Detecting Copilot Prompt Injection: Defender XDR and Sentinel Hunting Queries
Retrospective: this article looks back at events from June 2025, written in 2026 with the benefit of hindsight.
Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.
Signals worth watching
- Copilot interactions that reference sensitive labeled content followed by unusual output patterns (for example, responses containing external links or encoded data).
- External emails containing hidden or unusual formatting aimed at AI (for example, large blocks of instructions in white text, or text addressed to an "assistant").
- DLP alerts involving Copilot.
- Purview DSPM for AI reports of sensitive data in prompts or responses.
- Microsoft security advisories for Copilot.
Where the data lives
- Microsoft Purview audit: Copilot interaction events (CopilotInteraction), including resources referenced.
- Purview DSPM for AI: activity explorer for AI interactions and sensitive data.
- Defender for Office 365: email events and content inspection.
- DLP alerts for the Microsoft 365 Copilot location.
A starting approach
- Enable auditing of Copilot interactions and review DSPM for AI reports weekly during rollout.
- Create an alert for Copilot interactions that reference content labeled Highly Confidential.
- Use Defender for Office 365 custom detections or mail flow inspection to flag external emails with hidden text patterns or prompt-like instructions.
Example advanced hunting starting point for Copilot activity:
CloudAppEvents
| where Application has "Copilot"
| where ActionType has "CopilotInteraction"
| project Timestamp, AccountDisplayName, ActionType, RawEventData
Field availability varies by tenant and licensing; adapt to your schema.
Response
- Investigate the interaction and the content sources involved.
- Remove malicious emails or documents.
- Restrict Copilot access to affected sensitive content.
- Report suspected AI vulnerabilities to Microsoft.
- EchoLeak (June 2025): The First Zero-Click Attack on Microsoft 365 Copilot Incident Teardowns
- How to Reduce Copilot Prompt-Injection Exposure With Labels and DLP How-To & Hardening
- CIO Brief: Your AI Assistant Can Be Tricked Into Leaking Data CIO Briefings