Analysis
Unpacking the Microsoft 365 Copilot Attack Surface
First reported · Discovered guardz.com
Page published
Earliest dated coverage: 21 Aug 2025 · First observed: 10 Oct 2026 · Latest dated coverage: 21 Aug 2025
Coverage timeline
Single-source analysis — one report is available.
Why it matters
Microsoft 365 Copilot's deep access to enterprise data via Microsoft Graph means prompt injection and abuse of its permissions create new attack paths that defenders must account for in widely deployed productivity environments.
Guardz analyzes the Microsoft 365 Copilot attack surface, mapping how the AI layer sitting atop Microsoft Graph can be abused across a kill chain spanning reconnaissance, initial access, discovery, persistence, lateral movement, exfiltration, and C2. The piece highlights that prompt injection via documents, metadata, comments, or Loop components can steer Copilot, and that its user-scoped permissions can let compromised accounts retrieve data and automate malicious workflows.