QuestionQ23

Identify an implementation and adoption strategy for Microsoft’s AI apps and services

Your company intends to use generative AI to help summarize and analyze its internal business documents.

You need to recommend a solution that prevents the generative AI from accessing confidential or classified information.

What should you include in the recommendation?

  • A an information barrier (IB) policy
  • B communication monitoring
  • C a data retention policy
  • D data governance
Explanation

Preventing an AI system such as Microsoft 365 Copilot from surfacing confidential or classified content requires data governance controls — specifically data classification and sensitivity labeling combined with permission-based access enforcement. When documents are classified and protected through a data governance framework, the AI can only access and reference content that the requesting user is already authorized to view; labeled/restricted files are excluded from AI-generated responses for users without the necessary permissions. Information barrier policies instead restrict communication and collaboration between defined groups of users, communication monitoring reviews conversations for compliance/conduct issues, and data retention policies control the lifecycle (how long data is kept), none of which govern whether AI can read and process classified content the way data governance (classification and access control) does.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!