2&gt;When success creates a new problem&lt;/H2&gt;
&lt;P&gt;In early stages, conversations about Copilot agents focus on &lt;EM&gt;how &lt;/EM&gt;to build, with questions centering on tools, prompts, and connectors. As usage expands, the challenge shifts away from delivery and toward coordination.&lt;/P&gt;
&lt;P&gt;Organizations see signals like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Multiple teams building agents independently&lt;/LI&gt;
&lt;LI&gt;Overlapping use cases with different risk profiles&lt;/LI&gt;
&lt;LI&gt;Unclear ownership as agents move into shared workflows&lt;/LI&gt;
&lt;LI&gt;Hesitation around approving the next agent&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These aren’t failures. They’re signs that agent usage is becoming meaningful enough to require intent, especially at an enterprise level.&lt;/P&gt;
&lt;H2&gt;Why scale changes the conversation&lt;/H2&gt;
&lt;P&gt;As Copilot agents move from isolated experiments to shared enterprise capability, the conversation shifts. The challenge is no longer just how to deliver agents, but how—and which—agents the organization should operate at scale.&lt;/P&gt;
&lt;P&gt;That shift introduces tradeoffs that rarely appear during pilot phases:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How much autonomy should teams retain?&lt;/LI&gt;
&lt;LI&gt;Where does consistency start to matter?&lt;/LI&gt;
&lt;LI&gt;How should we support experimentation without creating fragmentation?&lt;/LI&gt;
&lt;LI&gt;How can leadership stay aligned as impact grows?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Without a shared way to reason through these decisions, choices begin to outpace clarity.&lt;/P&gt;
&lt;P&gt;This is where many IT and business leaders pause. Not to stop innovation, but to ask a more fundamental question:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What does “scaling well” actually look like for us?&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;A CIO‑level framework for deliberate scale&lt;/H2&gt;
&lt;P&gt;Organizations that recognize themselves at this inflection point will want to read Microsoft’s Accelerator article, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2359369" target="_blank" rel="noopener"&gt;&lt;EM&gt;A CIO framework for scaling Copilot agents&lt;/EM&gt;&lt;/A&gt;—a CIO‑level perspective designed for when agent adoption begins to scale.&lt;/P&gt;
&lt;P&gt;The framework explores:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What changes as agents move from pilots to enterprise capability&lt;/LI&gt;
&lt;LI&gt;How leadership decisions evolve with scale&lt;/LI&gt;
&lt;LI&gt;How to balance flexibility with coherence&lt;/LI&gt;
&lt;LI&gt;How to guide growth before friction sets in&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It’s framed for CIOs and senior IT leaders who are thinking beyond approving the next agent build, who are focusing now on aligning teams, expectations, and operating models at scale.&lt;/P&gt;
&lt;P&gt;👉 Read &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2359369" target="_blank" rel="noopener"&gt;the full framework on Microsoft 365 Accelerator&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Discussion&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What signals tell you it’s time to move from experimenting with agents to planning for scale?&lt;/LI&gt;
&lt;LI&gt;Where does agent growth create the most tension in your organization today?&lt;/LI&gt;
&lt;LI&gt;What’s the one decision you wish had been clearer earlier in your agent journey?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft 365 Accelerator is where planning conversations go deeper.&lt;/STRONG&gt;&lt;BR /&gt;If your organization is moving from &lt;EM&gt;“can we build this?”&lt;/EM&gt; to &lt;EM&gt;“how do we scale this responsibly?”&lt;/EM&gt;, Accelerator is where you want to go next.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 17:53:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-agents-are-scaling-faster-than-most-organizations/ba-p/4510366</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-04-17T17:53:04Z</dc:date>
    </item>
    <item>
      <title>Copilot Chat in financial services: 
Is productivity moving faster than policy?</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-chat-in-financial-services-is-productivity-moving-faster/ba-p/4510910</link>
      <description>&lt;P&gt;In financial services, it's rarely the value of a new technology that slows down adoption.&amp;nbsp;More often, it's when productivity starts to outpace the policies designed to govern it.&lt;/P&gt;
&lt;P&gt;That tension is beginning to surface with Copilot Chat.&lt;/P&gt;
&lt;P&gt;Teams are finding real efficiency gains—faster research, clearer summaries, better preparation—while leaders ask a different question:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;What does responsible, repeatable adoption look like once usage expands across regulated roles?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Those conversations usually appear when Copilot Chat becomes operational enough that ad hoc decisions feel insufficient.&lt;/P&gt;
&lt;P&gt;A new post on&amp;nbsp;&lt;STRONG&gt;Microsoft 365 Accelerator&lt;/STRONG&gt; is designed for that exact moment. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2358982" target="_blank"&gt;How financial leaders are scaling Microsoft 365 Copilot Chat without increasing risk&lt;/A&gt; introduces a planning kit that shows financial services leaders how to scale Copilot Chat usage while keeping governance, audit readiness, and oversight intact.&lt;/P&gt;
&lt;P&gt;Instead of features, the kit is focused on the decisions and guardrails that help organizations move forward and use Copilot Chat with confidence.&lt;/P&gt;
&lt;P&gt;If you’re seeing strong demand from business teams and equally strong questions from risk or compliance teams, this kind of guidance brings those conversations together.&lt;/P&gt;
&lt;P&gt;👉 &lt;STRONG&gt;Read &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2358982" target="_blank"&gt;the full planning guidance and explore the Copilot Chat kit &lt;/A&gt;on Microsoft 365 Accelerator.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;We'd like to know:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;At what point did Copilot Chat usage in your organization start raising governance or policy questions?&lt;/LI&gt;
&lt;LI&gt;Which decisions felt easy during early experimentation but harder once Copilot Chat became more widely used?&lt;/LI&gt;
&lt;LI&gt;How are you thinking about ownership and oversight as Copilot Chat moves beyond individual use cases?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Tell us in the comments below.&lt;/P&gt;
&lt;P&gt;If this discussion feels familiar, you’re not alone. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2359157" target="_blank"&gt;Microsoft 365 Accelerator&lt;/A&gt; is designed for the next phase—when teams start asking not just &lt;EM&gt;can we&lt;/EM&gt;, but &lt;EM&gt;how do we do this well&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 16:49:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-chat-in-financial-services-is-productivity-moving-faster/ba-p/4510910</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-04-13T16:49:44Z</dc:date>
    </item>
    <item>
      <title>Copilot adoption: Move your org from pilot to production with this guide</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-adoption-move-your-org-from-pilot-to-production-with/ba-p/4495997</link>
      <description>&lt;P&gt;Are you an IT admin or Copilot adoption lead ready to safely start or scale your rollout of Microsoft 365 Copilot?&lt;/P&gt;
&lt;P&gt;Piecing together the right guidance can be something of a treasure hunt so we created a trusted, single starting point for you: &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2353614" target="_blank"&gt;8 Copilot &amp;amp; agent hubs every adoption leader should bookmark&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;This guide is organized around the typical adoption lifecycle (plan → build → operate) to help you accelerate your Copilot adoption &lt;EM&gt;without&lt;/EM&gt; skipping governance.&lt;/P&gt;
&lt;P&gt;Inside the guide, you’ll learn:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;What each resource hub includes&lt;/STRONG&gt;—and how each maps to plan → build → operate for Copilot.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;How to turn guidance into motion&lt;/STRONG&gt;: Practical steps you can reuse for rollout and change management (not just reference links).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Which resources to share with each audience&lt;/STRONG&gt;—admins, champions, and business sponsors—so everyone stays aligned.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;How to scale with confidence&lt;/STRONG&gt;: Starting points. that support a governed, production-ready Copilot program&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To get started, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2353614" target="_blank"&gt;check out the full post&lt;/A&gt; and bookmark each resource hub today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Did you know?&lt;/H2&gt;
&lt;P&gt;FastTrack helps&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2267193" target="_blank"&gt;eligible customers&lt;/A&gt;&amp;nbsp;with Microsoft 365 Copilot adoption by providing expert guidance, self‑service resources, and structured engagements at no additional cost.&lt;/P&gt;
&lt;P&gt;If your adoption program could use a boost, FastTrack can help.&lt;/P&gt;
&lt;P&gt;Visit the&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347901" target="_blank"&gt;Microsoft 365 Accelerator site&lt;/A&gt;&amp;nbsp;for Copilot quickstart guides, governance templates, and adoption kits—or&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347354" target="_blank"&gt;submit a request for personalized deployment and change management assistance (RFA) from FastTrack&amp;nbsp;&lt;/A&gt;today.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 20:32:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/copilot-adoption-move-your-org-from-pilot-to-production-with/ba-p/4495997</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-02-19T20:32:15Z</dc:date>
    </item>
    <item>
      <title>The Copilot resource guide to share with your employees</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/the-copilot-resource-guide-to-share-with-your-employees/ba-p/4495989</link>
      <description>&lt;P&gt;From customers driving Microsoft Copilot adoption, one request we hear a lot is: “Can you send me to a simple starting place?”&lt;/P&gt;
&lt;P&gt;Now we can. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2353414" target="_blank" rel="noopener"&gt;Essential Copilot resource hubs for employees&lt;/A&gt; is a trusted, easy-to-share guide that rounds up key Microsoft-owned Copilot learning and support hubs. It's designed to help you speed up Copilot onboarding and get your employees building good habits from day one.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;How to use it with end users&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Adoption leaders:&lt;/STRONG&gt; Use the hubs to structure learning paths (new user onboarding, prompting basics, role-based scenarios) and reinforce them in champions and community programs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;IT admins:&lt;/STRONG&gt; Add a link to the guide in your rollout emails, intranet, and helpdesk macros so employees have a consistent “start here” link.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Everyone:&lt;/STRONG&gt; Share this as one source of truth, then keep your internal guidance focused on what’s unique to your organization (policies, approved use cases, and where to get help).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For more information about this simple approach that scales, read the guide: &lt;A href="https://go.microsoft.com/fwlink/?linkid=2353414" target="_blank"&gt;Essential Copilot resource hubs for employees&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Need help?&lt;/H2&gt;
&lt;P&gt;FastTrack helps&amp;nbsp;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267193" target="_blank" rel="noopener"&gt;eligible customers&lt;/A&gt;&amp;nbsp;with Microsoft 365 Copilot adoption by providing expert guidance, self‑service resources, and structured engagements at no additional cost.&lt;/P&gt;
&lt;P&gt;If your adoption program could use a boost, visit the&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347901" target="_blank" rel="noopener"&gt;Microsoft 365 Accelerator site&lt;/A&gt; for Copilot quickstart guides, governance templates, and adoption kits. Or,&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2347354" target="_blank" rel="noopener"&gt;submit a request for personalized deployment and change management assistance (RFA) from FastTrack&amp;nbsp;&lt;/A&gt;today.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 20:01:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/the-copilot-resource-guide-to-share-with-your-employees/ba-p/4495989</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2026-02-19T20:01:33Z</dc:date>
    </item>
    <item>
      <title>Ready to accelerate your Zero Trust journey? Discover what’s next</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/ready-to-accelerate-your-zero-trust-journey-discover-what-s-next/ba-p/4458866</link>
      <description>&lt;P&gt;&lt;STRONG&gt;For admins | &lt;/STRONG&gt;&lt;STRONG&gt;1-minute read&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Zero Trust isn’t just a security buzzword—it’s the new baseline for protecting your organization in a world where threats are always evolving.&lt;/P&gt;
&lt;P&gt;But what does it &lt;EM&gt;really&lt;/EM&gt; take to move from strategy to action?&lt;/P&gt;
&lt;P&gt;Find out by reading our recent blog, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2337627" target="_blank" rel="noopener"&gt;Accelerate your Zero Trust journey: Using the Microsoft Zero Trust workshop for impact&lt;/A&gt; on the M365 Accelerator site. In it, we break down some of the real-world challenges IT admins face and show how this hands-on workshop can help you build a clear roadmap forward.&lt;/P&gt;
&lt;P&gt;For example, learn how you can use the workshop to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess and improve your security posture by &lt;/STRONG&gt;evaluating your organization’s current security maturity across six critical Zero Trust pillars (Identity, Devices, Data, Network, Infrastructure, Security Operations), identify gaps, and prioritize actions for improvement.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Drive cross-team alignment and executive buy-in&lt;/STRONG&gt; by bringing together stakeholders from security, infrastructure, networking, and compliance for communication, consensus building, and creating a data-driven roadmap that resonates with leadership.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Turn security strategy into actionable results with &lt;/STRONG&gt;practical steps for leveraging the Zero Trust Workshop to transform security from a reactive task into a proactive, strategic advantage for your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Next steps&lt;/H1&gt;
&lt;P&gt;Ready to move beyond theory and see how Microsoft’s approach can help you secure identities, apps, and data?&lt;/P&gt;
&lt;P&gt;Then &lt;STRONG&gt;Accelerate your Zero Trust journey&lt;/STRONG&gt; is your next must-read.&lt;/P&gt;
&lt;P&gt;Get the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2337627" target="_blank" rel="noopener"&gt;full story and workshop details here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 16:40:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/ready-to-accelerate-your-zero-trust-journey-discover-what-s-next/ba-p/4458866</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-10-03T16:40:32Z</dc:date>
    </item>
    <item>
      <title>Governing Copilot agents: Your next step starts here</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/governing-copilot-agents-your-next-step-starts-here/ba-p/4446182</link>
