{"id":25255,"date":"2026-08-27T08:45:00","date_gmt":"2026-08-27T15:45:00","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=25255"},"modified":"2026-09-01T16:27:38","modified_gmt":"2026-09-01T23:27:38","slug":"securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/","title":{"rendered":"Securing AI agents in the enterprise: Learnings from our journey at Microsoft"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">As AI agents become more sophisticated and autonomous, large enterprises like ours face a fundamental challenge: How do you enable powerful new AI experiences among your employees without compromising security, governance, or operational control?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That was the guiding mantra behind an ambitious cross-company effort involving our team in Microsoft Digital\u2014the company\u2019s IT organization\u2014and a number of our product teams. The effort, internally referred to as the Securing AI Agents initiative, brought together teams from Microsoft Digital, Windows, Entra, Intune, Defender, Purview, and Microsoft Security to validate secure AI agent scenarios inside Microsoft&#8217;s corporate tenant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Together, we set out to prove that AI agents could operate safely inside a real enterprise environment, not just in a controlled demonstration.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Ragini-Singh.png\" alt=\"A photo of Singh.\" class=\"wp-image-25258\" style=\"width:150px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Ragini-Singh.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Ragini-Singh-300x300.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Ragini-Singh-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;Securing AI in the enterprise at pace requires an integrated, full-stack approach. By validating these capabilities together at enterprise scale, we\u2019re generating the real-world learning to strengthen Microsoft\u2019s products and give customers a trusted blueprint for secure AI adoption.&#8221;<\/p>\n<cite>Ragini Singh, partner group engineering manager, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">As part of our role as the company\u2019s <a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/customer-zero\/\">Customer Zero<\/a>, this work was recently <a href=\"https:\/\/www.youtube.com\/watch?v=J7ol1VDkg7w\" target=\"_blank\" rel=\"noreferrer noopener\">showcased by Samantha Song and Scott Hanselman<\/a> at the Microsoft Build 2026 conference<strong>.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSecuring AI in the enterprise at pace requires an integrated, full-stack approach,\u201d says Ragini Singh, a partner group engineering manager in Microsoft Digital. \u201cBy validating these capabilities together at enterprise scale, we\u2019re generating the real-world learning to strengthen Microsoft\u2019s products and give customers a trusted blueprint for secure AI adoption. Looking ahead, our vision is to make this integrated security foundation the standard for every enterprise, so organizations can scale autonomous agents with speed, confidence, and trust.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Secure AI Agents initiative was the result of an all-hands-on-deck project behind the scenes here at Microsoft: Months of testing, coordination, validation, and refinement that transformed an emerging concept into a governable enterprise pattern.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Shyam-Sunder-Gogi.png\" alt=\"A photo of Gogi.\" class=\"wp-image-25260\" style=\"width:150px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Shyam-Sunder-Gogi.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Shyam-Sunder-Gogi-300x300.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Shyam-Sunder-Gogi-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cAll of these teams came together and not only enabled the environment in our IT tenant but also ensured that all the right policies were deployed to make it so that these agents can run safely. That meant not bypassing any of the security parameters that we\u2019ve already deployed.\u201d<\/p>\n<cite>Shyam Sunder Gogi, technical program manager, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Shyam Sunder Gogi, a technical program manager in Microsoft Digital, served as the organizer of the effort, which initially began with a two-week sprint to get ready for <a href=\"https:\/\/build.microsoft.com\/en-US\/sessions\/KEY01?source=sessions\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Build 2026<\/a>. The project eventually involved more than 70 stakeholders representing different product and business groups.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAll of these teams came together and not only enabled the environment in our IT tenant but also ensured that all the right policies were deployed to make it so that these agents can run safely,\u201d Gogi says. \u201cThat meant not bypassing any of the security parameters that we\u2019ve already deployed.\u201d<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Testing in real-world scenarios<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Rather than validating solutions in an isolated sandbox, we ran a pilot inside Microsoft Digital, standing up a dedicated Windows 365 Cloud PC environment for roughly 100 internal users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pilot participants put the solution through its paces across common developer scenarios. These included:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Windows OS images with Copilot CLI and OpenClaw pre-installed<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Windows 365 Cloud PC provisioning<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Entra Agent IDs to distinguish human and agent identities<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Defender runtime protection and Purview data loss prevention policies<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Intune device and agent configuration policies<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/global-secure-access\/overview-what-is-global-secure-access\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Entra Global Secure Access (GSA)<\/a> network security controls at runtime<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Our goal was to pressure-test a full stack of security guardrails, and to do it the way an actual customer would: with real users and real workloads.