Skip to main content
epinheiro
Staff
Staff
January 21, 2026

Technical Tip: Unable to deep inspect Microsoft Copilot AI prompts

  • January 21, 2026
  • 0 replies
  • 845 views

Description

This article describes how to perform Deep Packet Inspection (DPI) on generative AI applications.

Scope

FortiGate, Deep Inspection, Generative AI Prompts.

Solution

FortiGate is capable of performing deep packet inspection (DPI) on traffic destined for major AI applications, including, but not limited to: ChatGPT, Gemini, and Copilot. 

However, a specific configuration is required to ensure inspection works correctly for Microsoft destinations.

Beyond applying the Application Control profile that allows or monitors the Generative AI category or application required, it is necessary to disable the certificate exemption, which is often enabled by default for Microsoft domains, to inspect this traffic successfully. This is achieved by creating a Custom Deep Inspection Profile, removing the 'Microsoft' FQDN, and applying the custom SSL inspection profile to the firewall policy:

Microsoft Destination.png

 

Firewall policy sample:

 

Firewall policy.png

 

To check the logs: Security Events -> Logs -> Application Control:

Security Event Logs.png

 
Some applications display this information under Application Details, as shown above, while others require selecting it to view the necessary details:

Copilot Prompt.png


Note: There are some caveats when dealing with Microsoft 365 Copilot. The traffic might be identified as Microsoft Portal instead, as Microsoft encapsulates different types of traffic in the same manner: Copilot, Sharepoint, etc. The opposite happens for browser-based and Copilot App, where the traffic is correctly identified and matched as Copilot. This is not a limitation of FortiGate, but of how Microsoft embeds the traffic when using Microsoft 365 Copilot.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.