Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Copilot Studio gives administrators control over how images and embedded URLs appear in agent responses. By blocking or allowing images and URLs, you can:
- Decide whether images and clickable links are shown to users.
- Help protect users from untrusted or potentially harmful content.
Malicious actors can exploit rendered images and embedded URLs in Copilot Studio to exfiltrate sensitive data. To mitigate this risk, organizations can disable image rendering and clickable links to prevent attacks and protect users from untrusted or potentially harmful content.
By controlling image rendering and embedded URLs, you can align Copilot Studio with your organization’s security and compliance needs, ensuring agent responses remain safe and trustworthy.
You can enable or disable the rendering of all images and URLs, or you can block untrusted images and URLs that aren't contextually related to the agent's conversation. You can configure these settings in the Power Platform admin center, either for a specific environment or for an environment group.
Block images and URLs in the Security tab
You can block all images and URLs from rendering in agent responses for a specific environment or group from the Security tab in the Power Platform admin center:
- In the Power Platform admin center, go to Security > Threat detection > Showing images and URLs.
- Select the environment or environment group you want to configure, and then select Setup.
- Select one of the options, as described in the following table, and then select Save. The setting is updated and you're returned to the environment selection pane. You can continue to configure environments, or close the pane.
| Setting name | Description |
|---|---|
| Block all images and other URLs | Blocks all images and clickable links in agent responses for the selected environment or environment group. |
| Block untrusted images and other URLs | Blocks any images and clickable links that aren't contextually related to the agent's conversation for the selected environment or environment group. |
| Allow images and URLs | Allows all images and clickable links in agent responses for the selected environment or environment group. |
You can also configure these settings when managing environments and environment groups in the Power Platform admin center:
In the Power Platform admin center, go to Manage > Environment groups > Rules > Showing images and URLs.
Select one of the options, as defined in the preceding table. Save your changes.
Block contextually untrusted images and URLs
This setting blocks any images and clickable links that aren't contextually related to the agent's conversation.
Only images and URLs from the following sources are considered contextually related to the agent's conversation:
- Agent response citations, such as images or URLs that come from a document or other content that the agent is summarizing or analyzing to use in its response.
- Direct input from the agent's user, such as images or URLs that the user provides to the agent for analysis or summarization.
- Content that Microsoft manages through the go.microsoft.com domain, such as images or URLs that come from Microsoft documentation or other Microsoft websites and sources.
If the response contains an image or URL that isn't contextually related to the agent's conversation, the system strips the image or URL to plain text and renders it unclickable.
If the response includes an image or URL that is contained (nested) within another image or URL by using Markdown, the system considers the containing image or URL as untrusted and replaces it with a message indicating the content is unsafe.
User experience when image rendering and embedded URLs are turned off
When you turn on these settings, the system automatically blocks images or clickable links in agent responses. Where an image or URL is blocked, agent users see a brief message indicating that content is restricted by their organization's policy.