Microsoft Enables Shadow IT By Letting People Sneak Their Personal Copilot Into Work
Welcome To Your Client’s Nightmare
There has been a new and frustrating challenge for IT teams that just got worse, trying to prevent LLMs from stealing proprietary data. The easy part is setting up a firewalled version of an LLM that employees can utilize without fear of proprietary data ending up where it shouldn’t. The hard part is keeping those employees from using a random LLM which will happily harvest and share company and client data with anyone who asks for it. Microsoft have made this quite difficult, by shoehorning Copilot into everything and forcing admins to find ways to block it on their systems. Since Microsoft keeps coming up with new products, the challenge changes almost daily.
This has apparently annoyed Redmond and they have found yet another way to sneak Copilot into your environment so it can innocently harvest data it has no businesses sharing. If an employee has a personal O359 account they will now be able use both personal and work accounts and now can “use Copilot features from their personal plan.” This can be blocked, but you first need to realize it is happening and then figure out where the options to disable personal Copilot are hidden.
Microsoft of course claims that no data will be exfiltrated and that any and all prompts your users enter can be captured by IT. They also don’t see how this could possibly upset the competition, who are also being blocked by businesses and don’t have a way to sneak their LLM past the defences IT has erected. Sysadmins should be unimpressed by Microsoft’s Copilot Trojan horse and the fact they decided this was a good idea in the first place.
Earlier this year, Microsoft said it had adopted a new approach to shadow IT. "While earlier eras of our IT history focused on trying to prevent shadow IT, we are now concentrating on managing it," the biz said in a blog post. By "managing," Microsoft also means "enabling."
More Tech News From Around The Web
- Microsoft Defender bug triggers erroneous BIOS update alerts @ Bleeping Computer
- That annoying SMS phish you just got may have come from a box like this @ Ars Technica
- 3.7M breach notification letters set to flood North America’s mailboxes @ The Register
- Red Hat Investigating Breach Impacting as Many as 28,000 Customers, Including the Navy and Congress @ Slashdot
- Windows 11 25H2 is mostly 24H2 with bits bolted on or ripped out @ The Register
- Intel and AMD Trusted Enclaves, a Foundation For Network Security, Fall To Physical Attacks @ Slashdot
- Brave browser surpasses the 100 million active monthly users mark @ Bleeping Computer
- Sending TOSLINK Wirelessly With Lasers @ Hackaday
- AirPods Pro 3 Impossible To Repair, Earn Score of 0 In iFixit Teardown @ Slashdot
- TP-Link 10Gbase-T PCIe Network Adapter @ ServeTheHome


