Let’s talk about IT

Beyond Basics: Making Microsoft Copilot Safe for Work

Guardrails, policies, and protections for confident adoption

Microsoft Copilot is boosting employee productivity — but without the right safeguards, adoption can expose your business to data leaks, compliance gaps, and misuse.

Join Macro’s Nicholas Frangopoulos and Ken Widmer as they go beyond the basics to show you how to integrate Copilot safely and responsibly.

In this webinar, you’ll discover:

  • How AI changes the threat landscape — and the training employees need to stay safe
  • Steps to create AI acceptable use policies and governance frameworks
  • Compliance and legal considerations every company needs to address
Read the transcript

The full conversation from the webinar above, lightly edited for readability. Timestamps mark each section of the recording.

0:05 · Welcome & Introductions

Nicholas: Welcome, everyone. This is Macro Technology Group’s next webinar in the series we’ve been running lately. This one is “AI at Work: Staying Secure with Microsoft Copilot.” Last time we went over the tool itself and how you can use it to improve productivity at work. Today’s session is all about staying secure with Microsoft Copilot and understanding the new realities of the AI workspace. I’m Nicholas Frangopoulos, Macro Technology Group’s Technical Account Manager. Joining me once again is Ken Widmer, our CTO. Without further ado, let’s get into it.

0:47 · What We’ll Cover

Nicholas: Here’s what we’ll be covering. Part one is what’s happening — an overview of the current landscape, how AI is changing the way we work, and the three major threats you need to know about. Part two is how those threats happen in real life, walking through real use cases to show how they play out in actual organizations. Part three is how to prevent them: practical steps for setting governance, policy, and compliance, plus how to set up Copilot with visibility and train your human firewall. Then we’ll wrap up with the next steps you can take to secure your organization’s AI adoption, and of course we’ll have time for a Q&A at the end. Our goal is to give you the confidence to adopt AI securely, so you can unlock its benefits without exposing your organization to unnecessary risk. So let’s get started.

1:48 · Part 1 — The New AI Threat Landscape

Nicholas: Let’s talk about the new AI threat landscape. With Copilot now part of our daily work and embedded in Microsoft 365, we’re seeing new technology — and new technology means new risks. Copilot sees what your users see, and that same access can expose sensitive data if guardrails are missing. There are three emerging threats you need to be aware of: compromised Copilot, where attackers hack Copilot accounts and quickly gather intelligence from Outlook, Teams, SharePoint, and OneDrive; prompt injection, where hidden instructions manipulate AI outputs, causing Copilot to reveal sensitive data or override organizational settings; and shadow AI, where employees use unsanctioned tools outside company control, which can lead to data loss and compliance violations.

Let’s break these down. AI-generated phishing is becoming more convincing and personalized than ever. Prompt injection can hide malicious text, code, or documents, tricking Copilot into taking actions it shouldn’t. And shadow AI is when staff use public tools like ChatGPT to work faster, which risks copying sensitive data into public systems and losing control of that data.

[3:02] Threat 1 — Compromised Copilot. Attackers can hack Copilot accounts to gather intelligence fast. Why is this so dangerous? Because Copilot has instant access to Outlook, Teams, and OneDrive. If an attacker gets in, they can ask Copilot to summarize all finance-related files, identify who has access to vendor contracts, or even surface details about mergers. The impact is real: 73% of enterprises have already experienced at least one AI-related security incident, and data exposure is the most common type. The bottom line is that Copilot doesn’t break your security — it exposes weak controls. If permissions aren’t set correctly, sensitive data can be surfaced in ways you never expected. That’s why it’s critical to have strong guardrails, clear policies, and ongoing monitoring to keep your organization’s data safe.

[4:04] Threat 2 — Prompt Injection. This is when Copilot gets tricked into turning on you by malicious actors. Malicious instructions are hidden inside text, code, or documents, and Copilot can unknowingly follow these commands — revealing sensitive data from connected files, executing actions outside its intended purpose, or even overriding organizational instructions or security settings. This isn’t just a theoretical risk. In fact, 82% of financial institutions reported attempted prompt injection attacks, and 47% experienced at least one successful breach exposing data. This is why you and your users need to be vigilant about the prompts you use and the data you expose to AI tools. Even a seemingly harmless document or message could contain hidden instructions that manipulate Copilot’s outputs.

