The use of Copilot to extract sensitive data

SharePoint often contains poorly protected sensitive files. Copilot Agents, Microsoft’s AI integrated by default with Microsoft 365 Copilot, allow seamless querying of these contents, including those protected by traditional access restrictions. The agents respond to queries phrased in neutral or “benevolent” language to bypass controls. Documents with restricted access can be summarized or fully read through the agent, leaving no trace in logs or histories.

Expert analysis
Integrating artificial intelligence into collaborative environments like SharePoint may have been premature. There is a clear gap between traditional access rights and the capabilities offered by AI. Where access restrictions previously prevented direct consultation, Copilot now acts as an invisible bypass interface. The agent functions as an interpreter, capable of reading, filtering, and summarizing sensitive information while staying off audit radars. It constitutes a critical blind spot.

The lack of specific monitoring for Copilot agents shows that AI adoption still largely outpaces the internal detection capabilities of most companies. Reinforcing SharePoint security without regulating agent usage is like locking the door while leaving the window wide open.

Read the full article here.

Stay informed with us!

You can subscribe to our monthly cybersecurity newsletter to receive updates about us and the industry

Blog

Check the latest updates on threats, stories, events and analysis.

New Twint Cyber Threat in 2025 | How Protect Yourself | ZENDATA

New Twint Cyber Threat in 2025

Logitech Targeted in Clop Cyberattack | ZENDATA Insight

Logitech Named in Cyberattack interview in Le Temps

Inside ZENDATA’s AI Powered SOC Dubai: How L1, L2 and L3 Cybersecurity Services Protect Your Business 24/7

Inside our AI Powered SOC in Dubai