Security for Microsoft Copilot
Microsoft's defense-in-depth security model for Copilot: identity, data protection, oversharing prevention, and the two security dashboards.
Summary
Security is foundational to Microsoft’s approach to Microsoft Copilot. Copilot inherits Microsoft 365’s enterprise security, compliance, and privacy protections — it only accesses data the user is authorized to access and respects existing compliance and data-residency commitments. Microsoft applies a layered defense-in-depth strategy so that if one control is bypassed, others remain in place.
Microsoft’s Defense-in-Depth Approach
Microsoft applies a multilayered strategy securing Copilot at every level, grounded in enterprise security, privacy, and compliance standards. Key layers include:
- Identity and access protection — built on Microsoft 365 identity controls and Zero Trust principles (strong identity verification, least-privilege access, continuous evaluation).
- Data protection and compliance — honors existing organizational controls; respects retention, privacy, and data-residency commitments.
- Enterprise data protection (EDP) — contractual and technical commitments for customer data under Microsoft Product Terms and the Data Protection Addendum.
- Prompt defense in depth — protection against prompt injection and other AI-specific attacks at every interaction layer.
See security-governance-copilot-control-system for the governance framework that operationalizes these controls, and copilot-studio-governance-and-agent-security-playbook for lifecycle guidance on securing Copilot Studio agents.
Identity and Access Protection
Copilot is built on Microsoft 365 identity and access controls and aligns with Zero Trust principles:
- Strong identity verification — every session is authenticated through Microsoft Entra ID.
- Least-privilege access — Copilot only returns data the user is already authorized to see; it cannot elevate permissions or access content the user cannot.
- Continuous evaluation — access decisions are re-evaluated based on device compliance, location, and risk signals.
For deployment guidance, see Apply principles of Zero Trust to Microsoft Copilot.
Data Protection and Compliance
Copilot honors your organization’s existing security and data protection controls:
- Respects permissions — Copilot only accesses data that the signed-in user is authorized to access. It does not bypass file, site, or application-level permissions.
- Compliance inheritance — Copilot inherits Microsoft 365 compliance, privacy, and data residency commitments.
- Auditing — interactions and data flows are auditable via Microsoft Purview. For deep technical details on data flow and protections, see Microsoft Copilot data protection architecture.
Preventing Oversharing
Even though Copilot respects existing permissions, overshared or poorly governed content can affect Copilot results and increase risk. Microsoft recommends:
- Assess your data foundation — identify overshared content before rolling out Copilot. Run data access governance reports and remediate before deployment.
- Archive or delete unneeded content — inactive or ownerless SharePoint sites and stale files introduce noise and risk.
- Use SharePoint Advanced Management — restricted content discovery and restricted access control can limit Copilot and agent access to overshared sites during remediation.
- Apply sensitivity labels — use Microsoft Purview Information Protection sensitivity labels to classify and protect sensitive content.
For prescriptive guidance:
- Secure & governed data foundation for Microsoft Copilot: A deployment blueprint
- How to configure a secure and governed foundation for Microsoft Copilot
- Get ready for Microsoft Copilot and agents with SharePoint Advanced Management
Security Dashboards
Microsoft provides two complementary dashboards for monitoring and acting on AI-related risk:
Copilot Security Dashboard (Microsoft 365 Admin Center)
Focused on Microsoft Copilot data protection, DLP, oversharing, and compliance insights.
- Navigate: Microsoft 365 admin center → Copilot → Overview → Security.
- Requires: Global Reader role to view; AI Administrator role to make changes.
- Capabilities:
- Prevent data leaks with a Data Loss Prevention policy.
- Manage data oversharing.
- Strengthen data compliance.
Microsoft Security Dashboard for AI (ai.security.microsoft.com)
A unified, cross-product view of AI risk that spans Microsoft Copilot, Copilot Studio agents, Microsoft Foundry apps/agents, and third-party AI apps and agents (including Google Gemini, OpenAI ChatGPT, and MCP servers). It also discovers unmanaged and shadow AI agents.
- Access: ai.security.microsoft.com or entry points in Defender, Entra, and Purview portals.
- No additional licensing for eligible Defender, Entra, and Purview customers.
- Capabilities:
- Real-time AI risk visibility — an AI risk scorecard on the Overview tab.
- Comprehensive AI inventory — coverage across Copilot, Copilot Studio agents, Foundry apps/agents, third-party models, and shadow AI.
- AI-powered insights with Security Copilot — suggested prompts to drill into risk assessments and correlate identity, data, and security signals.
- Tailored recommendations and remediation paths — prioritized recommendations with task delegation and Microsoft Teams integration.
- Executive reporting — board-ready analytics and compliance insights.
Dashboard Comparison
| Capability | Copilot Security Dashboard (M365 Admin Center) | Security Dashboard for AI |
|---|---|---|
| Primary scope | Copilot data protection, DLP, oversharing, compliance | Cross-product AI risk across agents, apps, and platforms |
| AI asset coverage | Microsoft Copilot | Copilot, Copilot Studio agents, Foundry apps/agents, third-party models/apps/agents, shadow AI |
| Signals aggregated | Purview signals for Copilot | Defender + Entra + Purview signals |
| AI-powered insights | — | Security Copilot–powered prompts, summaries, risk prioritization |
| Remediation workflow | Purview-based policies (e.g. DLP) | Tailored recommendations, task delegation, Teams integration |
| Access path | admin.microsoft.com → Copilot → Overview → Security | ai.security.microsoft.com or Defender/Entra/Purview portals |
| Roles / licensing | Global Reader (view) / AI Administrator (edit) | Existing Defender/Entra/Purview permissions; no extra licensing |
| Availability | Generally available | Public preview |
Note: The Security Dashboard for AI is currently in preview. Capabilities and coverage may change before general availability.
Related Pages
- security-governance-copilot-control-system — The Copilot Control System governance framework (foundational vs. optimized controls by license tier)
- copilot-studio-governance-and-agent-security-playbook — Lifecycle security guidance for Copilot Studio agents
- Cyber Resource Center — Master page with all resources
Sources
- Security for Microsoft Copilot (Microsoft Learn)
- Microsoft Copilot data protection architecture (Microsoft Learn)
- How does Microsoft Copilot work? (Microsoft Learn)
- Assess your organization’s AI risk with Microsoft Security Dashboard for AI (Microsoft Learn)