Managing Microsoft 365
Copilot & Third-Party
Generative AI Usage with
Purview and Defender
Nikki Chapple | MVP
About Me
Nikki Chapple
Expert in Microsoft 365 & Purview
NikkiChapple.com
All Things M365 Compliance Video
Podcast
Agenda
• How do we assess which Gen AI Apps are risky?
• How can we find out what Gen AI Apps are used?
• How can we block access to unwanted Gen AI apps?
• How do we keep track of new Gen AI Apps?
Part A Defender for Cloud Apps
• How can I track our Gen AI Usage?
• Can I see what sensitive data is shared with Gen AI Apps?
• Can I see who is using which Gen AI App and for what purpose?
Part B Data Security Management for AI
The Issue
of AI users are bringing their own AI tools to work
AI at Work Is Here. Now Comes the Hard Part - 2024 Work Trend Index Annual Report
Defender for Cloud
Apps
How do we assess
which Gen AI Apps
are risky?
Defender for Cloud Apps > Cloud App Catalog
View Gen AI App Catalog 1123
Apps
Assess the risk of an App
How can we find out
what Gen AI Apps are
used?
Defender for Cloud Apps > Cloud Discovery
Discover what Gen Ai Apps are
being used
How can we block
access to unwanted
Gen AI apps?
Sync Unsanctioned Apps to
Defender for Endpoint
Block URLs on Managed Devices
Get Notified of New apps
How do we keep
track of new Gen AI
Apps?
Defender for Cloud Apps > Policy Management
Data Security
Posture Management
for AI
Prerequisites
Audit enabled
Devices
onboarded
Purview Extension
deployed
Licensing
E5 Compliance
Copilot licenses
not required
Configuration
eDLP Polices
IRM policies
(optional)
RBAC
Compliance
Admin – configure
policies
Security reader –
view
IRM – view Risky
user info
Set Up
How can I track our
Gen AI Usage?
Data Security Posture Management for AI
View Copilot Usage
View 3rd Party Gen AI Usage
Current list
457 domains
Can I see what sensitive
data is shared with Gen
AI Apps?
View your custom SITs
Track Sensitive data
Track labelled data
Track Insider Risk
Can I see who is using
which Gen AI App and
for what purpose?
DSPM for AI > Activity Explorer
View Copilot Prompt & Response
Who is accessing which App
View DLP Triggers
Summary
Summary
• How to assess which Gen AI Apps are risky
• How to find out what Gen AI Apps are used
• How to block access to unwanted Gen AI apps
• How to keep track of new Gen AI Apps
Part A Defender for Cloud Apps
• How to track our Gen AI Usage
• See what sensitive data is shared with Gen AI Apps
• See who is using which Gen AI App and for what purpose
Part B Data Security Management for AI
Nikki Chapple
Thank you to this year’s Sponsors

Managing Microsoft 365 Copilot and Third-Party Generative AI: Securing Data, Monitoring Usage, and Mitigating Risks with Purview and Defender