Skip to content

Microsoft 365 AI governance security checks

AI assistants, agents and model access inside the tenant — what they can read, who can publish them, and how autonomously they act.

On Microsoft 365, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft 365 connector needs.

Checks (6)

severity: low Copilot Agent Generative Orchestration fix difficulty: medium #

Review if generative orchestration is appropriate for this agent's risk profile

  1. Assess the agent's data access and tool capabilities
  2. Consider switching to classic orchestration if the agent handles sensitive operations

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: critical Copilot Agent No Authentication fix difficulty: easy #

Enable Microsoft Entra authentication on this agent

  1. Open Power Platform Admin Center > Copilot Studio
  2. Select the agent and go to Authentication settings
  3. Enable Microsoft Entra authentication

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Copilot Agent Multi-Channel Exposure fix difficulty: easy #

Review channel exposure and remove unnecessary channels

  1. Open Power Platform Admin Center > Copilot Studio
  2. Review the channels the agent is published to
  3. Remove channels that are not required

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Copilot Agent Unconstrained Tool Use fix difficulty: medium #

Add usage constraints to tool operations instead of allowing anytime use

  1. Open Power Platform Admin Center > Copilot Studio
  2. Select the agent and review tool operation constraints
  3. Change whenCanBeUsed from Anytime to a specific condition

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Copilot Agent Unreviewed (14+ days) fix difficulty: easy #

Review the agent and update its approval status

  1. Navigate to AI Agent Governance in SSPM
  2. Review the agent and approve, restrict, or block it

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: high Copilot Agent High Risk Unblocked fix difficulty: easy #

Block or restrict high-risk agents with scores above 70

  1. Navigate to AI Agent Governance in SSPM
  2. Review the agent risk factors
  3. Block the agent until risks are mitigated

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

More Microsoft 365 checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial