Microsoft Copilot security directory

Cornerstone Learning vILT

Published by Cornerstone On Demand

High risk

The custom connector streamlines vILT integration by leveraging customers' Azure AD tenant environments, ensuring data integrity and simplifying authentication. No external Graph API permissions are needed, enhancing security. This versatile connector facilitates low-code solutions for diverse scenarios. By incorporating this custom connector, the full potential of Microsoft Teams API in the case of MS Teams integration is unlocked seamlessly within customers' infrastructure.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 7 tools or capabilities.

  • Respond to Add Instructor Event
  • Respond to Create Session Event
  • Respond to Delete Session Event
  • Respond to Get Attendance Event
  • Respond to Launch Session Event
  • Respond to Update Instructor Event
  • Respond to Update Session Event

The interactive security report will load automatically.