What's new
Recently added and updated content — newest first.
Guides
- The Microsoft agent landscape
Introduction to Microsoft's AI Agents — where each one sits, how much of an agent you build and therefore have to secure, and how Agent 365 governs them all once they exist.
- Security frameworks & regulations
The shared language for AI security — which acronyms are laws, frameworks, standards, and threat references, how they stack together, and how Microsoft turns them into practice.
Solutions
- Shadow AI
Discover, control, and govern unsanctioned AI app usage across your organisation — from building visibility into shadow AI activity to blocking risky destinations, preventing data loss, and governing sanctioned use.
Scenarios
- Govern Agent Identity and Access
Give every agent a first-class Entra identity, then govern what it authenticates as and what it can reach — assign a responsible owner, right-size access with packages and reviews, and enforce risk-based Conditional Access before it touches resources.
- Govern Sanctioned Enterprise AI
Bring the AI that runs outside Microsoft's Copilot family — custom apps you build and sanctioned SaaS such as ChatGPT Enterprise and Anthropic Claude — under Microsoft Purview, so their interactions are discovered, audited, and governed like the rest of your estate rather than remaining a blind spot.
- Investigate and Respond to Agent Incidents
Gives responders what they need to work an agent incident end to end — the agent inventory, the identity graph behind it, the conversation evidence, and the legal-hold path — so an alert can be scoped, understood, and acted on.
Capabilities
- Agent Threat Hunting & Investigation
Correlates AI agent alerts into incidents and gives analysts an incident graph to scope the blast radius, then queries Agent 365 observability data with Kusto Query Language in Advanced Hunting — across the AgentsInfo, CloudAppEvents, and BehaviorInfo tables — to investigate threats and proactively hunt for risk. Turns near-real-time agent detections into full investigation and threat-hunting workflows in the Microsoft Defender portal.
- Agent Identity Lifecycle Management
Governs the identity lifecycle of AI agents in Microsoft Entra ID Governance — enabling, disabling, and retiring agents, and keeping an accountable human sponsor on every agent so oversight is never lost. When a sponsor leaves, sponsorship transfers automatically to their manager, and Lifecycle Workflows automate the mover and leaver notifications that keep an agent's access from outliving its oversight.
- AI Interaction Retention
Applies Microsoft Purview retention policies and labels to the prompts and responses of Microsoft 365 Copilot, agents, and other AI apps, retaining what the organization must keep and deleting what it no longer needs. Covers both user Copilot experiences and agent interactions across the supported surfaces.
- Purview DSPM AI Interaction Discovery
Uses Microsoft Purview Data Security Posture Management reports, AI observability, and Activity explorer to surface user interactions with AI apps and agents, identify sensitive information in prompts and responses, and inform follow-up controls such as DLP, insider risk, investigation, and remediation workflows.
- eDiscovery for AI Interactions
Lets legal and compliance teams search, place holds on, review, and export the prompts and responses of Microsoft 365 Copilot, agents, and other AI apps in Microsoft Purview eDiscovery — treating a user mailbox or an agent instance as the custodian. Reduces the risk of being unable to preserve or investigate AI interaction data for legal and compliance cases.
- Enterprise AI App Connectors
Connects sanctioned non-Microsoft enterprise AI apps — ChatGPT Enterprise and Anthropic Claude (connector in preview) — to Microsoft Purview so their prompts and responses surface in Data Security Posture Management for AI with auditing, and, for ChatGPT Enterprise, insider risk, communication compliance, eDiscovery, and retention. Brings enterprise AI outside Microsoft under monitoring and compliance, though sensitivity-label, encryption, and DLP enforcement are not supported for these connected apps.
- Entra-registered AI App Governance
Registers custom, in-house AI apps in Microsoft Entra and integrates them with the Microsoft Purview SDK so their prompts and responses inherit the full Purview control plane — data classification, sensitivity labels, encryption, data loss prevention, insider risk, communication compliance, eDiscovery, retention, and Compliance Manager. Gives apps you build the same data governance as Microsoft Copilot rather than leaving them outside compliance.
- Encryption Enforcement Without Labels
Enforces Azure Rights Management VIEW and EXTRACT usage rights on content protected without a sensitivity label — such as Message Encryption, Information Rights Management, or Customer Key — so Microsoft 365 Copilot and Copilot Cowork only return data the user is entitled to see. Unlike labeled content, this protection is not inherited by newly generated output.
