Microsoft Copilot security directory

Windows 365

Published by Microsoft

Medium risk

Windows 365 is a cloud-based service that automatically creates a new type of Windows virtual machine (Cloud PCs) for your end users. Each Cloud PC is assigned to an individual user as a dedicated Windows device. Windows 365 provides the productivity, security, and collaboration benefits of Microsoft 365.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 9 tools or capabilities.

  • List Cloud PCs
  • Get provisioning policies
  • Get a provisioning policy
  • Create a provisioning policy
  • Assign a provisioning policy to a group
  • Update a provisioning policy
  • Get a provisioning policy
  • Start a remote action
  • Send a Microsoft Graph HTTP request

The interactive security report will load automatically.