{"id":15012,"date":"2024-05-30T09:00:00","date_gmt":"2024-05-30T16:00:00","guid":{"rendered":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/?p=15012"},"modified":"2026-03-12T15:19:33","modified_gmt":"2026-03-12T22:19:33","slug":"empowering-our-employees-with-generative-ai-while-keeping-the-company-secure","status":"publish","type":"post","link":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/","title":{"rendered":"Empowering our employees with generative AI while keeping the company secure"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Generative AI (GenAI) is rapidly changing the way businesses operate, and everyone wants to be in on the action. Whether it\u2019s to automate tasks or enhance efficiency, the allure of what GenAI can do is strong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, for companies considering the adoption of GenAI, there are a multitude of challenges and risks that must be navigated. These range from data exposure or exfiltration where your company\u2019s sensitive data can be accessed by unintended audiences to direct attacks on the models and data sources that underpin them. Not acting and waiting until the world of GenAI settles down poses its own risk. Employees eager to try out the latest and greatest will start using GenAI tools and products that aren\u2019t vetted for use in your enterprise\u2019s environment. It\u2019s safe to say that we\u2019re not just in the era of Shadow IT but Shadow AI, too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Add to that the fact that threat actors have begun to use these tools in their activities, and you get a real sense that navigating the cyberthreat landscape of today and tomorrow will be increasingly difficult\u2014and potentially headache-inducing!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here at Microsoft, our Digital Security &amp; Resilience (DSR) organization\u2019s Securing Generative AI program has focused on solving this problem since day one: How do we enable our employees to take advantage of the next generation of tools and technologies that enable them to be productive, while maintaining safety and security?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Building a framework for using GenAI securely<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">At any given moment, there are dozens of teams working on GenAI projects across Microsoft and dozens of new AI tools that employees are eager and excited to use to boost their productivity or use to be more creative.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When establishing our Securing AI program, we wanted to use as many of our existing systems and structures for the development, implementation, and release of software within Microsoft as possible. Rather than start from scratch, we looked at processes and workstreams that were already established and familiar for our employees and worked to integrate AI rules and guidance into those processes, such as the <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/securityengineering\/sdl\/practices\" target=\"_blank\" rel=\"noreferrer noopener\">Security Development Lifecycle (SDL)<\/a>, and the <a href=\"https:\/\/blogs.microsoft.com\/wp-content\/uploads\/prod\/sites\/5\/2022\/06\/Microsoft-RAI-Impact-Assessment-Template.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Responsible AI Impact Assessment<\/a> template.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Successfully managing the secure roll-out of a technology of this scale and importance takes the collaboration and cooperation of hundreds of people across the company, with representatives from diverse disciplines ranging from engineers and researchers working on the cutting edge of AI technology, to compliance and legal specialists, through to privacy advocates.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_SME.jpg\" alt=\"Portraits of Roy, Peterson, Enjeti, and Sharma are included together in a photo collage.\" style=\"width:750px\"\/><figcaption class=\"wp-element-caption\"><em>Justin Roy, Lee Peterson, Prathiba Enjeti, and Vivek Vinod Sharma are part of a team at Microsoft working to keep the company secure while allowing our employees to get the most out of GenAI.<\/em><\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">We work extensively with our partners in Microsoft Security; Aether (AI Ethics and Effects in Engineering and Research), the advisory body for Microsoft leadership on AI ethics and effects; and the extended community of Responsible AI. We also work with security champions who are embedded in teams and divisions across the enterprise. Together, this extended community helps develop, test, and validate the guidance and rules that AI experiences must adhere to for our employees to safely use them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most popular frameworks for successful change management is the simple three-legged stool. It\u2019s a simple metaphor, emphasizing the need for even efforts across the domains of technology, processes, and people. We\u2019ve focused our efforts to secure GenAI on strengthening and reinforcing the data governance for our technologies, integrating AI security into existing systems and processes, and addressing the human factor by fostering collaboration and community with our employees. The recent announcement of the <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/trust-center\/security\/secure-future-initiative\" target=\"_blank\" rel=\"noreferrer noopener\">Secure Future Initiative<\/a>, with its six security pillars, emphasizes security as a top priority across the company.