Instiq
Chapter 5 · Application and data security·v1.0.0·Updated 7/16/2026·~12 min

What's changed: Created SC-100 Chapter 5 (Domain 4 "Application and data security": M365 protection (Microsoft Secure Score/Defender for Office 365/Defender for Cloud Apps (CASB)/Intune/Purview labels/DLP); Copilot for Microsoft 365 (permission/label inheritance/oversharing/DSPM for AI/Purview Audit); app protection (threat modeling/secure development lifecycle/workload identity/API Management/Azure WAF); data protection (discovery/classification/encryption at rest-in transit/CMK/Key Vault/Defender for Storage/Defender for Databases/Azure SQL/Synapse/Cosmos DB/Storage)).

5.2Data security for Microsoft 365 Copilot

Key points

Understand evaluating data security and compliance controls for Microsoft 365 Copilot: inheritance of existing access permissions and sensitivity labels, curbing oversharing, and applying Purview auditing and DLP.

The generative-AI assistant Microsoft 365 Copilot answers across tenant data. Powerful, but it risks "data the user can access being surfaced en masse via Copilot," so architects design evaluation/controls from a data-governance standpoint.

5.2.1Inheriting permissions and sensitivity labels

Copilot creates no new permission model—it references and answers only within the access the user already has. It also respects Microsoft Purview sensitivity labels, so handling of encrypted/usage-restricted content follows the label’s protection, and generated responses inherit appropriate labels. The architect’s starting point: "Copilot’s security equals the health of the underlying M365 access permissions and labels."

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.