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Customer Zero only works if you&#8217;re willing to be the first to hit the rough edges,&#8221; says&nbsp;Tom McCleery, a principal group cloud network engineering manager on the Microsoft Infrastructure, Network and Tenant (MINT) team here in Microsoft Digital. &#8220;We took the agent scenarios into a live tenant with real users, found the issues product teams couldn&#8217;t have surfaced in a lab, and fed every one of them back to the team to address before this ever reached broader enterprise readiness.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The decision to use Windows 365 Cloud PCs in the pilot proved important.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We want these device agents to run on our employees\u2019 primary machines, and when necessary, to run on a secondary machine that can be easily isolated and reset if needed,&#8221; says Dave Rodriguez, a principal product manager for the Endpoint Experience (EE) team in Microsoft Digital. &#8220;That&#8217;s why we chose to go with Windows 365 Cloud PCs as a corporate-bound, non-primary environment, where we could have our end users work with those machines as they would with any other device.&#8221;<strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The approach created a safe environment for experimentation while giving teams realistic deployment conditions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;With Windows 365, there&#8217;s no real impact to the devices that we\u2019re using,&#8221; says Harshitha Digumarthi, a senior product manager on the EE team. &#8220;I really love how we leveraged Windows 365 for piloting this, iterating each time there was a change.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Digumarthi and her team helped to establish and validate all administrative controls and policies, confirm that they function as expected, and execute a phased rollout strategy\u2014starting with pilots and expanding incrementally while proactively monitoring for risks and user impact.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Identity, data, and network controls under load<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Much of the runtime security work fell to our Microsoft Digital team, which validated how the controls behaved once agents were actually operating. A foundational aspect was telling humans and agents apart, so that rules and governance can be more clearly defined based on who is overseeing a process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Entra Agent IDs let us give an agent its own distinct identity, instead of having it borrow a person&#8217;s,&#8221; says&nbsp;Joshua Green, principal software engineering manager on the Microsoft Digital team. &#8220;Once you can cleanly separate human and agent identities, everything downstream\u2014access decisions, auditing, runtime protection\u2014gets dramatically more trustworthy.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the protection and data-governance side, MINT exercised Defender and Purview against agent activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;We validated Defender runtime protection and Purview data loss prevention against live agent behavior,&#8221; says&nbsp;Diego Baccino, a principal software engineering manager on the MINT team. &#8220;It&#8217;s one thing to write a DLP policy; it&#8217;s another to confirm that it actually catches what an autonomous agent might try to move. That testing is exactly the kind of value that Customer Zero adds.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Network-layer controls rounded out the stack.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pradeep-Kunjunny.png\" alt=\"A photo of Kunjunny. \" class=\"wp-image-25261\" style=\"width:150px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pradeep-Kunjunny.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pradeep-Kunjunny-300x300.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Pradeep-Kunjunny-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;Entra Agent IDs let us give an agent its own distinct identity, instead of having it borrow a person&#8217;s. Once you can cleanly separate human and agent identities, everything downstream\u2014access decisions, auditing, runtime protection\u2014gets dramatically more trustworthy.&#8221;<\/p>\n<cite>Pradeep Kunjunny, principal PM manager, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">This was the advantage of using Global Secure Access, showing that the effort worked with traffic loads generated by a real agent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Entra Agent IDs let us give an agent its own distinct identity, instead of having it borrow a person&#8217;s,&#8221; says&nbsp;Pradeep Kunjunny, a principal PM manager in Microsoft Digital. &#8220;Once you can cleanly separate human and agent identities, everything downstream\u2014access decisions, auditing, runtime protection\u2014gets dramatically more trustworthy.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">From pilot to platform<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Across the initiative, Microsoft Digital drove coordination and execution across multiple organizations.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Aarkarsh-Nair.png\" alt=\"A photo of Nair.\" class=\"wp-image-25262\" style=\"width:150px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Aarkarsh-Nair.