SlideShare a Scribd company logo
Ready, Set,
Secure: Data
Governance for
Microsoft 365
Copilot
Nikki Chapple
Principal Cloud Architect at CloudWay
MVP in M365 Apps and Security
About Me
Nikki Chapple
Principal Cloud Architect
nikkichapple
@chapplenikki
www.nikkichapple.com
All Things M365 Compliance
Agenda
Are you worried about Copilot
for Microsoft 365?
Is your data ready for Copilot?
How to govern your workspaces
and secure your data
Are you
worried about
Microsoft 365
Copilot?
The issue
Employees want AI
at work - and they
won’t wait for their
organisation to
catch up
What are your main concerns about Copilot for Microsoft 365?
Microsoft & LinkedIn Work Trend Index Report
Three out of four people already use AI at work
2024 Work Trend Index Annual Report from Microsoft and LinkedIn)
ISMG Generative AI Survey
CISO Concerns
REPORT-Business-Rewards-vs-Security-Risks.pdf (exabeam.com)
Is your data
ready for
Copilot?
Copilot scope
Most of your data is stored outside Microsoft 365
3rd Party data
stores
SharePoint
OneDrive
You are only working in OneDrive
3rd Party data
stores
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
Pioneers start creating ungoverned Teams & Sites
3rd Party data
stores
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
3rd Party
data
stores
You create public Teams with default configuration
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
3rd Party
data
stores
No workspace governance just uncontrolled file sharing
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
You migrate all your historic data into Microsoft 365
3rd
party
Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
Your Admins are owners of all groups,
Teams & sites
Ungoverned content - Danger of revealing too much
You have implemented data security and
governance
Governed content – Just enough access and just enough permissions
Ready Set
and Secure
How to govern your
workspaces and secure
your data
1. Govern
Workspaces
To ensure only the right
people have access to
the right data
Ungoverned Workspaces (Microsoft 365 Groups,
Teams and Sites)
Ungoverned sites and files:
Risk of oversharing
Each circle represents a SharePoint site
1. Restricted SharePoint Search – not recommended
2. Convert Public workspaces to Private workspaces
Public sites:
Copilot can access all
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
3. Use Container sensitivity labels to control access
and files sharing links
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
4. Regularly review workspace membership
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
5. Use private/shared channels in Teams to restrict
access
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
6. Hide inactive workspaces and use Retention
polices to delete unwanted data
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
1.a Best of class
workspace
governance
Premium licensing
7. Block site access to non-members SAM
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
8. Restricted Content Discoverability (GA Nov 2024) -
SAM
Ungoverned
workspaces or sites
Governed workspace
You + Copilot have access
Governed workspace
You + Copilot no access
Governed workspace
You have access
Copilot & Search is blocked
Archive
9. Archive your inactive Sites M365 Archive
Ungoverned files:
Risk of oversharing
Governed Sites with access:
You and Copilot can access
Governed Sites no access:
You and Copilot cannot access
2. Secure
your files
To prevent oversharing
10. Add Sensitivity labels to your files
Labelled files:
If you have access, Copilot has access and inherits label
Each circle represents a file in a
SharePoint site
11. Add Sensitivity labels with encryption
Encrypted files:
If you have access, Copilot can access
Encrypted files:
If you can’t access, Copilot can’t access
12. Add Encrypted Sensitivity labels with limited
permissions
Encrypted files with restricted access: If you have limited access,
Copilot can’t access
13. Use Sensitivity labels to block content being
analysed by Copilot (+ search)
Labelled files that prevent connected experiences : If you can access,
Copilot cannot access in WPXO
14. Expire sharing links
Governed shared file:
You have time bound access
Ungoverned shared file:
You have time bound access
3. User Roles
and
Responsibilities
It’s not just the technical
controls
15. Data is everyone’s responsibility
Management
Governance and AI
policies
Workspace
owner
Workspace membership
Data Stewardship
Employees
Effective Work Practices
Sensitive Content
Labelling
IT
Technical controls
Data security
Copilot Oversharing
Incident Management
Summary
3 steps to ready, set and secure your data for Copilot
Workspace
governance
Data security
User
adoption

