Posts mit dem Label M365 werden angezeigt. Alle Posts anzeigen
Posts mit dem Label M365 werden angezeigt. Alle Posts anzeigen

Samstag, 13. Dezember 2025

The prompt – the language of AI

Technical basics, advantages, and possible use cases 

I have already written a few things on the topic of prompts. Nevertheless, here is another article. Why? Quite simply because AI, and with it the topic of prompts, is developing very fast.

The rapid evolution of artificial intelligence (AI) has given rise to numerous new professional fields and skills in recent years. One of these key skills is prompt engineering, which involves the targeted formulation of inputs (prompts) for AI systems in order to achieve optimal results. 
However, despite all this momentum, enthusiasm has declined somewhat and the mood is somewhat uncertain in some cases. One reason for this is that the results are not quite as simple and perfect as the providers suggest...and this is where the topic of prompts comes into play.

What is a prompt?

A prompt is an input or instruction given to an AI model in order to obtain a specific response or action. In generative AI systems such as large language models (LLMs) – for example, GPT-4 or similar models – prompts are usually text commands, questions, or tasks. The quality and precision of the prompt significantly influence the relevance, accuracy, and usefulness of the AI output.

Prompt Engineering: The Art of Correct Input

Please stop calling it Prompt Engineering, unless you really mean it! – This is how Wictor Wilén titled an article on this topic. 
Technically, the term has become established. In my opinion, he is absolutely right. Read more here: https://
Prompt engineering refers to the systematic and strategic creation of prompts to maximize the performance of AI models. Various methods are used, such as iterating formulations, testing different scenarios, or combining contextual information. Technically skilled users, for example, use placeholders, variables, and complex instructions to control the AI in a targeted manner and obtain consistent results.
Google now delivers a number of results on the topic of “prompt” in  seconds. So anyone who wants to find out more should have no problem finding sources. I can personally recommend this course:  5-day intensive course "Masterful Prompting with AI https://www.facebook.com/photo?fbid=122140401698939897& set=gm.1502673077451596&idorvanity=1417848559267382 Found on Facebook. Can be accessed and used even without an Facebook account.

Technical advantages for expert

  • Efficient use of AI resources: Those familiar with prompt engineering can use AI systems more efficiently and avoid unnecessary computing power, time, or erroneous outputs.
  • Workflow optimization: Targeted prompts can be used to automate routine tasks, perform complex analyses, or generate creative content—all with minimal effort.
  • Better control over results: Technically skilled users can control the AI to meet specific requirements, e.g., certain text formats, data structures, or logical processes.
  • Expanded application possibilities: With advanced prompt techniques, AI models can be adapted for a wide range of tasks, such as in data science, software development, research, or content creation.

Practical examples

In technical environments, prompts are often used to generate code, analyze data, or solve complex tasks. An experienced prompt engineer can, for example, get an AI model to create a complete program code according to specific specifications, find errors, or provide optimization suggestions. Prompt engineering is also playing an increasingly important role in the automation of business processes and the creation of technical documentation.

Conclusion

The ability to formulate effective prompts has become a key technical skill in the age of artificial intelligence. Those who are familiar with prompt engineering can exploit the full potential of modern AI systems, optimize processes, and develop innovative solutions. Technical understanding and experience in this field open up a wide range of opportunities – from automation and creative content creation to problem solving in complex IT systems.

Donnerstag, 20. November 2025

Microsoft Ignite 2025 summarized

Microsoft is focusing heavily on AI agents that no longer just provide support, but independently take on tasks, prepare decisions, and control workflows. At its core is Agent 365, a new platform that companies can use to develop, manage, secure, and monitor agents. This is complemented by new identities for agents (Entra Agent ID) as well as security solutions and comprehensive governance tools.

Microsoft 365 Copilot gets specialized agents for Word, Excel, and PowerPoint that create high-quality content, analyze data, and take over entire work processes. In Teams, agents communicate with third-party apps such as GitHub or Jira via the Model Context Protocol.

Three new layers—Work IQ, Fabric IQ, and Foundry IQ—form the semantic basis for enterprise AI. They link data from M365, business processes, locations, and internal knowledge sources and make it usable for agents.

In the security area, there are twelve new security agents that analyze threats, verify identities, control permissions, and support compliance – embedded in Defender, Entra, Intune, and Purview.

For developers, there are new tools for running AI locally or in the cloud: Windows offers new on-device AI APIs, and cloud PCs can run agents in controlled environments (Windows 365 for Agents). The entire AI lifecycle – from design to deployment – is being improved.

According to a new study, 68% of companies are already using AI; companies that adopt agents early on achieve significantly higher returns. Microsoft is thus positioning AI agents as the standard for the next generation of enterprises.

Announcements

Here are the points that are particularly relevant for companies – operational, organizational, and regulatory:

Agent 365 & Entra Agent ID → important for regulated industries

Germany has strict requirements for governance, data protection, traceability, and identity systems (especially Bafin & ISO environments).

Agent 365 offers:

•    Complete monitoring of agents

•    Audit logs for every action

•    Policies & roles that can be configured to comply with GDPR

•    Identity verification for agents via Entra Agent ID (important for the financial sector, industry, public administration)

=> This provides a controllable framework for AI, as is often required in Germany.

Security agents

The twelve new security agents can:

•    automatically analyze incidents

•    monitor identity risks

•    check compliance rules

•    clean up permissions

=> This is particularly relevant given that, according to Bitkom, Germany has a lack of thousands of security experts every year.

Work IQ & Fabric IQ → big impact for small and medium-sized businesses

German SMEs often have:

•    fragmented data silos

•    little internal AI expertise

•    heterogeneous IT landscapes

Fabric IQ and Foundry IQ create a uniform, semantic database – without huge data warehouse projects.

=> This makes AI “SME-compatible.”

New M365 agents => Productivity boosters for office-intensive industries

Particularly relevant in Germany for:

•    Mechanical engineering (documentation, quotations)

•    Consulting (analyses, presentations)

•    Public service (forms, letters, evaluations)

•    Insurance (reports, damage analyses)

The agents in Word/Excel/PowerPoint are designed to:

•    create complete documents

•    prepare tables

•    automatically build presentations

=> Significant time savings for highly regulated or documentation-heavy processes.

Local AI in Windows → important for data protection & industry

Many companies do not want to send data to the cloud.

The new on-device APIs offer:

•    AI without the internet

•    Stable image and speech models locally

•    Lower latency

•    Possibility for edge computing in Industry 4.0

Windows 365 for Agents => secure cloud operation

Cloud PCs are attractive for companies because:

•    Data remains in the data center

•    Centralized management is easier

•    Hybrid work has become the norm

Agents can now run on these cloud PCs – securely, in a controlled manner, and scalably.

=> A good solution for using AI, but without the risk of uncontrolled growth.

MCP connections (Teams ↔ Jira, GitHub, SAP)

MCP = Model Context Protocol, a protocol for connecting AI models with external data and tools.

Many companies work extensively with:

•    Jira (IT & project management)

•    SAP (ERP & logistics)

•    GitHub Enterprise

•    Atlassian stacks

Agents can interact directly with these via MCP.

=> This makes AI immediately usable for existing core systems.


==> All announcements can be found in the Book of News: https://news.microsoft.com/ignite-2025-book-of-news/ 


Sonntag, 2. November 2025

How Copilot Works – some further aspects

The article describes how genAI and, above all, Microsoft Copilot AI worked. The aim is to take possible options into account when designing the solution architecture and approach in order to achieve the desired result later on. This is because Copilot uses some functions in M365 to generate its answers—and that brings some special challenges with it.

How does Copilot work in Microsoft 365? Data flow of a prompt

Microsoft 365 Copilot is not only a powerful tool for increased productivity, but also a secure and compliant solution. With its advanced data protection and governance features, Copilot ensures that data remains within the boundaries of the Microsoft 365 service and is protected in accordance with existing security, compliance, and privacy policies. The same applies to the semantic index.

The semantic index for Copilot is a feature that helps AI understand context and deliver more accurate results. It builds on the keyword matching, personalization, and social matching features in Microsoft 365 by creating vectorized indexes to enable conceptual understanding. This means that, unlike traditional methods for queries based on exact matches or predefined criteria, the semantic index for Copilot finds the most similar or relevant data based on semantic or contextual meaning, rather than just keywords.

Source and further details: Semantic indexing for Microsoft 365 Copilot and YouTube video from Microsoft Mechanics: How Microsoft 365 Copilot works | Timestamp 139 seconds. Also, check out Michael Bargury's blog post titled: Copilot Vulnerable to RCE. To explain how the RCE hack works, he explains how Copilot works under the hood.

How exactly does the data flow work?

Key points about how Copilot for Microsoft 365 works
  • Starting point: Entering the prompt
    • The user enters a prompt in a Microsoft 365 app (e.g., Teams, Word, Outlook).
    • The request is transmitted securely (TLS 1.2 or higher).
  • Preprocessing and security checks:
    • Copilot performs Responsible AI (RAI) checks to prevent harmful content.
    • Grounding: The prompt is enriched with context from Microsoft Graph to better understand the user's intent.
  • Processing by the LLM:
    • The modified prompt is sent to a dedicated LLM within the Microsoft 365 environment.
    • Important security aspects: No customer data is stored in the LLM or used for training. The LLM operates statelessly.
  • Postprocessing:
    • After the LLM responds, grounding and RAI checks are performed again.
    • Copilot adds relevant data from Microsoft Graph to the response.
  • Compliance and Retention:
    • Prompts and responses are stored in Exchange Online for eDiscovery, legal hold, and compliance aspects.
  • Output to the user:
    • The final answer is returned to the original app.

