๐Ÿ“Œ Author's note: This site synthesises the author's own understanding from publicly available Microsoft documentation, official Microsoft Security blog posts, RSAC 2026 announcements, and insights from Microsoft Security professionals and MVPs. It is independent and not affiliated with or endorsed by Microsoft. Microsoft updates products and documentation frequently โ€” always verify current status directly with Microsoft before making architecture or purchasing decisions.
UPDATED ยท RSAC 2026 ยท MARCH 24, 2026

Microsoft Security
Products for AI

Every Microsoft security product mapped to the AI security stack. Updated with RSAC 2026 announcements. GA/Preview status reflects what was confirmed on March 20, 2026.

Control Plane & Governance

Unified Visibility & Agent Governance

โ†— Click on a product name to navigate to the Microsoft documentation page.

Agent 365 โ†—
Unified control plane for all agents. Inventory, governance, and security posture across Microsoft and partner agents. Licensing is per-user, not per-agent โ€” governance scope does not scale with agent count. Includes new Defender, Entra, and Purview capabilities to secure agent access and prevent data oversharing.
GA May 1 2026โš  Per-user only$15/user/mo
โ†— Learn More
Security Dashboard for AI โ†—
Unified CISO-level AI risk aggregation from Defender + Entra + Purview. AI inventory covering agents, MCP servers, models, apps โ€” including third-party AI (ChatGPT, Gemini). Security Copilot NL-driven risk exploration. Now generally available โ€” previously preview.
โœ“ Now GA ยท RSAC 2026No extra licenseAI Risk Scorecard
โ†— Learn More
Foundry Guardrails โ†—
Assign control collections to specific models or agents in Azure AI Foundry. Limits tools available to each agent, constrains output behaviour, enforces content safety at the orchestration layer. Only applies to Foundry-deployed agents.
PreviewPaaSPer-agent control setsFoundry only
โ†— Learn More
Microsoft 365 E7: The Frontier Suite โ†—
Bundles M365 Copilot + Agent 365 + Entra Suite + M365 E5. Agent 365 included but inherits the same per-user licensing model. Best for orgs where agents are tightly coupled to named users.
GA May 1 2026โš  Per-user licensing$99/user/mo
โ†— Learn More
Identity & Access

Identity Primitives for AI Agents

โ†— Click on a product name to navigate to the Microsoft documentation page.

Entra Agent ID โ†—
Register agents as non-human identities. Human sponsor required. Lifecycle automation. Currently limited preview โ€” frontier/large enterprise only. Agents still use OBO flow underneath. Only applies to Modern Agents โ€” most existing Copilot Studio agents are Classic Agents (Service Principals) and receive no Entra Agent ID protection. Migration tool from Classic to Modern does not yet exist. Agent names do not sync on rename โ€” original "Agent #" name persists in Entra.
โš  Preview ยท Frontier Onlyโš  Modern Agents onlyโš  Name sync bugโš  OBO underneath
โ†— Learn More
Entra Workload Identity โ†—
Today's real-world primitive for non-human identities. Designed for apps/services โ€” not purpose-scoped for individual agents. Lacks agent-specific lifecycle governance and sponsor model. The current stopgap while Agent ID matures.
GA ยท Available Nowโš  Not agent-purpose-scoped
โ†— Learn More
Conditional Access for AI Agents โ†—
Block risky agents; enforce least-privilege and JIT access. Critical caveat (field-validated March 2026): CA for Agents does not apply to Copilot Studio agents โ€” they authenticate via OBO or service principal, not modern Agent ID. CA for Agents is only active for Security Copilot and AI Foundry agents using OAuth 2.0 Agent ID authentication. For Copilot Studio, use Conditional Access policies targeting the user or workload identity instead.
โš  Does NOT apply to Copilot StudioApplies: Security Copilot ยท AI FoundryCA Optimization Agent ยท Preview
โ†— Learn More
Entra Internet Access โ†—
Secure web and AI gateway. Shadow AI Detection now GA on March 31 โ€” uses network layer to identify unknown AI applications. Prompt Injection Protection also GA March 31 โ€” enforces universal network-level policies to block malicious AI prompts across apps and agents.
Shadow AI Detection: GA Mar 31Prompt Injection: GA Mar 31
โ†— Learn More
Entra External MFA โ†—
Connect external MFA providers directly with Microsoft Entra โ€” leverage pre-existing MFA investments or use highly specialised MFA methods alongside Entra authentication flows. New at RSAC 2026.
โœ“ GA March 25, 2026External MFA Providers
โ†— Learn More
Entra Backup and Recovery โ†—
Automated backup of Entra directory objects to enable rapid recovery in case of accidental deletion or unauthorised changes. New resilience capability for identity infrastructure.
Preview ยท RSAC 2026Directory BackupRapid Recovery
โ†— Learn More
Entra Tenant Governance โ†—
Discover unmanaged (shadow) Entra tenants and establish consistent tenant policies and governance in multi-tenant environments. Addresses the risk of unsanctioned AI deployments creating orphaned tenants.
Preview ยท RSAC 2026Shadow Tenant DiscoveryMulti-tenant
โ†— Learn More
Unified Identity Security Dashboard โ†—
New dashboard in Microsoft Defender highlighting the most impactful insights across human and non-human identities. New identity risk score unifies account-level risk signals for real-time access decisions and SecOps investigations.
Preview ยท RSAC 2026Human + NHI IdentitiesRisk Score
โ†— Learn More
Threat Detection & Runtime

Runtime Defence & Threat Detection

โ†— Click on a product name to navigate to the Microsoft documentation page.

