For most of the last decade, the first hour of a business email compromise investigation followed a familiar path. We pulled the sign in logs, looked for inbox rules that quietly moved anything containing the word "invoice" into the RSS Feeds folder, checked for new mail forwarding, reviewed OAuth consent grants, and then went looking at what the account touched in SharePoint and OneDrive. The attacker in that scenario had a real constraint working against them. They had to hunt. They had to guess at file naming conventions, scroll through folders built by people who never expected an outsider to read them, and open documents one at a time hoping something valuable was inside. Time was on our side, at least a little.
That constraint is gone.
When an attacker takes over an account in a tenant with Microsoft 365 Copilot or a similar assistant enabled, they no longer have to search like an intruder. They can ask questions like an employee. Copilot reaches whatever the signed in user can reach through Microsoft Graph, which means the attacker inherits that reach the moment they inherit the session. The questions are not sophisticated, and that is exactly the problem. Where do we keep our banking and wire instructions. Which documents mention the acquisition. Summarize our cyber insurance policy including the limits. Who approves payments over fifty thousand dollars. Show me any file that contains a password or an API key. Work that used to take a patient adversary several days now takes a few minutes, and it produces better results than manual hunting ever did.
This is Not a Theoretical Concern
Varonis Threat Labs published two pieces of research in the past year that should have gotten more attention than they did. The first, which they called Reprompt, showed how a single click on a legitimate Microsoft link could hijack an active Copilot session and keep exfiltrating data after the user closed the chat window. The second, SearchLeak, chained three flaws in Copilot Enterprise Search into a silent exfiltration path that reached mailbox content, calendar detail, meeting notes, and indexed files. Microsoft rated it critical and shipped a fix this past June. The specific vulnerabilities matter less than the pattern they expose. An enterprise assistant is a fast, obedient, extremely well read insider that has no instinct for why a question is being asked and no sense that the person asking it logged in from a residential IP address in another hemisphere two hours ago.
There is a second problem underneath the first, and it is the one I raise with clients most often. The exfiltration itself has become quieter. Mass downloads from SharePoint generate volume, and volume generates alerts in tools like Defender for Cloud Apps or whatever data loss prevention platform the client has deployed. A conversation with an assistant generates almost nothing that looks like theft. The sensitive content arrives already summarized, already stripped of the surrounding noise, rendered in a chat pane that most monitoring programs are not watching. In that model the answer is the exfiltration. No file ever leaves.
Oversharing Stopped Being a Governance Problem
Almost every environment we assess carries permission debt. A SharePoint site built in 2019 for one project, shared with Everyone Except External Users because that was faster than picking a group. Broken inheritance three folders deep. A finance library that a departing controller opened up to a wider audience for a single quarterly close and never closed again. For years that debt sat there quietly, because finding it required knowing it existed. The assistant indexes all of it and will happily surface any of it to whoever is holding the session, which converts a tidy governance backlog into an active exposure with a blast radius you can measure.
So, the practical question becomes what you do about it without stopping the business from using tools it has already paid for.
Start by finding out what an attacker would find. Microsoft Purview Data Security Posture Management for AI runs data risk assessments that identify overshared sites, risky sharing links, and unlabeled sensitive content, and SharePoint Advanced Management adds content assessments that flag oversized audiences, broken inheritance, and ownerless sites. Run those before you assume your exposure is modest. In my experience the results are uncomfortable in a useful way, because they turn an abstract worry into a ranked list of sites with names attached to them.
Then put real boundaries around what the assistant can see. Restricted Content Discovery lets you exclude specific SharePoint sites from Copilot discovery entirely, which is the fastest lever available when you find a site that should never have been open. Purview data loss prevention policies can block Copilot from processing or grounding on content carrying particular sensitivity labels, and prompt level policies can stop a user from pasting regulated data into a prompt in the first place. Labeling everything is not achievable and I would not ask a client to attempt it. Label the material that would ruin your quarter if it walked out the door, which usually means board packages, contracts, client personal information, payroll, and anything describing your own security architecture.
Control the path to the assistant the same way you control the path to email. A Conditional Access policy that permits Copilot only from compliant, managed devices does more to blunt a stolen session than any amount of user training, because an attacker who defeats multifactor authentication through a phishing proxy still has to produce a device your tenant trusts. That control assumes Entra ID P1 and Intune enrollment, and it will frustrate anyone working from a personal laptop, so decide in advance what sanctioned alternative those people get.
Finally, change what you watch and what you collect. Copilot interactions are auditable through Purview, and Insider Risk Management includes policy templates aimed at risky AI usage. Treat a sudden burst of unusual prompts from an account as a detection signal worth investigating, in the same way you would treat a login from a new country followed by a mailbox rule change. More importantly, add assistant activity to the evidence you pull during an account compromise investigation, because if you cannot answer the question "what did the attacker ask, and what did the assistant tell them," you cannot honestly scope the incident, and scoping drives your notification obligations and your conversation with counsel.
None of this is an argument against deploying AI in your tenant. The productivity gains are real and the organizations that sit it out will feel that decision within a couple of years. It is an argument that the governance work most companies deferred, the permission cleanup and the labeling and the tightening of who can reach what, is now load bearing. Copilot does not make you more likely to be breached. It makes a single stolen password worth considerably more, and it collapses the window between that first successful login and the moment the attacker knows your business better than some of your own employees do.
Assume the account will eventually fall. Decide now what the assistant will be willing to say once it does.
Meet with the iCorps team to assess your current environment, identify opportunities, and build a practical path forward.