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Incorporating AI-focused security into existing development and release practices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Security Development Lifecycle has been central to our development and release cycle at Microsoft for more than a decade, ensuring that what we develop is secure by design, by default, and secure in deployment. We focused on strengthening the SDL to handle the security risks posed by the technology underlying GenAI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve worked to enhance embedded security requirements for AI, particularly in monitoring and threat detection. Mandating audit logging at the platform level for all systems provides visibility into which resources are accessed, which models are used, and the type and sensitivity of the data accessed during interactions with our various Microsoft 365 Copilot offerings. This is crucial for all AI systems, including large language models (LLMs), small language models (SLMs), and multimodal models (MMMs) that focus on partial or total task completion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Preventative measures are an equally important part of our journey to securing GenAI, and there\u2019s no shortage of work that\u2019s been done on this front. Our <a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/engineering\/threat-modeling-aiml\" target=\"_blank\" rel=\"noreferrer noopener\">threat modeling standards<\/a> and <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/ai-services\/openai\/concepts\/red-teaming?source=recommendations\" target=\"_blank\" rel=\"noreferrer noopener\">red teaming<\/a> for GenAI systems have been revamped to help engineers and developers consider threats and vulnerabilities tied to AI. All systems involving GenAI must go through this process before being deployed to our data tenant for our employees to use. Our standards are under constant review and are updated based on the discoveries from our researchers and the <a href=\"https:\/\/cm-edgetun.pages.dev\/en-US\/msrc\/aibugbar\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Security Response Center<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-302c57e2 wp-block-group-is-layout-constrained\" style=\"border-radius:20px;padding-top:var(--wp--preset--spacing--spacing-24);padding-right:var(--wp--preset--spacing--spacing-24);padding-bottom:var(--wp--preset--spacing--spacing-24);padding-left:var(--wp--preset--spacing--spacing-24)\">\n<div class=\"wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-6c531013 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642-icon-150x150.png\" alt=\"\" style=\"width:64px\"\/><\/figure>\n\n\n\n<p class=\"has-body-lg-font-size wp-block-paragraph\"><strong>Sharing our acceptance criteria for AI systems<\/strong><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">As GenAI and the types of risks and threats to models and systems are ever evolving, so too is our acceptance criteria for deploying AI to the enterprise. Here are some of the key points we take into consideration for our acceptance criteria:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Representatives from diverse disciplines<\/strong>: Our journey begins when a diverse team of experts. engineers, compliance teams, security SMEs, privacy advocates, and legal minds come together. Their collective wisdom ensures a holistic perspective.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Evaluate against enterprise standards:<\/strong> Every GenAI feature is subjected to rigorous scrutiny against our enterprise standards. This isn\u2019t a rubber-stamp exercise, it\u2019s a deep dive into ethical considerations; potential security, privacy, and AI risks; and alignment with <a href=\"https:\/\/responsibleaitoolbox.ai\/\" target=\"_blank\" rel=\"noreferrer noopener\">our Responsible AI standard<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Risk assessment and management:<\/strong> The risk workflow starts in our system to amplify risk awareness and management across leadership teams. It\u2019s more than a formality, it\u2019s a structured process that keeps us accountable. Risks evolve, and so do our mitigation strategies, which is why we revisit the risk assessment of a feature every three to six months. Our assessments are a living guide that adapts to the landscape.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Phased deployment to companywide impact: <\/strong>We used a phased deployment to allow us to monitor, learn, and fine-tune.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Risk contingency planning<\/strong>: This isn\u2019t about avoiding risks altogether; it\u2019s about managing them. By addressing concerns upfront, we ensure that GenAI deployment is safe, secure, and aligned with our values.<\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">By integrating AI into these existing processes and systems, we help ensure that our people are thinking about the potential risks and liabilities involved in GenAI throughout the development and release cycle\u2014not only after a security event has occurred.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Improving data governance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">While keeping Gen-AI models and AI systems safe from threats and harms is a top priority, this alone is insufficient for us to consider GenAI as secure and safe. We also see data governance as essential to prevent improper access, improper use, and to reduce the chance of data exfiltration\u2014accidental or otherwise.<\/p>\n\n\n\n<h3 class=\"wp-block-heading has-text-align-center\">GenAI data governance<\/h3>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"489\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/02\/10642_graphic-1024x489.jpg\" alt=\"Graphic showing the elements of GenAI security governance, including discovering risk, protecting apps, and governing usage.