Capabilities
- Abuse Monitoring
Detects recurring harmful content and misuse patterns in Azure OpenAI prompts and completions, and flags potentially abusive users through content classification and pattern scoring. Surfaces Risks & Safety monitoring signals so teams can respond to misuse of deployed models.
- Policy Templates
Bundle predefined governance and security policies from Microsoft Entra, Purview, SharePoint Online, and Defender into templates that administrators apply to agents in the Microsoft 365 admin center, standardizing controls and reducing manual configuration across the agent estate. Requires the Microsoft Agent 365 license.
- Copilot Web Grounding Controls
Governs whether Microsoft 365 Copilot and Copilot Chat can ground responses on the public web, and which external domains are off-limits. Admins turn web grounding on or off tenant-wide with the Allow web search in Copilot policy and exclude up to 1,000 domains, keeping untrusted or non-compliant web sources out of AI responses.
- Adaptive Protection for AI Risk
Dynamically assigns escalated DLP, data lifecycle, and Conditional Access controls to users whose insider risk level rises — automatically tightening restrictions when risk increases and relaxing them when it subsides.
- Power Platform Activity Monitoring
Collects agent and Power Platform activity into Microsoft Sentinel and applies analytics rules to detect, investigate, and respond to suspicious agent behavior alongside other tenant signals. Reduces the risk of undetected malicious agent activity.
- Isolated Agent Execution Environment
Runs agents inside pooled, stateless Cloud PCs that are Microsoft Entra-joined and Intune-enrolled and reset after every session. Contains what a manipulated or compromised agent can reach and leaves a per-session identity and audit trail for every action.
Capabilities
- Copilot Response Label Inheritance
Copilot responses and generated files inherit the highest-priority sensitivity label of the sources they draw on, carrying that label's encryption and markings onto the AI output so protection follows the content instead of stopping at the grounding data.
Scenarios
- Establish the Foundry Security Foundation
Lock down the Microsoft Foundry platform, its network path, and its data before any agent ships — scoped access, private networking, and customer-controlled encryption as the baseline every project inherits.
- Protect Foundry Agents at Runtime
Harden the running agent so it resists prompt attacks, doesn't leak sensitive or protected output, stays aligned to its assigned task, and has its tool traffic mediated.
Capabilities
- AI Red Teaming Agent
Runs automated adversarial scans against models and Foundry agents — simulating prompt injection, jailbreak, and agentic attacks with PyRIT strategies — and scores each attempt with an Attack Success Rate to surface safety and security weaknesses before deployment. In preview.
- Risk & Safety Evaluators
Scores model and agent outputs against built-in risk and safety evaluators — including groundedness, indirect prompt injection (XPIA), prohibited actions, and sensitive data leakage — so teams can gate releases and catch unsafe behaviour before deployment. Runs from the Azure AI Evaluation SDK or the Foundry portal and feeds results back into observability.
- Application Insights Agent Observability
Provides a unified Agent details view (in preview) that monitors AI agents across Microsoft Foundry, Copilot Studio, and third-party frameworks using OpenTelemetry Gen AI semantics — tracking performance, token usage and cost, Gen AI errors, and end-to-end traces. Copilot Studio agents can additionally emit opt-in, high-fidelity runtime telemetry for deep query-based analysis in KQL.
- Copilot Security Dashboard
Surfaces Microsoft 365 Copilot data-security posture in the Microsoft 365 admin center — data loss prevention, oversharing, and compliance insights — so administrators can monitor and act on Copilot data risk in one place. Draws on Microsoft Purview signals to give a single view of Copilot data governance.
- Security Dashboard for AI
Aggregates AI security posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into one scorecard and inventory spanning Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry apps and agents, and third-party or shadow AI. Gives security leaders a single cross-product view of AI assets and their risk; currently in preview.
- Communication Compliance for AI Interactions
Detects inappropriate, risky, or policy-violating content in AI prompts and responses — including Microsoft 365 Copilot, connected AI apps, and browser-accessed third-party AI tools — using built-in classifiers and custom policies.
- AI-Assisted Incident Investigation & Response
Gives SOC analysts a natural-language assistant that summarises incidents, correlates signals across Defender XDR, Sentinel, Entra, and Purview, and recommends guided responses — accelerating triage and response for incidents that involve AI agents. Runs standalone or embedded in the Defender portal, with agent identity and RBAC set by the Security Copilot owner.
