Cybersecurity Research

CrowdStrike Launches Tool to Find and Protect Sensitive Data in Microsoft 365

CrowdStrike · 5 Oct 2026
Key Takeaway Work out where your sensitive customer, staff and financial data sits in Microsoft 365, and review who and what, including AI tools like Copilot, can access it.

Many businesses keep their most valuable information in Microsoft 365. Strategic plans sit in SharePoint, employee records and customer data are held in OneDrive, and AI tools like Microsoft Copilot can increasingly access the same material. CrowdStrike notes that cloud platforms like these are attractive targets, and that once an attacker gains access, their activity can look like normal user behaviour.

To address this, CrowdStrike has announced the general availability of Falcon Data Security for SaaS. It works inside Microsoft 365 without needing an additional sensor. According to CrowdStrike, it continuously discovers and classifies sensitive data across SharePoint, OneDrive and Copilot as files are accessed, changed and shared. Built-in patterns identify regulated information such as personally identifiable information, protected health information and payment card data, while custom patterns can capture data unique to a business.

The company says AI-powered classification helps teams understand sensitive information in context, and a shared classification engine gives one consistent view of sensitive data across SaaS, endpoint and cloud. The stated goals are to reduce the risk of data theft, oversharing and unintended AI exposure, while cutting manual effort. This article is based on the opening of CrowdStrike's announcement, so further details are not covered here.

Summarised by CISO AI from CrowdStrike, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.