What's new
Recently added and updated content — newest first.
Guides
- Security frameworks & regulations
The shared language for AI security — which acronyms are laws, frameworks, standards, and threat references, how they stack together, and how Microsoft turns them into practice.
Guides
- The Microsoft agent landscape
Introduction to Microsoft's AI Agents — where each one sits, how much of an agent you build and therefore have to secure, and how Agent 365 governs them all once they exist.
Capabilities
- Abuse Monitoring
Detects recurring harmful content and misuse patterns in Azure OpenAI prompts and completions, and flags potentially abusive users through content classification and pattern scoring. Surfaces Risks & Safety monitoring signals so teams can respond to misuse of deployed models.
- Policy Templates
Bundle predefined governance and security policies from Microsoft Entra, Purview, SharePoint Online, and Defender into templates that administrators apply to agents in the Microsoft 365 admin center, standardizing controls and reducing manual configuration across the agent estate. Requires the Microsoft Agent 365 license.
- Copilot Web Grounding Controls
Governs whether Microsoft 365 Copilot and Copilot Chat can ground responses on the public web, and which external domains are off-limits. Admins turn web grounding on or off tenant-wide with the Allow web search in Copilot policy and exclude up to 1,000 domains, keeping untrusted or non-compliant web sources out of AI responses.
- Adaptive Protection for AI Risk
Dynamically assigns escalated DLP, data lifecycle, and Conditional Access controls to users whose insider risk level rises — automatically tightening restrictions when risk increases and relaxing them when it subsides.
- Power Platform Activity Monitoring
Collects agent and Power Platform activity into Microsoft Sentinel and applies analytics rules to detect, investigate, and respond to suspicious agent behavior alongside other tenant signals. Reduces the risk of undetected malicious agent activity.
- Isolated Agent Execution Environment
Runs agents inside pooled, stateless Cloud PCs that are Microsoft Entra-joined and Intune-enrolled and reset after every session. Contains what a manipulated or compromised agent can reach and leaves a per-session identity and audit trail for every action.
Capabilities
- Copilot Response Label Inheritance
Copilot responses and generated files inherit the highest-priority sensitivity label of the sources they draw on, carrying that label's encryption and markings onto the AI output so protection follows the content instead of stopping at the grounding data.
Scenarios
- Establish the Foundry Security Foundation
Lock down the Microsoft Foundry platform, its network path, and its data before any agent ships — scoped access, private networking, and customer-controlled encryption as the baseline every project inherits.
- Investigate and Respond to Agent Incidents
Gives responders what they need to work an agent incident end to end — the agent inventory, the identity graph behind it, the conversation evidence, and the legal-hold path — so an alert can be scoped, understood, and acted on.
- Protect Foundry Agents at Runtime
Harden the running agent so it resists prompt attacks, doesn't leak sensitive or protected output, stays aligned to its assigned task, and has its tool traffic mediated.
Capabilities
- AI Red Teaming Agent
Runs automated adversarial scans against models and Foundry agents — simulating prompt injection, jailbreak, and agentic attacks with PyRIT strategies — and scores each attempt with an Attack Success Rate to surface safety and security weaknesses before deployment. In preview.
- Risk & Safety Evaluators
Scores model and agent outputs against built-in risk and safety evaluators — including groundedness, indirect prompt injection (XPIA), prohibited actions, and sensitive data leakage — so teams can gate releases and catch unsafe behaviour before deployment. Runs from the Azure AI Evaluation SDK or the Foundry portal and feeds results back into observability.
- Application Insights Agent Observability
Provides a unified Agent details view (in preview) that monitors AI agents across Microsoft Foundry, Copilot Studio, and third-party frameworks using OpenTelemetry Gen AI semantics — tracking performance, token usage and cost, Gen AI errors, and end-to-end traces. Copilot Studio agents can additionally emit opt-in, high-fidelity runtime telemetry for deep query-based analysis in KQL.
- Copilot Security Dashboard
Surfaces Microsoft 365 Copilot data-security posture in the Microsoft 365 admin center — data loss prevention, oversharing, and compliance insights — so administrators can monitor and act on Copilot data risk in one place. Draws on Microsoft Purview signals to give a single view of Copilot data governance.
- Security Dashboard for AI
Aggregates AI security posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into one scorecard and inventory spanning Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry apps and agents, and third-party or shadow AI. Gives security leaders a single cross-product view of AI assets and their risk; currently in preview.