[4:56] Threat 3 — Shadow AI. This is one of the biggest hidden risks in today’s workplace. Shadow AI happens when well-meaning employees use public AI tools like ChatGPT or Gemini to work faster or solve problems. It sounds helpful, but it can create serious security gaps: employees might copy and paste sensitive or client data into public systems, thinking it’s just a quick shortcut. When that happens, we lose audit trails and control — suddenly, information that should be protected is outside our company’s boundaries. This can violate compliance regulations like HIPAA or PCI, putting the organization at risk. And the numbers are eye-opening: only 24% of generative AI products are currently secured, even though 82% of companies say trustworthy AI is critical to their business.

5:44 · What the Threats Look Like in Real Life

Nicholas: So what do these threats look like in real life? Let’s go over three cases we’ve seen.

Ken: [5:51] Case 1 — The Overshared Spreadsheet. This is Jordan, an office manager at a small company. His boss asked him to update the company directory — nothing crazy or outlandish about the ask. Since the company allows Jordan to use Copilot, he decides to give it a try to speed things up. He opens Copilot and types in a single prompt: “Create a detailed table of current employees; include name, title, department, manager, work email, and all other info.” He lets Copilot get to work. It searches through the files Jordan has made and the ones he has access to, and within seconds it generates the requested table with all the employee details he needs. Jordan’s pumped — a few seconds of his time, and he’s created this great employee table. But he notices something unexpected: next to the columns are salary figures. At first this catches him off guard, and he immediately notifies management.

Management blames Copilot, but that’s not what happened here. Copilot didn’t break security. This wasn’t some kind of prompt injection or data leak that Nicholas talked about earlier. Copilot and Jordan followed all the rules given to them; Copilot only pulled information from files Jordan was already allowed to see. The issue is that HR had stored a master spreadsheet in SharePoint that contained everything Jordan asked for, plus salary information. That file happened to live in a library with access granted to Jordan. He had permission to view it the whole time — he just didn’t realize it, because he doesn’t work in HR and had never tried to access the site or file before. It wasn’t synced to his computer, so he didn’t even realize it existed. Copilot didn’t create the security gap; it revealed one that had been quietly hiding in plain sight.

Nicholas: Thanks for that, Ken. One of the things to take away there is that, like you said, it revealed something — it wasn’t something Copilot created. That’s why it’s always important to secure your environments.

[8:24] Case 2 — Shadow AI. Shadow AI equals shadow risk. Imagine an engineer pastes code with credentials into ChatGPT to fix a PowerShell script. Internal data such as usernames, passwords, and domain names now exists outside company control. Logs show exposure of environment details, which is a blueprint into your systems.

This next one is Daniel, an account manager whose job is to be the main point of contact for several key clients. He handles everything from support escalations to billing questions and follow-ups, and he works mostly out of his inbox. It’s first thing Monday morning. Daniel opens his inbox to find a massive email waiting for him — this thing’s a novel. It’s packed with PII like names, phone numbers, and account and billing information, plus a long thread, a list of questions, and several attachments. His head’s spinning. This is an important client and he needs to get things right. He doesn’t know where to start, but he knows he needs a clear, concise summary of everything going on and a simple plan so he doesn’t miss a single thing when responding.

Thankfully, Daniel’s organization just purchased Copilot. Without leaving Outlook, he opens Copilot and types a quick prompt: “Give me a bulleted overview. What are my action items?” Within seconds, Copilot delivers exactly what he needs — a bolded summary of the key accounts, pulling everything together with a clear to-do list: confirm addresses, call schedule, update the tickets. Daniel didn’t paste anything into a personal ChatGPT or use an outside tool. He stayed inside Outlook using Microsoft 365 Copilot exactly how it was intended. But even when everything looks right on the surface, it raises an important question: was this truly safe to do, or did he expose sensitive information without realizing it? Could the way he used Copilot here conflict with company policy, privacy standards, or PII requirements? There was no bad intent by Daniel — but were the rules broken because they weren’t defined?

