Forum Discussion

pvuppala's avatar
pvuppala
Helper V
1 year ago

Copilot Governance Question

Hello,

Our team discovered that Premium workspace "Viewers" can interact with underlying data using Copilot "Preview" toggle effectively getting to any data outside of visuals created.  This can circumvent when you're dealing with sensitive content.  We are looking for ideas on how to effectively govern this feature for our tenant.  I wonder how many AD Groups can be allowed in the tenant settings to Include or Exclude Groups for Copilot feature?

 

How is everyone planning to rollout this feature by including or excluding certain AD Groups?

 

TIA

-Pawan

3 Replies

  • If you have RLS on your model Copilot will not return results that the user isn't allowed to see. RLS is a great way to restrict data so that everyone only sees what they are able to see. 

    • pvuppala's avatar
      pvuppala
      Helper V

      Agreed if all users behaved responsibly when it comes to dealing with senstive data.  Looking for some ideas not dependent on user/developer assumptions. 🙂  We have a large tenant with over 1000 workspaces.

      One suggestion from Micrsoft partners was to disable Q&A feature within a semantic model, that will turn off the Copilot feature but, its not feasible to set these for so much inventory.

      • Tutu_in_YYC's avatar
        Tutu_in_YYC
        Super User

        Try disabling or limiting this setting to just a certain security group. This is available in the Admin Portal > Tenant Setttings


        Update: you are already aware of this. Anyway this is how my clients deal with it. Regarding how many security groups, try nested security groups, due to the possible limit of entry you can put in the box.