{"id":127637,"date":"2025-03-04T09:00:00","date_gmt":"2025-03-04T17:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/power-platform\/blog\/?post_type=it-pro&p=127637"},"modified":"2025-03-06T12:41:30","modified_gmt":"2025-03-06T20:41:30","slug":"security-and-governance-for-agents","status":"publish","type":"it-pro","link":"https:\/\/www.microsoft.com\/en-us\/power-platform\/blog\/it-pro\/security-and-governance-for-agents\/","title":{"rendered":"Enable Robust Security and Governance for Agents in Microsoft 365 Copilot"},"content":{"rendered":"\n
Microsoft 365 Copilot<\/a> represents a leap forward in AI-powered assistance, designed to streamline workflows and enhance productivity. However, as with any robust system, ensuring data protection, governance, and monitoring are paramount.<\/p>\n\n\n The types of agents available within Microsoft Copilot range from task-specific agents that automate repetitive actions to conversational agents that assist with customer service inquiries. With such a wide range of agent capabilities, how do organizations balance security and governance concerns with the desire to bring great innovation and meet the demands of their makers and agent creators?<\/p>\n\n\n This guide explores the key aspects of securing and managing agents built with Microsoft Copilot Studio, Copilot Studio agent builder, and SharePoint agents, from data protection practices to governance at scale, visibility, and monitoring.<\/p>\n\n\n\n Data protection is a cornerstone of Microsoft Copilot, ensuring that sensitive information remains secure and compliant with organizational policies. Here are the primary components:<\/p>\n\n\n\n All data managed by Microsoft Copilot is encrypted both in transit and at rest, ensuring robust protection against unauthorized access. Data isolation mechanisms further safeguard sensitive information by preventing cross-tenant data leakage.<\/p>\n\n\n\n Agents use persistent label inheritance, meaning any new content generated inherits the sensitivity labels from the source content. This ensures that data loss prevention (DLP) policies<\/a> are consistently applied, reducing the risk of data breaches.<\/p>\n\n\n\n To enhance security, organizations can leverage risk-based conditional access and endpoint management<\/a>. This allows administrators to set policies that control access based on user risk levels and device compliance, ensuring that only authorized users can access sensitive data.<\/p>\n\n\n\n Effective governance ensures that agents are used responsibly and in alignment with organizational policies. Here\u2019s how to manage governance at scale:<\/p>\n\n\n\n Microsoft Copilot provides administration through the Microsoft 365 Admin Center<\/a> and Power Platform Admin Center<\/a>. This allows for streamlined management of permissions, policies, and compliance settings across the organization.<\/p>\n\n\n When building agents with Microsoft Copilot Studio, makers can choose from 1500+ connectors offered by Power Platform or build custom connectors by calling REST APIs to enrich the data used with their agents. Administrators can create and enforce connector management policies to govern data flows across those connectors and services. These policies<\/a> help prevent data leakage and ensure that sensitive information is adequately protected.<\/p>\n\n\n Visibility and monitoring are critical for maintaining the security and efficiency of agent deployments. Here are the key strategies:<\/p>\n\n\n\n Agents built with Agent Builder can be viewed in the Microsoft 365 admin center, where admins can view and search the inventory of shared agents in their tenant and block the sharing of agents. To view the usage of agents built by your organization using Microsoft Copilot Studio, Agent Builder, and Teams Toolkit, visit the Usage report in the Microsoft 365 admin center. Learn more at aka.ms\/MACAgentReport<\/a>.<\/p>\n\n\n Currently in public preview, admins who need to view their custom agents built in Microsoft Copilot Studio can view agent inventory in the Power Platform admin center, on the Mange page and inventory section.<\/p>\n\n\n DSPM for AI provides insights for IT and security teams to proactively discover data risks, such as data in user prompts, and receive recommended actions and insights for quick responses. This tool helps administrators identify potential security vulnerabilities and take proactive measures to mitigate them.<\/p>\n\n\n Agents built with Copilot Studio, Copilot Studio agent builder, and SharePoint agents include comprehensive activity logging and auditing capabilities. Administrators can have clear visibility into user interactions, detect anomalies, and risky AI usage. Additionally, administrators can ensure compliance with organizational policies and can govern user prompts and agent responses with audit, eDiscovery, retention policies, and non-compliant usage detection.<\/p>\n\n\n<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
Data Protection<\/h3>\n\n\n\n
Encryption and Isolation<\/h5>\n\n\n\n
Persistent Label Inheritance and DLP Policies<\/h5>\n\n\n\n
Conditional Access and Endpoint Management<\/h5>\n\n\n\n
Governance at Scale<\/h3>\n\n\n\n
Agent Administration<\/h5>\n\n\n\n
<\/figure>\n\n\n\n
Connector Management Policies<\/h5>\n\n\n\n
<\/figure>\n\n\n\n
Visibility and Monitoring<\/h3>\n\n\n\n
Agent Inventory<\/h5>\n\n\n\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
Data Security Posture Management (DSPM) for AI<\/h5>\n\n\n\n
<\/figure>\n\n\n\n
Agent Data Security and Compliance<\/h5>\n\n\n\n
<\/figure>\n\n\n\n
Copilot Dashboard and Analytics<\/h5>\n\n\n\n