Domain 3 of 4 · Chapter 1 of 3

Implement security for AI

Unlock the complete study guide + 1,040 practice questions across 16 full exams.

Bundled into the existing SC-500 premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • Four control points around an AI workload
  • Find the data an AI can already reach
  • Agent identity objects in Microsoft Entra Agent ID
  • How an agent gets a token, and who a policy sees
  • Conditional Access for agent identities
  • Sponsors, owners, and time-bound agent access
  • Agent inventory in the Microsoft 365 admin center
  • Real-time protection rules for agents
  • Network filtering for Copilot Studio agent traffic
  • An AI gateway in front of Foundry models
  • Foundry guardrails on models and agents
  • What Defender for AI Services covers
  • Investigating agent blast radius
  • The Data and AI security dashboard
  • Exam pattern recognition

Runtime surfaces compared

BehaviorCopilot Studio real-time protectionMicrosoft Foundry guardrailsAPI Management AI gatewayDefender for AI Services
What it inspectsTool invocations by connected Copilot Studio agents, for suspicious behavior and cross-prompt injectionPrompts, completions, and retrieved-document content for a Foundry model or agentEvery API call to an imported Foundry model endpoint, including its prompt and completion token countsRuntime activity of supported generative AI applications and agents in the subscription
Where you enable itSecurity for AI setup in the Defender portal, after connecting Copilot StudioGuardrail configuration on the Foundry model deployment or agentAPI Management, by importing the model endpoint and applying policiesThe AI services plan in Defender for Cloud environment settings for the subscription
What happens on a matchThe default rule audits and records to BehaviorInfo; a custom rule blocks the action before executionContent is annotated, or annotated and blocked, according to the configured controlThe policy applies: llm-token-limit rejects calls once the consumer's token allowance is spentAn alert is raised and can be integrated with Microsoft Defender XDR
Scope of one configurationAll agents or selected agents, per ruleOne model deployment or one agentOne API consumer, through the token-limit counter keyThe Azure subscription where the plan is enabled
Main gap to plan aroundIt surfaces no alerts or incidents without the Microsoft 365 app connectorHarmful-content filtering alone does not cover indirect injection from retrieved documentsIt controls nothing for a caller that reaches the backend model endpoint directlyIt scans text tokens only and covers documented models, so enablement is not proof of coverage

Decision tree

Is the exposure about datathe AI can reach?SharePoint reports andPurview DSPM for AIfix permissions and sharing linksYesIs it about who the agent isor what it may hold?NoConditional Access andagent access packagesblueprints, attributes, sponsorsYesDoes the agent run in theMicrosoft 365 estate?NoReal-time protection rulesin Security for AIcustom rule to block, default rule auditsGlobal Secure Access filters the trafficYesAPI Management AI gateway,Foundry guardrails, Defender for AItoken limits, prompt and output controlsruntime detection on the subscriptionNoAlways: keep the evidence pathconnectors, incidents, hunting tables

Cheat sheet

  • Microsoft 365 Copilot inherits the signed-in user's content access
  • SharePoint governance reports surface permission-driven overexposure
  • Purview DSPM for AI prioritizes AI-related data risks
  • The Data and AI security dashboard unifies resource risk and protection status
  • Connecting Copilot Studio enables real-time tool-invocation scanning
  • The Microsoft 365 app connector is required to surface agent alerts and incidents
  • The default agent protection rule audits without blocking
  • Custom real-time protection rules block scoped high-confidence actions
  • Full Defender agent monitoring depends on Agent 365 and Microsoft 365 data sources
  • Entra Agent ID gives an agent a distinct governable identity
  • Conditional Access can target agent identity blueprints
  • Custom security attributes scale agent Conditional Access targeting
  • Agent sponsors provide business accountability without technical ownership
  • Access packages make agent permissions governed and time-bound
  • Autonomous agents require agent-evaluable Conditional Access controls
  • Copilot Studio agent traffic must be forwarded before network policy applies
  • Defender incidents correlate entities to expose agent blast radius
  • AgentsInfo and CloudAppEvents provide complementary blast-radius evidence
  • The Microsoft 365 agent registry centralizes supported agent inventory
  • Agent management separates discovery, availability, and lifecycle actions
  • API Management centralizes Foundry model access through an AI gateway
  • AI gateway token limits control model consumption per caller
  • Defender for AI Services adds runtime threat detection to supported AI workloads
  • Defender for AI Services coverage is model and modality specific
  • Foundry guardrails address distinct input and output risks
  • Foundry model imports can use the API Management identity

Unlock with Premium — includes all practice exams and the complete study guide.

References

  1. Get ready for Microsoft 365 Copilot with SharePoint Advanced Management
  2. Microsoft Purview Data Security Posture Management for AI
  3. https://learn.microsoft.com/en-us/purview/data-security-posture-management-oversharing
  4. Data access governance reports for SharePoint sites
  5. Initiate site access reviews for data access governance reports
  6. https://learn.microsoft.com/en-us/sharepoint/restricted-content-discovery
  7. Restricted SharePoint Search
  8. What is Microsoft Entra Agent ID?
  9. Governing agent identities with Microsoft Entra ID Governance
  10. Agent identity blueprints in Microsoft Entra Agent ID
  11. Conditional Access for agents in Microsoft Entra
  12. Administrative relationships in Microsoft Entra Agent ID (owners, sponsors, managers)
  13. Access packages for agent identities in Microsoft Entra
  14. Agent registry in the Microsoft 365 admin center
  15. https://learn.microsoft.com/en-us/microsoft-365/admin/manage/agent-actions?view=o365-worldwide
  16. Enable security for AI agents using Microsoft Defender
  17. Protect AI agents in real time using Microsoft Defender
  18. BehaviorInfo table in the advanced hunting schema
  19. https://learn.microsoft.com/en-us/power-platform/admin/security/secure-web-ai-gateway-agents
  20. Secure Web and AI Gateway for Microsoft Copilot Studio agents
  21. https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-secure-web-ai-gateway-agents
  22. https://learn.microsoft.com/en-us/azure/api-management/genai-gateway-capabilities
  23. Import a Microsoft Foundry API into Azure API Management
  24. Azure API Management policy reference: llm-token-limit
  25. Guardrails in Microsoft Foundry overview
  26. Prompt Shields in Azure AI Content Safety
  27. Enable threat protection for AI services in Microsoft Defender for Cloud
  28. AI threat protection in Microsoft Defender for Cloud
  29. https://learn.microsoft.com/en-us/azure/defender-for-cloud/ai-security-posture
  30. Detect and investigate threats to AI agents using Microsoft Defender
  31. AgentsInfo table in the advanced hunting schema
  32. https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-cloudappevents-table
  33. Data and AI security dashboard in Microsoft Defender for Cloud