What's new
Recently added and updated content — newest first.
Scenarios
- Block Unsanctioned AI Destinations
Blocks access to unsanctioned AI apps at the network layer — enforcing org-wide blocking through Defender for Cloud Apps and applying user and group-level restrictions through Entra Internet Access.
Capabilities
- MCP Firewall (Preview)
Allows or blocks remote MCP servers and individual tools, resources, or prompt templates in user-scoped traffic, including traffic from agents on managed devices; currently in preview. Requires the Global Secure Access client and TLS inspection, and inspects streamable HTTP and Server-Sent Events traffic only, excluding local MCP servers and stdio transport.
Guides
- An introduction to agent identities
Understand what an agent identity represents, how Microsoft platforms create it, and when the Agent 365 SDK is needed. Learn the basic decisions about access and accountability before deploying an agent.
Solutions
- Establish a Central Azure AI Governance Hub
Operate Azure API Management and Azure API Center as shared governance services, then onboard secure AI workloads through explicit publication, identity, network, and telemetry boundaries.
Scenarios
- Establish Shared AI Gateway and Asset Governance
Operate Azure API Management and Azure API Center as shared platform services for runtime mediation, AI asset discovery, consumption controls, assessment evidence, and gateway telemetry across AI workload spokes.
- Onboard a Foundry Workload to the Governance Hub
Connect a Foundry workload spoke to shared governance by registering its AI assets, publishing approved runtime endpoints through API Management, authorizing hub-to-spoke paths, and correlating gateway and workload telemetry.
Capabilities
- AI Asset Assessment Evidence
Uses Azure API Center to score registered agents and skills against assessment criteria and analyze API definitions for conformance, giving reviewers design-time evidence for approval and reuse decisions.
- Design-Time AI Asset Catalog
Uses Azure API Center to maintain a design-time inventory of APIs, MCP servers, agents, skills, and plugins so solution builders can discover reusable assets with lifecycle and descriptive metadata before integration.
- AI Runtime Gateway and Access Mediation
Uses Azure API Management as the solution's runtime gateway for model, MCP, and A2A APIs, authenticating callers, protecting backend credentials, and applying consistent access and traffic policies at the Azure boundary.
- AI Token Rate Limits and Quotas
Enforces token-per-minute limits and token quotas by API consumer at the API Management runtime boundary so one application, team, or workload cannot exhaust shared model capacity.
- Gateway AI Traffic Observability
Sends language-model token usage and optional prompt and completion records from the API Management runtime boundary to Azure Monitor for gateway-level auditing, usage analysis, and troubleshooting by consumer and model.
- Gateway Content Safety Enforcement
Applies Azure AI Content Safety policies at the API Management runtime boundary for supported model, MCP, and A2A traffic, blocking configured harm categories, blocklist matches, and prompt-attack patterns.
- MCP and A2A API Gateway Governance
Brings MCP tools and servers and A2A agent APIs into the API Management runtime boundary so their operations, endpoint access, and discovery metadata can be governed with gateway policies.
Scenarios
- Govern the Foundry Model Supply Chain
Ensure only approved, eligible models reach Foundry projects and that every deployment meets a minimum guardrail bar — with consumption ceilings that keep usage within governed limits.
- Protect Foundry Agents at Runtime
Harden the running agent so it resists prompt attacks, doesn't leak sensitive or protected output, stays aligned to its assigned task, and has its tool traffic mediated.
Guides
- The agent landscape
Introduction to Microsoft's AI Agents — where each one sits, how much of an agent you build and therefore have to secure, and how Agent 365 governs them all once they exist.
Guides
- Security frameworks & regulations
The shared language for AI security — which acronyms are laws, frameworks, standards, and threat references, how they stack together, and how Microsoft turns them into practice.
Solutions
- Shadow AI
Discover, control, and govern unsanctioned AI app usage across your organisation — from building visibility into shadow AI activity to blocking risky destinations, preventing data loss, and governing sanctioned use.
Scenarios
- Govern Agent Identity and Access
Give every agent a first-class Entra identity, then govern what it authenticates as and what it can reach — assign a responsible owner, right-size access with packages and reviews, and enforce risk-based Conditional Access before it touches resources.
- Govern Sanctioned Enterprise AI
Bring the AI that runs outside Microsoft's Copilot family — custom apps you build and sanctioned SaaS such as ChatGPT Enterprise and Anthropic Claude — under Microsoft Purview, so their interactions are discovered, audited, and governed like the rest of your estate rather than remaining a blind spot.