- Communication Compliance for AI Interactions
Detects inappropriate, risky, or policy-violating content in AI prompts and responses — including Microsoft 365 Copilot, connected AI apps, and browser-accessed third-party AI tools — using built-in classifiers and custom policies.
- AI-Assisted Incident Investigation & Response
Gives SOC analysts a natural-language assistant that summarises incidents, correlates signals across Defender XDR, Sentinel, Entra, and Purview, and recommends guided responses — accelerating triage and response for incidents that involve AI agents. Runs standalone or embedded in the Defender portal, with agent identity and RBAC set by the Security Copilot owner.
- SharePoint Admin Agent
An AI-powered governance agent that lets administrators investigate tenant-level content risks — oversharing, sprawl, stale sites, and access — through natural-language queries instead of running reports manually. Analyzes SharePoint and SharePoint Advanced Management data to recommend and guide oversharing remediation before a Microsoft 365 Copilot rollout.
Solutions
- Agent Identity & Access Management
Give every agent a first-class identity, then govern what it authenticates as and what it can reach — registering agents in Microsoft Entra, assigning owners, right-sizing access with packages and reviews, and enforcing risk-based Conditional Access.
- Agent Observability & Governance
Bring the growing population of AI agents into view and under control with Microsoft Agent 365 — from a centralized, cross-platform inventory of every agent and who owns it, to lifecycle governance over which agents are allowed, what tools they can call, and which policies apply.
- Detect & Respond to AI Data Risk
Turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response — bridged into Microsoft Defender XDR and Microsoft Sentinel.
- Protect Enterprise Data Used by AI
Control what enterprise data AI can read and share — discover where sensitive data and oversharing create AI risk, classify and label it, prevent its loss to AI apps and agents, and govern its lifecycle.
- Secure the Agent Runtime
Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints.
Scenarios
- Classify and Label Data Feeding AI
Establish the information-protection foundation AI controls depend on — classify sensitive data and apply labels so protection travels with the content agents and Copilots ground on.
- Detect and Respond to Risky AI Data Activity
Close the loop — turn AI audit signals, insider-risk indicators, and communication-compliance findings into investigation and response, bridged into Defender XDR and Sentinel.
- Discover Sensitive Data and AI Risk
Start with visibility — find where sensitive data, oversharing, AI interactions, and unsanctioned AI usage create risk before choosing controls.
- Govern Agent Identity and Access
Give every agent a first-class Entra identity, then govern what it authenticates as and what it can reach — assign a responsible owner, right-size access with packages and reviews, and enforce risk-based Conditional Access before it touches resources.
- Govern AI Data Lifecycle and Retention
Decide how long AI prompts, responses, and related evidence are kept, deleted, preserved, or removed from active AI grounding.
- Prevent Data Loss to AI Apps and Agents
Turn classification and labels into enforcement boundaries for Copilot, agents, prompts, grounding data, and the browser-based AI apps users reach on their own.
- Protect Agents at Runtime
Protect the running agent from manipulation — control which destinations it can reach, block risky tool invocations before they execute, and inspect the local agent loop on endpoints for prompt injection and high-risk actions.
Capabilities
- AI Security Posture Management
Discovers deployed generative AI apps and models across Azure, AWS, and GCP — the AI bill of materials — and assesses their posture, surfacing identity, data, and internet-exposure recommendations, attack paths, and infrastructure-as-code misconfigurations.
- Prompt Injection Protection
Inspects prompts flowing to generative AI apps in Internet Access traffic and blocks adversarial prompt injection and jailbreak attempts before they reach the language model, enforced at the network layer through the Global Secure Access client. It ships with detectors for major generative AI services, extends to custom JSON-based apps, and currently covers text prompts only.
- Sensitive Information Types and Classifiers
Identifies sensitive data with pattern-based sensitive information types (SITs) and machine-learning trainable classifiers. In AI scenarios these classifiers find sensitive content in user prompts and responses and provide the detection basis that labels, DLP, DSPM reports, and investigation all build on.
- Browser Data Security for AI Prompts in Edge
Enforces DLP inline in Microsoft Edge for Business, inspecting text users type or paste into AI app prompts in real time and blocking sensitive submissions before they leave the browser — without onboarding the device. Configuration policies block users from reaching the same unmanaged AI apps in unprotected browsers.