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Aarkarsh-Nair-300x300.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Aarkarsh-Nair-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cOur close collaboration with Microsoft Digital demonstrates the power of validating security capabilities for AI agents in one of the world\u2019s largest and most complex enterprise environments. The insights we gain from real users and workloads help us strengthen our products and give customers greater confidence as they adopt AI agents securely.\u201d<\/p>\n<cite>Aakarsh Nair, vice president of engineering, Microsoft Security<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Pilot onboarding, validation of Intune-managed control rollouts, and rapid issue-triage loops improved decision confidence before it was demonstrated at Build, and it shaped the product to prepare it for broader enterprise use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOur close collaboration with Microsoft Digital demonstrates the power of validating security capabilities for AI agents in one of the world\u2019s largest and most complex enterprise environments,\u201d says Aakarsh Nair, vice president of engineering in Microsoft Security. \u201cThe insights we gain from real users and workloads help us strengthen our products and give customers greater confidence as they adopt AI agents securely.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result is a validated blueprint\u2014endpoint, identity, data, and network controls working together\u2014that our customers can now look to as they bring AI agents to their own tenants.<\/p>\n\n\n\n<figure class=\"wp-block-image alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Oltunde-Makinde.png\" alt=\"A photo of Makinde.\" class=\"wp-image-25264\" style=\"width:150px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Oltunde-Makinde.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Oltunde-Makinde-300x300.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/Oltunde-Makinde-150x150.png 150w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cThe winners in enterprise AI won\u2019t just be the teams with the best model experience. They\u2019ll be the teams that make AI operationally trustworthy within the enterprise.\u201d<\/p>\n<cite>Tunde Makinde, senior service engineer, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">It was an initiative that was all about proving that secure AI agent scenarios could work in a real enterprise environment, not just in a demo or a lab setup.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThe winners in enterprise AI won\u2019t just be the teams with the best model experience,\u201d says Tunde Makinde, a senior service engineer for tenant integration and management engineering in Microsoft Digital. \u201cThey\u2019ll be the teams that make AI operationally trustworthy within the enterprise.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our Secure AI Agents initiative is reinforcing a lesson we&#8217;ve learned repeatedly as Customer Zero for the company: Successfully deploying AI in the enterprise isn&#8217;t just about delivering innovative capabilities, it\u2019s about ensuring that identity, endpoint, network, runtime, and data protections work together as a cohesive system, enabling employees to use new technologies with confidence while maintaining the governance and security standards that organizations expect.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cBy validating these capabilities together at enterprise scale, we&#8217;re generating real-world learning to strengthen our products and give customers a trusted blueprint for secure AI adoption.\u201d<\/p>\n<cite>Ragini Singh, partner group engineering manager, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">By bringing together teams from across Microsoft and validating these capabilities in a live enterprise environment, we were able to test how AI agents perform under real-world conditions. The result was more than a successful Build demonstration. It was a practical blueprint that informs how we build our products and provides valuable guidance for companies preparing to adopt agents at scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSecuring AI in the enterprise at pace requires an integrated, full-stack approach,\u201d Singh says. \u201cThat\u2019s why our team in Microsoft Digital brought together Microsoft Agent 365, Windows 365, Intune, Entra Agent ID and Global Secure Access, Defender, and Purview to secure our agents.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Working in concert across endpoint, identity, network, runtime, and data, our partnership helped establish the layered security model needed to secure our AI agents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cBy validating these capabilities together at enterprise scale, we&#8217;re generating real-world learning to strengthen our products and give customers a trusted blueprint for secure AI adoption,\u201d she says.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Looking ahead, our vision is to make this integrated security foundation the standard for every enterprise, so organizations can scale autonomous agents with speed, confidence, and trust.<\/p>\n\n\n\n<div class=\"wp-block-group has-white-200-background-color has-background has-global-padding is-layout-constrained wp-container-core-group-is-layout-37425b6a wp-block-group-is-layout-constrained\" style=\"padding-top:var(--wp--preset--spacing--rd-xs);padding-right:var(--wp--preset--spacing--rd-xs);padding-bottom:var(--wp--preset--spacing--rd-xs);padding-left:var(--wp--preset--spacing--rd-xs)\">\n<h3 class=\"wp-block-heading\" style=\"margin-top:0;margin-bottom:0\">Key takeaways<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Keep these tips in mind as you consider deploying AI agents within your own enterprise organization:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Don&#8217;t miss an opportunity to think big.