Chatting about Purview, eDiscovery, Copilot and more with Tom O’Connor
Just a little light conversation about eDiscovery, Microsoft 365, Copilot, etc., before you head out to your holiday weekend.
That seems significant. As someone who works in the legal industry, this is concerning. Some of our clients will not look kindly on us using any third-party tool that can’t provide SOC reports, and I know anyone working with the federal government is looking at that first bullet point about FedRAMP and wondering if they should make sure this isn’t enabled in their environment.
If you’re rolling out Copilot at work and looking for ways to teach people about using it, this might also be a good place to start.
Here’s why this is such a big problem. Microsoft recommends blocking Copilot from accessing sensitive information in emails, meetings, documents, and related content by assigning a label to those items and creating a DLP policy that defines the block. This bug renders the system unusable for the affected emails. You simply can’t provide a governance tool that doesn’t deliver the governance it claims to provide. It’s a bad look, Microsoft. It doesn’t help build customer trust.
No, Copilot did not make these emails public or access private information and make it non-private. It accessed information in response to your prompt that it should ignore. That creates a risk that many users might assume does not exist. That is a significant issue, but it’s not equivalent to a data breach. There is another check in place before data leaks out: the end user.
OneDrive retention presents several challenges due to the variety of items that reside there by default. Share a file in a Teams chat and collaborate on it? It’s in OneDrive. Upload a file for Copilot to summarize, which will be copied to OneDrive. Meeting recordings and notes? OneDrive. Items from your local desktop and documents folders? Likely synced to OneDrive.
Use OneNote to store notes that you want to keep as a historical record? Yeah, OneDrive.
How do you establish a single policy to cover the retention of all these different scenarios?
If you can get Copilot to drop a link into the auto-summary, it would be less suspicious than an email sent from outside with a link. That’s probably true. After all, if you trust your AI Summarization tool to summarize the email instead of reading it, why wouldn’t you trust any links it included?
I think there are some opportunities in AI for completing tasks, but I also think there is a serious risk in taking action without proper oversight. I’ll be very interested in seeing how Microsoft gets this out to business customers.
Reposts