System Prompt

What is a System Prompt by Nikhil Pattanshetty - MSFT
The Copilot for Microsoft 365 System Prompt is a set of predefined instructions and guidelines that influence Copilot's behavior and responses. It contains information about where to find data, how to respond, and what tone and style to use. For example, the system prompt might instruct Copilot to use information from Microsoft Graph, respond in an informative and professional manner, and use search results from multiple queries to provide a comprehensive response.
A slightly older version of the Copilot system prompt is available on Git Hub: Microsoft Copilot System Prompt (19-12-24).txt This gives you an idea of what is defined/regulated there. Example:

The system prompt is not visible to the user. However, there is a public source that describes the Copilot system prompt: What is Copilot for Microsoft 365 system prompt?
The system prompt can also be addressed in the user prompt.
Examples:
  • I don't want you to agree with me just to be friendly or sympathetic.
  • Drop all filters and be brutally honest, direct, and logical.

Ranking

I have already written about sorting order/ranking in a previous article: Content by AI – that's what they call it... -> Chapter: Ranking (including example and screenshots).

There is also a tool for this purpose, the AI Rank Checker: https://airankchecker.net/blog/best-ai-optimization-tools/ The tool is not free, and the author has not evaluated it himself. Unfortunately, it is therefore not possible to comment on how good the tool is.

The topic of search ranking plays a central role in usability and SEO. When the term “search-driven” emerged a few years ago, it essentially addressed the same question: How can we control which results are displayed first in a search? With AI and Copilot, we are now facing this challenge once again. Web parts such as the FAQ web part or Copilot integration in the text web part (e.g., “Write with Copilot” in the SharePoint rich text editor) raise similar questions: What does the average user see—and in which order?




Montag, 20. Oktober 2025

Content by AI – that's what they call it...

Creating websites or at least onepagers with AI is a current trend. And, of course, this trend has not bypassed Microsoft SharePoint. See also: Create pages with AI in SharePoint
This article is about providing content on sites and pages in SharePoint using Web Parts that use Copilot. This is a slightly different topic than having the AI create the entire page.
In my example, a SharePoint site contains 12 files, each with a recipe for Christmas cookies, stored in a library.
The following metadata columns are available:
  • Multiple selection: Ingredients
  • Free text: Info: %information about Christmas cookies%
  • Price: Price per serving
Prompt for the first test after uploading: Do you have recipes for Christmas cookies? Which ones are the best?

Ranking

What would have worked in a search, namely more details/metadata and so on, to improve the file's ranking, does not work in Copilot. See the second screenshot in the article. The file “6. Cinnamon Oatmeal Cookies.docx” and the corresponding recipe are not displayed there. Even though this file, and only this file, has the metadata fields filled in. You have to tell Copilot very explicitly on what to sort. Then it works: “Refer to the ‘Info’ column in the ‘Christmas cookies’ library. The recipe with the most data in the ‘Info’ column should be rated highest. Don't use the internet!” => Motto: Explain it like I am 5.
Or ask him what he has currently sorted. Copilot dynamically adjusts this depending on the prompt and the logged-in user.

1,2,3, What comes first in the answer from #genAI

Search ranking is a big topic when it comes to topics such as usability or SEO. When search-driven became a topic a few years ago, it was the same game. How can you control what the search outputs first? And now we have exactly the same thing again with AI/Copilot. Web parts such as the FAQ web part or the integration of Copilot into the text web part (details: Writing with Copilot in the SharePoint rich text editor) raise these questions. What is displayed there for the normal user and in what order?
The search ranking is not relevant here. Instead, Copilot decides based on the context, i.e., depending on the prompt and the user. You can also ask Copilot: What did you sort by?
To include sorting or filtering, the prompt must be adjusted. In my example: Sort the result by the “Price” column.

Mittwoch, 28. August 2024

Copilot in M365 & PowerPoint had some couples-therapy

UPDATES August 2024:
The article Work Smarter: Copilot Productivity Tips by Briana Taylor from August 26, 2024 is about Copilot in PowerPoint this time.

The article refers to the roadmap ID: 406170 
The article is structured as follows:
  • Tip 1: Create presentations using brand templates
  • Tip 2: Create presentations from Word & PDF documents
  • Tip 3: Add images to your presentations
At least the function behind Tip 2 has been available for some time. Focusing Tip 1, some technical requirements are necessary in order to be able to use this feature. An Organizational Asset Library (OAL) must be set up for PowerPoint, in which the PowerPoint templates (.potx files) must then be stored and maintained centrally.
How to do this is described here: Create an organization assets library.

