L11. Securing Microsoft Copilot and AI Apps with Purview Data Security Posture Management
Video generating
Check back soon for the video lesson on Securing Microsoft Copilot and AI Apps with Purview Data Security Posture Management
Course outlineLesson 11 of 18
The biggest risk in enterprise AI adoption usually isn't the model, it's that Copilot answers with whatever the signed-in user's permissions can already reach, and most tenants have no idea how overexposed that actually is.
The Oversharing Problem
Microsoft 365 Copilot answers questions using whatever content the *signed-in user* already has permission to access across SharePoint, OneDrive, and Teams. This is by design (Copilot doesn't grant new access), but it also means years of accumulated oversharing in SharePoint, sites shared "Everyone except external users," stale permissions never cleaned up, forgotten broad links, suddenly becomes instantly discoverable through a single natural-language prompt instead of requiring someone to know where to look.
Identifying Overexposure in SharePoint
Before AI rollout, security teams need visibility into exactly how much content is overshared. Native SharePoint Advanced Management and Purview reporting surface:
- Sites with unusually broad sharing (organization-wide or "anyone" links)
- Sensitive-labeled content sitting in broadly-shared locations
- Stale sites with permissions that no longer match active team membership
This overexposure assessment is a prerequisite step, not an optional one, since Copilot's answers are a direct function of exactly this permission surface.
Microsoft Purview Data Security Posture Management (DSPM) for AI
Purview DSPM for AI is purpose-built to monitor AI usage risk, going beyond a one-time SharePoint audit:- Discovers interactions with Copilot and other AI apps (including third-party generative AI tools accessed through the browser) across the tenant
- Flags when a sensitive information type or sensitivity label was included in a prompt or a Copilot response, surfacing exactly which users and which content are driving the risk
- Provides recommendations to reduce oversharing risk, directly actionable back into SharePoint permission cleanup
- Extends coverage to custom Copilot Studio agents and Foundry-built AI applications, not just Microsoft 365 Copilot itself, giving one posture view across however many separate AI surfaces an organization has adopted
Real-Time Protection for Copilot Studio Agents
For Microsoft Copilot Studio (the low-code platform for building custom conversational agents), real-time protection applies Purview Data Loss Prevention (DLP) policies directly to agent interactions as they happen:
- A DLP policy can detect a sensitive information type appearing in an agent's generated response and block or redact it before the response reaches the user
- This closes a specific gap: a well-intentioned agent, built quickly by a business user rather than IT, could otherwise surface sensitive data it was never explicitly authorized to expose, simply because its underlying data source contained it
How This Feeds Access Decisions
Sensitivity labels and DLP aren't just reporting artifacts, they are inputs into what Copilot (and DSPM) treats as risky. Content correctly labeled as Highly Confidential is exactly the content DSPM for AI prioritizes when scoring oversharing risk, which is why a mature Purview labeling and DLP program is a prerequisite for a low-risk Copilot rollout, not a parallel, unrelated compliance project. Exam tip: SC-500 frames AI security as fundamentally a data security posture problem first: the exam expects you to recognize that fixing Copilot oversharing risk means fixing SharePoint permissions and labeling, and that Purview DSPM for AI is the tool that specifically surfaces which users, prompts, and content are driving that risk across every AI surface in the tenant, not just Microsoft 365 Copilot.
- ✓Microsoft 365 Copilot answers with whatever the signed-in user already has permission to access, so it surfaces existing SharePoint oversharing rather than granting new access
- ✓Identifying overexposure (broad sharing links, stale permissions, sensitive-labeled content in broadly-shared locations) is a required prerequisite before a low-risk Copilot rollout
- ✓Purview DSPM for AI discovers AI app interactions tenant-wide and flags when sensitive information types or labels appear in prompts or responses, across Copilot, Copilot Studio agents, and Foundry apps
- ✓Real-time protection applies Purview DLP policies directly to Copilot Studio agent responses, blocking or redacting sensitive content before it reaches the user
- ✓A mature sensitivity labeling and DLP program is a prerequisite input to AI security, not a separate compliance track
1. A tenant is preparing to roll out Microsoft 365 Copilot. What is the recommended first step from a security posture standpoint?
2. Which Purview capability discovers interactions with Copilot, Copilot Studio agents, and Foundry-built AI apps tenant-wide, flagging when sensitive labeled content appears in prompts or responses?
3. A custom Copilot Studio agent built by a business user is at risk of surfacing sensitive data from its underlying data source in a generated response. Which capability blocks or redacts that sensitive content before it reaches the user?
Recommended: Pluralsight
This free course covers the theory. Pluralsight adds structured Cloud and AI Security Engineer learning paths, hands-on Azure and Defender for Cloud labs, and timed practice exams to make it stick before exam day.