11:13 · Part 3 — Prevention Starts with Governance

Nicholas: Now that we’ve gone over some threats, I think it’s time to talk about how we can prevent them.

Ken: Before we roll out any tool across an organization, it’s important to build guardrails. We’re talking about AI here, but this is no different than anything else. We need to sit down and set clear governance and a clear policy, and make sure we meet compliance standards before we roll the tool out. The first step is to define acceptable AI use for the organization. To start, you’ll need to define what data can and cannot go into prompts, so employees know exactly where the line is. Your organization might be okay with internal documents going to AI, but maybe not client records, personal information, or financial info, based on compliance concerns. Next, we have to decide when AI outputs require human review — the general rule is that every AI response should be treated as a draft; AI is still fairly new and it gets things wrong. Before information from AI is added to a report, shared with a client, or used to make a decision, someone needs to verify it. Finally, it’s about accountability — not just holding employees accountable for AI use, but defining who does the oversight: who monitors AI usage, who reviews exceptions, and who steps in when something goes wrong. Without that ownership, policies become suggestions. So before anybody starts prompting, we need to define the rules.

Nicholas: I think you hit the nail on the head there, Ken. It’s one thing to have something as a guideline; it’s another to actually enforce it. Now that we’ve covered the key threats and the importance of strong governance, let’s shift gears and look at what a practical policy can actually look like in your organization. Note that what follows is a sample AI acceptable use policy that we drafted to present here. Take it away, Ken.

13:57 · A Sample AI Acceptable Use Policy

Ken: Purpose. Why do we need an AI policy? The goal isn’t to slow people down; it’s the opposite. It’s to unlock the productivity and creativity that AI tools like Copilot easily bring — while protecting the company, client data, and employees. A strong policy sets the bar for responsible use. It tells employees exactly how to use AI to draft, summarize, or analyze information with the same level of discretion we expect from any other business system. It removes guesswork: no gray areas, no uncertainty about what’s okay to use or share. Clear guardrails mean we can move fast and be innovative without taking on additional risk of data exposure or compliance violations. The purpose, again, is smart, secure AI adoption that helps the organization grow — we do not want to introduce another risk.

Scope. This is a very short section, but it’s incredibly crucial: it sets who the policy applies to. In short, it’s everybody — employees, contractors, interns, approved vendors. It also covers when it applies: anytime you use AI in connection with any company data. That means if company data shows up in a prompt, a file upload, or an email attachment, or even if the output generated is used, you’re operating under this policy. It doesn’t matter if it’s a quick draft or a full-blown workflow — if AI touches company data, the rules apply.

Approved AI Tools. This makes it crystal clear what’s actually allowed. This sample policy only allows organizationally licensed tools, like Microsoft 365, that are approved for use. That means no personal ChatGPT accounts, no Gemini accounts, and no browser extensions that process company data. Anything unsanctioned is not permitted and should be blocked — which completely shuts down shadow AI. Data Use and Classification defines what kind of data can be used. In our sample policy, it limits AI use to internal, non-sensitive business information: no personal information, no client-restricted data, no PII, and no PHI should ever go into a prompt. Even though Microsoft and Copilot work in the same ecosystem, compliance requirements and data handling still need to apply to Copilot specifically. Human Review and Accountability: every AI-generated output must be reviewed by a human before it’s shared externally or treated as final — critical for anything involving clients, finance, legal, or deliverables. AI can help you draft, but it can’t decide. Each employee remains fully responsible for accuracy, tone, and compliance. Finally, Privacy and Model Use reinforces privacy protections, and employees are required to complete annual AI safety training so everyone understands what’s safe to share and what isn’t.