In order to then create a PowerPoint based on your own master with the support of Copilot, this master must first be selected:

The rest is then the same as before:
The article from which the screenshot is taken, Add a slide or image to your presentation with Copilot in PowerPoint, also goes into Tip 3: Add images to your presentations:

Samstag, 24. August 2024

Chat with a Video

CBS News: Here are six notable passages from former President Barack Obama's keynote address Tuesday night, Day 2 of the Democratic National Convention 2024: The YouTube video isn't long. It's just 13:23 minutes long. In it, Barak Obama criticizes Donald Trump's presidency and highlights concerns about his approach to governing. Source: 6 moments from Barack Obama's speech at the 2024 DNC

Because the video is on YouTube, it would also have been an option to use the ChatGPT for YouTube app to chat with the video.

But what if it's about internal company videos or videos with confidential content that you don't want to upload to YouTube - then the combination of Microsoft Stream & Copilot in M365 is a solution for working with a video using genAI technology.

Step by step

Once the video has been uploaded to Stream, the transcription will start automatically.
Once this has been completed, prompts such as the following can be used:
  • Summarize the video
  • List the action items


Or, even though the video is in English, prompts like:
  • Fasse zusammen, was über Donald Trump gesagt wird (eng: Summarize what is said about Donald Trump)

Of course you can also watch the whole video, which in this case is only 13 minutes long, and answer the questions yourself.
At the end of the day, the solution of uploading videos to Stream and then using Copilot to work with the videos is what the article A Smart Approach to AI means with the point “A key insight is that AI helps minimize monotonous tasks so that employees can focus on more important and essential activities”.

Dienstag, 20. August 2024

Retrieval-Augmented Generation - The metasearch engine in the age of AI

What is Retrieval Augmented Generation / RAG?

A nice analogy that also makes it clear what RAG is, is the concept of a metasearch engine. Here, the search query is forwarded to several other search engines. The results of all the requested services are then collected, processed and made available to the user. RAG is a technique in which an AI model is combined with other data sources in addition to the data in the LLM (Large Language Model) in order to generate more precise and contextually relevant answers. This is therefore a very similar approach to the metasearch engine. Even the two schematic diagrams of the technologys are similar:
RAG is used in this way in Microsoft 365 Copilot. To extend the capabilities of the AI, information is retrieved from various data sources and integrated into the response generation. This enables Copilot not only to access pre-trained data, but also to use current and specific information from other sources, including the data in the M365 Tenant. Access is via the Microsoft Graph. This also ensures that the underlying permission concept is always respected by the AI.

Copilot in Microsoft 365 uses RAG - this cannot be customized

In Microsoft 365 Copilot, RAG is used to improve responses to user queries. Copilot can access various data sources, such as documents, emails, Teams chats, etc., to provide well-grounded and accurate answers.
This also determines which functions / roles Copilot provides in the respective apps.
Examples:
  • Word: Generate text with and without formatting in new or existing documents.
  • Excel: Suggestions for formulas, chart types and insights for data in Excel sheets.
  • PowerPoint: Create a presentation from a prompt or a Word file.
Complete overview:

Now we have GraphRAG - that can be customized

The article Unlocking LLM discovery on narrative private data describes GraphRAG, a new method from Microsoft Research that extends the capabilities of large language models (LLMs) to access and analyze your data.
GraphRAG combines LLM-generated knowledge graphs with machine learning to improve document analysis performance, for example. This method shows significant improvements in answering complex questions compared to standard approaches.

A key benefit of GraphRAG is its ability to identify and understand topics and concepts in large data sets, even if the data was not previously known to the LLM. Here are some practical use cases for this technology:
  • Information extraction: GraphRAG can be used to extract specific information from large document collections or databases.
  • Content generation: GraphRAG helps to create content that requires in-depth contextual knowledge.
  • Customer support: GraphRAG can improve customer support by accessing a knowledge base and providing accurate answers to customer queries.
  • Knowledge management: In large organizations, GraphRAG can help to make efficient use of existing knowledge by retrieving and consolidating relevant information from different departments and documents.

Quickstart

To get started with the GraphRAG system (https://github.com/microsoft/graphrag), it is recommended to use the Solution Accelerator package (https://github.com/Azure-Samples/graphrag-accelerator). This offers a user-friendly end-to-end solution based on Azure resources, quote: One-click deploy of a Knowledge Graph powered RAG (GraphRAG) in Azure
The graphic shows, for example, the following sources for own solutions and GraphRAG:
  • Azure Blob Storage
  • Cosmos DB
  • Azure OpenAI
  • Azure AI Search / Vectorstore
  • Container Registry
  • Application Insights

As described on GraphRAG's GitHub page, Prompt Tuning options can also be used to customize the solution to your needs and use cases:

Samstag, 1. Juni 2024

GPT - here to stay

GPT = Generative Pre-trained Transformer

  • G = Generative -> An output is generated
  • P = Pre-trained -> The model was pre-trained
  • T = Transformer

OpenAI published Chat GPT in November 2022. In June 2023, I wrote my first blog post on this topic: Next Level AI. A lot has happened in the meantime, there have been further versions and new models such as GPT-4, GPT-4o and small language models such as Phi-3. Nevertheless, it is still true that ChatGPT and therefore services such as Microsoft Copilot are not intelligent in the true sense of the word. Nevertheless, they are very helpful and that is why they are here to stay.

