Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
  • Management
    1. Role-Based Access Control
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Terminal Servers
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. AI Protections
    13. SaaS Restrictions
    14. Bookmark Manager
  • Secure Access (ZTNA)
    1. Configuration
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Policy Management
    1. Configuring Policies
    2. Configuring Consents
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Enforcing AI Protections for Copilot

In this document
  • Overview
  • How it works?
  • Configuration

Overview

DefensX AI Protections are designed to enforce robust commercial data protection over AI tools, ensuring that sensitive information remains secure when organizations and employees utilize generative AI services.

When using generative AI services, such as Microsoft Copilot, it’s crucial to understand how these services manage user and chat data. Microsoft Copilot includes features for commercial data protection. By signing in with a work or school account before using the tool, a green badge is displayed on the screen, indicating that "Commercial data protection applies to this chat."

However, if a user inadvertently uses Copilot or Bing chat without signing in, they risk exposing sensitive information. DefensX AI Protections address this vulnerability by enforcing Microsoft Commercial Data Protections at both the DNS and HTTP request levels. Once enabled, this ensures that no one can interact with Copilot services without proper authentication. This proactive measure prevents accidental data exposure, providing an additional layer of security and peace of mind for organizations.

How it works?

To prevent eligible users in your organization from accessing Copilot without commercial data protection (formerly Bing Chat) when signed in with their Entra ID, Microsoft supports both DNS redirection and HTTP header injection methods. [https://learn.microsoft.com/en-us/compliance/anz/blueprint-copilot-recconfig#enforce-commercial-data-protection]

In DefensX, both methods are also supported by redirecting the DNS requests with our agent and injecting required HTTP headers through the DefensX browser extensions.

After enforcing commercial data protection both user and organizational data are protected:

  • Prompts and responses aren’t saved

  • Microsoft has no eyes-on access

  • Chat data isn’t used to train the underlying large language models

Access to Copilot without commercial data protection enforcement:

copilot without cdp

Access to Copilot after enforcing commercial data protection:

copilot with cdp

Configuration

Tip
DefensX AI Protections feature is enabled for CORE+ and higher packages.

You can enable AI protections with a single click in the DefensX backend. Just navigate to the Settings → AI Protections menu and turn on the feature. After changing this setting, you may need to wait up to 5 minutes for the previously cached responses to expire and the new settings to take effect.

configuration
www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013