📌 Author's note: Independent, not affiliated with or endorsed by Microsoft. This site is a starting point — verify current product status against Microsoft documentation before architecture or purchasing decisions.
The taxonomy

The five AI
threat surfaces

Never let an AI security conversation drift into "agents only". An enterprise AI estate is five asset classes; coverage on one never implies coverage on another, and each is gated by a different licence axis. This page is the whole taxonomy on one screen.

SURFACE 1

AI apps & assistants

M365 Copilot, declarative agents, Security Copilot, GitHub Copilot, SaaS AI and shadow AI — the class every employee touches.

Top risksPrompt abuse (direct override, extractive abuse, indirect injection), sensitive data entering AI context, shadow AI outside any control
Owning controlsPurview audit + DLP for Copilot (CopilotActivity carries per-interaction Jailbreak / XPIA verdicts) · Defender for Cloud Apps for SaaS AI discovery · Edge / network DLP for public LLMs
Licence gateM365 E5 + M365 Copilot for the audited surface; browser and network DLP layers vary

Deep dive: Threats · Playbooks

SURFACE 2

AI platform & workloads

Microsoft Foundry accounts and projects, Azure OpenAI, custom LLM apps, RAG pipelines, vector stores and the grounding data they read.

Top risksWorkload compromise, insecure grounding data, model endpoint abuse — and the budgeting error of assuming an M365 licence covers any of it
Owning controlsDefender for Cloud (CSPM + AI Services plans) · Foundry guardrails and Prompt Shields · content-filter spans in workspace App Insights
Licence gateAzure axis — per resource and per tokens scanned. No M365 tier covers this

Deep dive: Foundry control plane

SURFACE 3

Agents

Copilot Studio (Classic and Modern), Foundry agents, declarative agents, third-party SDK and registry-sync agents — things with identity and autonomy.

Top risksSprawl and ungated creation · maker credentials · Classic agents outside the Entra perimeter · one blueprint secret compromising every agent under it
Owning controlsAgent 365 registry + Entra Agent ID (Conditional Access, ID Protection, lifecycle) · AgentsInfo posture · runtime spans in CloudAppEvents
Licence gateAgent 365 or M365 E7 — required for Copilot Studio and Foundry agent security since 1 July 2026. Identity objects readable at any Entra tier

Deep dive: Agent 365 · Identity

SURFACE 4

Tools, MCP servers & connectors

First-party, custom and third-party MCP servers; connectors, plugins and APIs — how agent decisions become real-world actions.

Top risksSupply-chain dependencies with tenant access · prompt injection converting to tool execution · unvetted third-party servers
Owning controlsMCP vetting gates at procurement · Work IQ governed MCP servers · real-time protection evaluating onboarded MCP tools · McpServers in AgentsInfo
Licence gateVaries — tool-call telemetry (ExecuteToolBy*) needs Agent 365 instrumentation

Deep dive: MCP security

SURFACE 5

Endpoints running local AI

Coding CLIs, desktop AI apps, local MCP configurations and local model runners on staff and developer devices.

Top risksInference outside every prompt-logging and DLP path · unknown local MCP servers · a class-1 surface governed only by class-5 mechanisms
Owning controlsDefender for Endpoint local-agent discovery (AgentsInfo, Platform == "LocalAgents" — vendor, version, host process, trust settings, local + remote MCP servers) · Intune policy · app control
Licence gateMDE P2 (in E5) for discovery and inventory — no Agent 365 needed. Risk scoring needs E7 or A365 + MDE P2

Deep dive: Playbooks

📌 The test to run against any vendor pitch or internal plan

Which of the five surfaces does it cover, and which does it silently ignore? Most products cover one or two. The Agent Telemetry Map shows surfaces 3–5 in motion: what each agent type emits, where it lands, and the licence gate on every table.