SlideShare a Scribd company logo
2024
Preparing for
Microsoft 365
Copilot
Best Practices
for Governance
and Data
Security
About Me
Nikki Chapple
Principal Cloud Architect
nikkichapple
@chapplenikki
www.nikkichapple.com
All Things M365 Compliance
Agenda
Are you worried
about Copilot for
Microsoft 365?
Is your data ready
for Copilot?
10 steps to secure
and govern your
data
Are you worried
about Copilot for
Microsoft365?
The issue
Employees want AI
at work - and they
won’t wait for their
organisation to
catch up
Commsverse survey
What are your main concerns about Copilot for Microsoft 365?
Microsoft & LinkedIn Work Trend Index Report
Three out of four people already use AI at work
2024 Work Trend Index Annual Report from Microsoft and LinkedIn)
ISMG Generative AI Survey
CISO Concerns
REPORT-Business-Rewards-vs-Security-Risks.pdf (exabeam.com)
Is your data
ready for
Copilot?
Copilot scope
Most of your data is stored outside Microsoft 365
3rd Party data
stores
SharePoint
OneDrive
No rule book on what to store where
3rd Party data
stores
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
Pioneers start creating ungoverned Teams & Sites
3rd Party data
stores
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
3rd Party
data
stores
You create public Teams with default configuration
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
3rd Party
data
stores
You have ungoverned file sharing
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
You migrated all your historic data into Microsoft 365
3rd
party
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
Your Admins are owners of all groups,
Teams & sites
Ungoverned content - Danger of revealing too much
You have implemented data security and
governance
Governed content – Just enough access and just enough permissions
Copilot for Microsoft 365 Optimization Assessment
Data Security readiness
score
License profile Deployment path
0% - 66% Office 365 E3, Microsoft 365 Business
Standard/Premium, or higher
Core
67% - 100% Microsoft 365 E5 Best-in-Class
Determine your deployment path
Solution Assessment Program
(microsoft.com)
10 steps to
secure and
govern your
data
Core
Workspace
Governance
Ungoverned Workspaces (Microsoft 365 Groups,
Teams and Sites)
Ungoverned sites and files:
Risk of oversharing
Each circle represents a
SharePoint site
Temporary measure - Restricted SharePoint Search
Add up to 100 sites
Frequently visited sites
Your OneDrive
Shared files with you & you have
accessed
This disables organization-wide
search
No impact on Purview e.g. DLP
Restricted SharePoint Search -
SharePoint in Microsoft 365 | Microsoft
Learn
1. Convert Public workspaces to Private workspaces
Public sites:
Copilot can access all
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
All users in the tenant can access
content in Public Groups
Use Container sensitivity labels to
restrict Public Teams being created
Add Container sensitivity labels to
existing Teams/ Microsoft 365 Groups
change settings to Private
Identify Viva Engage/ Teams that
need to be Public e.g All staff or social
Use sensitivity labels with Microsoft
Teams, Microsoft 365 Groups, and
SharePoint sites | Microsoft Learn
2. Use Container sensitivity labels to enforce“People
with existing access”link
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
Use Container sensitivity labels
with your Microsoft 365 Groups,
Teams and Sites to control file
access permissions
Use sensitivity labels with
Microsoft Teams, Microsoft 365
Groups, and SharePoint sites |
Microsoft Learn
Use sensitivity labels to
configure the default sharing link
type | Microsoft Learn
3. Regularly review workspace membership
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
User adoption to ensure workspace
owners review the membership on a regular
basis. Run regular communications
campaigns
Use Dynamic groups to automatically
manage membership (Entra ID P1)
Use Entra ID Access Reviews to review
Groups and Teams (Entra ID P2 licence)
What are access reviews? - Microsoft
Entra - Microsoft Entra ID Governance |
Microsoft Learn
Use SharePoint Advanced Management
to review SharePoint site membership
licenses $3 PUPM for all users
Manage site lifecycle policies -
SharePoint in Microsoft 365 | Microsoft Learn
4. Use private/shared channels in Teams to restrict
access
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
You can control who can
create Private and shared
channels
Using Shared channels
externally requires bi-directional
configuration
Overview of teams and
channels in Microsoft Teams -
Microsoft Teams | Microsoft
Learn
5. Use Retention to keep what you need and delete
the rest
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
Automated labelling
requires E5 Compliance
Learn about retention
policies & labels to retain or
delete | Microsoft Learn
Best in Class
Workspace
Governance
6. Block site access to non-members
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
SharePoint Advanced
Management
Restrict SharePoint site
access with Microsoft 365 groups
and Entra security groups -
SharePoint in Microsoft 365 |
Microsoft Learn
Licenses $3 per user per
month for all users
Archive
7. Archive your inactive Sites
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
Archive
7. Archive your inactive Sites
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
Microsoft 365
Archive is charged per-
GB once the total
SharePoint storage
used
Overview of
Microsoft 365 Archive -
Microsoft 365 Archive |
Microsoft Learn
Third-party options
are available.
