๐Ÿ“Œ Author's note: This site synthesises the author's own understanding from publicly available Microsoft documentation, official Microsoft Security blog posts, RSAC 2026 announcements, and insights from Microsoft Security professionals and MVPs. It is independent and not affiliated with or endorsed by Microsoft.
FEEDBACK ยท SUGGESTIONS ยท CORRECTIONS

Share your
thoughts

Found something wrong? Have a suggestion? Know about a Microsoft AI security update we've missed? This goes directly to the author โ€” nothing is published publicly.

ABOUT THIS SITE

This site doesn't follow the standard security blog format. It's a curated synthesis โ€” built by reading across Microsoft's official documentation, RSAC announcements, and the field research of practitioners who are closer to the product than most.

Where findings come from specific people โ€” Derk van der Woude's work on Copilot Studio auth patterns, Thalpius's research on orphaned agent identities, Cyphora's Foundry logging analysis โ€” they are named and linked. The goal is to give credit where it belongs and make it easy to go deeper at the source.

The site is independent and not affiliated with Microsoft. It reflects the author's understanding at a point in time โ€” Microsoft updates products frequently and corrections are always welcome. If something here is wrong, outdated, or missing, the form below is the fastest way to get it fixed.

Shashank Raina
Security Architect ยท aiagentsecurity.guide
๐Ÿ“ฌ Subscribe for updates
โš ๏ธ Factual correction
๐Ÿ†• Missing content
๐Ÿ”— Broken link
๐Ÿ’ก General suggestion
๐Ÿ“ Other
0 / 2000
Your feedback is sent to the author via Formspree and never published publicly. Email is optional and only used to reply to your message. Privacy policy โ†’
โœ…
Feedback received โ€” thank you!
The author reviews all submissions. If you left an email and a response is warranted, you'll hear back within a few days.
ABOUT THIS SITE
Who writes this?
This site is written and maintained by a security architect synthesising publicly available Microsoft documentation, official blog posts, RSAC announcements, and insights from Microsoft Security professionals and MVPs. It is independent โ€” not affiliated with or endorsed by Microsoft.
How often is it updated?
Significant content changes are tracked in the Changelog. The site is updated when meaningful new announcements, corrections, or field research becomes available โ€” typically within days of major Microsoft security events.
Privacy Policy

Privacy & Data โ€” Plain English

This site does not use cookies, does not track you across other sites, and does not sell your data. The only personal information collected is what you voluntarily submit via the contact form above.

What we collect and why

Contact form submissions

Name and email (if provided) are sent to and stored by Formspree. Used only to respond to your message. Email is optional. Submissions retained as long as needed to respond, then deleted. To request deletion, use the form above.

Web analytics

This site uses Cloudflare Web Analytics โ€” cookieless, no fingerprinting, no individual tracking, no data shared with advertisers. Aggregate anonymised metrics only (page views, referrer, approximate region).

AI chat widget

Password-protected, internal only. Messages processed in real time by the Anthropic API and not stored by this site. Sessions are ephemeral โ€” closing the tab clears everything.

Cookies

This site sets no cookies. Cloudflare may set technical delivery cookies โ€” not used for tracking. See Cloudflare's cookie policy.

Newsletter

Substack handles all newsletter data independently under their own privacy policy. This site has no access to subscriber data.

Your rights (GDPR)

EEA residents may request access, correction, or deletion of any personal data held (contact form submissions only). Use the form above.

Third-party services

ServicePurposePrivacy policy
Cloudflare PagesHosting and deliverycloudflare.com/privacypolicy
FormspreeContact form processingformspree.io/legal
Anthropic APIAI chat responsesanthropic.com/privacy
SubstackNewsletter subscriptionssubstack.com/privacy

This site is operated by Shashank Raina, independent security architect. Not affiliated with or endorsed by Microsoft. Changelog ยท Last updated: May 1, 2026.

STAY UPDATED
Get notified when Microsoft AI security changes
Monthly updates on new controls, GA announcements, and critical gaps โ€” direct to your inbox.
Subscribe to updates โ†’
aiagentsecurity.substack.com ยท Free ยท No spam