Never let an AI security conversation drift into "agents only". An enterprise AI estate is five asset classes; coverage on one never implies coverage on another, and each is gated by a different licence axis. This page is the whole taxonomy on one screen.
M365 Copilot, declarative agents, Security Copilot, GitHub Copilot, SaaS AI and shadow AI — the class every employee touches.
| Top risks | Prompt abuse (direct override, extractive abuse, indirect injection), sensitive data entering AI context, shadow AI outside any control |
| Owning controls | Purview audit + DLP for Copilot (CopilotActivity carries per-interaction Jailbreak / XPIA verdicts) · Defender for Cloud Apps for SaaS AI discovery · Edge / network DLP for public LLMs |
| Licence gate | M365 E5 + M365 Copilot for the audited surface; browser and network DLP layers vary |
Microsoft Foundry accounts and projects, Azure OpenAI, custom LLM apps, RAG pipelines, vector stores and the grounding data they read.
| Top risks | Workload compromise, insecure grounding data, model endpoint abuse — and the budgeting error of assuming an M365 licence covers any of it |
| Owning controls | Defender for Cloud (CSPM + AI Services plans) · Foundry guardrails and Prompt Shields · content-filter spans in workspace App Insights |
| Licence gate | Azure axis — per resource and per tokens scanned. No M365 tier covers this |
Deep dive: Foundry control plane
Copilot Studio (Classic and Modern), Foundry agents, declarative agents, third-party SDK and registry-sync agents — things with identity and autonomy.
| Top risks | Sprawl and ungated creation · maker credentials · Classic agents outside the Entra perimeter · one blueprint secret compromising every agent under it |
| Owning controls | Agent 365 registry + Entra Agent ID (Conditional Access, ID Protection, lifecycle) · AgentsInfo posture · runtime spans in CloudAppEvents |
| Licence gate | Agent 365 or M365 E7 — required for Copilot Studio and Foundry agent security since 1 July 2026. Identity objects readable at any Entra tier |
First-party, custom and third-party MCP servers; connectors, plugins and APIs — how agent decisions become real-world actions.
| Top risks | Supply-chain dependencies with tenant access · prompt injection converting to tool execution · unvetted third-party servers |
| Owning controls | MCP vetting gates at procurement · Work IQ governed MCP servers · real-time protection evaluating onboarded MCP tools · McpServers in AgentsInfo |
| Licence gate | Varies — tool-call telemetry (ExecuteToolBy*) needs Agent 365 instrumentation |
Deep dive: MCP security
Coding CLIs, desktop AI apps, local MCP configurations and local model runners on staff and developer devices.
| Top risks | Inference outside every prompt-logging and DLP path · unknown local MCP servers · a class-1 surface governed only by class-5 mechanisms |
| Owning controls | Defender for Endpoint local-agent discovery (AgentsInfo, Platform == "LocalAgents" — vendor, version, host process, trust settings, local + remote MCP servers) · Intune policy · app control |
| Licence gate | MDE P2 (in E5) for discovery and inventory — no Agent 365 needed. Risk scoring needs E7 or A365 + MDE P2 |
Deep dive: Playbooks
Which of the five surfaces does it cover, and which does it silently ignore? Most products cover one or two. The Agent Telemetry Map shows surfaces 3–5 in motion: what each agent type emits, where it lands, and the licence gate on every table.