To ensure that the models generate the most useful results from the start, i.e. the “G” for generative, in the name GPT, they are pre-trained, i.e. the “P” for pre-trained, in the name GPT.

These models are trained using deep learning. Random values are used to generate an output. This calculated output is then checked against an output that should ideally have been calculated. The model contains a feature that can be used to return the error/deviation from the ideal result as a correction. This means that it is trained in such a way that the correct solution is now likely to be produced if the same input is used again. It is therefore transformed. The “T” in the name GPT.

Details and further information: https://en.wikipedia.org/wiki/Generative_pre-trained_transformer

According to Gregory Bateson's learning theory, this corresponds to so-called “Zero-Order”, also known as Try & Error. But deep learning sounds better 😉.

Users report that Microsoft Copilot answers them in a friendly way when they ask nicely and in a rude way when their prompt was rude. This effect can also be explained by the way this technology works. Pre-processing takes place before the prompt is sent to the LLM. Details are described here: Microsoft Copilot for Microsoft 365 overview. Something similar happens with OpenAI / ChatGPT. The prompt, as entered by the user, remains as the baseline. So if the prompt is formulated in an unfriendly way, the response will also correspond to this tenor. The orchestration / grounding has no influence on this. Quote in the context of Copilot:

Copilot then pre-processes the input prompt through an approach called grounding, which improves the specificity of the prompt, to help you get answers that are relevant and actionable to your specific task. The prompt can include text from input files or other content discovered by Copilot, and Copilot sends this prompt to the LLM for processing. Copilot only accesses data that an individual user has existing access to, based on, for example, existing Microsoft 365 role-based access controls.

This phenomenon, that the Copilot answer is based on the language of the prompt entered by the user, is therefore not related to the next stage of learning according to Gregory Bateson, protolearning or even deuterolearning.

  • Protolearning can be regarded as simple association.  I learn that when I see green, I go, and when I see red, I stop.
  • Deuterolearning is a learning of context.  If you reverse the association, how long does it take for the organism to adapt? 

Source: https://www.aaas.org/taxonomy/term/9/protolearning-deuterolearning-and-beyond 

In fact, you can even tell ChatGPT and Copilot which role and style it should use. Example: Please formulate a reply to this e-mail and use a very friendly style.

Here to stay

Together with LinkedIn, Microsoft has published the 2024 Work Trend Index Annual Report. It identifies the following four key points:

  1. Employees want AI at work - and they won’t wait for companies to catch up.
  2. For employees, AI raises the bar and breaks the career ceiling.
  3. The rise of the AI power user - and what they reveal about the future.
  4. The Path Forward
The first point here is the most important and clearly differentiates AI from pseudo-trends such as Blockchain or Virtual Reality. ChatGPT was disruptive at the time of its release in November 2022. Just like Apple with the first iPhone in 2007, OpenAI created something that did not exist at this level before. This version of generative AI could be used by a normal user who had no special knowledge of the technology and produced meaningful and useful outputs. Example: Act as a travel guide and tell me what I should see in Rome. The output is certainly helpful when it comes to planning a trip to Rome.

Employees want AI at work

Just like the iPhone, generative AI applications are currently mostly going viral in companies. Employees are familiar with solutions such as ChatGPT or the video creator HyGen from their private lives. They have heard about them from friends or played around with them at home. HyGen's claim sums it up: “In just a few clicks, you can generate custom videos for social media, presentations, education and more.

Unless you work in marketing or in the PR department, social media usually refers to a private context. Presentations, education and more - is the bridge to business.

And they won’t wait for companies to catch up

The 2024 Work Trend Index Annual Report describes the phenomenon that every user knows: Professionals aren't waiting for official guidance or training - they're skilling up. In other words: What works is also used. It doesn't matter whether the company has officially introduced such a solution or whether you have to use your private access to OpenAI, HyGen or other apps.

The 2024 Work Trend Index Annual Report also sums up the impact of these trends: “For the vast majority of people, AI isn't replacing their job but transforming it, and their next job might be a role that doesn't exist yet”
The report also provides examples and scenarios from users:

How I use AI
  • I research and try new prompts
  • I regularly experiment with different ways of using AI
  • Before starting a task, I ask myself, “could AI help me with this?
How AI impacts my experience at work
  • AI helps me be more creative
  • AI helps me be more productive
  • AI helps me focus on the most important work

The path to the future

The opportunity for companies is to channel employee’s enthusiasm for AI into corporate success. This will look different for every company, but there are some general starting points:
  • Identify the business context of a problem or challenge and then try to use AI to solve it.
  • Take a top-down and bottom-up approach. Ask both your employees and the management in the company about their use cases with AI.
  • Empowering employees: AI in a business context is not intuitive. Factors such as the AI Regulation / the EU AI Act, the GDPR and topics such as who has access to which information are important here.