      <description>&lt;P&gt;For those of you navigating this shift, Rob Howard, Microsoft’s VP of Product Management for Microsoft 365 Copilot Extensibility, offers a practical governance framework in his article, &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2333222" target="_blank" rel="noopener"&gt;&lt;EM&gt;What IT admins need to know about governing AI agents&lt;/EM&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The article introduces three key governance pillars:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Security controls&lt;/STRONG&gt; using Microsoft Purview.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Management controls&lt;/STRONG&gt; through admin centers and deployment planning.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent reporting&lt;/STRONG&gt; to monitor usage and stay ahead of compliance.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You’ll also get a first look at governance zones—a planning model to help segment Copilot deployment based on your organization’s risk tolerance and data sensitivity. Think sandbox, controlled, and trusted zones, with guidance on how to phase rollout.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What else you’ll find:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;A checklist &lt;/STRONG&gt;to assess your readiness.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Real-world examples &lt;/STRONG&gt;of phased deployment.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Links to tools you already use&lt;/STRONG&gt;, like Purview, Power Platform admin center, and Microsoft 365 admin center.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A preview&lt;/STRONG&gt; of the upcoming white paper and webinar.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Next Steps&lt;/H2&gt;
&lt;P&gt;Ready to securely and strategically lead your organization into the future of AI?&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2333222" target="_blank" rel="noopener" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}"&gt;Read Rob’s blog&lt;/A&gt; today for reliable advice on governing Copilot agents. It’s part of a broader initiative by FastTrack for Microsoft 365 to support IT admins with actionable, admin-relevant content on governing Copilot AI agents—so stay tuned for future articles, webinars, and more on the topic!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 23:42:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/governing-copilot-agents-your-next-step-starts-here/ba-p/4446182</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-08-22T23:42:47Z</dc:date>
    </item>
    <item>
      <title>Bring AI out of the shadows with agents for Microsoft 365 Copilot Chat</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/bring-ai-out-of-the-shadows-with-agents-for-microsoft-365/ba-p/4426846</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For IT admins and Microsoft 365 admins&lt;/STRONG&gt;&lt;BR /&gt;7-minute read&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Shadow AI is almost certainly happening across your organization—whether you can see it or not. Employees are using tools like ChatGPT and Notion AI to get work done, even without organizational knowledge or approval. This creates real risks like data leakage, compliance violations, and a lack of visibility into how employees are using artificial intelligence.&lt;/P&gt;
&lt;P&gt;Fortunately, IT admins are in a unique position to fix the problem at its core.&lt;/P&gt;
&lt;P&gt;Today's article is intended to be a practical playbook for helping IT admins lead the charge toward responsible AI use in their organizations by empowering secure, compliant, and easy-to-manage agents for Microsoft 365 Copilot Chat.&lt;/P&gt;
&lt;H2&gt;What is shadow AI?&lt;/H2&gt;
&lt;P&gt;Like shadow IT, the term ‘shadow AI’ exists for a reason: it refers to unsanctioned, often hidden, use of AI tools.&lt;/P&gt;
&lt;P&gt;In the shadows, artificial intelligence can be hard to detect and even harder to govern. Tools can be browser-based, embedded in SaaS apps, or used on personal devices. Controls that mitigate shadow IT—like app blocking or firewall rules—don’t necessarily translate to AI use.&lt;/P&gt;
&lt;P&gt;Both shadow IT and shadow AI involve technical and behavioral elements, however unauthorized use of AI presents deeper behavioral challenges beyond unauthorized tools. These challenges center around how users make decisions and potentially bypass governance in ways that are harder to detect and control.&lt;/P&gt;
&lt;P&gt;While employees may not &lt;EM&gt;want&lt;/EM&gt; to go rogue or bypass IT—and they generally don’t want to put the organization at risk—they do want to get their work done efficiently. They turn to public AI tools when &lt;EM&gt;they can’t find the capabilities they need inside the tools they have permission to use&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;Agents for Microsoft 365 Copilot Chat give you a way to lead AI use into the light and meet your users’ needs with &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2325458" target="_blank" rel="noopener"&gt;modern AI business tools&lt;/A&gt;. By building and deploying task-specific, data-grounded chat experiences that live inside Microsoft 365, users get fast, relevant answers they’re looking for&amp;nbsp;&lt;EM&gt;without having to step into the shadows and leave the secure environment you manage&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;These agents are part of the broader Microsoft 365 Copilot ecosystem and are designed to automate and execute business processes directly within Copilot Chat.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Should you ignore or even allow shadow AI?&lt;/H2&gt;
&lt;P&gt;When employees use public AI tools without oversight, they create risks that are harder to detect, harder to govern, and harder to reverse.&lt;/P&gt;
&lt;P&gt;For IT admins, the stakes are high for operational, security, and technical risks:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Loss of visibility and control: &lt;/STRONG&gt;You can’t protect what you can’t see.&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Shadow AI obscures oversight.&lt;/STRONG&gt; It’s harder to track usage or enforce policies for tools used outside your environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;No centralized monitoring = no control.&lt;/STRONG&gt;&amp;nbsp;Without a unified view, you can’t troubleshoot issues, optimize usage, or step in when something goes wrong.&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Shadow data silos emerge.&lt;/STRONG&gt; Generative AI content created outside your tenant isn’t retained or governed, which complicates lifecycle management, legal holds, and compliance requests.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt; Security and compliance risks&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Enterprise-grade protections are lacking.&lt;/STRONG&gt; Most public AI tools don’t support conditional access, audit logs, or data loss prevention (DLP) policies, leaving you with blind spots and increased risk of data leaks.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Sensitive data exposure.&lt;/STRONG&gt; Employees may unknowingly input proprietary or regulated data into public models, risking violations of GDPR, HIPAA, or internal policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Compliance gaps.&lt;/STRONG&gt; If tools aren’t tracked or documented, they increase the burden of proving compliance and can become major liabilities during audits or regulatory reviews.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt; IT and governance challenges&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IT is out of the loop.&lt;/STRONG&gt; Adoption of unauthorized AI tools sidelines IT, preventing teams from recommending secure, supported alternatives or aligning tools with organizational standards. When users go rogue with AI tools, they aren't using recommended secure, supported options that align with your environment and policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tool sprawl = more support tickets&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt; Unapproved tools often lack integration with existing systems, creating support burdens and increasing the risk of misconfigurations.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Bottom line&lt;/STRONG&gt;: Allowing or ignoring shadow AI will make it much harder to manage later. That’s why Copilot Chat agents, combined with strong governance and user education, are such a powerful response: they give you a way to meet end user demand without losing control.&lt;/P&gt;
&lt;H3&gt;What IT admins are up against&lt;/H3&gt;
&lt;P&gt;When it comes to eradicating rogue AI, admins have their work cut out for them. Here’s a summary table of how activating Copilot Chat agents at your organization can help stem the tide:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5 lia-border-color-10 lia-border-style-outset" border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Unsanctioned AI use contributes to:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;How to stem the problem:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Loss of visibility and control&lt;/STRONG&gt;&lt;BR /&gt;Employees use unsanctioned AI tools.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Reframe shadow AI as a signal&lt;/STRONG&gt;&lt;BR /&gt;Offer sanctioned tools that meet user needs and bring AI usage into the light.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Data governance gaps&lt;/STRONG&gt;&lt;BR /&gt;Unapproved tools bypass DLP and compliance policies.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Keep data in your tenant&lt;/STRONG&gt;&lt;BR /&gt;Copilot agents respect Microsoft 365 compliance, identity, and data boundaries.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Inconsistent AI use across teams&lt;/STRONG&gt;&lt;BR /&gt;Different tools create fragmented workflows.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Centralize AI access&lt;/STRONG&gt;&lt;BR /&gt;Deploy agents across Teams and Microsoft 365 to unify usage.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Security and compliance risks&lt;/STRONG&gt;&lt;BR /&gt;Shadow tools may not meet regulatory standards.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Use enterprise-grade protection&lt;/STRONG&gt;&lt;BR /&gt;Copilot agents are authenticated with Azure AD and governed by Microsoft Purview.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Lack of deployment clarity&lt;/STRONG&gt;&lt;BR /&gt;Admins may not know where to start.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Follow a clear blueprint&lt;/STRONG&gt;&lt;BR /&gt;This blog outlines steps for setup, governance, and scaling.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Missed innovation opportunities&lt;/STRONG&gt;&lt;BR /&gt;IT is seen as a blocker, not a partner.&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Support safe innovation&lt;/STRONG&gt;&lt;BR /&gt;Let business units build AI chat agents with IT guardrails in place.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Copilot Chat agents remove the roadblocks to getting value from AI&lt;/H3&gt;
&lt;P&gt;Microsoft's chat agents aren’t just another AI tool—they’re designed to work the way IT works.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure by design&lt;/STRONG&gt;: Agents run inside your Microsoft 365 tenant and authenticate through Azure AD.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Compliant by default&lt;/STRONG&gt;: They respect DLP and audit policies and retention through Microsoft Purview.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Customizable and governable&lt;/STRONG&gt;: You can define access, data sources, and usage policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Easy to deploy&lt;/STRONG&gt;: Agents live inside Teams and Microsoft apps, so users don’t need to install anything new.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Copilot Chat agents strengthen governance&lt;/H3&gt;
&lt;P&gt;While Copilot for Microsoft 365 helps users work more efficiently inside apps like Word, Excel, and Teams, Copilot's AI agents go a step further. They give IT the ability to create task-specific, role-based, and data-grounded AI experiences that directly replace the kinds of tools employees might otherwise seek out on their own.&lt;/P&gt;
&lt;H3&gt;Key deployment benefits for IT admins&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-5 lia-border-color-10 lia-border-style-inset" border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Benefit&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Impact&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Visibility&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Know who’s using AI, how, and with what data.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Control&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Define and enforce usage policies.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Compliance&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Align AI use with regulatory standards.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Efficiency&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Reduce support tickets with self-service agents.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;&lt;STRONG&gt;Innovation&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-10"&gt;
&lt;P&gt;Empower business units without losing oversight.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Take the next step&lt;/H2&gt;
&lt;P&gt;Like shadow IT, you may not get rid of shadow AI completely or overnight. But you can meet it head-on with tools that work for your users and comply with your policies.&lt;/P&gt;
&lt;P&gt;Start by deploying a few AI Chat agents in high-impact areas. Use the resources in this article to guide your rollout.&lt;/P&gt;
&lt;P&gt;With Copilot Chat agents, you’re not just solving a technical problem. You’re leading your organization toward safer, smarter AI adoption.&lt;/P&gt;
&lt;H3&gt;Tools that make it easier&lt;/H3&gt;
&lt;P&gt;When it comes to Microsoft 365 deployments, you’re never alone. FastTrack for Microsoft 365 offers a full set of resources to help you learn about, build, manage, and instruct end users on Copilot Chat agents:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Credentialed access, sign in required:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2238685" target="_blank" rel="noopener"&gt;Microsoft 365 advanced deployment guides and assistance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 Copilot onboarding hub&lt;/LI&gt;
&lt;LI&gt;Microsoft 365 Copilot: Quickstart, Copilot Chat licensing&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Open access, no sign-in required:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Get started with &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2320131" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot extensibility&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2297292" target="_blank" rel="noopener"&gt;Microsoft 365 Copilot ADG: Streamlining your Copilot journey&lt;/A&gt; (video)&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2325519" target="_blank" rel="noopener"&gt;Copilot Chat Success Kit &lt;/A&gt;– Microsoft Adoption&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://aka.ms/CopilotM365SetupDB" target="_blank" rel="noopener"&gt;Microsoft Copilot AI setup and usage guides&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2325458" target="_blank" rel="noopener"&gt;AI in business: Artificial intelligence tools &amp;amp; solutions&lt;/A&gt; (blog)&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://setup.cloud.microsoft/microsoft-365-fasttrack-assistance" target="_blank" rel="noopener"&gt;Request assistance from FastTrack&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Deployment blueprint: Get started today&lt;/H2&gt;
&lt;P&gt;Remember: You don’t need to roll out everything at once. Start small, build momentum, and scale responsibly.&lt;/P&gt;
&lt;P&gt;Here’s a blueprint that will get you to the finish line:&lt;/P&gt;
&lt;H3&gt;Copilot Chat agent deployment checklist&lt;/H3&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1: Prepare your environment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Set up Copilot Studio and review licensing.&lt;/P&gt;
