Implement security for AI
Unlock the complete study guide + 1,040 practice questions across 16 full exams.
Bundled into the existing SC-500 premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- Four control points around an AI workload
- Find the data an AI can already reach
- Agent identity objects in Microsoft Entra Agent ID
- How an agent gets a token, and who a policy sees
- Conditional Access for agent identities
- Sponsors, owners, and time-bound agent access
- Agent inventory in the Microsoft 365 admin center
- Real-time protection rules for agents
- Network filtering for Copilot Studio agent traffic
- An AI gateway in front of Foundry models
- Foundry guardrails on models and agents
- What Defender for AI Services covers
- Investigating agent blast radius
- The Data and AI security dashboard
- Exam pattern recognition
Runtime surfaces compared
| Behavior | Copilot Studio real-time protection | Microsoft Foundry guardrails | API Management AI gateway | Defender for AI Services |
|---|---|---|---|---|
| What it inspects | Tool invocations by connected Copilot Studio agents, for suspicious behavior and cross-prompt injection | Prompts, completions, and retrieved-document content for a Foundry model or agent | Every API call to an imported Foundry model endpoint, including its prompt and completion token counts | Runtime activity of supported generative AI applications and agents in the subscription |
| Where you enable it | Security for AI setup in the Defender portal, after connecting Copilot Studio | Guardrail configuration on the Foundry model deployment or agent | API Management, by importing the model endpoint and applying policies | The AI services plan in Defender for Cloud environment settings for the subscription |
| What happens on a match | The default rule audits and records to BehaviorInfo; a custom rule blocks the action before execution | Content is annotated, or annotated and blocked, according to the configured control | The policy applies: llm-token-limit rejects calls once the consumer's token allowance is spent | An alert is raised and can be integrated with Microsoft Defender XDR |
| Scope of one configuration | All agents or selected agents, per rule | One model deployment or one agent | One API consumer, through the token-limit counter key | The Azure subscription where the plan is enabled |
| Main gap to plan around | It surfaces no alerts or incidents without the Microsoft 365 app connector | Harmful-content filtering alone does not cover indirect injection from retrieved documents | It controls nothing for a caller that reaches the backend model endpoint directly | It scans text tokens only and covers documented models, so enablement is not proof of coverage |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
References
- Get ready for Microsoft 365 Copilot with SharePoint Advanced Management
- Microsoft Purview Data Security Posture Management for AI
- https://learn.microsoft.com/en-us/purview/data-security-posture-management-oversharing
- Data access governance reports for SharePoint sites
- Initiate site access reviews for data access governance reports
- https://learn.microsoft.com/en-us/sharepoint/restricted-content-discovery
- Restricted SharePoint Search
- What is Microsoft Entra Agent ID?
- Governing agent identities with Microsoft Entra ID Governance
- Agent identity blueprints in Microsoft Entra Agent ID
- Conditional Access for agents in Microsoft Entra
- Administrative relationships in Microsoft Entra Agent ID (owners, sponsors, managers)
- Access packages for agent identities in Microsoft Entra
- Agent registry in the Microsoft 365 admin center
- https://learn.microsoft.com/en-us/microsoft-365/admin/manage/agent-actions?view=o365-worldwide
- Enable security for AI agents using Microsoft Defender
- Protect AI agents in real time using Microsoft Defender
- BehaviorInfo table in the advanced hunting schema
- https://learn.microsoft.com/en-us/power-platform/admin/security/secure-web-ai-gateway-agents
- Secure Web and AI Gateway for Microsoft Copilot Studio agents
- https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-secure-web-ai-gateway-agents
- https://learn.microsoft.com/en-us/azure/api-management/genai-gateway-capabilities
- Import a Microsoft Foundry API into Azure API Management
- Azure API Management policy reference: llm-token-limit
- Guardrails in Microsoft Foundry overview
- Prompt Shields in Azure AI Content Safety
- Enable threat protection for AI services in Microsoft Defender for Cloud
- AI threat protection in Microsoft Defender for Cloud
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/ai-security-posture
- Detect and investigate threats to AI agents using Microsoft Defender
- AgentsInfo table in the advanced hunting schema
- https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-cloudappevents-table
- Data and AI security dashboard in Microsoft Defender for Cloud