\" class=\"wp-image-18556\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/02\/10642_graphic-1024x489.jpg 1024w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/02\/10642_graphic-300x143.jpg 300w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/02\/10642_graphic-768x367.jpg 768w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/02\/10642_graphic-1536x734.jpg 1536w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2025\/02\/10642_graphic-2048x979.jpg 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Discovery, protection, and governance are key elements to protecting the company while enabling our employees to take advantage of GenAI.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">At the heart of our data governance strategy is a multi-part expansion of our labeling and classification efforts, which applies at both the model level and the user level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We set default labels across our platforms and the containers that store them using <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/information-protection\" target=\"_blank\" rel=\"noreferrer noopener\">Purview Information Protection<\/a> to ensure consistent and accurate tagging of sensitive data by default. We also employ auto-labeling policies where appropriate for confidential or highly confidential documents based on the information they contain. Data hygiene is an essential part of this framework; removing outdated records held in containers such as SharePoint reduces the risk of hallucinations or surfacing incorrect information, and it\u2019s something we reinforce through periodic attestation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To prevent data exfiltration, we rely on our <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/dlp-learn-about-dlp\" target=\"_blank\" rel=\"noreferrer noopener\">Purview Data Loss Prevention (DLP)<\/a> policies to identify sensitive information types and automatically apply the appropriate policies at the controls at the application or service level (e.g. Microsoft 365), and <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-cloud-apps\/what-is-defender-for-cloud-apps\" target=\"_blank\" rel=\"noreferrer noopener\">Defender for Cloud Apps (DCA)<\/a> to detect the use of risky websites and applications and (if necessary) block access to them. By combining these methods, we\u2019re able to reduce the risk of sensitive data leaving our corporate perimeter\u2014accidentally or otherwise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Encouraging deep collaboration and sharing of best practices<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So far, we\u2019ve covered the management of GenAI technologies and how we ensure that these tools are safe and secure to use. Now it\u2019s time to turn our attention to our people, the employees who work with and build with these GenAI systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We believe that anyone should be able to use GenAI tools confidently, knowing that they are safe and secure. But doing so requires essential knowledge, which might not be entirely self-evident. We\u2019ve taken a three-pronged approach to solving this need with training, purpose-made resource materials, and opportunities for our people to develop their skills.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All employees and contract staff working at Microsoft must take our three-part mandatory, companywide security training released throughout the year. The safe use of GenAI is comprehensively covered, including guidance on what AI tools to use and when to use them. Additionally, we\u2019ve added extensive guidance and documentation to our internal digital security portal, ranging from what to be mindful of when working with LLMs to which tools are best suited to various tasks and projects.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With so many of our employees wanting to learn how to use GenAI tools, we\u2019ve worked with teams across the company to create resources and venues where our employees can roll up their sleeves and work with AI hands-on in a way that\u2019s safe and secure. Hackathons are a big deal at Microsoft and we\u2019ve partnered with several events, including the main flagship event, which draws in more than 50,000 attendees. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Skill-Up AI presentation series hosted by our partners at the <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/garage\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Garage<\/a> allows curious employees to learn the safe and secure way to use the latest GenAI technologies not only in their everyday work, but also in their creative endeavors. By integrating guidance into the learning journey, we help enable safe use of GenAI without stifling creativity.<\/p>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"124\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways.png\" alt=\"Key Takeaways\" class=\"wp-image-7448\" style=\"width:300px\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways.png 500w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways-300x74.png 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here are our suggestions on how to empower your employees with GenAI while also keeping your company secure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Understand the challenges and risks associated with adopting GenAI technology at your company.<\/strong> Good places to start are assessing the potential for data exposure, direct attacks on models and data sources, and the risks associated with Shadow AI.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Develop resources and guidance for your employees to educate them on the risks of using AI.<\/strong> Foster collaboration and a strong community in support of secure use of GenAI.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>If applicable, incorporate AI-focused security into existing development and release practices.<\/strong> Check out the <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/securityengineering\/sdl\/practices\" target=\"_blank\" rel=\"noreferrer noopener\">10 key practices of the Security Development Lifecycle (SDL)<\/a> and the <a href=\"https:\/\/blogs.microsoft.com\/wp-content\/uploads\/prod\/sites\/5\/2022\/06\/Microsoft-RAI-Impact-Assessment-Template.