Use Zero Trust security to prepare for AI companions, including Microsoft Copilots
Alt
Security, especially data protection, is a top concern when introducing AI tools into an organization. Security recommendations for AI are anchored in Zero Trust. As a leader in security, Microsoft provides a practical roadmap and clear guidance for Zero Trust. By implementing recommended protections as you introduce AI tools and companions, you're building a foundation of Zero Trust security.
This series of articles helps you apply the principles of Zero Trust to Microsoft’s Copilots and similar AI companions. Zero Trust is a security strategy. It isn't a product or a service, but an approach in designing and implementing the following set of security principles:
Verify explicitly
Use least privileged access
Assume breach
Implementing the Zero Trust "never trust, always verify" mindset requires changes to cloud infrastructure, deployment strategy, and implementation.
Layer in protections for AI companions
Microsoft helps you prepare for AI tools and companions and build a Zero Trust foundation at the same time. Take a staged approach starting with protections for web-grounded prompts and maturing to protections for Microsoft 365 graph-grounded prompts. Protections for prompts grounded with data provided by your security tools (Security Copilot) focus on tuning up least privilege practices and honing threat protection.
In the illustration:
Web-grounded prompts are issued by Copilot Chat. Microsoft 365 Copilot includes the features of Copilot Chat (for example, when the work/web toggle is set to web).
Microsoft 365 graph-grounded prompts are issued by Microsoft 365 Copilot (for example, when the work/web toggle is set to work).
Prompts grounded with your security tools are issued by Microsoft Security Copilot.
Get started with Zero Trust by preparing your environment for AI companions
You can build a Zero Trust foundation by preparing your environment for AI companions.
The following table summarizes the illustration and links to articles for implementing the recommended protections.
This module equips learners with the knowledge and skills necessary to implement a robust Zero Trust security framework for their Microsoft 365 Copilot deployments.