πŸ“Œ Author's note: Independent, not affiliated with or endorsed by Microsoft. This site is a starting point β€” verify current product status against Microsoft documentation before architecture or purchasing decisions.
The starting point

Securing AI with Microsoft β€”
five surfaces, one map, and the licences between you and each control

I spend my working week securing Microsoft AI estates, and the guidance for doing it is scattered across product teams, blogs and licence tiers. This site is the primer I kept wishing I could hand people β€” deliberately small: the concepts you need to orient, and pointers outward for depth. Read the five surfaces, trace your agents on the map, check what your licences actually gate. Then go build.

500,000+ agentsin Microsoft's own tenant β€” this is scale, not a pilot (Customer Zero, Aug 2026)
Four screens count agentsand they disagree by design β€” always say which screen a number came from
Most telemetry is licence-gatedβ€” the dashed lines on the map are where every blind spot lives
πŸ—ΊοΈ
INTERACTIVE
Agent Telemetry Map β€” where do your agents leave a trace?
Seven creation paths Β· fourteen telemetry destinations Β· the licence gate on every table Β· what each connection delivers
β†’
The organising idea

Five AI threat surfaces

Everything on this site hangs off one taxonomy. Your AI estate is five asset classes, each with different risks, different owning controls, and different licence gates β€” and the most common failure I see is securing one class and assuming the others came along for free.

SURFACE 1

AI apps & assistants β†’

M365 Copilot, declarative agents, SaaS AI, shadow AI. The risk is what people paste in and what comes back out.

SURFACE 2

AI platform & workloads β†’

Foundry, Azure OpenAI, RAG pipelines, grounding data. Azure-side risk that no M365 licence covers.

SURFACE 3

Agents β†’

Copilot Studio, Foundry agents, third-party. Sprawl, maker credentials, and the blueprint blast radius.

SURFACE 4

Tools, MCP servers & connectors β†’

Every MCP server is a supply-chain dependency with tenant access β€” an asset with an owner, not plumbing.

SURFACE 5

Endpoints running local AI β†’

Coding CLIs, desktop AI, local model runners β€” inference outside every prompt-logging and DLP path you have. The class most organisations discover last; the one I check first.

Held positions

Five rules I don't bend

Enabled is not covered.
A discovery list is never a protection list.
Blocking relocates risk; it doesn't remove it. People route around controls β€” visibility usually beats prohibition.
An unevaluated asset is a visibility gap, not a pass.
Browser AI is a class-1 asset governed by class-5 mechanisms. Look at the endpoint, not only the tenant.

Then: what licences actually gate Β· where to start, in six phases Β· the deep-dive archive for everything this primer deliberately leaves out.