Managing Microsoft 365 Copilot and Third-Party Generative AI: Securing Data, Monitoring Usage, and Mitigating Risks with Purview and Defender
NikkiChapple
0 views
49 slides
Sep 27, 2025
Slide 1 of 49
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
About This Presentation
Title | Managing Microsoft 365 Copilot and Third-Party Generative AI: Securing Data, Monitoring Usage, and Mitigating Risks with Purview and Defender
Presenter | Nikki Chapple, 2 x MVP and Principal Cloud Architect at CloudWay
Event | Commsverse 2025
Format | In person, Deep Dive Technical Sessio...
Title | Managing Microsoft 365 Copilot and Third-Party Generative AI: Securing Data, Monitoring Usage, and Mitigating Risks with Purview and Defender
Presenter | Nikki Chapple, 2 x MVP and Principal Cloud Architect at CloudWay
Event | Commsverse 2025
Format | In person, Deep Dive Technical Session
Location | Mercedes-Benz World, Brooklands, UK
Date | 19 June 2025
Description:
With generative AI tools such as Microsoft 365 Copilot and third-party platforms rapidly entering the workplace, organisations face new challenges in protecting sensitive data and maintaining compliance. This session, led by Nikki Chapple—Microsoft MVP and Principal Cloud Architect at CloudWay—offers practical strategies for IT professionals, architects, and compliance managers to monitor, secure, and govern AI usage across Microsoft 365.
– Begin your AI journey with a clear understanding of how Copilot and third-party generative AI apps interact with organisational data.
– Discover how Microsoft Purview and Defender for Cloud Apps provide visibility into AI activity, helping you identify data exposure risks and detect shadow AI usage.
– Learn to assess the risk profile of over 1,000 generative AI apps using Defender’s Cloud App Catalog, and find out which apps are being used in your environment with Cloud Discovery.
– Apply real-time controls to block access to unsanctioned AI apps, sync policies to Defender for Endpoint, and enforce URL restrictions on managed devices.
– Stay ahead of emerging threats by tracking new generative AI apps and setting up governance actions and alerts for suspicious activity.
– Explore Data Security Posture Management for AI, including prerequisites such as audit enablement, device onboarding, and Purview extension deployment.
– Understand licensing requirements, including E5 Compliance and role-based access controls for policy configuration and monitoring.
– Monitor Copilot and third-party AI usage trends, track sensitive and labelled data shared with AI apps, and investigate insider risks and external access scenarios.
– Use Activity Explorer to see who is using which AI app and for what purpose, and review Copilot prompts and responses for compliance.
– Leverage DLP triggers and analytics to refine your policies and respond quickly to potential data loss incidents.
This session is designed for those responsible for data security, compliance, and governance in Microsoft 365 environments. You’ll leave with actionable advice to secure your organisation’s AI adoption, maintain regulatory compliance, and empower users—while keeping sensitive data protected.
🔐 Take control of your AI landscape. 📊 Monitor usage. ✅ Protect your data.
Don’t miss this essential guide to managing AI risk in the modern workplace—download, share, and join the conversation!
Size: 7.15 MB
Language: en
Added: Sep 27, 2025
Slides: 49 pages
Slide Content
Managing Microsoft 365
Copilot & Third-Party
Generative AI Usage with
Purview and Defender
Nikki Chapple | MVP
About Me
Nikki Chapple
Expert in Microsoft 365 & Purview
NikkiChapple.com
All Things M365 Compliance Video
Podcast
Agenda
•How do we assess which Gen AI Apps are risky?
•How can we find out what Gen AI Apps are used?
•How can we block access to unwanted Gen AI apps?
•How do we keep track of new Gen AI Apps?
Part A Defender for Cloud Apps
•How can I track our Gen AI Usage?
•Can I see what sensitive data is shared with Gen AI Apps?
•Can I see who is using which Gen AI App and for what purpose?
Part B Data Security Management for AI
The Issue
of AI users are bringing their own AI tools to work
AI at Work Is Here. Now Comes the Hard Part - 2024 Work Trend Index Annual Report
Defender for Cloud
Apps
How do we assess
which Gen AI Apps
are risky?
Defender for Cloud Apps > Cloud App Catalog
View Gen AI App Catalog 1123
Apps
Assess the risk of an App
How can we find out
what Gen AI Apps are
used?
Defender for Cloud Apps > Cloud Discovery
Discover what Gen Ai Apps are
being used
How can we block
access to unwanted
Gen AI apps?
Sync Unsanctioned Apps to
Defender for Endpoint
Block URLs on Managed Devices
Get Notified of New apps
How do we keep
track of new Gen AI
Apps?
Defender for Cloud Apps > Policy Management
Data Security
Posture Management
for AI
Prerequisites
Audit enabled
Devices
onboarded
Purview Extension
deployed
Licensing
E5 Compliance
Copilot licenses
not required
Configuration
eDLP Polices
IRM policies
(optional)
RBAC
Compliance
Admin – configure
policies
Security reader –
view
IRM – view Risky
user info
Set Up
How can I track our
Gen AI Usage?
Data Security Posture Management for AI
View Copilot Usage
View 3
rd
Party Gen AI Usage
Current list
457 domains
Can I see what sensitive
data is shared with Gen
AI Apps?
View your custom SITs
Track Sensitive data
Track labelled data
Track Insider Risk
Can I see who is using
which Gen AI App and
for what purpose?
DSPM for AI > Activity Explorer
View Copilot Prompt & Response
Who is accessing which App
View DLP Triggers
Summary
Summary
•How to assess which Gen AI Apps are risky
•How to find out what Gen AI Apps are used
•How to block access to unwanted Gen AI apps
•How to keep track of new Gen AI Apps
Part A Defender for Cloud Apps
•How to track our Gen AI Usage
•See what sensitive data is shared with Gen AI Apps
•See who is using which Gen AI App and for what purpose
Part B Data Security Management for AI