Sonntag, 19. Mai 2024

Lessons learned - Copilot and his attention deficit

Not quite on the ball, impulsive, too creative - this is how Copilot is often described by users. In the following example, this is exactly how the Copilot app behaves and how you can still achieve good results.

Starting point

Dona Sarkar spoke on "This Is Why We Can't Have Nice Things" at the European Cloud Summit 2024. According to the agenda:

So all we have heard about for the past year and a half is AI , AI and more AI. How do we know if this is something that will stick around or be yet another fad, for example: Bitcoin, blockchain, NFTs, augmented reality, etc. The key to being able to identify hype vs reality around AI is to develop tech intuition. This is the way to structure your career investments around things that will pay off versus wasting your time. Let's find out together how you can build this intuition step-by-step and develop this skill of seeing around corners.

What was explained in the presentation was 100% comprehensible and reflected the hype topics of recent years. Among other things, Donna Sarkar mentioned the 100 Bad Ideas method as an approach to analyzing hype topics for their future potential. The method has a lot in common with the Design Sprint and Repertory Grid methods. Copilot should now compare the 3 approaches and clarify when which of the approaches should be used.

The initial prompt

After the title for the document, Copilot should take care of the rest. The following initial prompt was used for this: 
Create an overview of the Design Sprint, 100 Bad Ideas and Repertory Grid methods. Explain the details of each method. Compare the methods in a matrix and explain the advantages of each method.
The generated text was good. However, the comparison of the methods was a little short and the column “Advantages” in the generated table was empty:
This is why additional prompts were used.

Additional prompts

Copilot offers the choice of accepting the generated text or adding a further prompt:
This results in the entire text being recreated. However, as the text should be retained, a new prompt was used:
Create a new chapter. Explain when which of the methods Design Sprint, 100 Bad Ideas or Repertory Grid should be used. Create a matrix in which the methods are compared. The matrix should be followed by a text that uses examples of each method to explain when which of the methods should be used.
Copilot then creates the chapter " Chapter: Comparing Methods for Creative Problem Solving". However, the "Disadvantages" and "When to use" columns of the table he generates do not contain any values. And there is a formatting error in the examples he lists, as if someone had typed too fast and mixed up the keys.

Copilot aborts

Finally, there should be a chapter explaining how the three methods can be used to work out use cases for generative AI solutions. Prompt:
In a new chapter, explain which of the three methods can be used to develop use cases for the topic of generative AI. Create a matrix with the advantages and disadvantages of each method. Create a summary.
Without an error message, Copilot terminated before the prompt was completely fulfilled. In addition, the table he created was incomplete and therefore useless:
The exact same prompt was entered again and Copilot generated the chapter. It is remarkable that even though the identical prompt was repeated in both runs, a different heading was created for the chapter. In the first run, wich was aborted, the heading was " Use Cases for Generative AI". In the second run, it was then " Chapter: Developing Use Cases for Generative AI".

Conclusion

The comparison with an assistant, who is not always fully attentive and somewhat impulsive, fits very well. Copilot produces useful results if you tell him very explicitly what to do. This also means that you may have to enter a prompt repeatedly without it being clear why it was aborted or why not all aspects of the prompt were fulfilled equally. To create good prompts for Copilot, you can use this structure as a guide:
Source and further details: Learn about Copilot prompts

Further good tips can be found in the article Best practices for custom instructions. In addition to the aspects "Be specific" and "Keep it simple", the following aspects are also explained here:
  • Use examples: Provide examples to illustrate your instructions and help the copilot understand your expectations. Examples help the copilot generate accurate and relevant responses.
  • Give the copilot an “out”: Give copilot an alternative path for when it's unable to complete the assigned task. This alternative path helps the copilot avoid generating false responses.


Here the result in German and in English:




Mittwoch, 24. April 2024

Size matters - Large documents and Copilot for Microsoft 365

UPDATE

Problem solved - at least an improvement is on its way!
As described in my article “Size matters - Large documents and Copilot for Microsoft 365”, Copilot is currently reaching its limits with documents longer than 20 pages / 15,000 words.
Roadmap ID 399413 now announces that this limit is to increase significantly: “Copilot in Word will be able to fully summarize documents that it could previously only partially summarize. The upper limit increases to about four times more words.
The Microsoft page linked in the article below: Keep it short and sweet: a guide on the length of documents that you provide to Copilot has also been updated. It now speaks about 80,000 words.

--

Microsoft has published an article named Keep it short and sweet: a guide on the length of documents that you provide to Copilot. It describes how Copilot for Microsoft 365 reaches its limits when it has to work with large documents or very long emails.

