Netskope Global Technical Success (GTS)
KB - Restrict Microsoft Copilot via Netskope Header Insertion
Netskope Cloud Version - 117
Objective
Prevent the use of Microsoft Copilot via Netskope Header Insertion.
Prerequisite
Netskope CASB/SWG license is required.
Context
There are scenarios where customers wish to prevent Microsoft Copilot usage as it does not have any business use case.
Configuration
Microsoft introduced a HTTP header approach to prevent the use of Copilot without commercial data protection.
Please visit: Manage Copilot
The Key-value for this feature is: “x-ms-entraonly-copilot: 1” which must be inserted on the following domains:
- bing.com
- copilot.microsoft.com
- edgeservices.bing.com
For bing.com (#1) and copilot.microsoft.com (#2), Netskope already has these domains as a part of 2 predefined connectors.
bing.com:
copilot.microsoft.com:
On the other hand, for the missing domain, we will need to create a custom connector leveraging our universal connector.
Go to: Settings >>> Security Cloud Platform >>> App Definition >>> Click on “New APP Definition Rule” >>> Select “Cloud App” >>> Click on “Universal Connector”, then add “Bing Edge Services” as name, then add: edgeservices.bing.com as domain, and / as path, then save and apply the changes.
Now, we just need to insert the required Key-value header.
Go to: Settings >>> Manage >>> Header Insertion >>> Click on “New Header Insertion Profile” >>> search for Microsoft Bing >>> Select “Custom” add: x-ms-entraonly-copilot, and value: 1, then repeat the same process for Microsoft Copilot and Custom Connector for edgeservices.bing.com.
Verification:
When accessing Microsoft Copilot via Microsoft Edge, you will see the following Network Error.
When accessing Microsoft Copilot via Chrome or any other browser, you will notice that the Copilot button is no longer available.
Notes to remember:
- As we have created a new custom connector, please ensure that Netskope Client has been updated prior to any testing.
- This article is authored by Netskope Global Technical Success (GTS).
- For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.