Secure Agents Built in Azure AI Foundry

Updated

Secure the pro-code build plane end to end — found the platform, govern the model supply chain, and protect the runtime — for agents built and deployed in Microsoft Foundry.

Pro-code agents built in Microsoft Foundry are a distinct build plane with their own controls, governed separately from low-code agents even though they converge on the same operate plane. This topic makes that plane concrete as a three-step motion: first found the platform by locking down identity, network, and data before any agent ships; then govern the model supply chain so only approved, eligible models reach projects under a minimum guardrail bar; then protect the runtime so the running agent resists prompt attacks, doesn't leak, stays task-aligned, and has its tool traffic mediated. Detection and investigation of these agents live in the SecOps for AI motion, into which Foundry telemetry feeds.

How to address Secure Agents Built in Azure AI Foundry

  1. Establish the Foundry Security Foundation

    Lock down the Microsoft Foundry platform, its network path, and its data before any agent ships — scoped access, private networking, and customer-controlled encryption as the baseline every project inherits.
  2. Govern the Foundry Model Supply Chain

    Ensure only approved, eligible models reach Foundry projects and that every deployment meets a minimum guardrail bar — with consumption ceilings that keep usage within governed limits.
  3. Protect Foundry Agents at Runtime

    Harden the running agent so it resists prompt attacks, doesn't leak sensitive or protected output, stays aligned to its assigned task, and has its tool traffic mediated.

Control coverage

Control coverage for Secure Agents Built in Azure AI Foundry — where its 13 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
AI Safety
6

Guardrails that keep generative AI outputs and inputs within safe, policy-aligned bounds — including content filtering, prompt shields, and groundedness evaluation.

Governance
5

Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.

Threat Detection
3

Capabilities that identify, alert on, and help respond to threats targeting AI models, inference endpoints, training pipelines, and supporting infrastructure.

Agent Security
2

Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.

Data Protection
2

Mechanisms that protect data confidentiality and integrity at rest, in transit, and during processing within AI workloads — including encryption, sensitivity labeling, and data loss prevention.

Network Protection
2

Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.

Discovery
1

Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.

Identity & Access
1

Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.

Monitoring
1

Continuous observability of AI workload behaviour, usage, and anomalies through logging, metrics, and alerting — enabling detection of drift, misuse, and security events.

Supply Chain
1

Controls that protect the integrity of AI model supply chains — covering model provenance, dependency vetting, third-party plugin and connector risk, and safeguards against tampered or poisoned models and training data.