A security engineer needs to monitor all interactions between employees and Microsoft 365 Copilot for signs of policy violations, including employees attempting to get Copilot to produce content that violates the acceptable use policy. Which Microsoft service should be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because Microsoft Purview Communication Compliance supports policies scoped to Microsoft Copilot for Microsoft 365 interactions, enabling reviewers to inspect user prompts and Copilot responses for policy violations including inappropriate content requests, regulatory compliance issues, and acceptable use policy breaches. A is incorrect because Insider Risk Management identifies risk indicators and patterns but does not provide content review of individual Copilot prompts and responses for policy violations.
Full explanation below image
Full Explanation
C is correct because Microsoft Purview Communication Compliance supports policies scoped to Microsoft Copilot for Microsoft 365 interactions, enabling reviewers to inspect user prompts and Copilot responses for policy violations including inappropriate content requests, regulatory compliance issues, and acceptable use policy breaches. A is incorrect because Insider Risk Management identifies risk indicators and patterns but does not provide content review of individual Copilot prompts and responses for policy violations. B is incorrect because Defender for Cloud Apps does not have a session policy capability that inspects Copilot for Microsoft 365 prompt content. D is incorrect because Sentinel analytics rules can alert on Copilot audit events but do not provide the content review workflow needed for policy violation investigation.