&lt;P&gt;☐ Create Power Platform environments that reflect your data boundaries and governance needs.&lt;/P&gt;
&lt;P&gt;☐ Identify early declarative agent use cases (e.g., HR FAQs, IT help desk).&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Note: Only declarative agents are currently supported in Copilot Chat. Agents that access tenant data (e.g., SharePoint, Graph) require pay-as-you-go billing.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2: Define governance policies&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Use role-based access control (RBAC) to manage who can create, publish, and use agents.&lt;/P&gt;
&lt;P&gt;☐ Apply naming conventions, approval workflows, and publishing guidelines.&lt;/P&gt;
&lt;P&gt;☐ Set up guardrails for data access, agent behavior, and knowledge sources.&lt;/P&gt;
&lt;P&gt;☐ Assign&amp;nbsp;maker permissions&amp;nbsp;via Microsoft Entra groups or Copilot Studio user licenses.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 3: Deploy and monitor&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Use the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2238685" target="_blank" rel="noopener"&gt;Microsoft admin center &lt;/A&gt;and Power Platform admin center to manage billing and access.&lt;/P&gt;
&lt;P&gt;☐ Monitor usage with audit logs, analytics, and the Copilot Control System.&lt;/P&gt;
&lt;P&gt;☐ Identify which teams are still using unauthorized AI tools and guide them toward approved Copilot agents.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 4: Support and scale&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;☐ Offer training, templates, and office hours to support agent creators and users.&lt;/P&gt;
&lt;P&gt;☐ Establish a Center of Excellence (CoE) to share best practices and governance.&lt;/P&gt;
&lt;P&gt;☐ Highlight successful use cases to drive adoption and build momentum.&lt;/P&gt;
&lt;P&gt;☐ Encourage feedback loops to refine agent behavior and expand scenarios.&lt;/P&gt;
&lt;H2&gt;Shadow AI prevention checklist&lt;/H2&gt;
&lt;P&gt;What else should you do to discourage shadow AI? Here's a handy checklist of actions to take:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Data protection&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Apply &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2093022" target="_blank" rel="noopener"&gt;Microsoft Purview DLP policies&lt;/A&gt; to monitor and restrict sensitive data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use sensitivity labels and encryption to protect data at rest and in transit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Set up conditional access policies to limit AI tool usage by role, device, or location.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Acceptable use&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Publish clear guidance on approved AI tools and data usage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Include AI-specific clauses in acceptable use and security policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Reinforce policies through onboarding, training, and regular reminders.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Monitoring and detection&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use Microsoft Defender for Cloud Apps (MCAS) to detect unsanctioned AI usage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Analyze browser traffic and app usage patterns for high-risk behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Set up alerts for uploads to known AI endpoints (e.g., ChatGPT, Claude).&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Education and empowerment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Run awareness campaigns about shadow AI risks and approved alternatives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Offer training on how to use Copilot and Copilot Chat agents effectively.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Create a feedback loop for users to request new AI capabilities.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Internal partnerships&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Collaborate with HR, legal, and other teams to understand AI needs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Support business units in building Copilot Chat agents with IT oversight.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use shadow AI behavior as a signal for unmet needs and prioritize accordingly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Governance alignment&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Align Copilot deployment with your organization’s responsible AI principles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Document how Copilot Chat agents support ethical and regulatory standards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;☐ Use audit logs and analytics to support transparency and accountability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jun 2025 22:17:46 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/bring-ai-out-of-the-shadows-with-agents-for-microsoft-365/ba-p/4426846</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-06-30T22:17:46Z</dc:date>
    </item>
    <item>
      <title>Driving adoption and measuring impact with the Microsoft 365 Copilot Dashboard</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/driving-adoption-and-measuring-impact-with-the-microsoft-365/ba-p/4414283</link>
      <description>&lt;P&gt;Since 2023, nearly &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2320471" target="_blank" rel="noopener"&gt;70%&lt;/A&gt; of Fortune 500 companies have &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2320471" target="_blank" rel="noopener"&gt;integrated Microsoft 365 Copilot’s advanced AI into their daily workflows&lt;/A&gt;, unlocking new efficiencies and streamlining collaboration—and they’re seeing measurable business impact.&lt;/P&gt;
&lt;P&gt;For example, Vodafone&amp;nbsp;discovered employees who use Copilot save an average of&amp;nbsp;3 hours per week, reclaiming 10% of their workweek. Lumen Technologies estimates that using Copilot will help their sales teams save $50 million per year.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are game-changing outcomes. But how do these companies know their numbers are accurate? And how did they achieve them? The key to maximizing the value of AI-driven productivity tools is more than simply licensing your end users and waiting for them to make the most of it. In fact, the key lies in &lt;STRONG&gt;measuring its impact&lt;/STRONG&gt;. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;To drive meaningful adoption and maximize ROI with Microsoft 365 Copilot, organizational leaders need clear visibility into how their workforces are using it. This means understanding:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Who’s adopting AI with Copilot.&lt;/LI&gt;
&lt;LI&gt;How effectively is Copilot supporting workflows.&lt;/LI&gt;
&lt;LI&gt;What measurable productivity gains are users achieving.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In this article, business leaders and IT can learn more about the Microsoft 365 Copilot dashboard, including its key features and core metrics.&lt;/P&gt;
&lt;P&gt;We'll also go over IT's tasks for configuring the dashboard and granting access to business leaders so they can analyze Copilot usage patterns themselves, refine their Copilot engagement strategies, and help drive productivity gains in their teams and throughout the organization.&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;What is the Copilot Dashboard?&lt;/H2&gt;
&lt;P&gt;The Microsoft Copilot Dashboard is a tool in Viva Insights that helps IT, business leaders, change managers, and other non-technical stakeholders track usage of Microsoft 365 Copilot with practical insights they can use to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Prepare users to work effectively with AI&lt;/LI&gt;
&lt;LI&gt;Drive Copilot adoption across teams&lt;/LI&gt;
&lt;LI&gt;Measure impact on workplace behavior&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Key features and core metrics of the Copilot Dashboard&lt;/H3&gt;
&lt;P&gt;With a Viva Insights license, your unlock advanced dashboard features, including:&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Comprehensive Metrics &lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;A 28-day aggregated view of Copilot usage, adoption, readiness, and impact, to help you understand engagement and Copilot business value.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Readiness tracking&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Based on Microsoft 365 app usage patterns, these metrics can help you identify which teams are ready to adopt AI into their daily workflows and which may need additional support, training or upskilling.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Adoption insights&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;With adoption insights, dashboard users can track active Copilot usage patterns within each Microsoft 365 app to measure how effectively teams are integrating Copilot into workflows. They can also pinpoint areas where Copilot users may need training or support to maximize productivity. By default, the dashboard’s Adoption trendline shows the prior six-month trend for all users in the organization. You can adjust filters at the top of the page for specific groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG style="color: rgb(30, 30, 30); font-size: 24px;"&gt;Impact analysis&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This insight allows you to analyze how often employees in your organization use Copilot during a specified time period. Leaders can also measure productivity gains through metrics like meeting efficiency, email usage, and document collaboration.&lt;/P&gt;
&lt;P&gt;Advanced tools, such as before-and-after behavioral data and employee surveys, can reveal early and even deeper insights into Copilot’s organizational impact.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;STRONG&gt;Learning opportunities&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Use qualitative feedback data from &lt;STRONG&gt;Copilot impact pulse surveys&lt;/STRONG&gt;&amp;nbsp;to identify Copilot satisfaction levels, challenges, and areas for improvement.&lt;/P&gt;
&lt;P&gt;For example, you can compare high-adoption teams with low-adoption ones to uncover training or awareness gaps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H2&gt;Managing the Copilot Dashboard: Key admin responsibilities&lt;/H2&gt;
&lt;P&gt;Global admins play a critical role in &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267974" target="_blank" rel="noopener"&gt;configuring and managing the Copilot Dashboard&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Their roles include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Setting up and configuring the Copilot Dashboard.&lt;/LI&gt;
&lt;LI&gt;Granting access and supporting business stakeholders.&lt;/LI&gt;
&lt;LI&gt;Integrating data.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;1. Setting up and configuring the Microsoft 365 Copilot Dashboard&lt;/H3&gt;
&lt;P&gt;Global IT admins are responsible for setting up and configuring the Copilot Dashboard to align with organizational goals and requirements. This includes managing settings and turning features on and off as needed.&lt;/P&gt;
&lt;H3&gt;2. Granting access and supporting business stakeholders&lt;/H3&gt;
&lt;P&gt;Admins, you'll also need to assign permissions to specific leaders, stakeholders, or groups through the &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2070783" target="_blank" rel="noopener"&gt;Microsoft 365 admin center&lt;/A&gt; or PowerShell. Make sure stakeholders in different roles have the correct permissions.&lt;/P&gt;
&lt;P&gt;You'll also play a critical role in supporting and troubleshooting issues that users might encounter, such as technical problems and related assistance.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Who should have access to the Copilot Dashboard?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;H5&gt;&lt;STRONG&gt;Business leaders&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;You can view engagement and adoption metrics directly and make informed decisions about how best to guide users on adopting Copilot.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;Department heads&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;You'll want to monitor how your teams are using Copilot and identify areas for improvement.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;IT managers&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;You'll need to oversee the technical aspects of Copilot deployment and ensure smooth operations.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;HR Managers&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Track employee sentiment and impact metrics for workforce planning and development.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;How do admins grant access to the Copilot Dashboard?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;You can delegate and manage access for individuals or groups to the dashboard in two different ways:&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;1. The Microsoft 365 admin center&lt;/STRONG&gt;&lt;/H5&gt;
&lt;OL&gt;
&lt;LI&gt;Access&lt;STRONG&gt; &lt;/STRONG&gt;the&lt;STRONG&gt; &lt;A href="https://go.microsoft.com/fwlink/?linkid=2267974" target="_blank" rel="noopener"&gt;Copilot Dashboard here&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;or&lt;/LI&gt;
&lt;LI&gt;Sign in to &lt;A href="https://go.microsoft.com/fwlink/?linkid=2070783" target="_blank" rel="noopener"&gt;Microsoft 365 admin center&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Navigate to the &lt;STRONG&gt;Settings&lt;/STRONG&gt; tab&lt;/LI&gt;
&lt;LI&gt;Select &lt;STRONG&gt;Setup&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Go to the &lt;STRONG&gt;Copilot Dashboard&lt;/STRONG&gt; to &lt;STRONG&gt;Manage access settings&lt;/STRONG&gt;. From there you can search for and select users to grant or revoke access.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Manage access for groups by selecting the &lt;STRONG&gt;Groups&lt;/STRONG&gt; option, searching for Entra ID groups, and adding or removing users as needed.&lt;/P&gt;
&lt;H5&gt;&lt;STRONG&gt;2. PowerShell&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;Viva Insights admins can delegate access to organizational insights and the Copilot Dashboard using PowerShell.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set policies to enable or disable access to the dashboard at the tenant level using PowerShell cmdlets. This method gives you more granular control. Use it to manage access for larger groups or the entire organization.&lt;/P&gt;
&lt;P&gt;Note: You can only delegate access to users with a Viva Insights license. Viva Insights is available as part of the Microsoft Viva Suite or as a standalone add-on to Microsoft 365 enterprise plans.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;How&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;do business stakeholders access the Copilot Dashboard?&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Business stakeholders, you can &lt;STRONG&gt;access the Microsoft 365 Copilot Dashboard through your Teams Viva Insights app&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;3. Integrating organizational data into the dashboard&lt;/H3&gt;
&lt;P&gt;Admins will upload organizational data directly through the admin center and configure it for analysis. If both the Viva Insights admin and the Global admin upload data, the dashboard will merge these uploads and display insights based on the most recent data.&lt;/P&gt;
&lt;H2&gt;Empowering business stakeholders with insights they can act on&lt;/H2&gt;
&lt;P&gt;Microsoft 365 Copilot is transforming productivity, and metrics powered by Viva Insights are proving its impact to the world.&lt;/P&gt;
&lt;P&gt;Access the Copilot Dashboard today for yourself and unlock Copilot’s full potential for driving organizational success.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Learn more&lt;/H3&gt;
