web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Copilot Studio / Avoid malicious multip...
Copilot Studio
Unanswered

Avoid malicious multiple sessions/conversations opening

(0) ShareShare
ReportReport
Posted on by 12

How can I avoid malicious multiple website PVA sessions/conversations opening from our customers?

Categories:
I have the same question (0)
  • peterswimm Profile Picture
    Moderator on at

    Is this a real problem, or one you are trying to mitigate proactively? I know PVA does throttle and block abusive usage of our endpoints, but would be interested in understanding better a little of the types of abuse you are trying to prevent.

  • Kalampoukas Profile Picture
    12 on at

    I want to be proactively for my organization. The main question is how to prevent multiple chatbot sessions created to prevent DOS attack and not have unwanted PVA billed sessions.

     

    Investigation:

      • If the attack is made by an automation, ask of whether there’s any security mechanism that can be implemented (say a Captcha, or similar) to prevent the chatbot sessions from being created.
      • If there is the concern is related with a human behind the attack, whether it is possible to allow a single session per IP

    Regarding these two bullets, I am trying to find a solution.

  • HenryJammes Profile Picture
    on at

    @Kalampoukas wrote:

    I want to be proactively for my organization. The main question is how to prevent multiple chatbot sessions created to prevent DOS attack and not have unwanted PVA billed sessions.

     

    Investigation:

      • If the attack is made by an automation, ask of whether there’s any security mechanism that can be implemented (say a Captcha, or similar) to prevent the chatbot sessions from being created.
      • If there is the concern is related with a human behind the attack, whether it is possible to allow a single session per IP

    Regarding these two bullets, I am trying to find a solution.


    Hi @Kalampoukas


    For a bot published on a public website, you could add additional logic on the client side to prevent these.

    E.g. implement a captcha before loading the PVA web chat, etc.

  • Kalampoukas Profile Picture
    12 on at

    We are trying to implement a google invisible Captcha on our public website before loading the PVA but it will not solve our concern because we have to final a solution for all the other channels (Facebook, Viber, Whatsapp etc) maybe through the PVA. I have already escalated to MS Product Group and they told that it will be as a top priority.

     

    I posted here, if there is an alternative solution or if you have any other ideas to prevent it.

     

    Thank you for your reply.

  • Kalampoukas Profile Picture
    12 on at

    Hello @HenryJammes,

     

    We tried to implement a captcha before loading the PVA web chat but we cannot do this cause its an iframe. Do you have any idea or any documentation how can we implement it?

     

    Thank you.

  • HenryJammes Profile Picture
    on at

    Sorry, I'm not aware of any available sample for this.

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Kudos to our 2025 Community Spotlight Honorees

Congratulations to our 2025 community superstars!

Leaderboard > Copilot Studio

#1
Valantis Profile Picture

Valantis 436

#2
chiaraalina Profile Picture

chiaraalina 145 Super User 2026 Season 1

#3
Michael E. Gernaey Profile Picture

Michael E. Gernaey 98 Moderator

Last 30 days Overall leaderboard