<\/strong> A two-week sprint for the Build 2026 conference turned into a much bigger cross-company effort to test secure AI agents in the enterprise.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Find the balance between controlled testing environments and real-world scenarios.<\/strong> Windows 365 Cloud PCs provided a safe environment for experimentation while creating real conditions that users will experience.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Differentiate between humans and agents. <\/strong>Access, security, and decision making gets easier when there are clearly defined roles for humans and agents.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Think about operational reality for AI in the enterprise. <\/strong>There\u2019s a difference between a promising capability and a governable enterprise pattern. Create tests that will help you understand the opportunities in real tenant conditions.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Try it out<\/h3>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/securing-the-new-risk-surface-local-agents-claws-and-open-runtimes\/4524602?OCID=InsideTrack_Product_10918\" target=\"_blank\" rel=\"noreferrer noopener\">Find out how your organization can secure your systems against threats posed by localized AI agents and other internal technologies.<\/a><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Related links<\/h3>\n\n\n\n<ul style=\"margin-top:var(--wp--preset--spacing--spacing-20)\" class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/microsoft-ciso-advice-how-to-build-trustworthy-agentic-ai\/\">Read advice from a Microsoft deputy CISO about building trustworthy agentic AI.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/blog\/2026\/06\/02\/introducing-microsoft-scout-your-always-on-personal-agent\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn about Microsoft Scout, an always-on personal agent powered by OpenClaw.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.youtube.com\/watch?v=J7ol1VDkg7w\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the Microsoft Build demo of sandboxed OpenClaw in the&nbsp;Build 2026 Keynote.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/blogs.windows.com\/windowsdeveloper\/2026\/06\/02\/build-2026-furthering-windows-as-the-trusted-platform-for-development\/\" target=\"_blank\" rel=\"noreferrer noopener\">Get more news from Build 2026: Furthering Windows as the trusted platform for development.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/blogs.windows.com\/windowsdeveloper\/2026\/06\/02\/windows-platform-security-for-ai-agents\/\" target=\"_blank\" rel=\"noreferrer noopener\">Find out more information on Windows platform security for AI agents.<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>As AI agents become more sophisticated and autonomous, large enterprises like ours face a fundamental challenge: How do you enable powerful new AI experiences among your employees without compromising security, governance, or operational control? That was the guiding mantra behind an ambitious cross-company effort involving our team in Microsoft Digital\u2014the company\u2019s IT organization\u2014and a number [&hellip;]<\/p>\n","protected":false},"author":234,"featured_media":25256,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[199,920,923,904,820,922,237,903,937,419],"coauthors":[918],"class_list":["post-25255","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-digital","tag-ai","tag-ai-and-copilot","tag-cloud-platform","tag-customer-zero","tag-device-management","tag-digital-worker","tag-governance","tag-security","tag-security-and-governance","tag-zero-trust","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Inside Track - Securing AI agents in the enterprise: Learnings from our journey at Microsoft<\/title>\n<meta name=\"description\" content=\"Learn how agents can operate safely and securely inside a real enterprise environment like ours here at Microsoft.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Inside Track - Securing AI agents in the enterprise: Learnings from our journey at Microsoft\" \/>\n<meta property=\"og:description\" content=\"Learn how agents can operate safely and securely inside a real enterprise environment like ours here at Microsoft.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-27T15:45:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-01T23:27:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10918-Hero_image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1293\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Mark Armstrong\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mark Armstrong\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/\"},\"author\":{\"name\":\"Mark Armstrong\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/f67ab771617afb5ca855a1ed4a320344\"},\"headline\":\"Securing AI agents in the enterprise: Learnings from our journey at Microsoft\",\"datePublished\":\"2026-08-27T15:45:00+00:00\",\"dateModified\":\"2026-09-01T23:27:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/\"},\"wordCount\":1998,\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10918-Hero_image.jpg\",\"keywords\":[\"AI\",\"AI and Copilot\",\"Cloud platform\",\"Customer Zero\",\"Device management\",\"Digital worker\",\"Governance\",\"Security\",\"Security and governance\",\"Zero Trust\"],\"articleSection\":[\"Microsoft Digital\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/\",\"name\":\"Inside Track - Securing AI agents in the enterprise: Learnings from our journey at Microsoft\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10918-Hero_image.jpg\",\"datePublished\":\"2026-08-27T15:45:00+00:00\",\"dateModified\":\"2026-09-01T23:27:38+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/f67ab771617afb5ca855a1ed4a320344\"},\"description\":\"Learn how agents can operate safely and securely inside a real enterprise environment like ours here at Microsoft.