- Investigate and Respond to Agent Incidents
Gives responders what they need to work an agent incident end to end — the agent inventory, the identity graph behind it, the conversation evidence, and the legal-hold path — so an alert can be scoped, understood, and acted on.
Capabilities
- Agent Threat Hunting & Investigation
Correlates AI agent alerts into incidents and gives analysts an incident graph to scope the blast radius, then queries Agent 365 observability data with Kusto Query Language in Advanced Hunting — across the AgentsInfo, CloudAppEvents, and BehaviorInfo tables — to investigate threats and proactively hunt for risk. Turns near-real-time agent detections into full investigation and threat-hunting workflows in the Microsoft Defender portal.
- Agent Identity Lifecycle Management
Governs the identity lifecycle of AI agents in Microsoft Entra ID Governance — enabling, disabling, and retiring agents, and keeping an accountable human sponsor on every agent so oversight is never lost. When a sponsor leaves, sponsorship transfers automatically to their manager, and Lifecycle Workflows automate the mover and leaver notifications that keep an agent's access from outliving its oversight.
- AI Interaction Retention
Applies Microsoft Purview retention policies and labels to the prompts and responses of Microsoft 365 Copilot, agents, and other AI apps, retaining what the organization must keep and deleting what it no longer needs. Covers both user Copilot experiences and agent interactions across the supported surfaces.
- Purview DSPM AI Interaction Discovery
Uses Microsoft Purview Data Security Posture Management reports, AI observability, and Activity explorer to surface user interactions with AI apps and agents, identify sensitive information in prompts and responses, and inform follow-up controls such as DLP, insider risk, investigation, and remediation workflows.
- eDiscovery for AI Interactions
Lets legal and compliance teams search, place holds on, review, and export the prompts and responses of Microsoft 365 Copilot, agents, and other AI apps in Microsoft Purview eDiscovery — treating a user mailbox or an agent instance as the custodian. Reduces the risk of being unable to preserve or investigate AI interaction data for legal and compliance cases.
- Enterprise AI App Connectors
Connects sanctioned non-Microsoft enterprise AI apps — ChatGPT Enterprise and Anthropic Claude (connector in preview) — to Microsoft Purview so their prompts and responses surface in Data Security Posture Management for AI with auditing, and, for ChatGPT Enterprise, insider risk, communication compliance, eDiscovery, and retention. Brings enterprise AI outside Microsoft under monitoring and compliance, though sensitivity-label, encryption, and DLP enforcement are not supported for these connected apps.
- Entra-registered AI App Governance
Registers custom, in-house AI apps in Microsoft Entra and integrates them with the Microsoft Purview SDK so their prompts and responses inherit the full Purview control plane — data classification, sensitivity labels, encryption, data loss prevention, insider risk, communication compliance, eDiscovery, retention, and Compliance Manager. Gives apps you build the same data governance as Microsoft Copilot rather than leaving them outside compliance.
- Encryption Enforcement Without Labels
Enforces Azure Rights Management VIEW and EXTRACT usage rights on content protected without a sensitivity label — such as Message Encryption, Information Rights Management, or Customer Key — so Microsoft 365 Copilot and Copilot Cowork only return data the user is entitled to see. Unlike labeled content, this protection is not inherited by newly generated output.
Capabilities
- Abuse Monitoring
Detects recurring harmful content and misuse patterns in Azure OpenAI prompts and completions, and flags potentially abusive users through content classification and pattern scoring. Surfaces Risks & Safety monitoring signals so teams can respond to misuse of deployed models.
- Policy Templates
Bundle predefined governance and security policies from Microsoft Entra, Purview, SharePoint Online, and Defender into templates that administrators apply to agents in the Microsoft 365 admin center, standardizing controls and reducing manual configuration across the agent estate. Requires the Microsoft Agent 365 license.
- Copilot Web Grounding Controls
Governs whether Microsoft 365 Copilot and Copilot Chat can ground responses on the public web, and which external domains are off-limits. Admins turn web grounding on or off tenant-wide with the Allow web search in Copilot policy and exclude up to 1,000 domains, keeping untrusted or non-compliant web sources out of AI responses.
- Adaptive Protection for AI Risk
Dynamically assigns escalated DLP, data lifecycle, and Conditional Access controls to users whose insider risk level rises — automatically tightening restrictions when risk increases and relaxing them when it subsides.