&lt;P&gt;For more information on connecting to the Copilot Dashboard for Microsoft 365 customers, watch our recent video,&amp;nbsp;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2321702" target="_blank" rel="noopener"&gt;AI Transformation: Maximize the value of Copilot with Copilot Dashboard&lt;/A&gt; and check out our article: &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2321701" target="_blank" rel="noopener"&gt;Connect to the Microsoft Copilot Dashboard for Microsoft 365 customers | Microsoft Learn.&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Need more assistance? FastTrack is here to help!&lt;/H2&gt;
&lt;P&gt;FastTrack is available to support customers with&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267193" target="_blank" rel="noopener"&gt;eligible licenses&lt;/A&gt;. &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2267262" target="_blank" rel="noopener"&gt;Request assistance from FastTrack&lt;/A&gt; today or contact your assigned FastTrack Architect (FTA).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 18:35:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/driving-adoption-and-measuring-impact-with-the-microsoft-365/ba-p/4414283</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-05-29T18:35:37Z</dc:date>
    </item>
    <item>
      <title>Deploy Microsoft Defender XDR today and start protecting your entire digital estate</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/deploy-microsoft-defender-xdr-today-and-start-protecting-your/ba-p/4399254</link>
      <description>&lt;P&gt;The average organization now hosts 351 exploitable attack pathways, says Microsoft’s 2024 State of Multicloud Security Risk Report&lt;SUP class="footnote-ref"&gt;&lt;A href="#community--1-footnote1" target="_blank"&gt;1&lt;/A&gt;&lt;/SUP&gt;, so it’s no wonder leaders across sectors are calling for enhanced protection of high-value assets within applications, email, endpoints, identity, and more.&lt;/P&gt;
&lt;P&gt;But deploying a comprehensive security solution like Microsoft Defender XDR can be a big lift, especially in organizations using legacy systems or a mix of third-party tools. Complex integrations and configurations combined with common issues like limited staffing resources can further delay or even prevent full product implementation.&lt;/P&gt;
&lt;P&gt;Fortunately, FastTrack for Microsoft 365 is ready to help streamline your security product deployment and today we’ll explain how.&lt;/P&gt;
&lt;P&gt;In this blog, you’ll learn:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Why Microsoft Defender platform adds value beyond security.&lt;/LI&gt;
&lt;LI&gt;How to deploy Microsoft Defender efficiently and securely using Microsoft admin center advanced deployment guides.&lt;/LI&gt;
&lt;LI&gt;Answers to FAQs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Microsoft Defender: The industry leading&lt;SUP class="footnote-ref"&gt;&lt;A href="#community--1-footnote2" target="_blank"&gt;2&lt;/A&gt;&lt;/SUP&gt;, XDR solution with added value&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Microsoft Defender protects your entire organization with a unified security platform that consolidates multiple security functions (e.g., endpoint, identity, cloud security) under a single tool.&lt;/P&gt;
&lt;P&gt;This comprehensive coverage creates &lt;EM&gt;overlapping&lt;/EM&gt; security, which strengthens overall security and helps reduce workloads for security and IT teams.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And while in some cases, transitioning security systems can create vulnerabilities in the short term, FastTrack engineers at Microsoft have solved for this by providing&lt;STRONG&gt; incremental security coverage &lt;/STRONG&gt;as you wind down third-party point solutions. We’ll describe this in more detail later on but first let’s go over the Microsoft Defender platform.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;The Microsoft Defender platform&lt;/STRONG&gt;:&amp;nbsp;&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps prevent, detect, investigate, and respond to advanced threats with next-gen antivirus, endpoint detection response (EDR), automated investigation, and prioritized remediation capabilities. &lt;A href="https://go.microsoft.com/fwlink/?linkid=2281448" target="_blank"&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint setup guide&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Office 365&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Protects email and collaboration tools like SharePoint, OneDrive, and Microsoft Teams against advanced threats, i.e., phishing, business email compromise, and malware attacks. &lt;A href="https://go.microsoft.com/fwlink/?linkid=2281529" target="_blank"&gt;&lt;STRONG&gt;Microsoft Defender for Office 365 setup guide&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Identity&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Protects on-premises Active Directory from targeted attacks with signals that identify, detect, and investigate compromised identities and malicious insider actions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2281530" target="_blank"&gt;&lt;STRONG&gt;Microsoft Defender for Identity&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;U&gt; setup guide&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Cloud Apps&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;A Cloud Access Security Broker (CASB) that uses rich visibility, control over data travel, and sophisticated analytics to identify and combat cyber threats across cloud services. Gain visibility into Shadow IT, discover cloud apps in use, control and protect data within apps, and detect and respond to threats across all potential threat vectors.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2281449" target="_blank"&gt;&lt;STRONG&gt;Microsoft Defender for Cloud Apps setup guide&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Microsoft Defender XDR, powered by AI, integrates seamlessly with other Microsoft 365 products and security tools&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Seamless integration provides for stronger, more consistent, automated security across the entire software ecosystem. For example:&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;Microsoft Defender is embedded with Microsoft Sentinel&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Microsoft Sentinel is a new FastTrack offering. It’s a very powerful cloud-native, AI-powered security information and event management (SIEM) solution that helps teams address top cyberthreats, including ransomware attacks, by: &amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Enriching data with machine learning:&lt;/STRONG&gt; Sentinel employs machine learning to enrich data with Microsoft's threat intelligence, the secret ingredient that fuels capabilities, including threat hunting, detecting, investigating, and responding to threats across an ecosystem.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reducing “alert fatigue”:&lt;/STRONG&gt; Sentinel filters through billions of signals, correlates them into alerts and incidents, and even prioritizes incidents. This allows for more efficient and cost-effective remediation strategies and reduced alert fatigue for SOC teams.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;STRONG&gt;Microsoft Defender integrates with Azure’s Microsoft Defender for Cloud&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Microsoft Defender for Cloud is a cloud-native application protection platform (CNAPP) that secures full-stack workloads, end to end, across Amazon Web Services, Google Cloud Platform, and Azure Cloud Services with constant cyberthreat monitoring at the code level.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;How to deploy Microsoft Defender security products efficiently and securely &lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Because each organization’s deployment scenario will be as unique as the organization itself, Microsoft engineers designed Defender to be highly customizable and able to accommodate a variety of different scenarios. However, no one should let complexities surrounding custom configurations delay deployment.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;FastTrack for Microsoft 365 is here to help&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;With a variety of self-serve resources, detailed documentation, automated, step-by-step deployment guides, and even one-on-one assistance (with an eligible license), FastTrack can help you reduce complexity and get your Microsoft Defender products up-and-running quickly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Here’s how to start&lt;/STRONG&gt;:&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;STRONG&gt;Visit the Microsoft 365 Setup site&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Regardless of license status or credentials, start your journey at the Microsoft 365 Setup site for open, self-service access to detailed setup guides, on-demand videos, and helpful blogs to plan secure and efficient Microsoft Defender deployment workloads.&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;STRONG&gt;Sign in to the Microsoft admin center &lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Once your organization owns a license and you’re ready to deploy, sign in to the Microsoft admin center and access Microsoft Defender advanced deployment and setup guides.&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;STRONG&gt;Deploy using Microsoft Defender advance deployment guides&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Start with zero trust&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2281448" target="_blank"&gt;Microsoft Defender for Endpoint setup guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2281529" target="_blank"&gt;Microsoft Defender for Office 365 setup guide&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2281530" target="_blank"&gt;Microsoft Defender for Identity setup guide&lt;/A&gt;&lt;U&gt; &lt;/U&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2281449" target="_blank"&gt;Microsoft Defender for Cloud Apps setup guide&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These streamlined, automated guides combine detailed documentation with stateful personalization, so you know you’re following the right instructions for your organization’s scenario. The step-by-step instructions also lead you through the correct order of operations so you can be confident you’re setting up each Microsoft Defender solution correctly, from beginning to end.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Microsoft Defender setup guides: What to expect once you get there&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Each Microsoft Defender setup guide follows a similar pattern.&lt;/P&gt;
&lt;P&gt;They begin with an &lt;STRONG&gt;Overview&lt;/STRONG&gt;, describing foundational prerequisites and &lt;STRONG&gt;Requirements&lt;/STRONG&gt;, then have you identify your organization’s particular &lt;STRONG&gt;Scenario&lt;/STRONG&gt; and goals, before walking you through your recommended &lt;STRONG&gt;Deployment&lt;/STRONG&gt; and &lt;STRONG&gt;Configuration&lt;/STRONG&gt; steps based on your scenario and Microsoft’s best practices.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Let’s walk through the &lt;STRONG&gt;Microsoft Defender for Endpoint guide&lt;/STRONG&gt; as an example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2281448" target="_blank"&gt;&lt;STRONG&gt;Microsoft Defender for Endpoint setup guide&lt;/STRONG&gt;&lt;/A&gt;&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;Arrive at &lt;STRONG&gt;Overview&lt;/STRONG&gt; (see above) to learn more about the Defender setup guide and watch a short video.&lt;/LI&gt;
&lt;LI&gt;Follow the subway navigation&lt;STRONG&gt; &lt;/STRONG&gt;and&amp;nbsp;review &lt;A href="https://learn.microsoft.com/microsoft-365/security/defender-endpoint/minimum-requirements" target="_blank"&gt;Microsoft Defender for Endpoint’s minimum setup requirements&lt;STRONG&gt;‎&lt;/STRONG&gt;&lt;/A&gt; to make sure you’re ready for a secure setup experience before you begin.&lt;/LI&gt;
&lt;LI&gt;At &lt;STRONG&gt;Scenario&lt;/STRONG&gt;, identify your organization’s current security situation and your goals, for example:&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;Do you already have an endpoint security solution in place?&lt;/LI&gt;
&lt;LI&gt;Would you like to see how Defender for Endpoint works before rolling it out?&lt;/LI&gt;
&lt;LI&gt;Do you want help designing configurations?&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;At &lt;STRONG&gt;Deployment&lt;/STRONG&gt;, find Microsoft’s recommended next steps based on your &lt;STRONG&gt;Scenario&lt;/STRONG&gt;. These steps include:&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Preparation&lt;/STRONG&gt;: Key points to consider as you prepare for migration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Setup&lt;/STRONG&gt;: Guidance on which specific steps you should carry out next.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Onboarding to your tenant&lt;/STRONG&gt;: Advice on how to onboard while protecting other platforms in your environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;5. Lastly,&lt;STRONG&gt; Configuration&lt;/STRONG&gt; is where you’ll configure various settings and learn more about:&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;Attack surface reduction&lt;/LI&gt;
&lt;LI&gt;Mobile threat defense&lt;/LI&gt;
&lt;LI&gt;Next-generation protection&lt;/LI&gt;
&lt;LI&gt;Auto remediation and investigation&lt;/LI&gt;
&lt;LI&gt;Microsoft Secure Score&lt;/LI&gt;
&lt;LI&gt;Endpoint detection and response&lt;/LI&gt;
&lt;LI&gt;Threat and vulnerability management&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;Frequently asked questions&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Transitioning to or implementing a new security suite can be tricky. However, Microsoft Defender setup guides have been designed to eliminate as much risk and friction as possible from the deployment process. They also do a great job of anticipating and addressing questions admins frequently ask. Here are a few frequently asked questions and answers:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;How do I securely migrate to Microsoft Defender for Office 365?&amp;nbsp;&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN class="lia-text-color-21"&gt;Read&amp;nbsp;&lt;SPAN class="lia-text-color-10"&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2313419" target="_blank"&gt;this Learn article&lt;/A&gt;&lt;/SPAN&gt; to understand &lt;SPAN class="lia-text-color-10"&gt;securely &lt;/SPAN&gt;&lt;SPAN class="lia-text-color-10"&gt;migrating from a third-party protection service or device &lt;/SPAN&gt;to ‎Microsoft Defender for Office 365‎.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;How should I deal with urgent security incident response issues?&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Get a better understanding of the&lt;STRONG style="font-style: var(--lia-blog-font-style); font-family: var(--lia-blog-font-family); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base); background-color: var(--lia-rte-bg-color);"&gt; &lt;/STRONG&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base); background-color: var(--lia-rte-bg-color);"&gt;complex threats affecting your organization. Subscribers to &lt;/SPAN&gt;&lt;A class="lia-external-url" style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); font-size: var(--lia-bs-font-size-base);" href="https://go.microsoft.com/fwlink/?linkid=2313334" target="_blank"&gt;Defender Experts for Hunting&lt;/A&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base); background-color: var(--lia-rte-bg-color);"&gt; can engage with their own security incident response teams to address urgent security incident response issues.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="font-style: var(--lia-blog-font-style); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base);"&gt;Where can I go to learn how to fix onboarding issues myself?