Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Securing Microsoft 365 Copilot with Varonis Data Protection

Varonis
06/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


the company's generative AI assistant, but are concerned about data security. With Varonis for Microsoft 365 CoPilot, organizations can adopt the tool safely and securely. Let's take a look at the capabilities. On the CoPilot dashboard, you can get a real-time view of how many prompts users are making, and how many files and sensitive files are being referenced by CoPilot. CoPilot leverages the user's existing permissions to access data. So if your sensitive data is exposed org-wide to all users, it will be accessible by CoPilot as well. Further down in the CoPilot dashboard are widgets that show overexposed and sensitive data for folders, shares, sites, and more. The first step in safeguarding sensitive information from CoPilot is to remediate any overexposure. With other platforms, this is a tedious process. With Varonis, you can automate this process. Each widget with a blue shield icon has at least one associated remediation policy that can be run automatically. Click on any of the policies to see their configuration and make changes if needed. By clicking on Preview Scope, you can see how much this policy will reduce your blast radius. You can require these actions to be approved before execution and set a schedule for the policy to run. To see the full library of policies, mouse over to the briefcase icon and select Policies. Now, let's answer security team's biggest concern. What sensitive data are people getting from CoPilot? Back to the CoPilot dashboard, here we see sensitive files referenced today. Clicking on this widget gives you a log of the sensitive files gives you a log of every CoPilot event referencing sensitive data from the last 24 hours. Now, having a record of the events is useful, but to really understand what's going on, we need context. We can get that by viewing the actual conversation. To do so, click on the prompt and easily replay a user's conversation with CoPilot to see all the prompts, responses, and files referenced. What if you wanted to search for conversations asking about something specific like social security numbers? Varonis can filter conversations based on keywords or user account depending on your goal. This level of granular insights and information can be used for troubleshooting, incident response, and privacy or legal case review. Speaking of incident response, because Varonis monitors CoPilot interactions, we can also alert on suspicious CoPilot usage. The alerts dashboard provides you an overview of the top alerts, top alerted users, MITRE mappings, and more. You can view all of the alerts by clicking on the top alerted threat detection policies widget. To only view CoPilot related alerts, you can add a filter. Click on a specific alert to get an overview of the users involved, the data accessed, and see the events tied to the alert. From there, we can drill down into the actual CoPilot conversation. Varonis has introduced two new privacy features in relation to concerns about prompt auditing. The first is AI conversation auditing consent. By default, Varonis monitors metadata about CoPilot conversations, usernames, times, paths, source device, and other valuable points of reference. Customers who want conversation auditing will need to provide consent by specifically enabling this configuration. Changing this configuration can only be done by the highest Varonis role in your environment. The second privacy feature is a restricted role for viewing audited AI conversations. Only Varonis users assigned as an AI prompt auditor will be able to view the contents of CoPilot conversations. Those without the role will only see basic event metadata. Varonis is committed to helping organizations confidently adopt and use Microsoft CoPilot while ensuring their sensitive data remains secure. Schedule a demo today to discover more about Varonis for Microsoft 365 CoPilot and how it can help your organization protect data today.

TL;DR

  • Copilot inherits user permissions, so overexposed sensitive data becomes accessible to the AI—Varonis provides visibility into this risk through a dedicated dashboard showing prompts and sensitive file references.
  • Automated remediation policies can reduce data exposure blast radius with configurable schedules and approval workflows, eliminating tedious manual permission cleanup.
  • Security teams can replay actual Copilot conversations to see prompts, responses, and files referenced—enabling incident response, troubleshooting, and legal case review.
  • Two privacy features address prompt auditing concerns: opt-in conversation auditing requiring explicit consent, and a restricted AI prompt auditor role limiting who can view conversation contents.

Summary

This product demonstration showcases how Varonis enables organizations to safely adopt Microsoft 365 Copilot by addressing the core security challenge: Copilot inherits users' existing data permissions, meaning overexposed sensitive data becomes accessible to the AI assistant. The walkthrough covers Varonis's dedicated Copilot dashboard for real-time visibility into prompts and sensitive file references, automated remediation policies to reduce data exposure blast radius, and granular conversation auditing that allows security teams to replay actual Copilot interactions. The demo also highlights two privacy-focused features—consent-based conversation auditing and a restricted AI prompt auditor role—designed to balance security monitoring with employee privacy concerns. These capabilities position Varonis as a solution for organizations wanting to leverage generative AI productivity tools without compromising their data security posture.

Chapters

0:00 - Introduction and Security Challenge
0:19 - Copilot Dashboard Overview
0:52 - Automated Remediation Policies
1:38 - Monitoring Sensitive Data Access
2:44 - Alert Management and Incident Response
3:26 - Privacy Features and Controls

Key Quotes

0:30 "CoPilot leverages the user's existing permissions to access data. So if your sensitive data is exposed org-wide to all users, it will be accessible by CoPilot as well."
0:58 "With other platforms, this is a tedious process. With Varonis, you can automate this process."
2:33 "This level of granular insights and information can be used for troubleshooting, incident response, and privacy or legal case review."

FAQ

How does Varonis help reduce the risk of sensitive data exposure through Copilot?

Varonis identifies overexposed sensitive data across folders, shares, and sites, then provides automated remediation policies that can run on schedule to reduce the blast radius. Each policy can be previewed to see its impact before execution and configured to require approval.

Can security teams see what employees are asking Copilot?

Yes, but with privacy controls. By default, Varonis only monitors metadata like usernames, times, and file paths. Full conversation auditing must be explicitly enabled by the highest Varonis role, and only users assigned the AI prompt auditor role can view actual conversation contents.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Data Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Data Privacy
  • Data Protection
  • Compliance & Governance
  • Demo
  • Microsoft 365 Copilot security
  • Generative AI data protection
  • Data access governance
  • Sensitive data exposure remediation
  • AI prompt auditing
  • Permission management automation
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Securing Microsoft 365 Copilot with Varonis Data Protection

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Jul
                    14

                    Crafting a Championship-Caliber Security Team for Lasting Defense

                    07/14/202601:00 PM ET
                    • Jul
                      14

                      Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data

                      07/14/202602:00 PM ET
                      • Jul
                        22

                        Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue

                        07/22/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/14/2026
                          01:00 PM
                          07/14/2026
                          Crafting a Championship-Caliber Security Team for Lasting Defense
                          https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-caliber-security-team-for-lasting-defense/
                        • 07/14/2026
                          02:00 PM
                          07/14/2026
                          Understanding the Crucial Role of Context in Safeguarding AI-Accessible Data
                          https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-safeguarding-ai-accessible-data/
                        • 07/21/2026
                          04:00 AM
                          07/21/2026
                          Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                          https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
                        • 07/22/2026
                          06:30 AM
                          07/22/2026
                          Insights and Strategies in Data Protection and Privacy Management
                          https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-in-data-protection-and-privacy-management/
                        • 07/22/2026
                          01:00 PM
                          07/22/2026
                          Insights from Attackers During the FIFA World Cup: A HUMAN Dialogue
                          https://www.truthinit.com/index.php/channel/2029/insights-from-attackers-during-the-fifa-world-cup-a-human-dialogue/
                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights from Cyera's Expertise
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-from-cyeras-expertise/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version