Secure your
files
8. Add Sensitivity labels to your files
Labelled files:
If you have access, Copilot has access and inherits label
Copilot will inherit the label of
the source content
Use DLP with sensitivity labels
to block access
Automated labelling & default
label on Document Library requires
E5 Compliance
Microsoft Purview data security
and compliance protections for
Microsoft Copilot and other
generative AI apps | Microsoft
Learn
9. Add Sensitivity labels with encryption
Encrypted files:
If you have access, Copilot can access
Encrypted files:
If you can’t access, Copilot can’t access
Copilot will inherit the label
of the source content
If you cannot access the file,
Copilot will not include
Automated labelling &
default label on Document
Library requires E5 Compliance
Apply encryption using
sensitivity labels | Microsoft
Learn
10. Add Encrypted Sensitivity labels with limited
permissions
Encrypted files with restricted access: If you have limited access,
Copilot can’t access
Copilot needs EXTRACT usage
rights
Copilot will inherit the label of
the source content
Automated labelling & default
label on Document Library
requires E5 Compliance
Microsoft Purview data
security and compliance
protections for Microsoft Copilot
and other generative AI apps |
Microsoft Learn
Coming
soon
11. Add Sensitivity labels that block Copilot analysis
in WPXO
Labelled files that prevent connected experiences : If you can access,
Copilot cannot access in WPXO
Planned July 2024 Message ID
MC802004 - Use Microsoft Purview
to prevent some connected
experiences that analyse content
Blocks content in Word,
PowerPoint, Excel and Outlook
(WPXO) being sent to Copilot
Content can still be accessed via
Copilot in other scenarios e.g. Teams
Impacts other activities
Manage sensitivity labels in
Office apps | Microsoft Learn
12. Coming soon - Expire sharing links
Governed shared file:
You have time bound access
Ungoverned shared file:
You have time bound access
Planned July 2024
Message ID MC799277 -
Microsoft 365 apps: Set
expiration available for all
links when sharing
Summary
3 steps to implementing governance for Copilot for Microsoft 365
Workspace
governance
Data security
User
adoption
Thank you to our 2024 sponsors
 Microsoft 365 Copilot data security and governance |Commsverse 2024 | June 2024

More Related Content

PPSX
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
PDF
Copilot for Microsoft 365 data security and governance | Workplace Ninjas Den...
PDF
Deciphering Copilot Unravelling Data Security and Governance in Microsoft 365...
PDF
Ready Set Secure your Data |GRC User Group| Oct 2024.pdf
PDF
Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data...
PDF
Microsoft 365 Copilot data security and governance with Notes | CollabDays B...
PDF
Unlock the Potential of Microsoft 365 Copilot | Norwegian M365 User Group |...
PPTX
Prepare your data for Microsoft Copilot with new tools
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
Copilot for Microsoft 365 data security and governance | Workplace Ninjas Den...
Deciphering Copilot Unravelling Data Security and Governance in Microsoft 365...
Ready Set Secure your Data |GRC User Group| Oct 2024.pdf
Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data...
Microsoft 365 Copilot data security and governance with Notes | CollabDays B...
Unlock the Potential of Microsoft 365 Copilot | Norwegian M365 User Group |...
Prepare your data for Microsoft Copilot with new tools

Similar to Microsoft 365 Copilot data security and governance |Commsverse 2024 | June 2024 (20)

PPTX
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
PDF
May 2020 Microsoft 365 Need to Know Webinar
PPTX
Copilot-for-Microsoft-365-technical.pptx
PPTX
B2 - The History of Content Security: Part 2 - Adam Levithan
PDF
Webinar: Protect your teams work across office 365
PPTX
Microsoft Information Protection: Your Security and Compliance Framework
PPTX
Understanding Security and Compliance in Microsoft Teams M365 North 2023
PPTX
Protecting your Teams Work across Microsoft 365
PPTX
Securing SharePoint & OneDrive in Office 365
PPTX
SC-900 Capabilities of Microsoft Compliance Solutions
PPTX
M365 Virtual Marthon: Protecting your Teamwork across Microsoft 365
PPTX
ELNL2025 - Unlocking the Power of Sensitivity Labels - A Comprehensive Guide....
PPTX
Governance in SharePoint Premium:What's in the box?
PPTX
Azure Information Protection at the Cybercrime and Security Forum 2018
PDF
CSF18 Azure Information Protection - Albert Hoitingh
PPTX
Administrators guide to managing Microsoft 365 and collaboration workloads - ...
PDF
June 2020 Microsoft 365 Need to Know Webinar
PPTX
Understanding Security and Compliance in Microsoft Teams - M365 Saturday Bang...
PPTX
Intelligent Security, Compliance and Privacy in Office 365
PPTX
What's new in Security and Compliance in SharePoint , OneDrive for Business &...
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
May 2020 Microsoft 365 Need to Know Webinar
Copilot-for-Microsoft-365-technical.pptx
B2 - The History of Content Security: Part 2 - Adam Levithan
Webinar: Protect your teams work across office 365
Microsoft Information Protection: Your Security and Compliance Framework
Understanding Security and Compliance in Microsoft Teams M365 North 2023
Protecting your Teams Work across Microsoft 365
Securing SharePoint & OneDrive in Office 365
SC-900 Capabilities of Microsoft Compliance Solutions
M365 Virtual Marthon: Protecting your Teamwork across Microsoft 365
ELNL2025 - Unlocking the Power of Sensitivity Labels - A Comprehensive Guide....
Governance in SharePoint Premium:What's in the box?
Azure Information Protection at the Cybercrime and Security Forum 2018
CSF18 Azure Information Protection - Albert Hoitingh
Administrators guide to managing Microsoft 365 and collaboration workloads - ...
June 2020 Microsoft 365 Need to Know Webinar
Understanding Security and Compliance in Microsoft Teams - M365 Saturday Bang...
Intelligent Security, Compliance and Privacy in Office 365
What's new in Security and Compliance in SharePoint , OneDrive for Business &...
Ad

More from Nikki Chapple (20)

PDF
Protecting Your Sensitive Data with Microsoft Purview - IRMS 2025
PDF
Measuring Microsoft 365 Copilot and Gen AI Success
PDF
Measuring Copilot and Gen AI Success with Viva Insights and Purview
PDF
Microsoft 365 Copilot data quality with semantic index and how Topics plays...
PDF
Microsoft Viva and Copilot Governance | M365 ReVival | Feb 2024
PDF
Real World Governance Risk and Compliance | European Collaboration Summit | M...
PDF
Microsoft 365 Copilot: How to boost your productivity with AI. Part one: Adop...
PDF
Cracking the Code- Expert Tips for Mastering GRC | CollabDays Bletchley | Sep...
PDF
Microsoft Viva Security and Privacy | CollabDays Bletchley | Sept 23
PDF
Demystifying security and privacy in Viva | Commsverse | June 2023
PDF
Demystifying security and compliance in Viva | European Collaboration Summit ...
PDF
Real World Governance Risk and Compliance | European Collaboration Summit 2023
PDF
Dont let governance risk and compliance be a roll of the device | Modern Wor...