More Related Content

PPSX
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
PDF
Deciphering Copilot Unravelling Data Security and Governance in Microsoft 365...
PDF
Microsoft 365 Copilot data security and governance |Commsverse 2024 | June 2024
PDF
Copilot for Microsoft 365 data security and governance | Workplace Ninjas Den...
PDF
Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data...
PDF
Unlock the Potential of Microsoft 365 Copilot | Norwegian M365 User Group |...
PDF
Microsoft 365 Copilot data security and governance with Notes | CollabDays B...
PPTX
Prepare your data for Microsoft Copilot with new tools
Preparing for Microsoft 365 Copilot - Best Practices for Governance and Data ...
Deciphering Copilot Unravelling Data Security and Governance in Microsoft 365...
Microsoft 365 Copilot data security and governance |Commsverse 2024 | June 2024
Copilot for Microsoft 365 data security and governance | Workplace Ninjas Den...
Microsoft 365 Copilot: How to boost your productivity with AI. Part two: Data...
Unlock the Potential of Microsoft 365 Copilot | Norwegian M365 User Group |...
Microsoft 365 Copilot data security and governance with Notes | CollabDays B...
Prepare your data for Microsoft Copilot with new tools

Similar to Ready Set Secure your Data |GRC User Group| Oct 2024.pdf (20)

PPTX
Copilot-for-Microsoft-365-technical.pptx
PPTX
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
PPTX
What's new in Security and Compliance in SharePoint , OneDrive for Business &...
PPTX
B2 - The History of Content Security: Part 2 - Adam Levithan
PPTX
Scottish Summit 2022 - Secure and manage your data in Microsoft Teams
PDF
May 2020 Microsoft 365 Need to Know Webinar
PPTX
Protecting your Teams Work across Microsoft 365
PDF
Webinar: Protect your teams work across office 365
PPTX
Microsoft Information Protection: Your Security and Compliance Framework
PPTX
Workshop security and compliance - SPS Cambridge
PPTX
Safely Enabling Office 365
PPTX
Office 365 Saturday - Office 365 Security Best Practices
PPTX
M365 Virtual Marthon: Protecting your Teamwork across Microsoft 365
PPTX
Understanding Security and Compliance in Microsoft Teams M365 North 2023
PDF
Microsoft365-Copilot-Partner-Guide
PDF
June 2020 Microsoft 365 Need to Know Webinar
PPTX
Understanding Security and Compliance in Microsoft Teams - Scottish Summit 2022
PPTX
Getting Ready for Copilot for Microsoft 365 with Governance Features in Share...
PPTX
Securing SharePoint & OneDrive in Office 365
PPTX
Security and compliance in Office 365 -Part 1
Copilot-for-Microsoft-365-technical.pptx
Securing Team, SharePoint, and OneDrive in Microsoft 365 - M365VM
What's new in Security and Compliance in SharePoint , OneDrive for Business &...
B2 - The History of Content Security: Part 2 - Adam Levithan
Scottish Summit 2022 - Secure and manage your data in Microsoft Teams
May 2020 Microsoft 365 Need to Know Webinar
Protecting your Teams Work across Microsoft 365
Webinar: Protect your teams work across office 365
Microsoft Information Protection: Your Security and Compliance Framework
Workshop security and compliance - SPS Cambridge
Safely Enabling Office 365
Office 365 Saturday - Office 365 Security Best Practices
M365 Virtual Marthon: Protecting your Teamwork across Microsoft 365
Understanding Security and Compliance in Microsoft Teams M365 North 2023
Microsoft365-Copilot-Partner-Guide
June 2020 Microsoft 365 Need to Know Webinar
Understanding Security and Compliance in Microsoft Teams - Scottish Summit 2022
Getting Ready for Copilot for Microsoft 365 with Governance Features in Share...
Securing SharePoint & OneDrive in Office 365
Security and compliance in Office 365 -Part 1
Ad

More from Nikki Chapple (20)

