Scenarios
A single security outcome and the capabilities that deliver it.
Block Unsanctioned AI Destinations
Blocks access to unsanctioned AI apps at the network layer — enforcing org-wide blocking through Defender for Cloud Apps and applying user and group-level restrictions through Entra Internet Access.
Classify and Label Data Feeding AI
Establish the information-protection foundation AI controls depend on — classify sensitive data and apply labels so protection travels with the content agents and Copilots ground on.
Control AI Apps on Managed Devices
Prevents installation and execution of unsanctioned AI apps and local AI agents on managed devices using Intune app control policies and Microsoft 365 admin center shadow AI governance across Windows, iOS/iPadOS, Android, and macOS.
Detect and Respond to Risky AI Data Activity
Close the loop — turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response, bridged into Defender XDR and Sentinel.
Detect Threats to AI Agents
Turns agent activity into detections — surfacing prompt injection, jailbreak, credential theft, and abnormal execution against agents and the AI infrastructure they depend on, with alerts centralized for the SOC.
Discover Sensitive Data and AI Risk
Start with visibility — find where sensitive data, oversharing, AI interactions, and unsanctioned AI usage create risk before choosing controls.
Discover Shadow AI Usage
Builds visibility into which AI apps users are accessing, who is using them, and whether sensitive data is flowing into AI prompts — before taking any blocking action.
Establish the Foundry Security Foundation
Lock down the Microsoft Foundry platform, its network path, and its data before any agent ships — scoped access, private networking, and customer-controlled encryption as the baseline every project inherits.
Govern Agent Distribution
Control how agents reach users and how much to trust an agent you did not build — judge third-party trust signals, gate org-built agents through approval, scope who gets which agents, and block the ones that should not be there.
Govern Agent Identity and Access
Give every agent a first-class Entra identity, then govern what it authenticates as and what it can reach — assign a responsible owner, right-size access with packages and reviews, and enforce risk-based Conditional Access before it touches resources.
Govern Agent Lifecycle
Decide which agents are allowed, who owns them, what tools they can call, and which governance and compliance policies apply — establishing consistent guardrails across the agent lifecycle from onboarding through retirement.
Govern AI Data Lifecycle and Retention
Decide how long AI prompts, responses, and related evidence are kept, deleted, preserved, or removed from active AI grounding.
Govern Power Platform Environments
Route makers into governed Power Platform environments and enforce consistent guardrails — sharing limits, security scanning, and Dataverse data protection — so agents are built inside a controlled boundary rather than the open default environment.
Govern SharePoint-Grounded Agents
Reduce oversharing and grounding-data exposure for agents that ground on SharePoint — find overshared sites, restrict what agents can discover and access, and protect the sensitive data behind them.
Govern the Foundry Model Supply Chain
Ensure only approved, eligible models reach Foundry projects and that every deployment meets a minimum guardrail bar — with consumption ceilings that keep usage within governed limits.
Harden Copilot Studio Agents
Harden a low-code agent at build time, before it becomes an enterprise asset, by combining Power Platform data-policy guardrails with Copilot Studio security settings that govern authentication, knowledge, tools, channels, and runtime protection.
Investigate and Respond to Agent Incidents
Gives responders what they need to work an agent incident end to end — the agent inventory, the identity graph behind it, the conversation evidence, and the legal-hold path — so an alert can be scoped, understood, and acted on.
Observe the Agent Estate
Builds visibility into every AI agent and agent identity across the tenant and connected platforms — a centralized inventory, source of truth, and usage insight into who owns each agent and how it is used.
Prevent Data Loss to AI Apps and Agents
Turn classification and labels into enforcement boundaries for Copilot, agents, prompts, grounding data, and the browser-based AI apps users reach on their own.
Promote Copilot Studio Agents to Production
Move a low-code agent safely from development to production through a governed pipeline, locking the production environment so changes arrive only via approved, reviewed releases.
Protect Agents at Runtime
Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints for prompt injection and high-risk actions.
Protect Foundry Agents at Runtime
Harden the running agent so it resists prompt attacks, doesn't leak sensitive or protected output, stays aligned to its assigned task, and has its tool traffic mediated.
Stream Agent Activity to Security Operations
Routes agent telemetry — invocations, tool calls, and interactions — from the agent platforms into the SOC's tooling, so that agent activity is monitored, hunted, and correlated alongside the rest of the estate.
No scenarios match the selected filters.