I spend my working week securing Microsoft AI estates, and the guidance for doing it is scattered across product teams, blogs and licence tiers. This site is the primer I kept wishing I could hand people β deliberately small: the concepts you need to orient, and pointers outward for depth. Read the five surfaces, trace your agents on the map, check what your licences actually gate. Then go build.
Everything on this site hangs off one taxonomy. Your AI estate is five asset classes, each with different risks, different owning controls, and different licence gates β and the most common failure I see is securing one class and assuming the others came along for free.
M365 Copilot, declarative agents, SaaS AI, shadow AI. The risk is what people paste in and what comes back out.
Foundry, Azure OpenAI, RAG pipelines, grounding data. Azure-side risk that no M365 licence covers.
Copilot Studio, Foundry agents, third-party. Sprawl, maker credentials, and the blueprint blast radius.
Every MCP server is a supply-chain dependency with tenant access β an asset with an owner, not plumbing.
Coding CLIs, desktop AI, local model runners β inference outside every prompt-logging and DLP path you have. The class most organisations discover last; the one I check first.
Then: what licences actually gate Β· where to start, in six phases Β· the deep-dive archive for everything this primer deliberately leaves out.