PDF
Protecting Your Sensitive Data with Microsoft Purview - IRMS 2025
PDF
Measuring Microsoft 365 Copilot and Gen AI Success
PDF
Measuring Copilot and Gen AI Success with Viva Insights and Purview
PDF
Microsoft 365 Copilot data quality with semantic index and how Topics plays...
PDF
Microsoft Viva and Copilot Governance | M365 ReVival | Feb 2024
PDF
Real World Governance Risk and Compliance | European Collaboration Summit | M...
PDF
Microsoft 365 Copilot: How to boost your productivity with AI. Part one: Adop...
PDF
Cracking the Code- Expert Tips for Mastering GRC | CollabDays Bletchley | Sep...
PDF
Microsoft Viva Security and Privacy | CollabDays Bletchley | Sept 23
PDF
Demystifying security and privacy in Viva | Commsverse | June 2023
PDF
Demystifying security and compliance in Viva | European Collaboration Summit ...
PDF
Real World Governance Risk and Compliance | European Collaboration Summit 2023
PDF
Dont let governance risk and compliance be a roll of the device | Modern Wor...
PDF
Dont let governance risk and compliance be a roll of the dice | ESPC22 | De...
PDF
Microsoft Viva governance and compliance implications | Viva Explorers Commun...
PDF
Implementing Microsoft Teams Lifecycle Governance to Stop Team Sprawl M365C...
PDF
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
PDF
Build a Teams creation workflow using Power Automate | ESPC 22 Microsoft Team...
PDF
Implementing Microsoft Teams lifecycle governance to stop Team sprawl | MN Mi...
PDF
Microsoft 365 Governance Risk and Compliance Maturity model | MM4M365 practit...
Protecting Your Sensitive Data with Microsoft Purview - IRMS 2025
Measuring Microsoft 365 Copilot and Gen AI Success
Measuring Copilot and Gen AI Success with Viva Insights and Purview
Microsoft 365 Copilot data quality with semantic index and how Topics plays...
Microsoft Viva and Copilot Governance | M365 ReVival | Feb 2024
Real World Governance Risk and Compliance | European Collaboration Summit | M...
Microsoft 365 Copilot: How to boost your productivity with AI. Part one: Adop...
Cracking the Code- Expert Tips for Mastering GRC | CollabDays Bletchley | Sep...
Microsoft Viva Security and Privacy | CollabDays Bletchley | Sept 23
Demystifying security and privacy in Viva | Commsverse | June 2023
Demystifying security and compliance in Viva | European Collaboration Summit ...
Real World Governance Risk and Compliance | European Collaboration Summit 2023
Dont let governance risk and compliance be a roll of the device | Modern Wor...
Dont let governance risk and compliance be a roll of the dice | ESPC22 | De...
Microsoft Viva governance and compliance implications | Viva Explorers Commun...
Implementing Microsoft Teams Lifecycle Governance to Stop Team Sprawl M365C...
Governance, Risk and Compliance and you | CollabDays Bletchley Park 2022
Build a Teams creation workflow using Power Automate | ESPC 22 Microsoft Team...
Implementing Microsoft Teams lifecycle governance to stop Team sprawl | MN Mi...
Microsoft 365 Governance Risk and Compliance Maturity model | MM4M365 practit...
Ad

Recently uploaded (20)

PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Cloud computing and distributed systems.
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
KodekX | Application Modernization Development
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Big Data Technologies - Introduction.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Dropbox Q2 2025 Financial Results & Investor Presentation
Cloud computing and distributed systems.
Mobile App Security Testing_ A Comprehensive Guide.pdf
KodekX | Application Modernization Development
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Encapsulation_ Review paper, used for researhc scholars
Understanding_Digital_Forensics_Presentation.pptx
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Network Security Unit 5.pdf for BCA BBA.
Unlocking AI with Model Context Protocol (MCP)
Big Data Technologies - Introduction.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
NewMind AI Weekly Chronicles - August'25 Week I
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
MYSQL Presentation for SQL database connectivity
Diabetes mellitus diagnosis method based random forest with bat algorithm
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...