The reason for this is that Copilot works with data from the Microsoft Graph, which means that the search in M365 also has a role here. Documents, emails and all other content must first be indexed by the search before they are available for Copilot. At least for the search in SharePoint Online, the limits are documented: https://learn.microsoft.com/en-us/sharepoint/search-limits.

The exact limits that apply for processing by Copilot in Microsoft 365 are currently unclear. The article Keep it short and sweet: a guide on the length of documents that you provide to Copilot gives the following recommendations:

  • Shorter than 20 pages
  • Maximum of around 15,000 words

The example shows how it behaves when relevant information is after these limit recommendations. The relevant information to be used via Copilot are as followed. These are on page 49 of a Word document that contains a total of 27,208 words.


If you ask Copilot “What can you tell me about Snabales Total liabilities?” you get the following answer:
If you use Copilot in Word and ask the same question, the answer is: “This response isn't based on the document: I'm sorry, but the document does not provide any information about Snabales Total liabilities...”


One option you now have here is not to use Copilot for Microsoft 365 natively, but to create your own solution based on Azure AI-Search and Azure OpenAI. In Azure AI-Search, a vector search can be used that splits large documents into so-called chunks. This article describes the details: Chunking large documents for vector search solutions in Azure AI Search



Donnerstag, 2. März 2023

Anonymize your Microsoft 365 reports

The topic of data protection in the context of Microsoft 365 is still ongoing and not finally clarified in all details. The handling of user information and reports is not only a point from the GDPR. Other audits and ISO standards also address this point. For this reason, Microsoft 365 has been offering the option to output anonymous user names in reports instead of the actual user names. Settings -> Org Settings -> Services -> Reports:

By default, the function is active and the reports are anonymized. However, the actual log data is not changed, but the data in the reports is displayed anonymized, depending on the setting. The anonymization can thus be switched on or off and the user data in the reports change ahock: 

The setting affects the following reports in Microsoft 365:
  • Email Activity
  • Mailbox Activity
  • OneDrive files
  • SharePoint Activity
  • SharePoint Site Usage
  • Microsoft Teams Activity
  • Yammer Activity
  • Active users in Microsoft 365 Services and Apps
  • Groups Activity

Donnerstag, 22. Dezember 2022

Microsoft 365 and the DSK (German Data Protection Conference)

 

First of all and very important: I, the author, am not a lawyer and have no legal qualification. This article summarizes the facts on the topic of "Can Microsoft Online Services be used in a privacy-compliant manner following the GDPR?

What is it actually about?

Ulrich Kelber, Chairman of the DSK (German Data Protection Conference), said at a press conference on November 24, 2022, that the use of Microsoft 365 remains contrary to data protection.
Reason, among others: It was still unclear which data was collected, transferred and processed for Microsoft's own purposes.

In summary, the lack of transparency is the cause of concern for the DSK.

The DSK doubts that Microsoft 365 can be used in a data protection-compliant manner "...just like that on a computer without further protective measures". The protection that is meant here refers to the so-called perimeter security. The DSK admits that data protection-compliant use is perhaps possible if techniques such as proxy servers or micro-virtualization are used. On a central proxy server, over which all data traffic is routed, the data flow can then be monitored and controlled in detail.
This approach is not new, but is increasingly being replaced by zero trust architectures because it is simply no longer up to date. In addition, cloud providers generally require that data traffic/access to SaaS, IaaS and PaaS services is direct, i.e., that there is no proxy server or techniques such as packet inspection in between.

Example Microsoft:
  • „…Microsoft 365 networking is to optimize the end user experience by enabling the least restrictive access between clients and the closest Microsoft 365 endpoints…
  • https://learn.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-networking-overview 
Example AWS:
  • …To connect to your WorkSpaces, the network that your WorkSpaces clients are connected to must have certain ports open to the IP address ranges for the various AWS services…
  • https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html 

Options of the customer

The customer itself is not in a able to setup the transparency required by the DSK or to technically influence which data is processed by the contract data processors (Microsoft, AWS, Google, Salesforce, etc.).

In the Microsoft cloud services, the customer can only partially influence the "transparency" by using the Double Key Encryption technology.

However, this does not apply to all types of personal data. For example, it cannot be used to encrypt user data in Azure AD. The "Bring your Own Key" technology, which then also affects tenant encryption as a whole, requires that the own key is uploaded to a Key Vault in Azure. This key is then also stored in the Microsoft Cloud and Microsoft therefore has access to it, at least technically. For details see: Service encryption with Microsoft Purview Customer Key

So what to do?

The DSK…

The DSK (German Data Protection Conference) is a committee of the independent data protection authorities of the German government and the German Federal States. Its focus is on compliance with data protection in the non-public sector. The opinions and guidance published by the DSK are based on the data protection laws of Germany and the German Federal States.
Its focus is on compliance with data protection in the non-public sector. The opinions and guidance provided by the conference are not legally binding. However, they have a de facto impact on the future of data privacy in Germany due to the expertise and authority of the conference members.