&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2313504" target="_blank"&gt;Microsoft Defender for Endpoint&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2313420" target="_blank"&gt;Microsoft Defender for Identity&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2313421" target="_blank"&gt;Microsoft Defender for Office 365&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2313422" target="_blank"&gt;Microsoft Defender for Cloud Apps&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base);"&gt;&amp;nbsp; &amp;nbsp; 4. &lt;STRONG&gt;Does &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG style="font-style: var(--lia-blog-font-style); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base);"&gt;Microsoft offer training for Microsoft Defender?&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI&gt;Yes! To get started with Microsoft Defender training, browse the &lt;A href="https://learn.microsoft.com/en-us/training/browse/?products=m365-ems-cloud-app-security%2Cdefender-for-cloud-apps%2Cdefender-identity%2Cm365-information-protection%2Cm365-threat-protection%2Cmdatp%2Cdefender-office365&amp;amp;expanded=m365%2Coffice-365" target="_blank"&gt;list of learning paths&lt;/A&gt;, and filter by product, role, level, and subject.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;Need additional assistance?&amp;nbsp;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Whether you have a few questions or want assistance with deployment of your entire Microsoft Defender suite, FastTrack Engineers and Partners are ready to help.&amp;nbsp;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2311906" target="_blank"&gt;Eligible customers&lt;/A&gt;&amp;nbsp;can &lt;A class="lia-external-url" href="https://aka.ms/FastTrackRFA" target="_blank"&gt;request direct, remote assistance from FastTrack for Microsoft 365&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_ftnref1" name="_ftn1" target="_blank"&gt;[1]&lt;/A&gt; &lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-product-and-services/security/pdf/2024-State-of-Multicloud-Security-Risk-Report.pdf" target="_blank"&gt;Microsoft’s 2024 State of Multicloud Security Report&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="#community--1-_ftnref2" name="_ftn2" target="_blank"&gt;[2]&lt;/A&gt; Microsoft Defender was named an XDR leader in &lt;A href="https://www.microsoft.com/en-us/security/blog/2024/06/03/microsoft-is-named-a-leader-in-the-forrester-wave-for-xdr/#:~:text=Get%20end-to-end%20protection%20with%20Microsoft%E2%80%99s%20unified%20security%20operations%20platform.?msockid=11c237fa8d2766be11f723698c9d67ca" target="_blank"&gt;The Forrester Wave: XDR platforms&lt;/A&gt;, Q2 2024, receiving top scores in 15 of 22 criteria, including Endpoint Detection, Threat Hunting, and Innovation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 18:22:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/deploy-microsoft-defender-xdr-today-and-start-protecting-your/ba-p/4399254</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-03-31T18:22:33Z</dc:date>
    </item>
    <item>
      <title>The future of Microsoft 365 deployment: Microsoft 365 Setup Expert</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/the-future-of-microsoft-365-deployment-microsoft-365-setup/ba-p/4390838</link>
      <description>&lt;P&gt;Are you an IT professional, a business or technical decision-maker, or stakeholder involved with managing Microsoft 365 environments? If so, you need quick and reliable access to setup and deployment information. Now you have that access at your fingertips with&amp;nbsp;&lt;STRONG&gt;Microsoft 365 Setup Expert&lt;/STRONG&gt;. Read below for more details or &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2309800" target="_blank"&gt;check out the full blog post here&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;What is Microsoft 365 Setup Expert?&lt;/H2&gt;
&lt;P&gt;Microsoft 365 Setup Expert is an innovative, AI-powered solution that helps IT, BDMS, TDMs, and related stakeholders streamline their Microsoft 365 setup and deployment workloads.&lt;/P&gt;
&lt;P&gt;Developed by FastTrack engineers, this tool responds to queries with the information you need to make informed decisions about product purchases, licensing, deployment, and troubleshooting.&lt;/P&gt;
&lt;H2&gt;Advantages of Using Setup Expert&lt;/H2&gt;
&lt;P&gt;Setup Expert delivers essential insights for navigating Microsoft 365 setup workflows with confidence, regardless of your job role or credentials.&lt;/P&gt;
&lt;H4&gt;Key Features&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Prepurchase guidance&lt;/STRONG&gt;: Evaluate different Microsoft 365 solutions, compare licensing options, and get recommendations for compliance, remote work, and security scenarios.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Post-purchase support&lt;/STRONG&gt;: Plan product rollouts, deploy advanced features, troubleshoot issues, and scale deployments based on organizational needs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reliable information&lt;/STRONG&gt;: Sourced from official Microsoft channels, ensuring accuracy and relevance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Role-based responses&lt;/STRONG&gt;: Tailored insights for both technical and non-technical users.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Real-World Applications&lt;/H4&gt;
&lt;P&gt;Whether you're planning a new deployment or managing an existing environment, Microsoft 365 Setup Expert can help you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Simplify and expedite deployments&lt;/LI&gt;
&lt;LI&gt;Reduce reliance on credentialed admins&lt;/LI&gt;
&lt;LI&gt;Foster collaboration across roles&lt;/LI&gt;
&lt;LI&gt;Streamline procurement decisions&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Learn more about Microsoft 365 Setup Expert&lt;/H2&gt;
&lt;P&gt;Dive deeper into how Setup Expert can transform your setup processes in the&lt;A href="https://go.microsoft.com/fwlink/?linkid=2309800" target="_blank"&gt;&amp;nbsp;full blog post&lt;/A&gt; at the Setup site.&lt;/P&gt;
&lt;P&gt;Find Setup Expert at &lt;A href="https://go.microsoft.com/fwlink/?linkid=2309800" target="_blank"&gt;setup.cloud.microsoft&lt;/A&gt; and start leading your organization through smarter, faster, and more collaborative deployments today!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 20:45:21 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/the-future-of-microsoft-365-deployment-microsoft-365-setup/ba-p/4390838</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-03-07T20:45:21Z</dc:date>
    </item>
    <item>
      <title>3 internal obstacles to overcome for comprehensive security</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/3-internal-obstacles-to-overcome-for-comprehensive-security/ba-p/4366840</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Organizations today face relentless security challenges, fending off an average of 59 data security incidents each year.&lt;/SPAN&gt;&lt;SUP&gt;&lt;A href="#community--1-footnote1" target="_self"&gt;1&lt;/A&gt;&lt;/SUP&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;At&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;an average cost of $15 million,&lt;SUP&gt;&lt;A href="#community--1-footnote2" target="_blank"&gt;2&lt;/A&gt;&lt;/SUP&gt;&amp;nbsp;successful exploits&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;can be devasting.&lt;/SPAN&gt; To a&lt;SPAN data-contrast="auto"&gt;ddress these risks, organizations need a comprehensive defense, including committed leadership and cutting-edge tools. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At Microsoft, safeguarding data, technology, and &lt;/SPAN&gt;&lt;A href="https://clouddamcdnprodep.azureedge.net/gdc/gdckHueRY/original" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;secure AI adoption&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;SPAN data-contrast="auto"&gt;is a year-round priority.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In fact, Charlie Bell, executive vice president of Microsoft Security, recently underscored &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2024/09/23/securing-our-future-september-2024-progress-update-on-microsofts-secure-future-initiative-sfi/?msockid=11c237fa8d2766be11f723698c9d67ca" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft’s “unique responsibility&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; in safeguarding the future for our customers and community.”&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As part of meeting this responsibility, Microsoft’s advanced security solutions include Microsoft Defender XDR, a platform designed to provide holistic security against today’s complex threats. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;While solutions like Microsoft Defender XDR are invaluable, getting them deployed can sometimes be challenging. Organizations may face internal hurdles—conflicting priorities, resource limitations, even resistance to change—that can slow or stall implementation of essential security tools. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In this article, we’ll explore three common hurdles and discuss how, by deploying Microsoft security products, you can help ensure a more secure future at your organization.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;3 common internal obstacles to achieving comprehensive security&lt;/SPAN&gt;&lt;/H2&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;1. Reluctance to replace individual, legacy solutions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In the past, organizations commonly implemented individual security tools for different, siloed areas of the organization. Today, we know this fragmented approach&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;weakens&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; data security.&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;In fact, according to Microsoft’s &lt;/SPAN&gt;&lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-product-and-services/security/pdf/2024-State-of-Multicloud-Security-Risk-Report.pdf" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;2024 State of Multicloud Security Risk Report&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; organizations using multiple individual point solutions experience 2.8 times as many data security incidents as those using fewer, integrated tools. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Here's a table comparing the performance of individual point solutions vs. Microsoft Defender XDR, the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;industry-leading unified security platform.&lt;SUP&gt;&lt;A href="#community--1-footnote3" target="_self"&gt;3&lt;/A&gt;&lt;/SUP&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Is sunk cost fallacy to blame?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;“&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Security is an area significantly impacted by behavioral economics."&lt;SUP&gt;&lt;A href="#community--1-footnote4" target="_self"&gt;4&lt;/A&gt;&lt;/SUP&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;Sunk cost fallacy can lead cybersecurity professionals to resist replacing existing systems, even when evidence suggests it's necessary. &lt;SPAN data-contrast="auto"&gt;According to Forbes: “The biggest risk in viewing cybersecurity as a sunk cost is inaction. In other words, thinking that you are safe because you haven’t yet suffered a major breach. Remember this maxim: Everyone is vulnerable."&lt;SUP&gt;&lt;A href="#community--1-footnote5" target="_self"&gt;5&lt;/A&gt;&lt;/SUP&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To move past sunk-cost fallacy, Forbes says decision-makers need to understand that “the implementation of robust security measures can deliver substantial value beyond just mitigating risks.”  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;By examining ROI and a products’ impact on improving security, reducing complexity, and streamlining operations “...businesses can start recognizing cybersecurity as a &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;driver&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; of competitive advantage, innovation and operational efficiency,” instead of as simply a cost center&lt;SUP&gt;&lt;A href="#community--1-footnote6" target="_self"&gt;6 &lt;/A&gt;&lt;/SUP&gt;&lt;SPAN data-contrast="auto"&gt;[Emphasis added]. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As an example of the potential for ROI, a &lt;/SPAN&gt;&lt;A href="https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE567qf#:~:text=The%20decision-maker%20interviews%20and%20financial%20analysis%20found%20that%20a%20composite" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;2022 Forrester TEI study&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; found that a &lt;/SPAN&gt;&lt;A href="https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE567qf#:~:text=The%20decision-maker%20interviews%20and%20financial%20analysis%20found%20that%20a%20composite" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;composite company&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; achieved &lt;STRONG&gt;an ROI of 242% over three years and a net present value (NPV) of $17 million from switching to Microsoft Defender.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;It's easy to overestimate the value of individual or legacy security solutions but the clear security advantages and proven ROI of Microsoft Defender XDR demonstrate that replacing legacy systems can be well worth the effort. &lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="3"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;2. Concerns about ensuring secure integration&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259,&amp;quot;469777462&amp;quot;:[720],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[0]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If not managed carefully, integrations involving newly opened communication, authentication, or data transfer channels can introduce vulnerabilities that become attack vectors. Microsoft’s &lt;/SPAN&gt;&lt;A href="https://microsoft-my.sharepoint.com/personal/v-jhersum_microsoft_com/Documents/2024-State-of-Multicloud-Security-Risk-Report.pdf%20(microsoft.com)" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;2024 State of Multicloud Security Risk Report&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; notes that “...misconfigured APIs were one of the leading causes of cloud data breaches in 2023.”&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As a unified security platform, Microsoft Defender XDR mitigates such risks through a multilayered approach, through a multilayered approach, offering centralized management (including identity access), comprehensive visibility, and stronger security controls to help prevent human error. This approach “help[s] security teams proactively detect and monitor misconfigurations so they can remediate as needed."&lt;SUP&gt;&lt;A href="#community--1-footnote7" target="_self"&gt;7&lt;/A&gt;&lt;/SUP&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Consistent, automated security with Microsoft Defender XDR&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender XDR integrates seamlessly with other Microsoft security tools, Microsoft 365 products, and AI, delivering consistent, automated security across the entire stack. For example:  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="25" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender XDR is &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/introducing-a-unified-security-operations-platform-with/ba-p/3983341" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;embedded with Microsoft Sentinel&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, a cloud-native, AI-powered SIEM solution that aids Microsoft Defender XDR in addressing top cyberthreats like ransomware through: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Improved visibility across domains:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; By ingesting data from an organization's infrastructure, devices, users, applications, and cloud environments, Microsoft Sentinel gives security teams a broad view of security threats.