Ready Set Secure your Data |GRC User Group| Oct 2024.pdf

  • 1. Ready, Set, Secure: Data Governance for Microsoft 365 Copilot Nikki Chapple Principal Cloud Architect at CloudWay MVP in M365 Apps and Security
  • 2. About Me Nikki Chapple Principal Cloud Architect nikkichapple @chapplenikki www.nikkichapple.com All Things M365 Compliance
  • 3. Agenda Are you worried about Copilot for Microsoft 365? Is your data ready for Copilot? How to govern your workspaces and secure your data
  • 5. The issue Employees want AI at work - and they won’t wait for their organisation to catch up
  • 6. What are your main concerns about Copilot for Microsoft 365?
  • 7. Microsoft & LinkedIn Work Trend Index Report Three out of four people already use AI at work 2024 Work Trend Index Annual Report from Microsoft and LinkedIn)
  • 8. ISMG Generative AI Survey CISO Concerns REPORT-Business-Rewards-vs-Security-Risks.pdf (exabeam.com)
  • 9. Is your data ready for Copilot?
  • 10. Copilot scope Most of your data is stored outside Microsoft 365 3rd Party data stores SharePoint OneDrive
  • 11. You are only working in OneDrive 3rd Party data stores Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 12. Pioneers start creating ungoverned Teams & Sites 3rd Party data stores Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 13. 3rd Party data stores You create public Teams with default configuration Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 14. 3rd Party data stores No workspace governance just uncontrolled file sharing Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 15. You migrate all your historic data into Microsoft 365 3rd party Ungoverned content - Danger of revealing too much Copilot cannot reach - Danger of poor data quality
  • 16. Your Admins are owners of all groups, Teams & sites Ungoverned content - Danger of revealing too much
  • 17. You have implemented data security and governance Governed content – Just enough access and just enough permissions
  • 18. Ready Set and Secure How to govern your workspaces and secure your data
  • 19. 1. Govern Workspaces To ensure only the right people have access to the right data
  • 20. Ungoverned Workspaces (Microsoft 365 Groups, Teams and Sites) Ungoverned sites and files: Risk of oversharing Each circle represents a SharePoint site
  • 21. 1. Restricted SharePoint Search – not recommended
  • 22. 2. Convert Public workspaces to Private workspaces Public sites: Copilot can access all Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 23. 3. Use Container sensitivity labels to control access and files sharing links Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 24. 4. Regularly review workspace membership Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 25. 5. Use private/shared channels in Teams to restrict access Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 26. 6. Hide inactive workspaces and use Retention polices to delete unwanted data Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 27. 1.a Best of class workspace governance Premium licensing
  • 28. 7. Block site access to non-members SAM Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 29. 8. Restricted Content Discoverability (GA Nov 2024) - SAM Ungoverned workspaces or sites Governed workspace You + Copilot have access Governed workspace You + Copilot no access Governed workspace You have access Copilot & Search is blocked
  • 30. Archive 9. Archive your inactive Sites M365 Archive Ungoverned files: Risk of oversharing Governed Sites with access: You and Copilot can access Governed Sites no access: You and Copilot cannot access
  • 31. 2. Secure your files To prevent oversharing
  • 32. 10. Add Sensitivity labels to your files Labelled files: If you have access, Copilot has access and inherits label Each circle represents a file in a SharePoint site
  • 33. 11. Add Sensitivity labels with encryption Encrypted files: If you have access, Copilot can access Encrypted files: If you can’t access, Copilot can’t access
  • 34. 12. Add Encrypted Sensitivity labels with limited permissions Encrypted files with restricted access: If you have limited access, Copilot can’t access
  • 35. 13. Use Sensitivity labels to block content being analysed by Copilot (+ search) Labelled files that prevent connected experiences : If you can access, Copilot cannot access in WPXO
  • 36. 14. Expire sharing links Governed shared file: You have time bound access Ungoverned shared file: You have time bound access
  • 37. 3. User Roles and Responsibilities It’s not just the technical controls
  • 38. 15. Data is everyone’s responsibility Management Governance and AI policies Workspace owner Workspace membership Data Stewardship Employees Effective Work Practices Sensitive Content Labelling IT Technical controls Data security Copilot Oversharing Incident Management
  • 40. 3 steps to ready, set and secure your data for Copilot Workspace governance Data security User adoption