Concept and mechanism
AI can make excessively shared information easier to find. A DSPM assessment helps locate that risk; correction requires reviewing source access and sharing. An autonomous agent does not necessarily have an interactive user or device. Policies should target the identity type and available signals. Agent risk and agent-user options have preview components in the inspected documentation. Do not copy human MFA or device-compliance requirements without validating the flow. At the AI gateway, identify consumers and use trustworthy counter keys for token limits. A header freely chosen by the client can allow bypassing the intended isolation.
Guided application
Foundry agent guardrails are in preview, including tool-call and tool-response intervention. Check assignment, risk compatibility, and intervention point. A custom agent guardrail overrides the model guardrail; do not assume an automatic union. Documented support covers Foundry Agent Service agents rather than any agent merely registered in the control plane. In fictional retrieval containing adversarial instructions, also constrain tool actions and rights, because content filtering is not authorization. Defender for AI Services provides GA threat protection with documented coverage of text tokens and supported services. Do not claim audio, image, or all-cloud scanning. Record limitations and owners at handover.
A tool response requests export: retrieved content does not authorize a tool to export data.
Common pitfalls
All users as all agents; always-additive guardrails; preview as universal coverage; content similarity as authorization.
Related topics: Identity, access, and governance · Storage, SQL, and keys · Private networks and diagnosis
Verify the control actually applied to identity, content, and action.
Reference: Agent guardrail assignment and preview controls · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30