As organizations increasingly adopt AI agents to automate processes, access enterprise data, and interact with business systems, securing these agents has become a critical responsibility for Cloud and AI Security Engineers.
In this session, we will explore how Microsoft security technologies can help organizations manage AI agent identities, control their access to resources, assess identity-related risks, and protect Copilot Studio agents against threats during runtime.
AI agents can authenticate to services, access data, call APIs, perform actions, and make decisions on behalf of users or business processes. When these identities are overprivileged, poorly governed, or compromised, they can expose sensitive information and create new attack paths across the organization.
This session will introduce participants to the security controls available across:
Microsoft Entra Agent ID
Microsoft Entra Conditional Access
Microsoft Defender XDR
Microsoft Defender for Cloud Apps
Microsoft Copilot Studio
Participants will learn how to apply Zero Trust principles to AI agents by verifying their identities, limiting their permissions, assessing their potential blast radius, investigating attack paths, and enabling runtime protection.
What You Will Learn
By the end of the session, participants should be able to
Explain how AI agents authenticate and access enterprise resources
Understand the purpose of Microsoft Entra Agent ID
Identify where Conditional Access can be applied to agent identities
Configure Conditional Access policies for AI agents
Control agent access based on organizational security requirements
Manage agent identity ownership and lifecycle events
Discover AI agents through the Microsoft Defender XDR agent inventory
Review the permissions and knowledge sources available to an AI agent
Assess the potential blast radius of a compromised agent identity
Analyze attack paths that could lead to unauthorized access
Understand the protection cap