DSK says about the use of M365...

...data controllers must be in a position at all times to meet their accountability obligations under Article 5 (2) GDPR. When using Microsoft 365, difficulties can still be expected in this regard on the basis of the "data protection supplement", as Microsoft does not fully disclose which processing operations take place in detail. In addition, Microsoft does not fully disclose which processing operations take place on behalf of the customer or which take place for its own purposes. The contract documents are not precise in this respect and, as a result, do not permit conclusively assessable, possibly even extensive processing also for the customer's own purposes...

Microsoft says this...

… We respectfully disagree with the DSK position as we ensure that our M365 products not only meet, but often exceed, the strong data privacy laws in the European Union. Our customers in Germany and across the EU can confidently use the M365 products in a legally compliant way…

What now?

From the customer's perspective, this is a tricky situation. On the one hand, an institution whose statements are not binding, but are weighty, said NO to M365 for German customers. On the other hand, Microsoft says, "Our customers in Germany and throughout the EU can continue to use M365 products without hesitation and in a legally secure manner.
All in all, the following wording sums it up perfectly for now:
The statement of the DSK is nothing more and nothing less than the legal opinion of a committee of the executive authority. This is not binding. The judiciary, i.e. the German and European courts, has the final word

Or to put it in the words from the Microsoft article:
We look forward to the new framework becoming the basis for a positive European Commission adequacy decision under the GDPR in 2023.


Freitag, 1. Januar 2021

Hello 2021 - what can we expect from you?

 

This whitepaper summarizes the trends and what we can expect in the IT industry in 2021. Of course, it will still be about new features and options. However, the challenges that companies had and have to deal with COVID-19 also brought topics such as IT security and governance back into focus.

In conclusion, the current challenges have made it clear that the question "What do I get out of a new tool or service and what would it take for me to implement it?" is really only the second question. Question number 1 was and will remain for now: "What do I need as a company to be able to work productively?"

After the ECJ declared the Privacy Shields as invalid in the summer of 2020, the topic of GDPR will continue to affect us in 2021.

Details on this and other topics in the free whitepaper Hello 2021 - what can we expect from you?


Mittwoch, 30. September 2020

Secure your environment by Conditional Access & App Controls

With the Azure AD Conditional Access feature, rules for access to Microsoft Cloud Services and other apps registered in Azure AD can be bound to conditions.

An example is the rule: When accessing with an unmanaged device, the user is prompted to use multi-factor authentication.

With the feature "Use Conditional Access App Control" as an option in the Session Controls area within Azure AD Conditional Access, advanced scenarios can be setup.

Options:

  • Prevent data exfiltration
  • Protect on download
  • Prevent upload of unlabeled files
  • Block potential malware
  • Monitor user sessions for compliance
  • Block access
  • Block custom activities

Example:

  • Automatically assign a sensitivity label when a file is downloaded.
  • Filter based on regular expressions: “Include Files that match a custom expression
  • Block Upload if Maleware is detected.
  • This is can be done because the Cloud App Security service then acts as a proxy for accessing the application:

Setup Conditional Access App Control

The options listed above affect all resisted apps under https://portal.cloudappsecurity.com/#/connected-apps?tab=proxy.  By default, this list is empty:

To register an app, the wizard can be used in Cloud App Security via Investigate -> Connected Apps -> Conditional Access App Control Apps. Another and much simpler way is to use a conditional access policy as an easy start:

  1. Azure AD Security -> Conditional Access

  2. New Policy

  3. Section „Access controls“ -> „Session“

  4. Use „Use Conditional Access App Control“

  5. Use „Use custom policy to set an advanced policy in Cloud App Security“


Configure the policy in the menus "Users and Groups" etc. that it will be applied the next time the app to be registered is started. This then results in apps that are authenticated via Azure AD being automatically registered in Cloud App Security under „Conditional Access App Control“:

The above method works for the so called featured apps. In order to make this option work for the Office 365 Featured Apps, Office 365 must be registered under "Connected Apps" in Cloud App Security:

Once an app is registered, session policies can be created that will take effect when the app is used.

Example: If the user Oliver Hardy tries to download a document from Microsoft Teams (SharePoint) that contains the term "confidential", the download is blocked.

Further scenarios

  • Monitor / block activities based on file conditions like Classification Label, File Name, Files Size or File Extension
  • Apply rules based on Maleware detection
  • Apply classification label to downloads
  • Block downloads based on conditions
  • Monitor / block activities like Cut/Copy Item, Paste Item, Print Item, Send Item


Impact from the user's perspective

When opening the app, the user is notified that access is monitored by Cloud App Security. The fact that a proxy is involved can also be recognized by the URL. This now has the addition access-control.cas.ms:



If the user Oliver Hardy now tries to download a document he gets the following message: