Skip to main content

Notifications

Community site session details

Community site session details

Session Id :
Copilot Studio - Bot Administration
Unanswered

Avoid malicious multiple sessions/conversations opening

(0) ShareShare
ReportReport
Posted on by 12

How can I avoid malicious multiple website PVA sessions/conversations opening from our customers?

  • HenryJammes Profile Picture
    on at
    Re: Avoid malicious multiple sessions/conversations opening

    Sorry, I'm not aware of any available sample for this.

  • Kalampoukas Profile Picture
    12 on at
    Re: Avoid malicious multiple sessions/conversations opening

    Hello @HenryJammes,

     

    We tried to implement a captcha before loading the PVA web chat but we cannot do this cause its an iframe. Do you have any idea or any documentation how can we implement it?

     

    Thank you.

  • Kalampoukas Profile Picture
    12 on at
    Re: Avoid malicious multiple sessions/conversations opening

    We are trying to implement a google invisible Captcha on our public website before loading the PVA but it will not solve our concern because we have to final a solution for all the other channels (Facebook, Viber, Whatsapp etc) maybe through the PVA. I have already escalated to MS Product Group and they told that it will be as a top priority.

     

    I posted here, if there is an alternative solution or if you have any other ideas to prevent it.

     

    Thank you for your reply.

  • HenryJammes Profile Picture
    on at
    Re: Avoid malicious multiple sessions/conversations opening

    @Kalampoukas wrote:

    I want to be proactively for my organization. The main question is how to prevent multiple chatbot sessions created to prevent DOS attack and not have unwanted PVA billed sessions.

     

    Investigation:

      • If the attack is made by an automation, ask of whether there’s any security mechanism that can be implemented (say a Captcha, or similar) to prevent the chatbot sessions from being created.
      • If there is the concern is related with a human behind the attack, whether it is possible to allow a single session per IP

    Regarding these two bullets, I am trying to find a solution.


    Hi @Kalampoukas


    For a bot published on a public website, you could add additional logic on the client side to prevent these.

    E.g. implement a captcha before loading the PVA web chat, etc.

  • Kalampoukas Profile Picture
    12 on at
    Re: Avoid malicious multiple sessions/conversations opening

    I want to be proactively for my organization. The main question is how to prevent multiple chatbot sessions created to prevent DOS attack and not have unwanted PVA billed sessions.

     

    Investigation:

      • If the attack is made by an automation, ask of whether there’s any security mechanism that can be implemented (say a Captcha, or similar) to prevent the chatbot sessions from being created.
      • If there is the concern is related with a human behind the attack, whether it is possible to allow a single session per IP

    Regarding these two bullets, I am trying to find a solution.

  • peterswimm Profile Picture
    Moderator on at
    Re: Avoid malicious multiple sessions/conversations opening

    Is this a real problem, or one you are trying to mitigate proactively? I know PVA does throttle and block abusive usage of our endpoints, but would be interested in understanding better a little of the types of abuse you are trying to prevent.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

🌸 Community Spring Festival 2025 Challenge Winners! 🌸

Congratulations to all our community participants!

Warren Belz – Community Spotlight

We are honored to recognize Warren Belz as our May 2025 Community…

Congratulations to the April Top 10 Community Stars!

Thanks for all your good work in the Community!

Leaderboard > Copilot Studio - Bot Administration

#1
Michael E. Gernaey Profile Picture

Michael E. Gernaey 2 Super User 2025 Season 1

Overall leaderboard

Featured topics