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="o" data-font="Courier New" data-listid="46" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Enriched data with machine learning: &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Sentinel employs machine learning to enrich data with Microsoft threat intelligence, powering threat hunting, detection, investigation, and response across an ecosystem. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI data-leveltext="o" data-font="Courier New" data-listid="46" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Reduced alert fatigue:&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Filtering billions of signals, correlating them into alerts, and prioritizing incidents helps SOC teams handle alerts more efficiently, minimizing fatigue and enabling focused remediation. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="29" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender integrates with Azure’s Microsoft Defender for Cloud&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, a cloud-native application protection platform (CNAPP) that secures workloads across Amazon Web Services, Google Cloud Platform, and Azure Cloud Services with constant cyberthreat monitoring at the code level. This capability allows: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI data-leveltext="o" data-font="Courier New" data-listid="47" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Broad attack investigation&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: Security teams can investigate threats across cloud resources, devices, and identities. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI data-leveltext="o" data-font="Courier New" data-listid="47" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Workload-specific protections&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: Dedicated protections extend to servers, containers, storage, databases, and more. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI data-leveltext="o" data-font="Courier New" data-listid="47" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Actionable security recommendations&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;: Defender for Cloud provides insights to improve overall security posture and prevent breaches. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;3. Resource, staff, and time constraints&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Resource constraints, staff shortages, and time limitations are intensifying today’s already challenging cybersecurity landscape and can, understandably, impede deployments of new security products. For example:  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="34" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Resource constraints:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;Many organizations face limited budgets for security tools, technology, and personnel, leading them to continue with patchwork solutions or delay implementing critical security measures, potentially leaving gaps in security. &lt;SPAN style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="35" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Staff shortages:&lt;/SPAN&gt; &lt;/STRONG&gt;As cyber threats become more sophisticated, global demand for skilled IT and security professionals continues to grow while supply hasn’t been able to keep up.&lt;SUP style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color);"&gt;&lt;A href="#community--1-footnote8" target="_self"&gt;8&lt;/A&gt;&lt;/SUP&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base);" data-contrast="auto"&gt;&amp;nbsp;When insufficient staff results in missed security tasks, reduced monitoring, and slower incident responses, organizations can be left vulnerable to risk. &lt;/SPAN&gt;&lt;SPAN style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="36" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Limited time: &lt;/SPAN&gt;&lt;/STRONG&gt;Time constraints are a problem as old as time itself, but for IT teams with already heavy workloads, one more thing to do is more than stressful, it can leave systems vulnerable and increase windows of opportunity for bad actors. &lt;SPAN style="font-style: var(--lia-blog-font-style); font-weight: var(--lia-blog-font-weight); font-family: var(--lia-blog-font-family); background-color: var(--lia-rte-bg-color); color: var(--lia-bs-body-color); font-size: var(--lia-bs-font-size-base);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;FastTrack resources to help you get Microsoft Defender up and running&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For Microsoft 365 customers experiencing any of the issues mentioned above, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;FastTrack for Microsoft 365&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; is here to help with accessible resources, automated, prescriptive setup guides, and even one-on-one assistance.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Here’s how to start: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;1. Visit the Microsoft 365 Setup site&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Review &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296734" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;openly accessible setup resources&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; at the Microsoft 365 Setup site. Both business and IT leaders will find value in perusing detailed &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296734" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender setup guides&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, &lt;/SPAN&gt;&lt;A href="https://setup.cloud.microsoft/videos" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;on-demand videos&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, and helpful blogs to plan for safe, efficient Microsoft Defender deployment workloads. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;2. Sign in to the Microsoft Admin Center (MAC) and start deploying Mic&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;osoft Defender using FastTrack’s automated setup guides&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When you &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296159" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;deploy Microsoft Defender XDR from the MAC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; using &lt;/SPAN&gt;&lt;A href="https://admin.microsoft.com/#/setupguidance" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;advanced deployment guides&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, you’re taking the most accurate, efficient, and secure deployment path possible.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These automated guides combine detailed documentation with step-by-step instructions tailored specifically for your environment to give you streamlined guidance from beginning to end. Start by &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296159" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;setting up&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt; Microsoft Defender Zero Trust &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;security &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;model for &lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;your organization&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;3. Request&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;assistance&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; from FastTrack for Microsoft 365&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers with &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-365/fasttrack/eligibility" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;eligible licenses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can &lt;/SPAN&gt;&lt;A href="https://aka.ms/ftcrfa" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;request remote, one-on-one assistance from FastTrack&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; before, during, or even post-deployment of Microsoft Defender.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Take the next step&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; to implement unified protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security is too crucial—and the cost of breaches are too high—to let any impediments, real or potential, delay or dissuade you from fully implementing your security investments. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When you &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296159" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;deploy Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, you’re protecting your organization with a unified security platform that combines multiple security functions—including endpoint, identity, and cloud security—under a single tool.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Start protecting your entire digital estate today:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;Keep your organization, data, and users safe by &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296159" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;implementing the comprehensive power of Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, the industry-leading XDR solution that reduces costs and overhead while helping you keep your organization secure across all domains from costly cybercrime. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more about improving your security posture with Microsoft Defender, check out our recent webinar: &lt;/SPAN&gt;&lt;A href="https://setup.cloud.microsoft/videos/supercharging-your-soc-unlock-the-power-of-endpoint-security-in-microsoft-defender-xdr" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Supercharging your SOC: Unlock the power of endpoint security in Microsoft Defender XDR.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="footnotes" style="line-height: 1; margin: 0;"&gt;
&lt;H3&gt;Footnotes&lt;/H3&gt;
&lt;H4 id="footnote1" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;1 &lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/2024-State-of-Multicloud-Security-Risk-Report.pdf#:~:text=In%20February%202022%2C%20we%20became%20the%20first%20cloud,by%20more%20than%2078%20trillion%20daily%20security%20signals." target="_blank" rel="noopener"&gt;Microsoft’s 2024 State of Multicloud Security Risk Report&lt;/A&gt;&lt;/SUP&gt;&amp;nbsp;&lt;/H4&gt;
&lt;H4 id="footnote2" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;2 &lt;A href="https://www3.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2022.pdf" target="_blank" rel="noopener"&gt;Microsoft’s Global Cybersecurity Outlook Insight Report, 2022&lt;/A&gt;&lt;/SUP&gt;&lt;/H4&gt;
&lt;H4 id="footnote3" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;3 Microsoft Defender was named&lt;A href="https://www.microsoft.com/en-us/security/blog/2024/06/03/microsoft-is-named-a-leader-in-the-forrester-wave-for-xdr/#:~:text=Get%20end-to-end%20protection%20with%20Microsoft%E2%80%99s%20unified%20security%20operations%20platform.?msockid=11c237fa8d2766be11f723698c9d67ca an XDR leader in The Forrester Wave: XDR platforms, Q2 2024&amp;lt;/a&amp;gt;&amp;lt;/a&amp;gt;, receiving top scores  in 15 of 22 criteria, including Endpoint Detection, Threat Hunting, and Innovation.&amp;lt;a href=" target="_blank" rel="noopener" is=""&gt;&amp;nbsp;an XDR leader in The Forrester Wave: XDR platforms, Q2 2024&lt;/A&gt;&lt;/SUP&gt;&lt;/H4&gt;
&lt;H4 id="footnote4" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;4 &lt;A href="https://www.darkreading.com/vulnerabilities-threats/3-ways-behavioral-economics-obstructs-cybersecurity" target="_blank" rel="noopener"&gt;3 Ways Behavioral Economics Obstructs Cybersecurity&lt;/A&gt;&lt;/SUP&gt;&lt;/H4&gt;
&lt;H4 id="footnote5" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;5 &lt;A href="https://blogs.microsoft.com/blog/2022/03/23/closing-the-cybersecurity-skills-gap-microsoft-expands-efforts-to-23-countries/" target="_blank" rel="noopener"&gt;Closing the cybersecurity skills gap&lt;/A&gt;&lt;/SUP&gt;&lt;/H4&gt;
&lt;H4 id="footnote6" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;6 &lt;A href="https://www.forbes.com/councils/forbestechcouncil/2023/08/16/cybersecurity-as-a-strategic-investment-how-roi-optimization-can-lead-to-a-more-secure-future/" target="_blank" rel="noopener"&gt;Cybersecurity As a Strategic Investment (forbes.com)&lt;/A&gt;&lt;/SUP&gt;&lt;/H4&gt;
&lt;H4 id="footnote7" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;7 &lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-product-and-services/security/pdf/2024-State-of-Multicloud-Security-Risk-Report.pdf" target="_blank" rel="noopener"&gt;2024-State-of-Multicloud-Security-Risk-Report.pdf (microsoft.com)&lt;/A&gt;&lt;/SUP&gt;&lt;/H4&gt;
&lt;H4 id="footnote8" style="font-size: 1em; margin: 0;"&gt;&lt;SUP&gt;8 &lt;A href=" https://blogs.microsoft.com/blog/2022/03/23/closing-the-cybersecurity-skills-gap-microsoft-expands-efforts-to-23-countries/" target="_blank" rel="noopener"&gt;Closing the cybersecurity skills gap (microsoft.com)&lt;/A&gt;&lt;/SUP&gt;&lt;/H4&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 28 Jan 2025 12:45:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/3-internal-obstacles-to-overcome-for-comprehensive-security/ba-p/4366840</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2025-01-28T12:45:00Z</dc:date>
    </item>
    <item>
      <title>Bring your users the future of secure personal computing with Windows 365</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/bring-your-users-the-future-of-secure-personal-computing-with/ba-p/4292015</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In this age of hybrid and remote work, organizations face a couple of challenging realities. One is that end users need to access their Windows experience seamlessly and securely from anywhere in order to stay productive. Another is that Microsoft’s end-of-service date for Windows 10 is coming up October 14, 2025.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The good news is that by migrating to Windows 365 now, you can help your organization smoothly and effectively address each of these challenges.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 allows users to stream Windows 10 or Windows 11 from the Microsoft Cloud to their personal or corporate devices with secure and reliable access to apps and data. Admins also have the ability to access and manage settings remotely and securely, empowering all to stay productive from anywhere.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Windows 365: Productivity from anywhere&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 is software-as-a-service (SaaS) that creates a Cloud PC for each user, empowering them with a familiar, personalized, and secure Windows experience, regardless of location or endpoint.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 is also a turnkey Cloud PC solution for admins, meaning it’s easy to deploy and manage with integrated tools that maximize technology investments, like Microsoft Intune and the Intune Suite.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Windows 10 end of support&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 10 end of support is coming on October 14, 2025. By embracing cloud-native management and operations with Windows 365 now, well ahead of the Windows 10 end-of-support date, you’ll be able to: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Achieve high ROI by fully capitalizing on the benefits of cloud-native solutions, such as enhanced collaboration and seamless hybrid work capabilities. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Safeguard your organization and its data by embracing cloud-native management and operations. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Support a work-from-anywhere and manage-to-anywhere environment while providing exceptional user experiences. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In addition, by utilizing Windows 365, you can receive Extended Security Updates (ESU) for any Windows 10 devices that connect to a Cloud PC and run Windows 11, at no additional cost.