Q
A company has a Microsoft Copilot Studio agent in Microsoft Teams that answers HR policy questions by grounding responses in Microsoft SharePoint Online documents.
Some documents are labeled as Highly Confidential and only certain HR users are authorized to access the documents.
Testing shows that the agent can process and summarize Highly Confidential files. The company's security team requires that the agent NOT process content labeled Highly Confidential, even when a user has access.
You need to recommend a security solution to ensure that the agent enforces this restriction.
What should you recommend?
Question Info
Choose the Best Option
Click any option to instantly check if you're correct.
Explanation
Objective:
3.4 Design responsible AI, security, governance, risk management, and compliance
What This Item Tests:
Design security for agents
Additional Reading:
Secure AI agents built in Copilot Studio
Data governance and compliance
Secure your Copilot Studio projects
Rationale:
A Microsoft Purview DLP policy scoped to Microsoft 365 Copilot can prevent Copilot from processing SharePoint content that has specific sensitivity labels, enforcing agent-level security controls regardless of user permissions. Retention policies and transcript logging do not restrict content processing, and relying on user context alone does not meet the requirement to block Highly Confidential data from being handled by the agent.
Share This Question
Challenge a friend or share with your study group.