- Endpoint DLP for AI App Uploads
Monitors managed devices and blocks paste, upload, or clipboard copy of sensitive information to AI application websites, keeping sensitive data from leaving endpoints through third-party AI apps.
- Network Data Security for AI Traffic
Monitors and blocks sensitive data shared with unmanaged AI apps through non-Microsoft browsers, apps, APIs, and add-ins by integrating with SASE and secure web gateway solutions to inspect HTTP/HTTPS traffic at the network layer — the surface Endpoint DLP cannot see.
- Insider Risk Signals for AI Activity
Uses Microsoft Purview Insider Risk Management to identify users with potentially risky AI-related behavior, such as sharing sensitive content with AI apps or interacting with unsanctioned AI services, by correlating configured activity signals from Microsoft Purview, Microsoft 365, browser, endpoint, and network controls. These insights are integrated into Microsoft Defender XDR, where IRM alerts correlate per user into a single incident for unified investigation.
Solutions
- SecOps for AI
Connect agent activity to security operations — stream telemetry to the SOC, detect AI-specific threats, and investigate and respond to agent incidents across Microsoft Sentinel, Defender, and Purview.
Scenarios
- Detect Threats to AI Agents
Turns agent activity into detections — surfacing prompt injection, jailbreak, credential theft, and abnormal execution against agents and the AI infrastructure they depend on, with alerts centralized for the SOC.
- Stream Agent Activity to Security Operations
Routes agent telemetry — invocations, tool calls, and interactions — from the agent platforms into the SOC's tooling, so that agent activity is monitored, hunted, and correlated alongside the rest of the estate.
Capabilities
- Agent 365 Observability
Copilot Studio agents automatically emit OpenTelemetry telemetry — agent invocations and tool calls — to the Agent 365 observability backend without SDK instrumentation. This telemetry feeds the Microsoft 365 admin center, Microsoft Defender, and Microsoft Purview, forming the activity backbone for agent monitoring, threat detection, and compliance.
- Conversation Transcript Retention
Retains Copilot Studio conversation transcripts and their metadata in Dataverse, with per-environment and environment-group controls over whether transcripts are saved, who can view and download them, and how long they are kept. Provides the conversation evidence store for agent investigations — though transcripts aren't written for Microsoft 365 Copilot agents, and for SharePoint-grounded answers the generated answer is redacted while the source content is retained.
- AI Threat Protection
Detects threats to generative AI workloads at runtime — prompt injection, jailbreak, credential theft, data leakage, and wallet-abuse attacks — for Azure OpenAI models and Azure AI model inference, working with Content Safety Prompt Shields and Microsoft threat intelligence. Alerts are centralized in Microsoft Defender XDR for correlation and response.
- Agent Security Posture Management
Assesses each agent's posture risk from risk indicators — weak instructions, indirect prompt injection exposure, privileged business-system access, and active threats — assigns an overall risk level, and provides security recommendations to reduce exposure in the Microsoft Defender portal. Posture is derived from the Agent 365 inventory on the AI agents page and the AgentsInfo advanced hunting table.
- AI Agent Inventory
Discovers all Agent 365-managed agents in the Microsoft Defender portal — cloud agents from Copilot Studio, Foundry, Microsoft 365, and supported non-Microsoft platforms plus local agents on endpoints — through the AI agents page and the AgentsInfo advanced hunting table, and surfaces their security-relevant configuration for posture assessment.
- Real-time Agent Protection
Inspects agent activity throughout the agentic loop and blocks risky actions before they execute, using a default audit rule and custom blocking rules scoped to specific agents from Security for AI policies in the Microsoft Defender portal. Covers Agent 365 tool invocations and Copilot Studio agents, and records audit and block events as behaviors in the BehaviorInfo table for hunting and custom detections.
- eDiscovery for Agent Interactions
Lets legal and compliance teams search, place holds on, review, and export AI agent prompts and responses in Microsoft Purview eDiscovery, treating an agent instance as its own custodian. Reduces the risk of being unable to preserve or investigate agent interaction data for legal and compliance cases.
- Agent 365 Data Connector
Streams AI agent telemetry from Agent 365, Azure AI Foundry, and Microsoft Copilot into the Microsoft Sentinel data lake, where SOC teams investigate agent behavior, tool usage, and execution through KQL hunting, the Sentinel graph, and MCP query workflows. In public preview.