- Power Platform Activity Monitoring
Collects agent and Power Platform activity into Microsoft Sentinel and applies analytics rules to detect, investigate, and respond to suspicious agent behavior alongside other tenant signals. Reduces the risk of undetected malicious agent activity.
- Isolated Agent Execution Environment
Runs agents inside pooled, stateless Cloud PCs that are Microsoft Entra-joined and Intune-enrolled and reset after every session. Contains what a manipulated or compromised agent can reach and leaves a per-session identity and audit trail for every action.
Capabilities
- Copilot Response Label Inheritance
Copilot responses and generated files inherit the highest-priority sensitivity label of the sources they draw on, carrying that label's encryption and markings onto the AI output so protection follows the content instead of stopping at the grounding data.
Scenarios
- Establish the Foundry Security Foundation
Lock down the Microsoft Foundry platform, its network path, and its data before any agent ships — scoped access, private networking, and customer-controlled encryption as the baseline every project inherits.
Capabilities
- AI Red Teaming Agent
Runs automated adversarial scans against models and Foundry agents — simulating prompt injection, jailbreak, and agentic attacks with PyRIT strategies — and scores each attempt with an Attack Success Rate to surface safety and security weaknesses before deployment. In preview.
- Risk & Safety Evaluators
Scores model and agent outputs against built-in risk and safety evaluators — including groundedness, indirect prompt injection (XPIA), prohibited actions, and sensitive data leakage — so teams can gate releases and catch unsafe behaviour before deployment. Runs from the Azure AI Evaluation SDK or the Foundry portal and feeds results back into observability.
- Application Insights Agent Observability
Provides a unified Agent details view (in preview) that monitors AI agents across Microsoft Foundry, Copilot Studio, and third-party frameworks using OpenTelemetry Gen AI semantics — tracking performance, token usage and cost, Gen AI errors, and end-to-end traces. Copilot Studio agents can additionally emit opt-in, high-fidelity runtime telemetry for deep query-based analysis in KQL.
- Copilot Security Dashboard
Surfaces Microsoft 365 Copilot data-security posture in the Microsoft 365 admin center — data loss prevention, oversharing, and compliance insights — so administrators can monitor and act on Copilot data risk in one place. Draws on Microsoft Purview signals to give a single view of Copilot data governance.
- Security Dashboard for AI
Aggregates AI security posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into one scorecard and inventory spanning Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry apps and agents, and third-party or shadow AI. Gives security leaders a single cross-product view of AI assets and their risk; currently in preview.
- Communication Compliance for AI Interactions
Detects inappropriate, risky, or policy-violating content in AI prompts and responses — including Microsoft 365 Copilot, connected AI apps, and browser-accessed third-party AI tools — using built-in classifiers and custom policies.
- AI-Assisted Incident Investigation & Response
Gives SOC analysts a natural-language assistant that summarises incidents, correlates signals across Defender XDR, Sentinel, Entra, and Purview, and recommends guided responses — accelerating triage and response for incidents that involve AI agents. Runs standalone or embedded in the Defender portal, with agent identity and RBAC set by the Security Copilot owner.
- SharePoint Admin Agent
An AI-powered governance agent that lets administrators investigate tenant-level content risks — oversharing, sprawl, stale sites, and access — through natural-language queries instead of running reports manually. Analyzes SharePoint and SharePoint Advanced Management data to recommend and guide oversharing remediation before a Microsoft 365 Copilot rollout.
Solutions
- Agent Identity & Access Management
Give every agent a first-class identity, then govern what it authenticates as and what it can reach — registering agents in Microsoft Entra, assigning owners, right-sizing access with packages and reviews, and enforcing risk-based Conditional Access.
- Agent Observability & Governance
Bring the growing population of AI agents into view and under control with Microsoft Agent 365 — from a centralized, cross-platform inventory of every agent and who owns it, to lifecycle governance over which agents are allowed, what tools they can call, and which policies apply.
- Detect & Respond to AI Data Risk
Turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response — bridged into Microsoft Defender XDR and Microsoft Sentinel.
- Protect Enterprise Data Used by AI
Control what enterprise data AI can read and share — discover where sensitive data and oversharing create AI risk, classify and label it, prevent its loss to AI apps and agents, and govern its lifecycle.
- Secure the Agent Runtime
Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints.