Secure the Agent Runtime

Updated

Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints.

Governance decides which agents are allowed and what they may reach; runtime security answers a different question — can the agent be manipulated while it is actually running. This topic covers the estate-wide, cross-surface runtime controls that Agent 365 brings to every agent: enforce at the network layer which destinations an agent may reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints for prompt injection and high-risk actions. Surface-specific runtime hardening for Foundry and Copilot Studio agents lives with those build surfaces; detection and response to runtime threats live in the SecOps for AI motion.

How to address Secure the Agent Runtime

  1. Protect Agents at Runtime

    Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints for prompt injection and high-risk actions.

Control coverage

Control coverage for Secure the Agent Runtime — where its 4 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
AI Safety
2

Guardrails that keep generative AI outputs and inputs within safe, policy-aligned bounds — including content filtering, prompt shields, and groundedness evaluation.

Threat Detection
2

Capabilities that identify, alert on, and help respond to threats targeting AI models, inference endpoints, training pipelines, and supporting infrastructure.

Agent Security
1

Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.

Network Protection
1

Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.