Single Choice Moderate

Q

A company has a Microsoft Copilot Studio agent used by employees to answer HR policy questions. The agent grounds responses in Microsoft SharePoint Online content and employee records stored in Microsoft Dynamics 365.

During testing, the agent attempts to retrieve data beyond a user's normal HR permissions.

You need to ensure that the solution design complies with the Microsoft responsible AI principle of privacy and security by returning only data that each signed-in user is authorized to access.

Which design change best complies with the responsible AI principle? More than one answer choice may achieve the goal. Select the BEST answer.

ID: #26616 Practice Assessment for Exam AB-100: Agentic AI Business Solutions Architect 7 views
Question Info
#26616Q ID
ModerateDifficulty
Practice Assessment for Exam AB-100: Agentic AI Business Solutions ArchitectTopic

Choose the Best Option

Click any option to instantly check if you're correct.

  • A Add a welcome message stating that users must not request sensitive data. ✔ ✖
  • B Rely on TLS encryption between Copilot Studio, Dynamics 365, and Azure OpenAI. ✔ ✖
  • C Grant the agent a single service account with broad read access to SharePoint Online and Dynamics 365. ✔ ✖
  • D Enforce user-scoped access by retrieving data based on the signed-in user’s permissions by using Microsoft Entra and the principle of least privilege. ✔ ✖
Correct Answer

Explanation

Objective:

3.4 Design responsible AI, security, governance, risk management, and compliance

What This Item Tests:

Review solution for adherence to responsible AI principles

Additional Reading:

Data privacy and security

Data governance and compliance

Introduction to Microsoft's Responsible AI Approach - Introduction

Rationale:

Enforcing user-scoped access ensures that the agent respects existing authorization boundaries and returns only data that each user is permitted to access, complying with the principle of least privilege and the responsible AI principle of privacy and security. A shared service account bypasses user permissions, encryption protects data in transit but does not enforce authorization, and user guidance does not technically prevent unauthorized data access.

Share This Question

Challenge a friend or share with your study group.

Related MCQ Questions