{
  "id": 4919071,
  "title": "Closing an Azure OpenAI assistant's retrieval gap didn't take a new identity platform. It took one filter and a narrower assistant.",
  "url": "https://urgent.news/2026/09/01/closing-an-azure-openai-assistants-retrieval-gap-didnt-take-a-new",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-01T18:59:54.000Z",
  "source": {
    "name": "VentureBeat",
    "slug": "venturebeat",
    "url": "https://venturebeat.com/security/azure-openai-agent-passed-every-evaluation-served-files-user-couldnt-open"
  },
  "original_language": "en",
  "account": "Cioffi, an IT architect and CEO of SynSphere Italia, developed a retrieval system for an Azure OpenAI email assistant. The assistant resolved 60% of customer emails, passing evaluation scores and unit tests. However, a critical flaw was discovered when a low-privilege account executed queries that the high-privilege account could not have completed. The assistant returned SharePoint content that the low-privilege account could not access. This discrepancy was not detected by the evaluations, which only tested factual accuracy, relevance, and task completion. The issue stems from the retrieval pipeline bypassing the native retrieval-time entitlement check, allowing unauthorized data access. The fix is available in Azure AI Search with SharePoint indexer and Entra-backed principals, but it is not universally applied.",
  "summary": "Egiziago Cioffi is the IT and Enterprise Architect and CEO of SynSphere Italia, a Microsoft partner based in Milan. He built an agent himself. He wrote the indexing job, configured the Azure OpenAI retrieval pipeline, connected it to SharePoint, and watched it pass every evaluation his team ran. His Azure OpenAI email assistant auto-resolves about 60% of inbound customer email, Cioffi told…",
  "key_points": [
    "Retrieval system developed for Azure OpenAI email assistant",
    "Low-privilege account accessed unauthorized SharePoint content",
    "Fix available in Azure AI Search with Entra-backed principals"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}