OMG. #Microsoft #Copilot bypasses #Sharepoint #security so you don’t have to!
“CoPilot gets privileged access to SharePoint so it can index documents, but unlike the regular search feature, it doesn’t know about or respect any of the access controls you might have set up. You can get CoPilot to just dump out the contents of sensitive documents that it can see, with the bonus feature* that your access won’t show up in audit logs.”
The S in CoPilot stands for Security!
https://pivotnine.com/the-crux/archive/remembering-f00fs-of-old/
"Connecting SharePoint and Microsoft OneDrive to ChatGPT deep research"
– Or, just... I don't know, erm... don't?
With regards to reducing our institutional storage footprint: discovered that our Teams/SharePoint sites retain the entire version history forever.
I have student project teams where a single report/presentation file might be 200mb. With auto save on, that file quickly takes up 10gb of server space with just a few days of working on it. Every 10 minutes is a new 200gb file version. This one team is using 42gb for what is realistically 2gb of documents.
Microsoft Copilot for SharePoint just made recon a whole lot easier.
One of our Red Teamers came across a massive SharePoint, too much to explore manually. So, with some careful prompting, they asked Copilot to do the heavy lifting...
It opened the door to credentials, internal docs, and more.
All without triggering access logs or alerts.
Copilot is being rolled out across Microsoft 365 environments, often without teams realising Default Agents are already active.
That’s a problem.
Jack, our Head of Red Team, breaks it down in our latest blog post, including what you can do to prevent it from happening in your environment.
Read it here: https://www.pentestpartners.com/security-blog/exploiting-copilot-ai-for-sharepoint/
OUT NOW: Cryptomator for iOS 2.7.0!
We’re excited to introduce SharePoint integration in our latest iOS update! This means you can now securely encrypt your files stored in Microsoft SharePoint and Teams with end-to-end encryption.
Upgrade to Cryptomator 2.7.0 today and take control of your data security!
I used to say that I miss #SharePoint Server 2013 because #Kerberos was a lot less trouble than anything else currently in use for authentication.
But now with all this AI being put into everything I can say #SharePointServer 2013 has never looked sexier before today!
I used #PowerBI, #ReportBuilder, #Excel, & #VBA to do ~5 mos of work in < 1 week.
Now I’m working on a #PowerAutomate flow to move 1 file from #OneDrive to #SharePoint at a set interval (w/ some random variance). That would trigger a flow to notify my colleagues a file is ready, so I’d be done & automated for quite some time.
BUT I cannot for the life of me figure out how to use PowerAutomate to copy the 1st file in a folder. It keeps trying to do a “for each” loop & copy them all. Any ideas?
𝗙𝘂𝗶𝘁𝗲 𝗱𝗲 𝗱𝗼𝗻𝗻𝗲́𝗲𝘀 𝗰𝗵𝗲𝘇 𝗙𝗼𝗿𝘁𝗶𝗻𝗲𝘁 : un pirate a volé 𝟰𝟰𝟬 𝗚𝗼 de données sur un serveur 𝗦𝗵𝗮𝗿𝗲𝗣𝗼𝗶𝗻𝘁 ! L'incident a été confirmé par Fortinet !
https://www.it-connect.fr/fuite-de-donnees-fortinet-440-go-de-donnees-sharepoint/
Collabora Online & SharePoint Integration!
#CollaboraOnline seamlessly integrates with Microsoft #SharePoint, offering organizations enhanced capabilities for secure document management and collaborative editing. With this integration, you can effortlessly open, edit, and collaborate on your DOCX, ODT, Visio, and Publisher files directly within SharePoint.
Learn more about Collabora's rich editing features and SharePoint's powerful document management system. https://buff.ly/3AHOzrR
There are days I dislike #Sharepoint, and then there are days that I loathe it.
Finally trying to write more documentation for my sharepointr package https://elipousson.github.io/sharepointr/articles/read-write.html
Feedback on the vignette is welcome as is feedback on the package. Documentation is hard to write!
#Microsoft365 #SharePoint #RStats
Hey, you know how Microsoft is obsessed with SharePoint, and Teams is implemented in SharePoint?
Is OneDrive a SharePoint app too?!
Technical article about Restricted SharePoint Search enablement and setup: https://learn.microsoft.com/en-us/sharepoint/restricted-sharepoint-search
Public Roadmap item with current Restricted SharePoint Search rollout progress (ID 385352): https://www.microsoft.com/en-gb/microsoft-365/roadmap?filters=&searchterms=385352
Users in the organization can continue to interact w/ files & content they own or that they have previously accessed in Copilot for #Microsoft 365.
Their experience will be a banner at the top of the Graph-grounded Chat UI:
“Your org's admin has restricted Copilot from accessing certain SharePoint sites. This limits the content #Copilot can search and reference when responding to your prompts. Learn more.”
Read more details about Restricted #SharePoint Search here: https://techcommunity.microsoft.com/t5/copilot-for-microsoft-365/introducing-restricted-sharepoint-search-to-help-you-get-started/ba-p/4071060
Restricted SharePoint Search is now generally available for Copilot for M365 enabling admins to review content mgmt & data governance practices w/out losing momentum w/ Copilot for #M365 deployment.
#Microsoft 365 admins can turn off org-wide search & restrict both Enterprise Search & Copilot to a curated set of #SharePoint sites, so they can review & audit site permissions in parallel w/ the #Copilot rollout.
Read more details about Restricted SharePoint Search here: https://lnkd.in/eyxaYEXE
So, Microsoft offers some new(ish?) SharePoint list templates. They are well-structured, thoughtful, and cover a variety of use cases, and some even come with pre-built Power Automate automations that the template will recommend and help you set up!
Except . . . we had a DIFFERENT automation in mind, but half of the fields from the list (including both items we added AND items that were part of the template) weren't visible to Power Automate.
MICROSOFT!
#PoweAutomate #SharePoint