๐Ÿ“Œ Author's note: This site synthesises the author's own understanding from publicly available Microsoft documentation, official Microsoft Security blog posts, RSAC 2026 announcements, and insights from Microsoft Security professionals and MVPs. It is independent and not affiliated with or endorsed by Microsoft.
FEEDBACK ยท SUGGESTIONS ยท CORRECTIONS

Share your
thoughts

Found something wrong? Have a suggestion? Know about a Microsoft AI security update we've missed? This goes directly to the author โ€” nothing is published publicly.

โš ๏ธ Factual correction
๐Ÿ†• Missing content
๐Ÿ”— Broken link
๐Ÿ’ก General suggestion
๐Ÿ“ Other
0 / 2000
Your feedback is sent to the author via Formspree and never published publicly. Email is optional and only used to reply to your message. Privacy policy โ†’
โœ…
Feedback received โ€” thank you!
The author reviews all submissions. If you left an email and a response is warranted, you'll hear back within a few days.
ABOUT THIS SITE
Who writes this?
I'm a security architect who spends the working week securing Microsoft AI estates. This site is the primer I kept wishing I could hand people: the five threat surfaces, the licences that gate each control, an interactive map of where agents leave a trace, and field notes from real deployments. Everything traces to Microsoft's public documentation or my own hands-on work. It is independent โ€” not affiliated with or endorsed by Microsoft.
How often is it updated?
This stack moves monthly, so the primer pages are updated as Microsoft ships โ€” typically within days of a major announcement, with changes tracked in the git history.
Privacy Policy

Privacy & Data โ€” Plain English

This site does not use cookies, does not track you across other sites, and does not sell your data. The only personal information collected is what you voluntarily submit via the contact form above.

What we collect and why

Contact form submissions

Name and email (if provided) are sent to and stored by Formspree. Used only to respond to your message. Email is optional. Submissions retained as long as needed to respond, then deleted. To request deletion, use the form above.

Web analytics

This site uses Cloudflare Web Analytics โ€” cookieless, no fingerprinting, no individual tracking, no data shared with advertisers. Aggregate anonymised metrics only (page views, referrer, approximate region).

Cookies

This site sets no cookies. Cloudflare may set technical delivery cookies โ€” not used for tracking. See Cloudflare's cookie policy.

Newsletter

Substack handles all newsletter data independently under their own privacy policy. This site has no access to subscriber data.

Your rights (GDPR)

EEA residents may request access, correction, or deletion of any personal data held (contact form submissions only). Use the form above.

Third-party services

ServicePurposePrivacy policy
Cloudflare PagesHosting and deliverycloudflare.com/privacypolicy
FormspreeContact form processingformspree.io/legal
SubstackNewsletter subscriptionssubstack.com/privacy

This site is operated independently by aiagentsecurity.guide. Not affiliated with or endorsed by Microsoft. Last updated: September 5, 2026.

STAY UPDATED
Get notified when Microsoft AI security changes
Monthly updates on new controls, GA announcements, and critical gaps โ€” direct to your inbox.
Subscribe to updates โ†’
aiagentsecurity.substack.com ยท Free ยท No spam