問題文
A company enables Microsoft 365 Copilot. Which statement correctly describes how existing Microsoft 365 protections apply to what Copilot can use?
選択肢
- Copilot can only use the files that the asking user has opened at least once before, because the recent activity signal is what builds each user's working set, so permissions never come into play and no permission review is needed.
- Copilot works through a service identity that holds tenant-wide read access so that it can ground on everything the organization owns, which means the existing permissions have to be re-expressed as a separate set of Copilot settings before the rollout.
- Copilot retrieves content under the identity of the user who asked, so a user only sees material they already have permission to open, which is why oversharing is the biggest obstacle to a rollout and has to be corrected before Copilot is enabled.
- Copilot ignores permissions while it builds its index, because indexing has to see everything to be complete, and then applies the permissions at the moment it renders the citations so that the links a user cannot open are hidden from the answer.