• News/
  • https://www.bleepingcomputer.com/news/security/6-prompts-you-dont-want-employees-putting-in-microsoft-copilot/

6 Prompts You Don't Want Employees Putting in Microsoft Copilot

BleepingComputer
·
Sponsored by Varonis
·
Published Apr 3, 2024
·
Updated

Crowned the greatest productivity tool in the age of AI, Microsoft Copilot is a powerful asset for companies today. But with great power comes great responsibility. If your organization has low visibility of your data security posture, Copilot and other gen AI tools have the potential to leak sensitive information to employees they shouldn’t, or even worse, threat actors. Microsoft Copilot is an AI assistant integrated into each of your Microsoft 365 apps — Word, Excel, PowerPoint, Teams, Outlook, and so on. Copilot’s security model bases its answers on a user's existing Microsoft permissions. Users can ask Copilot to summarize meeting notes, find files for sales assets, and identify action items to save an enormous amount of time. However, if your org’s permissions aren’t set properly and Copilot is enabled, users can easily surface sensitive data. Why is this a problem? People have access to way too much data. The average employee can access 17 million files on their first day of work. When you can’t see and control who has access to sensitive data, one compromised user or malicious insider can inflict untold damage. Most of the permissions granted are also not used and considered high risk, meaning sensitive data is exposed to people who don't need it. At Varonis, we created a live simulation that shows what simple prompts can easily expose your company’s sensitive data in Copilot. During this live demonstration, our industry experts also share practical steps and strateg...

Read full article

Affected Software

1 affected component
Microsoft Copilot
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the security risks associated with using Microsoft Copilot by employees.

2

What security implications are discussed in the article?

The article highlights potential data exposure and privacy issues when employees input sensitive prompts into Microsoft Copilot.

3

What products or software are affected by the discussed risks?

The risks specifically pertain to Microsoft Copilot.

4

What measures can organizations take to mitigate risks with Microsoft Copilot?

Organizations should implement strict guidelines on what prompts can be used with Microsoft Copilot.

5

Why is visibility of data security posture important in the context of Microsoft Copilot?

Low visibility can lead to unintentional data leaks and compromised sensitive information when using the AI tool.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
6 Prompts You Don't Want Employees Putting in Microsoft Copilot - SecAlerts