Microsoft 365 AI governance security checks
AI assistants, agents and model access inside the tenant — what they can read, who can publish them, and how autonomously they act.
On Microsoft 365, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft 365 connector needs.
Checks (6)
severity: low Copilot Agent Generative Orchestration fix difficulty: medium #
Review if generative orchestration is appropriate for this agent's risk profile
- Assess the agent's data access and tool capabilities
- Consider switching to classic orchestration if the agent handles sensitive operations
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: critical Copilot Agent No Authentication fix difficulty: easy #
Enable Microsoft Entra authentication on this agent
- Open Power Platform Admin Center > Copilot Studio
- Select the agent and go to Authentication settings
- Enable Microsoft Entra authentication
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Copilot Agent Multi-Channel Exposure fix difficulty: easy #
Review channel exposure and remove unnecessary channels
- Open Power Platform Admin Center > Copilot Studio
- Review the channels the agent is published to
- Remove channels that are not required
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Copilot Agent Unconstrained Tool Use fix difficulty: medium #
Add usage constraints to tool operations instead of allowing anytime use
- Open Power Platform Admin Center > Copilot Studio
- Select the agent and review tool operation constraints
- Change whenCanBeUsed from Anytime to a specific condition
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Copilot Agent Unreviewed (14+ days) fix difficulty: easy #
Review the agent and update its approval status
- Navigate to AI Agent Governance in SSPM
- Review the agent and approve, restrict, or block it
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: high Copilot Agent High Risk Unblocked fix difficulty: easy #
Block or restrict high-risk agents with scores above 70
- Navigate to AI Agent Governance in SSPM
- Review the agent risk factors
- Block the agent until risks are mitigated
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4