📌 Author's note: Independent, not affiliated with or endorsed by Microsoft. This site is a starting point — verify current product status against Microsoft documentation before architecture or purchasing decisions.
The taxonomy

The five AI
threat surfaces

Never let an AI security conversation drift into "agents only" — every estate I've assessed turned out to be five asset classes, and coverage on one never implied coverage on another. Each class answers to a different owning control and a different licence axis. This page is the whole taxonomy on one screen.

SURFACE 1

AI apps & assistants

M365 Copilot, declarative agents, Security Copilot, GitHub Copilot, SaaS AI and shadow AI — the class every employee touches.

Top risksPrompt abuse (direct override, extractive abuse, indirect injection), sensitive data entering AI context, shadow AI outside any control
Owning controlsPurview audit + DLP for Copilot (CopilotActivity carries per-interaction Jailbreak / XPIA verdicts) · Defender for Cloud Apps for SaaS AI discovery · Edge / network DLP for public LLMs
Licence gateM365 E5 + M365 Copilot for the audited surface; browser and network DLP layers vary
SURFACE 2

AI platform & workloads

Microsoft Foundry accounts and projects, Azure OpenAI, custom LLM apps, RAG pipelines, vector stores and the grounding data they read.

Top risksWorkload compromise, insecure grounding data, model endpoint abuse — and the budgeting error of assuming an M365 licence covers any of it
Owning controlsDefender for Cloud (CSPM + AI Services plans) · Foundry guardrails and Prompt Shields · content-filter spans in workspace App Insights
Licence gateAzure axis — per resource and per tokens scanned. No M365 tier covers this
SURFACE 3

Agents

Copilot Studio (Classic and Modern), Foundry agents, declarative agents, third-party SDK and registry-sync agents — things with identity and autonomy.

Top risksSprawl and ungated creation · maker credentials · Classic agents outside the Entra perimeter · one blueprint secret compromising every agent under it
Owning controlsAgent 365 registry + Entra Agent ID (Conditional Access, ID Protection, lifecycle) · AgentsInfo posture · runtime spans in CloudAppEvents
Licence gateAgent 365 or M365 E7 — required for Copilot Studio and Foundry agent security since 1 July 2026. Identity objects readable at any Entra tier
SURFACE 4

Tools, MCP servers & connectors

First-party, custom and third-party MCP servers; connectors, plugins and APIs — how agent decisions become real-world actions. The supply-chain conversation nobody schedules.

Top risksSupply-chain dependencies with tenant access · prompt injection converting to tool execution · unvetted third-party servers
Owning controlsMCP vetting gates at procurement · Work IQ governed MCP servers · real-time protection evaluating onboarded MCP tools · McpServers in AgentsInfo
Licence gateVaries — tool-call telemetry (ExecuteToolBy*) needs Agent 365 instrumentation
SURFACE 5

Endpoints running local AI

Coding CLIs, desktop AI apps, local MCP configurations and local model runners on staff and developer devices.

Top risksInference outside every prompt-logging and DLP path · unknown local MCP servers · a class-1 surface governed only by class-5 mechanisms
Owning controlsDefender for Endpoint local-agent discovery (AgentsInfo, Platform == "LocalAgents" — vendor, version, host process, trust settings, local + remote MCP servers) · Intune policy · app control
Licence gateMDE P2 (in E5) for discovery and inventory — no Agent 365 needed. Risk scoring needs E7 or A365 + MDE P2
📌 The test I run against every vendor pitch and internal plan

Which of the five surfaces does it cover, and which does it silently ignore? Ask it out loud in the meeting — most products cover one or two, and the seller usually knows which. The Agent Telemetry Map shows surfaces 3–5 in motion: what each agent type emits, where it lands, and the licence gate on every table.