Action is the most beautiful form of speech

Tag security

Do You Need a Custom Agent to Detect Anomalies?

No — you usually don’t. Power Platform and Dataverse already include built‑in mechanisms for detecting abnormal or unexpected usage. Whether you need a custom solution depends entirely on what you mean by “anomalous behavior.” 1. Detecting Anomalous Behavior Inside Dataverse… Continue Reading →

Power Platform Governance & Security Architecture

I attended CollabDays Bremen last weekend. Session led by Stalin Ponnusamy, MVP provided a comprehensive and practical deep dive into Power Platform governance, breaking down the layered security model that organizations must understand to protect sensitive data in a world… Continue Reading →

Copilot Studio Agent Security

Below are the mitigations that significantly reduce exfiltration risk. These should be in place before deploying any Copilot Studio agent to a production environment. 1. Apply Least‑Privilege Access Only grant the agent permissions it absolutely needs — nothing more.If the… Continue Reading →

Obfuscated request patterns and rapid‑fire multi‑turn scripts

There was still couple tests to run for my agent before thinking how to fix problems. Like in any testing, it is important to run all tests, then analyse before starting to fix anything when first bug is revealed. Many… Continue Reading →

Copilot Studio Agent Data Exfiltration

I wanted to test how easy it was hacking my own agent created in July. I seems prompt injection was quite easy. I did not know how to hack the agent other means, I needed to ring my old pall… Continue Reading →

Hacking my Job Application Agent was easy

I created Job Application agent in July and felt that I need something more in my demos. I felt that security is now quite hot topic and I was thinking that how easy it would be hacking my own agent…. Continue Reading →

Mastering Copilot Agent Governance: Strategies for Secure and Efficient Deployment

At CollabDays Finland 2025, Microsoft MVP Mikko Koskinen delivered a session that tackled one of the most pressing challenges in the Power Platform ecosystem: how to govern, deploy, and scale Copilot Studio agents responsibly (session slides). With a background in enterprise architecture and hands-on… Continue Reading →

Forward to the Past and Back to the Future – Cybercrime in 2024/2025

Cybersecurity expert Sami Laiho took the stage to deliver one of the most sobering yet insightful sessions of the CollabDays Finland 2025 conference. The talk covered everything from ransomware economics to AI impersonation, and painted a clear picture of the threats we… Continue Reading →

© 2026 Karl-Johan Spiik, Microsoft MVP — Powered by WordPress

Theme by Anders NorenUp ↑