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10918-Hero_image.jpg\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2026\\\/08\\\/10918-Hero_image.jpg\",\"width\":2300,\"height\":1293,\"caption\":\"An ambitious Customer Zero effort across Microsoft showed us how to secure our AI agents.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Securing AI agents in the enterprise: Learnings from our journey at Microsoft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/f67ab771617afb5ca855a1ed4a320344\",\"name\":\"Mark Armstrong\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c1df08d431d50629d4dc93c0bb303092d0ab9e80272d9af9589ffcc6bb6e4a35?s=96&d=mm&r=g688774f8f5d4d38ab58bfa32e2a4aa89\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c1df08d431d50629d4dc93c0bb303092d0ab9e80272d9af9589ffcc6bb6e4a35?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c1df08d431d50629d4dc93c0bb303092d0ab9e80272d9af9589ffcc6bb6e4a35?s=96&d=mm&r=g\",\"caption\":\"Mark Armstrong\"},\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/author\\\/marmstrong\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Inside Track - Securing AI agents in the enterprise: Learnings from our journey at Microsoft","description":"Learn how agents can operate safely and securely inside a real enterprise environment like ours here at Microsoft.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/","og_locale":"en_US","og_type":"article","og_title":"Inside Track - Securing AI agents in the enterprise: Learnings from our journey at Microsoft","og_description":"Learn how agents can operate safely and securely inside a real enterprise environment like ours here at Microsoft.","og_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/","og_site_name":"Inside Track","article_published_time":"2026-08-27T15:45:00+00:00","article_modified_time":"2026-09-01T23:27:38+00:00","og_image":[{"width":2300,"height":1293,"url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10918-Hero_image.jpg","type":"image\/jpeg"}],"author":"Mark Armstrong","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Mark Armstrong","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/#article","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/"},"author":{"name":"Mark Armstrong","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/f67ab771617afb5ca855a1ed4a320344"},"headline":"Securing AI agents in the enterprise: Learnings from our journey at Microsoft","datePublished":"2026-08-27T15:45:00+00:00","dateModified":"2026-09-01T23:27:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/"},"wordCount":1998,"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10918-Hero_image.jpg","keywords":["AI","AI and Copilot","Cloud platform","Customer Zero","Device management","Digital worker","Governance","Security","Security and governance","Zero Trust"],"articleSection":["Microsoft Digital"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/","name":"Inside Track - Securing AI agents in the enterprise: Learnings from our journey at Microsoft","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/#primaryimage"},"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10918-Hero_image.jpg","datePublished":"2026-08-27T15:45:00+00:00","dateModified":"2026-09-01T23:27:38+00:00","author":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/f67ab771617afb5ca855a1ed4a320344"},"description":"Learn how agents can operate safely and securely inside a real enterprise environment like ours here at Microsoft.","breadcrumb":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/#primaryimage","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10918-Hero_image.jpg","contentUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10918-Hero_image.jpg","width":2300,"height":1293,"caption":"An ambitious Customer Zero effort across Microsoft showed us how to secure our AI agents."},{"@type":"BreadcrumbList","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/securing-ai-agents-in-the-enterprise-learnings-from-our-journey-at-microsoft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.microsoft.com\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"Securing AI agents in the enterprise: Learnings from our journey at Microsoft"}]},{"@type":"WebSite","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/","name":"Inside Track","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/f67ab771617afb5ca855a1ed4a320344","name":"Mark Armstrong","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c1df08d431d50629d4dc93c0bb303092d0ab9e80272d9af9589ffcc6bb6e4a35?s=96&d=mm&r=g688774f8f5d4d38ab58bfa32e2a4aa89","url":"https:\/\/secure.gravatar.com\/avatar\/c1df08d431d50629d4dc93c0bb303092d0ab9e80272d9af9589ffcc6bb6e4a35?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c1df08d431d50629d4dc93c0bb303092d0ab9e80272d9af9589ffcc6bb6e4a35?s=96&d=mm&r=g","caption":"Mark Armstrong"},"url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/author\/marmstrong\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-6zl","jetpack_featured_media_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2026\/08\/10918-Hero_image.jpg","_links":{"self":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/25255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/234"}],"replies":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=25255"}],"version-history":[{"count":3,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/25255\/revisions"}],"predecessor-version":[{"id":25363,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/25255\/revisions\/25363"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/25256"}],"wp:attachment":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=25255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=25255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=25255"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=25255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}