web
You’re offline. This is a read only version of the page.
close
Skip to main content

Announcements

News and Announcements icon
Community site session details

Community site session details

Session Id :
Copilot Studio
Answered

Prompt Injection

(2) ShareShare
ReportReport
Posted on by 18
How are you handling prompt injection through enterprise knowledge sources such as SharePoint or uploaded documents? Are you relying primarily on Copilot Studio guardrails, or implementing additional controls outside the agent?
Categories:
  • Verified answer
    Muhammad Shahzad Shafique Profile Picture
    50 on at

    Knowledge retrieved from SharePoint should be treated as untrusted data, not instructions.

    I would combine:

    • Strict agent/system instructions
    • Controlled knowledge-source ownership
    • Content governance
    • Least-privilege access
    • Separation between knowledge retrieval and privileged actions
    • Server-side authorization for actions

    Most importantly, retrieved content should never be able to override higher-priority instructions or directly authorize a privileged operation.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Season of Sharing Community Challenge Winners!

Congratulations to our community stars!

Kudos to our 2025 Community Spotlight Honorees

Expanding mentorship, skilling, and AI innovation

Leaderboard > Copilot Studio

#1
Mohsin Ali Profile Picture

Mohsin Ali 356

#2
Valantis Profile Picture

Valantis 253 Super User 2026 Season 2

#3
11manish Profile Picture

11manish 179 Super User 2026 Season 2

Last 30 days Overall leaderboard