18:42 · The Do’s and Don’ts

Ken: This section is the part everyone actually remembers — the practical, day-to-day rules. Start with the Do’s: Copilot is safe for internal tasks like drafting, summarizing, analyzing, or rewriting internal content. Always verify accuracy and tone before sending or publishing anything that comes from AI. Keep inputs minimal — include only what’s necessary to get the result you need. And if you ever think data might have been mishandled or exposed, report it immediately; fast reporting is how we prevent small mistakes from turning into big issues.

Then the Don’ts: never enter passwords, credentials, API keys, or secrets into any AI prompt. Don’t upload or reference client data or personal information without authorization. Do not assume AI output is automatically correct — everything needs human validation before it’s shared or used. Avoid unapproved tools, plugins, and extensions, and never remove confidential markings or anything else to bypass protections. The theme is simple: Copilot can assist you, but you are responsible.

20:24 · Setting Governance & Compliance

Ken: Every organization already lives under some combination of compliance frameworks — it could be HIPAA, PCI, SOC 2, FERPA, or others depending on your industry. Those frameworks shouldn’t sit on one side and AI on the other; the goal is to connect everything. If your organization is handling patient data under HIPAA or payment data under PCI, the same safeguards that protect that data everywhere else need to apply to AI tools like Copilot. That means reviewing business associate agreements and data processing agreements to confirm they actually include AI use. If they don’t, that’s your signal that that type of data cannot be allowed into AI. But if they do, and you already have DLP policies doing data labeling and classification controls, this can easily be expanded into your AI use. The key is that alignment determines position: whether AI can touch regulated data isn’t a technical decision, it’s a compliance decision. And compliance isn’t a one-time checkbox — reasonable safeguards extend to AI policies, training, and oversight. Take your existing standards, extend those protections to AI, and make sure your agreements and safeguards actually match what your security standards allow.

22:53 · Configuring Copilot

Ken: The next logical step is to start configuring Copilot with configuration controls. First, restrict Copilot’s access to sensitive SharePoint sites — narrow the search scope so Copilot only sees the data it should. Exclude personal OneDrive sites and Teams channels, and shift away from an allow-all model to an allow-list, where only approved SharePoint sites are permitted. This keeps sensitive information and legacy data from accidentally being exposed through prompts. Also review SharePoint permissions before Copilot can access a site, including disabling “anyone” links.

After that, go into the Purview module — ideally paired with E5 compliance licensing for data discovery and protection. Purview lets you classify and label content so Copilot knows exactly how to treat it. If a document is labeled confidential, that label transfers with the file, so Copilot respects that boundary automatically. With E5, you can turn on auto-labeling in SharePoint, OneDrive, and Exchange, which catches items at scale — you don’t have to manually tag every document. Things like the payroll export, HR reports, or client data that shouldn’t be in an AI prompt won’t make it in. Then apply conditional access for approved devices only. This is where you can require multifactor authentication and enforce compliance policies, making sure Copilot can only work on company-managed devices on a trusted network — so sensitive information isn’t accessible through personal laptops, home networks, or unmanaged browsers.

25:04 · Monitoring & Oversight

Ken: Track Copilot activity with audit logs and DLP alerts. You want visibility into who’s prompting what and when, and against which data sources. This is not about micromanaging employees; it’s about identifying risk, internal or external. Next, have a plan to investigate unusual prompt activity — if someone is repeatedly querying financial data or referencing client records, that might be malicious, or it could be a permissions gap, a training issue, or perfectly allowed. Either way, define who gets the alerts and who investigates. This is how you prevent a repeat of Jordan’s case, where overpositioned data made salaries visible through Copilot. Finally, communicate with employees about what’s being monitored. Like everything else security-related, transparency is key — this is not surveillance, it’s about protecting them and, ultimately, the company and the data they rely on.

All of these steps help reduce shadow AI. They lower the chance of employees turning to unapproved AI tools, because the company provides a safe, well-configured alternative and there’s no need for workarounds. If we look at Daniel’s example — the client email full of sensitive data — he wouldn’t have unknowingly put the company at risk, because this would have already been defined for him by policy and backed by governance. And if he chose to break the policy anyway, it would have automatically been stopped and logged in real time. Knowing exactly what Copilot has access to, where it can be reached, and how it’s being used — and then configuring the controls and oversight — all works together to make sure Copilot delivers value and does not create risk for your organization.