- SharePoint Admin Agent
An AI-powered governance agent that lets administrators investigate tenant-level content risks — oversharing, sprawl, stale sites, and access — through natural-language queries instead of running reports manually. Analyzes SharePoint and SharePoint Advanced Management data to recommend and guide oversharing remediation before a Microsoft 365 Copilot rollout.
Solutions
- Agent Identity & Access Management
Give every agent a first-class identity, then govern what it authenticates as and what it can reach — registering agents in Microsoft Entra, assigning owners, right-sizing access with packages and reviews, and enforcing risk-based Conditional Access.
- Agent Observability & Governance
Bring the growing population of AI agents into view and under control with Microsoft Agent 365 — from a centralized, cross-platform inventory of every agent and who owns it, to lifecycle governance over which agents are allowed, what tools they can call, and which policies apply.
- Detect & Respond to AI Data Risk
Turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response — bridged into Microsoft Defender XDR and Microsoft Sentinel.
- Protect Enterprise Data Used by AI
Control what enterprise data AI can read and share — discover where sensitive data and oversharing create AI risk, classify and label it, prevent its loss to AI apps and agents, and govern its lifecycle.
- Secure the Agent Runtime
Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints.
Scenarios
- Classify and Label Data Feeding AI
Establish the information-protection foundation AI controls depend on — classify sensitive data and apply labels so protection travels with the content agents and Copilots ground on.
- Detect and Respond to Risky AI Data Activity
Close the loop — turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response, bridged into Defender XDR and Sentinel.
- Discover Sensitive Data and AI Risk
Start with visibility — find where sensitive data, oversharing, AI interactions, and unsanctioned AI usage create risk before choosing controls.
- Govern AI Data Lifecycle and Retention
Decide how long AI prompts, responses, and related evidence are kept, deleted, preserved, or removed from active AI grounding.
- Prevent Data Loss to AI Apps and Agents
Turn classification and labels into enforcement boundaries for Copilot, agents, prompts, grounding data, and the browser-based AI apps users reach on their own.
- Protect Agents at Runtime
Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints for prompt injection and high-risk actions.
Capabilities
- AI Security Posture Management
Discovers deployed generative AI apps and models across Azure, AWS, and GCP — the AI bill of materials — and assesses their posture, surfacing identity, data, and internet-exposure recommendations, attack paths, and infrastructure-as-code misconfigurations.
- Prompt Injection Protection
Inspects prompts flowing to generative AI apps in Internet Access traffic and blocks adversarial prompt injection and jailbreak attempts before they reach the language model, enforced at the network layer through the Global Secure Access client. It ships with detectors for major generative AI services, extends to custom JSON-based apps, and currently covers text prompts only.
- Sensitive Information Types and Classifiers
Identifies sensitive data with pattern-based sensitive information types (SITs) and machine-learning trainable classifiers. In AI scenarios these classifiers find sensitive content in user prompts and responses and provide the detection basis that labels, DLP, DSPM reports, and investigation all build on.
- Browser Data Security for AI Prompts in Edge
Enforces DLP inline in Microsoft Edge for Business, inspecting text users type or paste into AI app prompts in real time and blocking sensitive submissions before they leave the browser — without onboarding the device. Configuration policies block users from reaching the same unmanaged AI apps in unprotected browsers.
- Endpoint DLP for AI App Uploads
Monitors managed devices and blocks paste, upload, or clipboard copy of sensitive information to AI application websites, keeping sensitive data from leaving endpoints through third-party AI apps.
- Network Data Security for AI Traffic
Monitors and blocks sensitive data shared with unmanaged AI apps through non-Microsoft browsers, apps, APIs, and add-ins by integrating with SASE and secure web gateway solutions to inspect HTTP/HTTPS traffic at the network layer — the surface Endpoint DLP cannot see.
- Insider Risk Signals for AI Activity
Uses Microsoft Purview Insider Risk Management to identify users with potentially risky AI-related behavior, such as sharing sensitive content with AI apps or interacting with unsanctioned AI services, by correlating configured activity signals from Microsoft Purview, Microsoft 365, browser, endpoint, and network controls. These insights are integrated into Microsoft Defender XDR, where IRM alerts correlate per user into a single incident for unified investigation.
Solutions
- SecOps for AI
Connect agent activity to security operations — stream telemetry to the SOC, detect AI-specific threats, and investigate and respond to agent incidents across Microsoft Sentinel, Defender, and Purview.