Urgent.News

What's breaking now, across thousands of outlets.

AI

Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.

Egiziago Cioffi is the IT and Enterprise Architect and CEO of SynSphere Italia, a Microsoft partner based in Milan. He built an agent himself. He wrote the indexing job, configured the Azure OpenAI retrieval pipeline, connected it to SharePoint, and watched it pass every evaluation his team ran. His Azure OpenAI email assistant auto-resolves about 60% of inbound customer email, Cioffi told…

Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.

Cioffi, an IT architect and CEO of SynSphere Italia, developed a retrieval system for an Azure OpenAI email assistant. The assistant resolved 60% of customer emails, passing evaluation scores and unit tests. However, a critical flaw was discovered when a low-privilege account executed queries that the high-privilege account could not have completed.

The assistant returned SharePoint content that the low-privilege account could not access. This discrepancy was not detected by the evaluations, which only tested factual accuracy, relevance, and task completion. The issue stems from the retrieval pipeline bypassing the native retrieval-time entitlement check, allowing unauthorized data access.

The fix is available in Azure AI Search with SharePoint indexer and Entra-backed principals, but it is not universally applied.

Written by urgent.news from VentureBeat's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at venturebeat.com →

More in AI

More from Tuesday 1 September →