PDF
Dont let governance risk and compliance be a roll of the dice | ESPC22 | De...
PDF
Microsoft Viva governance and compliance implications | Viva Explorers Commun...
PDF
Implementing Microsoft Teams Lifecycle Governance to Stop Team Sprawl M365C...
PDF
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
PDF
Build a Teams creation workflow using Power Automate | ESPC 22 Microsoft Team...
PDF
Implementing Microsoft Teams lifecycle governance to stop Team sprawl | MN Mi...
PDF
Microsoft 365 Governance Risk and Compliance Maturity model | MM4M365 practit...
Protecting Your Sensitive Data with Microsoft Purview - IRMS 2025
Measuring Microsoft 365 Copilot and Gen AI Success
Measuring Copilot and Gen AI Success with Viva Insights and Purview
Microsoft 365 Copilot data quality with semantic index and how Topics plays...
Microsoft Viva and Copilot Governance | M365 ReVival | Feb 2024
Real World Governance Risk and Compliance | European Collaboration Summit | M...
Microsoft 365 Copilot: How to boost your productivity with AI. Part one: Adop...
Cracking the Code- Expert Tips for Mastering GRC | CollabDays Bletchley | Sep...
Microsoft Viva Security and Privacy | CollabDays Bletchley | Sept 23
Demystifying security and privacy in Viva | Commsverse | June 2023
Demystifying security and compliance in Viva | European Collaboration Summit ...
Real World Governance Risk and Compliance | European Collaboration Summit 2023
Dont let governance risk and compliance be a roll of the device | Modern Wor...
Dont let governance risk and compliance be a roll of the dice | ESPC22 | De...
Microsoft Viva governance and compliance implications | Viva Explorers Commun...
Implementing Microsoft Teams Lifecycle Governance to Stop Team Sprawl M365C...
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
Build a Teams creation workflow using Power Automate | ESPC 22 Microsoft Team...
Implementing Microsoft Teams lifecycle governance to stop Team sprawl | MN Mi...
Microsoft 365 Governance Risk and Compliance Maturity model | MM4M365 practit...
Ad

Recently uploaded (20)

PPTX
MACRO-PERSPECTIVE-IN-HOSPITALITY-AND-TOURISM-MODULES.pptx
PDF
How to Choose the Best Tour Operators in Rajasthan – A Complete Guide.pdf
PDF
Travel Agents Email List for Effective Tourism and Hospitality Marketing.pdf
PPTX
Minimalist Business Slides XL by Slidesgo.pptx
PDF
Why Everyone Misses These 7 Extraordinary Cities — And Why You Should Visit I...
PDF
Golden Triangle Tour A Complete Travel Guide.pdf
PDF
Understanding Travel Insurance: Your Safety Net While Exploring the World
PDF
Travel Adventures: Explore the Gem Around The World.
PDF
Villa Oriente Porto Rotondo - Luxury Villlas Sardinia.pdf
PDF
Memorable Outdoor Adventures with Premium River Rafting & Guided Tours
PPTX
How Indian Culture Is Perceived Around the World,Infouncle.pptx
PDF
Step Into Lima’s Magic Explore Peru’s Historic Capital From Anywhere.pdf
PDF
4Days Golden Triangle Tour India Pdf Doc
PDF
Explore Luxemburry.eu, the ancient of lands in Europe
PDF
Delhi to Kashmir Tour Package at Best Price.pdf
PPTX
Airline API Integration | Flight API Supplier
PPTX
Telangana Culture and tradtion musicals .pptx
PDF
Which Month is Best for Kailash Mansarovar Yatra.pdf
PPTX
Exploration of Botanical Gardens of India
PDF
How Expensive is Mansarovar Yatra cost from Mumbai.pdf
MACRO-PERSPECTIVE-IN-HOSPITALITY-AND-TOURISM-MODULES.pptx
How to Choose the Best Tour Operators in Rajasthan – A Complete Guide.pdf
Travel Agents Email List for Effective Tourism and Hospitality Marketing.pdf
Minimalist Business Slides XL by Slidesgo.pptx
Why Everyone Misses These 7 Extraordinary Cities — And Why You Should Visit I...
Golden Triangle Tour A Complete Travel Guide.pdf
Understanding Travel Insurance: Your Safety Net While Exploring the World
Travel Adventures: Explore the Gem Around The World.
Villa Oriente Porto Rotondo - Luxury Villlas Sardinia.pdf
Memorable Outdoor Adventures with Premium River Rafting & Guided Tours
How Indian Culture Is Perceived Around the World,Infouncle.pptx
Step Into Lima’s Magic Explore Peru’s Historic Capital From Anywhere.pdf
4Days Golden Triangle Tour India Pdf Doc
Explore Luxemburry.eu, the ancient of lands in Europe
Delhi to Kashmir Tour Package at Best Price.pdf
Airline API Integration | Flight API Supplier
Telangana Culture and tradtion musicals .pptx
Which Month is Best for Kailash Mansarovar Yatra.pdf
Exploration of Botanical Gardens of India
How Expensive is Mansarovar Yatra cost from Mumbai.pdf

Microsoft 365 Copilot data security and governance |Commsverse 2024 | June 2024

  • 1. 2024 Preparing for Microsoft 365 Copilot Best Practices for Governance and Data Security
  • 2. About Me Nikki Chapple Principal Cloud Architect nikkichapple @chapplenikki www.nikkichapple.com All Things M365 Compliance
  • 3. Agenda Are you worried about Copilot for Microsoft 365? Is your data ready for Copilot? 10 steps to secure and govern your data
  • 4. Are you worried about Copilot for Microsoft365?
  • 5. The issue Employees want AI at work - and they won’t wait for their organisation to catch up
  • 6. Commsverse survey What are your main concerns about Copilot for Microsoft 365?
  • 7. Microsoft & LinkedIn Work Trend Index Report Three out of four people already use AI at work 2024 Work Trend Index Annual Report from Microsoft and LinkedIn)
  • 8. ISMG Generative AI Survey CISO Concerns REPORT-Business-Rewards-vs-Security-Risks.pdf (exabeam.com)
  • 9. Is your data ready for Copilot?
  • 10. Copilot scope Most of your data is stored outside Microsoft 365 3rd Party data stores SharePoint OneDrive
  • 11. No rule book on what to store where 3rd Party data stores Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 12. Pioneers start creating ungoverned Teams & Sites 3rd Party data stores Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 13. 3rd Party data stores You create public Teams with default configuration Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 14. 3rd Party data stores You have ungoverned file sharing Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 15. You migrated all your historic data into Microsoft 365 3rd party Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 16. Your Admins are owners of all groups, Teams & sites Ungoverned content - Danger of revealing too much
  • 17. You have implemented data security and governance Governed content – Just enough access and just enough permissions
  • 18. Copilot for Microsoft 365 Optimization Assessment Data Security readiness score License profile Deployment path 0% - 66% Office 365 E3, Microsoft 365 Business Standard/Premium, or higher Core 67% - 100% Microsoft 365 E5 Best-in-Class Determine your deployment path Solution Assessment Program (microsoft.com)
  • 19. 10 steps to secure and govern your data
  • 21. Ungoverned Workspaces (Microsoft 365 Groups, Teams and Sites) Ungoverned sites and files: Risk of oversharing Each circle represents a SharePoint site
  • 22. Temporary measure - Restricted SharePoint Search Add up to 100 sites Frequently visited sites Your OneDrive Shared files with you & you have accessed This disables organization-wide search No impact on Purview e.g. DLP Restricted SharePoint Search - SharePoint in Microsoft 365 | Microsoft Learn
  • 23. 1. Convert Public workspaces to Private workspaces Public sites: Copilot can access all Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access All users in the tenant can access content in Public Groups Use Container sensitivity labels to restrict Public Teams being created Add Container sensitivity labels to existing Teams/ Microsoft 365 Groups change settings to Private Identify Viva Engage/ Teams that need to be Public e.g All staff or social Use sensitivity labels with Microsoft Teams, Microsoft 365 Groups, and SharePoint sites | Microsoft Learn
  • 24. 2. Use Container sensitivity labels to enforce“People with existing access”link Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access Use Container sensitivity labels with your Microsoft 365 Groups, Teams and Sites to control file access permissions Use sensitivity labels with Microsoft Teams, Microsoft 365 Groups, and SharePoint sites | Microsoft Learn Use sensitivity labels to configure the default sharing link type | Microsoft Learn