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more details, please refer to &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Plan for Windows 10 EOS with Windows 11, Windows 365, and ESU | Windows IT Pro Blog (microsoft.com)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;A note on security with Microsoft Zero Trust&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 is aligned with Microsoft’s Zero Trust strategy that’s secure by design—from the network to the application layers—and helps organizations: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Mitigate risks and leaks by centralizing data and access in the Microsoft cloud, not on devices. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Protect data in transit and at rest with integrated identity management and encryption. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Adopt new use cases that increase velocity, efficiency, and customer satisfaction. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Meet industry-specific requirements with centralized, cloud-based operations and security controls from Microsoft. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Achieve all of the above with minimal IT admin effort. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Get started deploying Windows 365 today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Embrace the future of work with Windows 365, the robust solution for organizations that need secure, reliable IT infrastructure and cloud capabilities that support hybrid work.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;FastTrack for Microsoft 365 is here to help&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With comprehensive technical and remote deployment assistance, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;FastTrack for Microsoft 365&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; can help you experience a streamlined and efficient transition to Windows 365 or upgrade from Windows 10 to Windows 11.   &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Windows 365 deployment resources&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI style="font-weight: bold;" data-leveltext="" data-font="Symbol" data-listid="31" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Admins with credentials&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI data-leveltext="o" data-font="Courier New" data-listid="31" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Credentialed admins can &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;start deploying Windows 365 today&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; with the &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296117" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 deployment checklist&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; located within the Microsoft 365 Admin Center.  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="font-weight: bold;" data-leveltext="" data-font="Symbol" data-listid="31" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Uncredentialed or non-admins&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="list-style-type: none;"&gt;
&lt;UL&gt;
&lt;LI data-leveltext="o" data-font="Courier New" data-listid="31" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Courier New&amp;quot;,&amp;quot;469769242&amp;quot;:[9675],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;o&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Visit the Setup site to access &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2296600" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 setup guidance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Need Windows 365 deployment &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;assistance&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;?&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers with &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-365/fasttrack/eligibility" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;eligible licenses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can request deployment assistance from FastTrack. &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-365/enterprise/request-fasttrack-assistance-microsoft-365?view=o365-worldwide" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and &lt;/SPAN&gt;&lt;A href="https://aka.ms/ftcrfa" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;submit a request for assistance here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Learn more&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/windows-365?msockid=11c237fa8d2766be11f723698c9d67ca" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Watch an &lt;/SPAN&gt;&lt;A href="https://aka.ms/Windows365Interactive" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;interactive demo of Windows 365&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 11 Nov 2024 20:43:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/bring-your-users-the-future-of-secure-personal-computing-with/ba-p/4292015</guid>
      <dc:creator>AzharullahMeer</dc:creator>
      <dc:date>2024-11-11T20:43:07Z</dc:date>
    </item>
    <item>
      <title>Microsoft 365 Copilot onboarding hub—where onboarding AI is as intuitive as using it</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/microsoft-365-copilot-onboarding-hub-where-onboarding-ai-is-as/ba-p/4245123</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Securely onboarding AI across an organization can involve several processes. Applying access controls, monitoring integrations with existing infrastructure, managing end user adoption, and more can make the project downright daunting. Add on challenges like staffing shortages and limited in-house AI expertise and you just might decide to put off introducing AI—even a system as valuable as &lt;/SPAN&gt;&lt;A href="https://adoption.microsoft.com/en-us/copilot/#implement" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 Copilot&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;—until tomorrow, or even next month.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At FastTrack for Microsoft 365, we get it.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We also know AI is too important to put off. So, to continue helping admins implement AI across their organizations as seamlessly and responsibly as possible, Microsoft 365 engineers have updated a few key portions of the &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2285748" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 Copilot onboarding hub&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These updates help simplify Microsoft 365 Copilot onboarding processes so you can empower your organization to achieve more with AI quicker and more securely than ever before.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What’s new at the Microsoft 365 Copilot onboarding hub?&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2285748" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 Copilot onboarding hub&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; has a fresh look and feel, including an upgraded, modern UI, stateful personalization, and exportable project management.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size="4"&gt;1.&amp;nbsp;&lt;SPAN class="NormalTextRun SCXW202786149 BCX0" data-ccp-parastyle="heading 3"&gt;Modern &lt;/SPAN&gt;&lt;SPAN class="NormalTextRun SCXW202786149 BCX0" data-ccp-parastyle="heading 3"&gt;UI&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;The first thing you may notice is the sleek, new card-based layout that now displays Microsoft 365 Copilot’s &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Readiness assessment&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; and three setup guides: &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Quickstart&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Foundations+&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;, and &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Advanced configurations&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;2. Microsoft 365 Copilot setup guides: Interactive, personalized, actionable&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Don’t let the onboarding hub’s pretty (inter)face fool you though, there’s more value behind those cards than meets the eye. First, here’s a quick run-down of each:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Readiness assessment&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;: Start here to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;optimize your tailored setup experience&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;. The responses you provide help Copilot’s setup guides determine which tasks you should complete, and in what order, for the safest and most efficient onboarding experience.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Quickstart&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;: In this, Copilot’s most streamlined setup guide, you can safely &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;get Copilot up and running right away&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;, with&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; minimal configuration and customization. If your organization needs a little more time to shore up data hygiene and governance, you can temporarily restrict Copilot search with &lt;/SPAN&gt;&lt;A href="https://aka.ms/RSSBlogLink" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;RSS (Restricted SharePoint Search)&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; while completing those projects.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Foundations+&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;: Build on your Quickstart setup by following steps in the Foundations+ setup guide &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;for &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;fine-tuning data protection settings and readiness options&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; according to your organizational policies.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Advanced configuration&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;:&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; L&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;everage the full potential of Copilot with &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;advanced security, privacy, and data protection controls&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;. This Advanced configuration guide also provides &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;advanced Microsoft 365 Copilot adoption resources&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; to help you boost end-user engagement.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Each Microsoft 365 Copilot setup guide uses automated wizards with customizable, stateful personalization to lead you, &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;step-by-step&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, through streamlined, interactive setup experiences&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This means Copilot setup guides are personalized &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;according to your organization’s specific scenarios and requirements, resulting in&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; a unique and highly proficient onboarding experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;How it works:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Information from your Microsoft 365 organization profile, combined with your&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;readiness assessment responses, prepopulates each guide for a comprehensive overview of your organization’s environment. This, coupled with Microsoft’s engineering expertise, allows each setup guide to accurately suggest your next task and lead you through the most efficient and secure path to onboarding Microsoft 365 Copilot.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&lt;img /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;As you advance and complete tasks, each guide also tracks your progress, accounts for tasks you’ve already finished, and adjusts Microsoft’s next suggested actions accordingly. Look for &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;personalized task tables&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; within the guides as well as &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;suggested action &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;cards at the Copilot onboarding hub.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you take a break, Copilot’s setup guides remember what steps you’ve already completed and suggest the next recommended task when you return.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;For example&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Say you’re an organization that owns E5 licensing and has deployed sensitive data policies—maybe you’re a bank. By responding “Yes” to Copilot’s readiness assessment&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;question, “Does your organization have regulated or sensitive data types?” you might be instructed to review and apply Microsoft Purview best practices next to ensure Microsoft’s strongest security and compliance standards.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;On the other hand, you could be a small organization that wants to add Copilot to your Teams subscription primarily to iterate on images. If you respond “No” to the readiness assessment question, "Do you have regulated or sensitive data types?” the guide is likely to minimize your number of basic onboarding steps.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Mature organizations and long-time customers who’ve already deployed several Microsoft 365 products may have already completed Microsoft Purview best practices. If you’re an admin in this scenario, you’ll likely have fewer steps in your Microsoft 365 Copilot onboarding journey. The guides will detect and update previously completed or nonapplicable tasks and highlight your remaining, pertinent tasks.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;In another scenario, maybe your organization purchased 100 Microsoft 365 Copilot licenses. You’ve finished assigning them all and have completed every onboarding guide. Back at the Microsoft 365 Copilot onboarding hub, you may find personalized suggested action cards to guide you on next steps. For example:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&lt;img /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;3. Expanded project management for your Microsoft 365 Copilot onboarding tasks&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We know admins rely on integrated and comprehensive project management tools to assign tasks, set deadlines, and track setup progress. To help make your job easier, Microsoft engineers have streamlined project management too.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Now you can find workload monitoring inside each&lt;/SPAN&gt; &lt;A href="https://go.microsoft.com/fwlink/?linkid=2285748" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 Copilot setup guide&lt;/SPAN&gt;&lt;/A&gt; &lt;SPAN data-contrast="none"&gt;that is:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Assignable:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; Easily distribute tasks among team members.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Trackable:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; Keep an eye on progress.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Schedulable:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; Set deadlines and timelines.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Exportable:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; T&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;rack Copilot onboarding tasks outside of the hub.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The option to &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;export&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;task management &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;is a new and practical update&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;To carry it out, simply place task information into a CSV, and then import the information to your usual project management software.