27:32 · Training Your Human Firewall

Nicholas: Thank you for talking through the setup, Ken. At the risk of sounding like a broken record, I’ve mentioned training users quite a bit over the last few sessions, so I’ll keep hammering that home: your people are your best defense if they know what to do. Make AI use training mandatory and trackable. Add AI policies, like the one Ken just went over, to your employee handbook. Reinforce safe prompting — no PII, credentials, or financial data unless it’s explicitly allowed and everything has been set up securely and meets compliance requirements. Include AI-driven phishing simulations in awareness training; we’re starting to see those in a lot of the tools we use for simulated phishing training. Shadow AI shortcuts can expose your organization to serious risks, but with the right training and controls, your people become the strongest firewall. Block the riskiest tools, promote safe internal AI use, and empower your team with knowledge. Remember, security is everybody’s responsibility, and ongoing education is key.

29:08 · Next Steps

Nicholas: As we wrap up, let’s talk about what you can do next to secure your organization’s AI adoption. First, build your AI acceptable use policy so everyone knows what’s allowed and what’s not. Second, configure Microsoft 365 for secure Copilot use — set up the right controls and guardrails so Copilot only accesses the data it should. Third, train your teams on AI safety; empower your people to use AI tools confidently and securely. And get ongoing governance and compliance support to stay up to date with best practices and keep your policies fresh. If you need help, remember that we here at Macro can always help make Copilot safe for work.

29:57 · Audience Q&A

[30:08] Should AI safety training be separate from cybersecurity training, or combined?

Ken: It should be separate. There are really two parts. In our training recommendations, there are AI phishing attempts, which are role-based — if you’re in finance and you use a certain system, the attack knows that and tailors it to you. That goes in your normal cybersecurity training. But if we’re talking about Copilot, ChatGPT, or whatever tool your company goes with, that’s a separate training module that needs to happen, and it happens in correlation with your policy. It needs to happen at least once a year — completely separate, just like HIPAA training or whatever the compliance training is, is separate from cybersecurity. It probably needs to be very defined: the tool you’re using, and what compliance you have to meet.

[31:40] Do you think regulators — HIPAA, PCI, and so on — will explicitly include AI in the next few years?

Nicholas: My answer is probably yes. For those who don’t know, I come from a medical background — I worked in a local hospital for quite a while and had to stay compliant with HIPAA. Ken, I’d think you’re probably in agreement there. Ken: You would think so; if you expand it out, how does it not? But I have no direct insight on that. Nicholas: I can speak to the trainings — those were updated very explicitly every single year and became mandatory for us. So I could definitely see AI being included within the next couple of years, especially as adoption grows across the space.

[32:46] How can a managed service provider like Macro help us operationalize all this?

Nicholas: We have a checklist of items — it’s pretty extensive, maybe 100 items or so — that we’d walk through with you to identify what information and compliance you have, what you already have set up, where we need to go before we start, and how the rollout is going to be. It’s essentially the same process we just went through: we have to understand your organization, make sure you have the safeguards in check, and then figure out how you’re going to be using this. Are we going to allow it in meetings? Are we going to allow it to access files? What are we actually allowing Copilot to do, and what information is in those items? Then we start talking about rolling it out and what safeguards you need.

34:33 · Closing

Nicholas: That last question really ties into our final slide — that’s us telling you we’re always here to help. As usual with these webinars, the recording will be emailed out, and we are offering a Copilot setup workshop. You have my information at the bottom; for those of you who work with me, feel free to call or email me directly and I’d be happy to help set you up with that. Thank you, everyone, for joining today. If you have any additional questions after the presentation, feel free to shoot me an email — I can loop you in with Ken if it’s something more technical. We’ll see you all in the next one.

Speakers

Ken Widmer
Chief Technology Officer, Macro Technology Group

Nicholas Frangopoulos
Technical Account Manager, Macro Technology Group