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Responsible AI Impact Assessment template<\/a> for inspiration.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Work to bolster your data governance policies.<\/strong> We strongly recommend starting with labeling and classification efforts, employing auto-labeling policies, and improving data hygiene. Consider tools such as <a href=\"https:\/\/learn.microsoft.com\/en-us\/purview\/dlp-learn-about-dlp\" target=\"_blank\" rel=\"noreferrer noopener\">Purview Data Loss Prevention (DLP<\/a>) and <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-cloud-apps\/what-is-defender-for-cloud-apps\" target=\"_blank\" rel=\"noreferrer noopener\">Defender for Cloud Apps (DCA)<\/a> to prevent data exfiltration and limit improper data access.<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-medium is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"68\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-300x68.png\" alt=\"Try it out\" class=\"wp-image-11919\" style=\"width:360px\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-300x68.png 300w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-1024x234.png 1024w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-768x175.png 768w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out.png 1319w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-were-tackling-microsoft-365-copilot-governance-internally-at-microsoft\/?OCID=InsideTrack_Product_10642\">Learn more about our overall approach to Microsoft 365 Copilot governance internally here at Microsoft.<\/a><\/p>\n<\/div>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"135\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links.png\" alt=\"Related links\" class=\"wp-image-7482\" style=\"width:300px\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links.png 500w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links-300x81.png 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2024\/05\/01\/responsible-ai-transparency-report-2024\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn how we\u2019re providing further transparency on our responsible AI efforts at Microsoft.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/security\/blog\/2024\/02\/14\/staying-ahead-of-threat-actors-in-the-age-of-ai\/\" target=\"_blank\" rel=\"noreferrer noopener\">See how we\u2019re staying ahead of threat actors in the age of AI.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/implementing-a-zero-trust-security-model-at-microsoft\/\">Learn more about implementing a Zero Trust security model at Microsoft.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/start-reducing-your-organizations-shadow-it-risk-in-3-steps\/\">Start reducing your organization\u2019s Shadow IT risk in three steps.<\/a><\/li>\n<\/ul>\n<\/div>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2023\/05\/Customer-Survey-580x85-1.png\" alt=\"We'd like to hear from you!\" style=\"width:580px\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"mailto:msitstaff@microsoft.com\">Want more information? Email us and include a link to this story and we\u2019ll get back to you.<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Generative AI (GenAI) is rapidly changing the way businesses operate, and everyone wants to be in on the action. Whether it\u2019s to automate tasks or enhance efficiency, the allure of what GenAI can do is strong. However, for companies considering the adoption of GenAI, there are a multitude of challenges and risks that must be [&hellip;]<\/p>\n","protected":false},"author":175,"featured_media":15013,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[199,827,848,419],"coauthors":[774,793],"class_list":["post-15012","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-ai","tag-microsoft-365-copilot","tag-security-and-risk-management","tag-zero-trust","program-ms-digital-stories","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Empowering our employees with generative AI while keeping the company secure - Inside Track Blog<\/title>\n<meta name=\"description\" content=\"Learn how we\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Empowering our employees with generative AI while keeping the company secure - Inside Track Blog\" \/>\n<meta property=\"og:description\" content=\"Learn how we\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track Blog\" \/>\n<meta property=\"article:published_time\" content=\"2024-05-30T16:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-12T22:19:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_wordpress_hero.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1293\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Justin Couture, Prathiba Enjeti\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Justin Couture, Prathiba Enjeti\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/\"},\"author\":{\"name\":\"Justin Couture\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/704b4d7a329da8d9906373d0e80386c9\"},\"headline\":\"Empowering our employees with generative AI while keeping the company secure\",\"datePublished\":\"2024-05-30T16:00:00+00:00\",\"dateModified\":\"2026-03-12T22:19:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/\"},\"wordCount\":1988,\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2024\\\/05\\\/10642_wordpress_hero.jpg\",\"keywords\":[\"AI\",\"Microsoft 365 Copilot\",\"Security and risk management\",\"Zero Trust\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/\",\"name\":\"Empowering our employees with generative AI while keeping the company secure - Inside Track Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2024\\\/05\\\/10642_wordpress_hero.jpg\",\"datePublished\":\"2024-05-30T16:00:00+00:00\",\"dateModified\":\"2026-03-12T22:19:33+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/704b4d7a329da8d9906373d0e80386c9\"},\"description\":\"Learn