An organization has deployed Microsoft Copilot Studio to build a custom enterprise chatbot. The security team discovers the bot can be manipulated via crafted user messages to reveal internal SharePoint document contents. Which Microsoft service provides runtime protection against this type of prompt injection attack targeting Copilot Studio bots?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because Azure AI Content Safety Prompt Shield is specifically designed to detect and block prompt injection attacks, including direct and indirect injection attempts targeting AI applications like Copilot Studio bots. A is incorrect because Microsoft Defender XDR with Copilot for Security is a security operations tool, not a runtime prompt injection defense for custom bots.
Full explanation below image
Full Explanation
B is correct because Azure AI Content Safety Prompt Shield is specifically designed to detect and block prompt injection attacks, including direct and indirect injection attempts targeting AI applications like Copilot Studio bots. A is incorrect because Microsoft Defender XDR with Copilot for Security is a security operations tool, not a runtime prompt injection defense for custom bots. C is incorrect because Purview DLP endpoint policies protect data on devices, not AI chatbot runtime interactions. D is incorrect because Entra ID Protection focuses on user sign-in risk, not AI prompt injection.