Prompt Shields โ†—
Runtime defence against direct and indirect prompt injection at the orchestration layer. Inspects user inputs AND content retrieved by the agent (RAG, tool outputs) before it reaches the model decision loop.
GADirect + Indirect PIOrchestration Layer
โ†— Learn More
Azure AI Content Safety โ†—
API-level model I/O filters: harmful content, jailbreak attempts, protected material, groundedness violations. Operates at the model boundary โ€” separate from Prompt Shields which operates at the orchestration layer.
GAModel BoundaryJailbreak ยท Groundedness
โ†— Learn More
Defender Predictive Shielding โ†—
Dynamically adjusts identity and access policies during active attacks โ€” reducing exposure and limiting lateral movement in real time. Applies to both human and agent identities during incidents. New at RSAC 2026.
Preview ยท RSAC 2026Dynamic PolicyActive Attack Response
โ†— Learn More
Defender for Cloud (AI Workloads) โ†—
CSPM and runtime threat protection for AI infrastructure. Monitors model deployments, API access patterns, and agent behaviour. Expanded container security at RSAC 2026 including binary drift and antimalware prevention.
GAContainer security: PreviewMulti-cloud
โ†— Learn More
Copilot Data Connector (Sentinel) โ†—
Ingests Copilot audit logs and activity telemetry into a new CopilotActivity table in Sentinel. Enables analytic rules, workbooks, hunting queries, and automation specifically targeting AI/agent interactions. Record types include: CopilotInteraction, plugin lifecycle (create/update/delete), CopilotPromptBook operations, CopilotForSecurityTrigger, CopilotAgentManagement. Also supports Sentinel data lake for low-cost long-term retention and MCP server integration. Note: data ingestion costs apply. Prompt content ingested becomes a sensitive artifact โ€” apply field-level masking and access controls on CopilotActivity table.
Preview ยท Feb 2026CopilotActivity tableโš  Ingestion costs applyโš  Prompt data sensitivity
โ†— Learn More
AI Model Scanning (Defender for Cloud) โ†—
Scans AI models in Azure ML registries and workspaces for malware, unsafe operators, and backdoors across common model formats. Recurring scans surface as security recommendations per model. High-confidence detections generate Defender XDR SOC alerts. CLI integration enables in-pipeline scanning during CI/CD build. Gating capability blocks unsafe models from reaching a registry. New at RSAC 2026.
GA ยท RSAC 2026Azure MLSupply ChainCI/CD Gating
โ†— Learn More
Defender for Cloud Apps (CASB) โ†—
Governs how AI agents and MCP tools access SaaS. Discovers shadow AI, governs OAuth permissions, detects over-privileged agent-to-SaaS access. For Copilot Studio specifically: provides real-time protection โ€” blocks tool invocations if a prompt is suspicious. 1-second timeout: if no decision returned in time, tool executes. Not a guaranteed prevention control.
GAOAuth GovernanceMCP-SaaSRT Protection: Preview ยท 1s timeout
โ†— Learn More
AI Agent Inventory (Defender for Cloud Apps) โ†—
Detects all Copilot Studio agents in the tenant and surfaces misconfigurations via the AIAgentsInfo Advanced Hunting table. Detects no-auth agents, ownerless agents, and risky configurations. Setup requires collaboration between Defender admin AND Power Platform admin โ€” two separate portals. Takes up to 30 minutes for initial connection and longer for full data population. Three Defender preview features must be enabled separately.
Preview ยท Copilot Studio onlyโš  Complex dual-admin setupAIAgentsInfo KQL
โ†— Learn More
Microsoft Sentinel โ†—
SIEM + SOAR. Ingests AI-specific telemetry: agent behaviour logs, MCP server activity, Copilot interaction signals. RSAC 2026 updates: Data Federation via Microsoft Fabric, Playbook Generator with natural language orchestration, MCP Entity Analyzer (GA April), Sentinel Custom Graphs, and Connector Builder Agent (Preview March 31). UEBA Behaviors layer now GA. Custom Guidebooks for Copilot Guided Response now GA.
GAMCP Entity Analyzer: GA AprilUEBA Behaviors: GACustom Guidebooks: GAData Federation: PreviewPlaybook Generator: PreviewConnector Builder: Preview Mar 31
โ†— Learn More
Data Security

Purview โ€” Data Governance for AI

โ†— Click on a product name to navigate to the Microsoft documentation page.