how we\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2024\\\/05\\\/10642_wordpress_hero.jpg\",\"contentUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2024\\\/05\\\/10642_wordpress_hero.jpg\",\"width\":2300,\"height\":1293,\"caption\":\"We\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Empowering our employees with generative AI while keeping the company secure\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track Blog\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/704b4d7a329da8d9906373d0e80386c9\",\"name\":\"Justin Couture\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d307839d4f6445d9528bbf6a0c59c1a9caed5e3d5d759b85fb3f6b9af45ca815?s=96&d=mm&r=ga41c9d43312f2b8dc833449214ede474\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d307839d4f6445d9528bbf6a0c59c1a9caed5e3d5d759b85fb3f6b9af45ca815?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d307839d4f6445d9528bbf6a0c59c1a9caed5e3d5d759b85fb3f6b9af45ca815?s=96&d=mm&r=g\",\"caption\":\"Justin Couture\"},\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/author\\\/jcouture\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Empowering our employees with generative AI while keeping the company secure - Inside Track Blog","description":"Learn how we\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/","og_locale":"en_US","og_type":"article","og_title":"Empowering our employees with generative AI while keeping the company secure - Inside Track Blog","og_description":"Learn how we\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure.","og_url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/","og_site_name":"Inside Track Blog","article_published_time":"2024-05-30T16:00:00+00:00","article_modified_time":"2026-03-12T22:19:33+00:00","og_image":[{"width":2300,"height":1293,"url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_wordpress_hero.jpg","type":"image\/jpeg"}],"author":"Justin Couture, Prathiba Enjeti","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Justin Couture, Prathiba Enjeti","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/#article","isPartOf":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/"},"author":{"name":"Justin Couture","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#\/schema\/person\/704b4d7a329da8d9906373d0e80386c9"},"headline":"Empowering our employees with generative AI while keeping the company secure","datePublished":"2024-05-30T16:00:00+00:00","dateModified":"2026-03-12T22:19:33+00:00","mainEntityOfPage":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/"},"wordCount":1988,"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_wordpress_hero.jpg","keywords":["AI","Microsoft 365 Copilot","Security and risk management","Zero Trust"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/","url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/","name":"Empowering our employees with generative AI while keeping the company secure - Inside Track Blog","isPartOf":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/#primaryimage"},"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_wordpress_hero.jpg","datePublished":"2024-05-30T16:00:00+00:00","dateModified":"2026-03-12T22:19:33+00:00","author":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#\/schema\/person\/704b4d7a329da8d9906373d0e80386c9"},"description":"Learn how we\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure.","breadcrumb":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/#primaryimage","url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_wordpress_hero.jpg","contentUrl":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_wordpress_hero.jpg","width":2300,"height":1293,"caption":"We\u2019re enabling our employees to get the most out of generative AI while also keeping the company secure."},{"@type":"BreadcrumbList","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/empowering-our-employees-with-generative-ai-while-keeping-the-company-secure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"Empowering our employees with generative AI while keeping the company secure"}]},{"@type":"WebSite","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#website","url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/","name":"Inside Track Blog","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#\/schema\/person\/704b4d7a329da8d9906373d0e80386c9","name":"Justin Couture","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d307839d4f6445d9528bbf6a0c59c1a9caed5e3d5d759b85fb3f6b9af45ca815?s=96&d=mm&r=ga41c9d43312f2b8dc833449214ede474","url":"https:\/\/secure.gravatar.com\/avatar\/d307839d4f6445d9528bbf6a0c59c1a9caed5e3d5d759b85fb3f6b9af45ca815?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d307839d4f6445d9528bbf6a0c59c1a9caed5e3d5d759b85fb3f6b9af45ca815?s=96&d=mm&r=g","caption":"Justin Couture"},"url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/author\/jcouture\/"}]}},"jetpack_featured_media_url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2024\/05\/10642_wordpress_hero.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-3U8","_links":{"self":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/15012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/175"}],"replies":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=15012"}],"version-history":[{"count":35,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/15012\/revisions"}],"predecessor-version":[{"id":22731,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/15012\/revisions\/22731"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/15013"}],"wp:attachment":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=15012"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=15012"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=15012"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=15012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}