  • 25. 3. Regularly review workspace membership Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access User adoption to ensure workspace owners review the membership on a regular basis. Run regular communications campaigns Use Dynamic groups to automatically manage membership (Entra ID P1) Use Entra ID Access Reviews to review Groups and Teams (Entra ID P2 licence) What are access reviews? - Microsoft Entra - Microsoft Entra ID Governance | Microsoft Learn Use SharePoint Advanced Management to review SharePoint site membership licenses $3 PUPM for all users Manage site lifecycle policies - SharePoint in Microsoft 365 | Microsoft Learn
  • 26. 4. Use private/shared channels in Teams to restrict access Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access You can control who can create Private and shared channels Using Shared channels externally requires bi-directional configuration Overview of teams and channels in Microsoft Teams - Microsoft Teams | Microsoft Learn
  • 27. 5. Use Retention to keep what you need and delete the rest Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access Automated labelling requires E5 Compliance Learn about retention policies & labels to retain or delete | Microsoft Learn
  • 29. 6. Block site access to non-members Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access SharePoint Advanced Management Restrict SharePoint site access with Microsoft 365 groups and Entra security groups - SharePoint in Microsoft 365 | Microsoft Learn Licenses $3 per user per month for all users
  • 30. Archive 7. Archive your inactive Sites Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 31. Archive 7. Archive your inactive Sites Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access Microsoft 365 Archive is charged per- GB once the total SharePoint storage used Overview of Microsoft 365 Archive - Microsoft 365 Archive | Microsoft Learn Third-party options are available.
  • 33. 8. Add Sensitivity labels to your files Labelled files: If you have access, Copilot has access and inherits label Copilot will inherit the label of the source content Use DLP with sensitivity labels to block access Automated labelling & default label on Document Library requires E5 Compliance Microsoft Purview data security and compliance protections for Microsoft Copilot and other generative AI apps | Microsoft Learn
  • 34. 9. Add Sensitivity labels with encryption Encrypted files: If you have access, Copilot can access Encrypted files: If you can’t access, Copilot can’t access Copilot will inherit the label of the source content If you cannot access the file, Copilot will not include Automated labelling & default label on Document Library requires E5 Compliance Apply encryption using sensitivity labels | Microsoft Learn
  • 35. 10. Add Encrypted Sensitivity labels with limited permissions Encrypted files with restricted access: If you have limited access, Copilot can’t access Copilot needs EXTRACT usage rights Copilot will inherit the label of the source content Automated labelling & default label on Document Library requires E5 Compliance Microsoft Purview data security and compliance protections for Microsoft Copilot and other generative AI apps | Microsoft Learn
  • 37. 11. Add Sensitivity labels that block Copilot analysis in WPXO Labelled files that prevent connected experiences : If you can access, Copilot cannot access in WPXO Planned July 2024 Message ID MC802004 - Use Microsoft Purview to prevent some connected experiences that analyse content Blocks content in Word, PowerPoint, Excel and Outlook (WPXO) being sent to Copilot Content can still be accessed via Copilot in other scenarios e.g. Teams Impacts other activities Manage sensitivity labels in Office apps | Microsoft Learn
  • 38. 12. Coming soon - Expire sharing links Governed shared file: You have time bound access Ungoverned shared file: You have time bound access Planned July 2024 Message ID MC799277 - Microsoft 365 apps: Set expiration available for all links when sharing
  • 40. 3 steps to implementing governance for Copilot for Microsoft 365 Workspace governance Data security User adoption
  • 41. Thank you to our 2024 sponsors