๐ Author's note: This site synthesises the author's own understanding from publicly available Microsoft documentation, official Microsoft Security blog posts, RSAC 2026 announcements, and insights from Microsoft Security professionals and MVPs. It is independent and not affiliated with or endorsed by Microsoft. Microsoft updates products and documentation frequently โ always verify current status directly with Microsoft before making architecture or purchasing decisions.
PERSONALISED READING GUIDE
Where should you start?
This guide covers 8 sections of Microsoft AI security. Pick your role and we'll show you exactly which pages matter most โ and why.
๐๏ธ
CISO / Security Leader
EXECUTIVE
โ๏ธ
Security Engineer
TECHNICAL
๐ค
Copilot / M365 Admin
OPERATIONS
๐๏ธ
Power Platform Maker
BUILDER
๐
Compliance / GRC
GOVERNANCE
โญ Day 1: Set up the Security Dashboard for AI โ single pane of glass across your AI estate. GA, 30 min setup.
๐๏ธ As a CISO, your key questions are:
What is our AI agent exposure and how do we compare to best practice?
What are the most dangerous gaps in Microsoft's current AI security stack?
What should I be asking my security team to prioritise right now?
How does this map to frameworks we're already complying with (NIST, ISO)?
The Copilot Studio Specific Risks section with the six risk cards โ no-auth, org-wide sharing, Classic vs Modern, MCP tools, name sync, ownerless agents.
Everything in the "Copilot Studio Specific Risks" section applies directly to what you build. Maker credentials and org-wide sharing are configuration choices you make.
Scenario 3 โ Maker Credential Blast Radius โ walks through exactly what an attacker does with an insecurely built agent. Read it. Then check your agents.
SHOULD READ
MCP
If you're adding MCP tools to your agent, read the "Maker Credentials ร MCP Tools" section. The blast radius compounds with each tool you add.
๐ As a Compliance / GRC professional, your key questions are:
How do Microsoft's AI security controls map to NIST AI RMF and ISO 42001?
What are the gaps in coverage that affect our compliance posture?
How do we evidence AI governance controls for auditors?
What's the roadmap โ what's GA, what's preview, what's missing?
Enter the team passphrase to unlock the AI assistant.
Incorrect passphrase โ please try again.
Hi! I can answer questions about Microsoft AI security based on this site's content โ auth patterns, product coverage, gaps, KQL queries, playbooks, and more. What would you like to know?