← SC-500: cloud and AI security
04 / 6 · 40 MIN

Agent and AI security

Constrain data, identities, tools, and consumption around actual control coverage.

Concept and mechanism

AI can make excessively shared information easier to find. A DSPM assessment helps locate that risk; correction requires reviewing source access and sharing. An autonomous agent does not necessarily have an interactive user or device. Policies should target the identity type and available signals. Agent risk and agent-user options have preview components in the inspected documentation. Do not copy human MFA or device-compliance requirements without validating the flow. At the AI gateway, identify consumers and use trustworthy counter keys for token limits. A header freely chosen by the client can allow bypassing the intended isolation.

Guided application

Foundry agent guardrails are in preview, including tool-call and tool-response intervention. Check assignment, risk compatibility, and intervention point. A custom agent guardrail overrides the model guardrail; do not assume an automatic union. Documented support covers Foundry Agent Service agents rather than any agent merely registered in the control plane. In fictional retrieval containing adversarial instructions, also constrain tool actions and rights, because content filtering is not authorization. Defender for AI Services provides GA threat protection with documented coverage of text tokens and supported services. Do not claim audio, image, or all-cloud scanning. Record limitations and owners at handover.

IN PRACTICE

A tool response requests export: retrieved content does not authorize a tool to export data.

Common pitfalls

All users as all agents; always-additive guardrails; preview as universal coverage; content similarity as authorization.

Related topics: Identity, access, and governance · Storage, SQL, and keys · Private networks and diagnosis

Take this idea with you

Verify the control actually applied to identity, content, and action.

Create account

Reference: Agent guardrail assignment and preview controls · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30