Q
A company has a Microsoft Copilot Studio agent used by employees to answer HR policy questions. The agent grounds responses in Microsoft SharePoint Online content and employee records stored in Microsoft Dynamics 365.
During testing, the agent attempts to retrieve data beyond a user's normal HR permissions.
You need to ensure that the solution design complies with the Microsoft responsible AI principle of privacy and security by returning only data that each signed-in user is authorized to access.
Which design change best complies with the responsible AI principle? More than one answer choice may achieve the goal. Select the BEST answer.
Question Info
Choose the Best Option
Click any option to instantly check if you're correct.
Explanation
Objective:
3.4 Design responsible AI, security, governance, risk management, and compliance
What This Item Tests:
Review solution for adherence to responsible AI principles
Additional Reading:
Data governance and compliance
Introduction to Microsoft's Responsible AI Approach - Introduction
Rationale:
Enforcing user-scoped access ensures that the agent respects existing authorization boundaries and returns only data that each user is permitted to access, complying with the principle of least privilege and the responsible AI principle of privacy and security. A shared service account bypasses user permissions, encryption protects data in transit but does not enforce authorization, and user guidance does not technically prevent unauthorized data access.
Share This Question
Challenge a friend or share with your study group.