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Why use FastTrack for Microsoft 365 resources to onboard Copilot?&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Can we set up and onboard Microsoft 365 Copilot manually instead, by following &lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN data-contrast="auto"&gt;a &lt;/SPAN&gt;&lt;/I&gt;&lt;A href="https://aka.ms/LearnCopilotArticle" target="_blank" rel="noopener"&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Learn article&lt;/SPAN&gt;&lt;/I&gt;&lt;/A&gt;&lt;I&gt;&lt;SPAN data-contrast="none"&gt;? y&lt;/SPAN&gt;&lt;/I&gt;&lt;SPAN data-contrast="none"&gt;ou might wonder.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Yes, you can. In fact, Microsoft Learn articles are valuable, comprehensive resources for anyone looking to understand Microsoft technologies. They're also freely accessible and kept up to date.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;However, Learn articles are static resources with universal guidance and information that’s applicable to many different industries and user environments. Following them to onboard Microsoft 365 Copilot across your organization involves interpreting which tasks and best practices apply to your specific environment and then making sure you’ve fulfilled each one.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 Copilot setup guides: a more efficient and secure way to onboard AI&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Aligned with Microsoft’s commitment to making AI broadly and responsibly available—thereby empowering every person and every organization on the planet to achieve more—Microsoft engineers have designed Microsoft 365 Copilot automated setup guides to be:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Tailored to your current state&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: From a panoramic vantage point, each Microsoft 365 Copilot setup guide assesses your organization’s environment to curate the most relevant onboarding and configuration path for you. This allows for pointed, prescriptive recommendations you can rely on.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Incorporated with Microsoft best practices&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: You’ll get a smooth, guided setup experience with prepopulated information and step-by-step instructions defined by Microsoft experts for an optimal setup experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Streamlined&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;:&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;You’ll know you’re prioritizing the correct order of operations as you progress through your Microsoft 365 Copilot onboarding journey. You won’t have to worry whether you’ve made a wrong move or missed a helpful resource.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Comprehensive&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;: Should you need additional onboarding or adoption resources, Copilot’s guides will connect you to the right resource at the right point in your setup journey.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Make the Microsoft 365 Copilot onboarding hub your destination for onboarding AI&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With modern UI, improved automation, and new capabilities, the Microsoft 365 Copilot onboarding hub and setup guides offer a faster and safer way to onboard AI.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Replace guesswork and wasted time with efficiency and security.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Feel confident you’re onboarding AI responsibly.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Shorten your time to discovering value with Microsoft 365 Copilot.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Head over to the Microsoft 365 Copilot onboarding hub and empower your end users to achieve more today, instead of waiting until tomorrow.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Navigating to the Microsoft 365 Copilot onboarding hub&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Bookmark the &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2285748" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft 365 Copilot onboarding hub&lt;/SPAN&gt;&lt;/A&gt; &lt;SPAN data-contrast="auto"&gt;for quickest access or navigate there by following these instructions:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Sign in to the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft 365 admin center&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Follow &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Setup&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; from the side menu and select &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Advanced deployment guides &amp;amp; assistance&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&lt;img /&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Scroll down or filter guides by &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Product&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; and select &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Set up Microsoft 365 Copilot&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;OL class="lia-list-style-type-lower-alpha"&gt;
&lt;LI&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&lt;img /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This takes you directly to &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2285748" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Setup Microsoft 365 Copilotopilot for Microsoft 365&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, your Microsoft 365 Copilot onboarding hub&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;. You’ve arrived!&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="4"&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;&lt;I&gt;&lt;SPAN data-contrast="auto"&gt;Need onboarding assistance?&lt;/SPAN&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:80,&amp;quot;335559739&amp;quot;:40,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;I&gt;&lt;/I&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Customers with &lt;/SPAN&gt;&lt;A href="https://aka.ms/EligibilityRequirements" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;eligible licenses&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can &lt;/SPAN&gt;&lt;A href="https://nam.safelink.emails-stable.azure-test.net/redirect/?destination=https://admin.microsoft.com/adminportal/Home?q=rfadigtar#/SetupGuidance/FastTrackAssistance&amp;amp;p=dT1hZW8mbD1lNTUwZTU0Ni0zM2Y0LTRlMzAtOThkNi03Mzg1MWI1ZGYwOWU=" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;submit a request for assistance&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; to FastTrack for help onboarding Copilot.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:true,&amp;quot;134233118&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/microsoft-365-copilot-onboarding-hub-where-onboarding-ai-is-as/ba-p/4245123</guid>
      <dc:creator>JulieHersum</dc:creator>
      <dc:date>2024-09-16T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Simplify your Windows 365 Enterprise deployment with the updated Windows 365 deployment checklist</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/simplify-your-windows-365-enterprise-deployment-with-the-updated/ba-p/4014841</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We’re excited to announce that we’ve just released an updated Windows 365 deployment checklist in the &lt;/SPAN&gt;&lt;A href="https://admin.microsoft.com/Adminportal/Home#/setupguidance" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Microsoft 365 admin center (MAC)&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What is Windows 365?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 is a cloud-based Desktop as a service (DaaS) solution that automatically creates a new type of Windows virtual machine for your customer, known as a Cloud PC. A Cloud PC is a highly available, optimized, and scalable virtual machine that provides customers with a rich Windows desktop experience. Cloud PCs are hosted in the Windows 365 service and is accessible from anywhere, on any device (&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/windows-365/enterprise" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Learn more about Windows 365&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;).&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 deployment is made to be simple (to see an end-to-end deployment overview, visit &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/deployment-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Overview of Windows 365 deployment&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;). However, we understand that our customers have unique and complex environments.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What is the Windows 365 deployment checklist?&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:257}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To help you integrate Windows 365 with your existing enterprise environment, we've compiled learnings and best practices from the Microsoft 365 FastTrack Team, which has worked with hundreds of enterprise customers. We're excited to offer these in an updated Windows 365 deployment checklist experience as part of the Advanced Deployment Guides in the Microsoft 365 Admin Center. This checklist will guide you as you plan, deploy, and scale Windows 365 in your environment.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Windows 365 deployment checklist guides admins through the considerations around Azure basics, identity, networking, licensing, management, security, applications, and end user experiences that are applicable to their deployment configuration. Admins can assign tasks for each area to the responsible stakeholders and define a target date of completion. Admins can also see a summary view with an overall status to track progress against their timelines.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;img /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;How can I access the Windows 365 deployment checklist?&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;To access the Windows Enterprise 365 checklist, visit&lt;/SPAN&gt; &lt;A href="https://go.microsoft.com/fwlink/?linkid=2251210" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;this link&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or directly at &lt;/SPAN&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2251210" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;https://go.microsoft.com/fwlink/?linkid=2251210&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:279}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Additional Resources:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://www.microsoft.com/en-us/windows-365/enterprise" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Product Info: Windows 365 Enterprise on Microsoft.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Learn: What is Windows 365 Enterprise?&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-365/enterprise/requirements?tabs=enterprise%2Cent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Learn: Requirements for ‎Windows 365‎&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://admin.microsoft.com/#/setupguidance" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Access all Microsoft 365 Advanced Deployment Guides&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Jan 2024 22:16:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/simplify-your-windows-365-enterprise-deployment-with-the-updated/ba-p/4014841</guid>
      <dc:creator>Josh_Gutierrez</dc:creator>
      <dc:date>2024-01-29T22:16:15Z</dc:date>
    </item>
    <item>
      <title>Please join us for this special event: Secure Your Identity Front and Back Door</title>
      <link>https://techcommunity.microsoft.com/t5/fasttrack-blog/please-join-us-for-this-special-event-secure-your-identity-front/ba-p/3998588</link>
      <description>&lt;H2&gt;&lt;FONT size="4"&gt;&lt;A href="https://emails.azure.microsoft.com/redirect/?destination=https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurity%2Fblog%2F2023%2F05%2F04%2Fhow-microsoft-can-help-you-go-passwordless-this-world-password-day%2F&amp;amp;p=bT0wMDAwMDAwMC0wMDAwLTAwMDAtMDAwMC0wMDAwMDAwMDAwMDAmdT1hZW8tcHJldmlldyZsPWhvdy1taWNyb3NvZnQtY2FuLWhlbHAteW91LWdvLXBhc3N3b3JkbGVzcy10aGlzLXdvcmxkLXBhc3N3b3JkLWRheQ%3D%3D" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;“Hackers don’t break in. They log in.”&lt;/STRONG&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;H2&gt;&lt;FONT size="4"&gt;Bret Arsenault, Chief Information Security Officer, Microsoft.&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Please join us for this special event: Secure Your Identity Front and Back Door: A Technical Discussion with Microsoft Experts. &lt;/STRONG&gt;&lt;/H3&gt;
&lt;H3&gt;&amp;nbsp;&lt;/H3&gt;
&lt;H3&gt;&lt;STRONG&gt;Topic:&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Secure Your Identity Front and Back Door&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H3&gt;&lt;STRONG&gt;Date:&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wednesday, December 6, 2023&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H3&gt;&lt;STRONG&gt;Time:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 11:00 AM to 12:00 PM Eastern Time (US &amp;amp; Canada) (UTC-05:00)&lt;/STRONG&gt;&lt;/H3&gt;
&lt;H2&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Join Microsoft Engineers in a focused discussion around securing logins from&amp;nbsp;threats with Risk Based Conditional Access in the cloud and Microsoft Defender for Identity on-premises.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Both capabilities are low/no user impacting, are simple to deploy, &lt;STRONG&gt;and you might already own them.&lt;/STRONG&gt; Please bring your questions and doubts and discuss them with our deployment experts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Details:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Date:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Wednesday, December 6, 2023&lt;/P&gt;
&lt;P&gt;Time:&amp;nbsp;&amp;nbsp;&amp;nbsp; 11:00 AM - 12:00 PM EDT&lt;/P&gt;
&lt;P&gt;Details: Online event, Registration required&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2254710" target="_blank" rel="noopener"&gt;Click Here to Register&lt;/A&gt;&lt;/H4&gt;
&lt;P&gt;Learn how Microsoft Entra ID and Microsoft Defender for Identity (MDI) can help your organization prevent, detect, and respond to ever-growing identity-related threats.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agenda:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Microsoft Zero Trust guided path&lt;/LI&gt;
&lt;LI&gt;Microsoft Entra ID risk-based conditional access, is a quick way to enhance security&lt;/LI&gt;
&lt;LI&gt;Detection of and response to advanced identity threats on-premises—Microsoft Defender for Identity&lt;/LI&gt;
&lt;LI&gt;Deployment resources and FastTrack assistance&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Speakers:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Wendell Caroll&lt;/STRONG&gt;, Senior FastTrack Architect, Microsoft&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Adam Findlan, Principal &lt;/STRONG&gt;FastTrack Architect, Microsoft&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Jason Bingham&lt;/STRONG&gt;, Principal FastTrack Architect, Microsoft&lt;/P&gt;
&lt;P&gt;This is a live event, and it won’t be recorded to ensure customer privacy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;&lt;A href="https://go.microsoft.com/fwlink/?linkid=2254710" target="_blank" rel="noopener"&gt;Registration Link&lt;/A&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 21:50:20 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/fasttrack-blog/please-join-us-for-this-special-event-secure-your-identity-front/ba-p/3998588</guid>
      <dc:creator>JessicaGuindi</dc:creator>
      <dc:date>2023-12-04T21:50:20Z</dc:date>
    </item>
  </channel>
</rss>

