Microsoft has rolled out new data protection controls this month aimed at stopping sensitive company information ending up in AI tools staff have not been approved to use.
- What it is: Microsoft Purview and Entra Global Secure Access can now block staff from uploading confidential files to unsanctioned cloud or AI applications.
- Who is affected: Microsoft 365 business and enterprise customers, particularly those with staff using AI chatbots or file-sharing tools outside the approved company toolkit.
- What the risk is: Without these controls, an employee could unintentionally paste or upload sensitive documents into a public AI tool, exposing that data outside the business.
- What action is needed: Ask your IT provider whether these Purview policies are worth enabling for your organisation, particularly if staff regularly use AI tools for work.
We recommend reviewing which AI and cloud tools your staff currently use, so any new controls can be configured without disrupting day-to-day work.
Source: Microsoft Security Blog