DSPM for AI โ†—
Discovers where sensitive data exists across AI workloads. Identifies oversharing risks before agents exploit them. Posture assessments and automated remediation for AI data risks.
PreviewOversharing RiskAI Workloads
โ†— Learn More
DLP for Microsoft 365 Copilot โ†—
Two distinct DLP capabilities for M365 Copilot and Copilot Chat. โ‘  Block files/emails with sensitivity labels (GA): prevents labelled files and emails from being used in Copilot response summaries. Items still appear in citations but content is excluded. โ‘ก Block SITs in prompts (Preview โ€” GA planned June/July 2026): when a typed prompt contains a selected Sensitive Information Type (credit card numbers, passport numbers etc), Copilot returns no response at all โ€” it does not fall back to internal Graph sources. Blocks both internal and external web searches. Available in M365 Copilot, Copilot Chat, Word/Excel/PowerPoint, and prebuilt agents. Key caveats: The two conditions cannot be combined in the same rule. DLP cannot scan files uploaded directly into prompts โ€” only typed text is evaluated. Policy changes take up to 4 hours to apply. Admin Units not supported.
Label Blocking: GASIT Prompt Blocking: Preview ยท GA June/July 2026โš  No response when triggeredโš  Uploaded files not scanned
โ†— Learn More
Information Protection (AI) โ†—
Extends sensitivity labels into AI workflows. Prevents agents from accessing, generating, or transmitting content violating classification policies. Integrates with Entra Internet Access for network-layer enforcement.
GASensitivity LabelsDLP in AI
โ†— Learn More
Communication Compliance (AI) โ†—
Monitors Copilot and agent conversations for policy violations and regulatory issues. OBO note: attribution may show user identity rather than agent identity in audit logs.
GAโš  OBO attributionAudit Trail
โ†— Learn More
Purview in Copilot Control System โ†—
Unified view of AI-related data risk directly in the Microsoft 365 Admin Center. Brings Purview data security insights into the same admin surface where Copilot is configured and governed. New at RSAC 2026.
GA April ยท RSAC 2026M365 Admin CenterUnified Risk View
โ†— Learn More
AI Observability (Purview) โ†—
Tracks what data agents access, process, and output at runtime. Creates a complete data access audit map for compliance and forensics teams. Feeds into eDiscovery workflows.
PreviewAgent Activity LogseDiscovery
โ†— Learn More
AI-Powered SecOps

Security Copilot & Autonomous Agents

โ†— Click on a product name to navigate to the Microsoft documentation page.

Security Copilot โ†—
AI assistant embedded in Defender, Entra, Intune, Purview. Automates threat hunting, phishing triage, identity risk remediation. Included for M365 E5 at 400 SCU per 1,000 users/month. Over 15 new partner-built agents available via Security Store.
Included in E5 + E7400 SCU/1K users/mo15+ Partner Agents
โ†— Learn More
Security Analyst Agent โ†—
Helps accelerate threat investigations by providing contextual analysis and guided workflows in Microsoft Defender. Deep multi-step investigation using Defender and Sentinel telemetry. Announced at RSAC 2026.
Preview Mar 26 ยท RSAC 2026Contextual AnalysisGuided Workflows
โ†— Learn More
Security Alert Triage Agent โ†—
Extends the phishing triage agent to cloud and identity โ€” autonomously analyses, classifies, prioritises, and resolves repetitive low-value alerts at scale. Reduces analyst alert fatigue across identity and cloud signals.
Preview April ยท RSAC 2026Cloud + IdentityAutonomous Triage
โ†— Learn More
Conditional Access Optimization Agent โ†—
Adds context-aware recommendations, deeper analysis, and phased rollout to strengthen identity security through Conditional Access policies. Agent is GA; RSAC 2026 enhancements are in preview.
Agent: GAEnhancements: PreviewEntra
โ†— Learn More
Data Security Posture Agent โ†—
Purview agent with new credential scanning capability โ€” proactively detects credential exposure in your data estate. Helps surface hidden identity risks embedded in documents, repositories, and data stores.
Preview ยท RSAC 2026Credential ScanningPurview
โ†— Learn More
Data Security Triage Agent โ†—
Purview alert triage agent with advanced AI reasoning layer and improved interpretation of custom Sensitive Information Types โ€” improves agent outputs during alert review. Agent is GA; RSAC 2026 enhancements in preview from March 31.
Agent: GAEnhancements: Preview Mar 31Purview
โ†— Learn More
Intune Security Copilot Agents โ†—
Automate device policy reviews, offboarding, and risk-based remediation within Intune. Policy Configuration Agent lets IT create and validate policies via natural language. Enhanced app inventory for AI-enabled apps GA in May.
GAApp Inventory: GA MayNatural Language Config
โ†— Learn More