Follow the latest coverage, related explainers and connected technology stories.
A test using a low-privilege account revealed that an assistant built on Azure OpenAI and SharePoint was retrieving content the user could not access directly, despite passing accuracy evaluations and unit tests. The analysis shows that checking the user’s permissions at retrieval time—not service identity management alone—is the dividing line for preventing this type of leak.