How Microsoft Copilot Studio Creator Permissions Expand the Blast Radius of Prompt Injection Attacks

Published
Written by:
Vishwa Pandagle
Vishwa Pandagle
Cybersecurity Staff Editor

Question: What permissions are organizations giving Microsoft Copilot Studio AI agents today in terms of read access, write access, workflow execution rights, and delegated identity permissions, and what is the potential blast radius if those privileges are abused? Also, what logging, segmentation, or approval workflows are currently missing in most deployments?  


Simon Maxwell-Stewart, Staff Cyber Security Researcher at BeyondTrust

Most organizations are handing these agents a broader set of permissions than they realize, because the access is assembled quietly through the agent's tools, knowledge, and identity rather than granted in one obvious step.

On the read side, agents are pointed at business knowledge sources and given file analysis and search over that content. On the write and execution side, the majority are enabled for generative actions and wired to connectors and cloud flows, which lets them call out to other systems and trigger automations. 

The piece that matters most is delegated identity: 

That delegation is where the blast radius comes from. The connectors in play reach across the everyday Microsoft estate:

Because the agent runs on maker credentials, its effective reach is the maker's reach, which is often far higher than the people consuming the agent. 

Once an agent is published to a channel such as Teams, a lower privileged user can reach a higher privileged agent, which is the lateral movement path.

Indirect prompt injection through 

The controls that would contain this are usually the ones missing, and they are missing for a simple reason: they are all opt-in. 

Connector segmentation through Data Loss Prevention (DLP) policies is frequently absent, 

Environments tend to be left unmanaged, and their creation is rarely gated by approval, 

Auditing at the data layer is not consistently turned on, 

And maker credentials remain the default

None of these are exotic misconfigurations. They are the platform's out-of-the-box posture, which is exactly why the same gaps show up almost everywhere unless someone deliberately closes them. That deliberate 


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: