AI SECURITY / AGENTS ON AZURE + MICROSOFT 365

AI security consultant for agents that act.

AI agents read your data and take actions on your behalf. I help you design, test and monitor Microsoft Foundry and Copilot Studio agents so access, data and actions stay under control.

01 / THE RISKS

Where agents go wrong.

Most agent incidents are not exotic. They come from ordinary gaps in access, data handling and oversight that an agent can exploit at speed.

  • Prompt injection: instructions hidden in documents, emails or web content that hijack an agent
  • Data oversharing: agents surface whatever a user can technically access, including badly permissioned files
  • Excessive agency: broad tools, connectors and actions with no approval step
  • Weak identity: shared credentials, over-privileged service accounts and unmanaged secrets
  • Blind spots: no logging, no detections and no way to investigate an agent incident
  • Shadow AI: unapproved agents and tools outside security review

02 / HOW I SECURE THEM

Identity, data, guardrails.

I start from the architecture and a threat model, then apply controls in layers.

  • Identity first: Microsoft Entra ID, Conditional Access, least-privilege access and managed identities for agents
  • Data first: permissions cleanup, Microsoft Purview sensitivity labels and DLP before agents see content
  • Guardrails: content filtering, grounding and human approval for high-impact actions
  • Adversarial testing: scenarios informed by the OWASP Top 10 for LLM Applications and MITRE ATLAS
  • Monitoring: logging and detections in Microsoft Defender and Microsoft Sentinel, plus an agent incident playbook
  • Governance: NIST AI RMF and ISO/IEC 42001-informed policies, ownership and evidence
See my ISO 42001 work

03 / WHAT YOU CAN BOOK

Focused engagements.

  • AI agent security review: architecture and threat model
  • Copilot readiness and data oversharing assessment
  • Secure design for a Microsoft Foundry or Copilot Studio rollout
  • Monitoring and AI incident response design

My background is in Microsoft 365 and cloud security, which is why I begin with identity and data rather than the model. You can read more about me.

Discuss your agents

04 / COMMON QUESTIONS

AI security,
answered.

What is prompt injection?

It is an attack where text the agent reads, such as a document, email or web page, contains instructions that override the agent's intended behavior. Defenses combine limited permissions, approval steps for risky actions, input and output controls, and monitoring.

Is my data exposed through Microsoft 365 Copilot?

Copilot works within the permissions of the signed-in user, so the larger risk is often existing oversharing in SharePoint and other repositories. A readiness assessment finds and fixes this before agents amplify it.

Do you test agents against attacks?

Yes. I run adversarial scenarios against your agent design as part of a security review. It reduces risk and improves your controls, but it is not a guarantee that an agent is free of vulnerabilities.

Where does ISO 42001 fit?

Security controls are one part of an AI management system. I can align them with ISO/IEC 42001 so security work also produces governance evidence.

SECURE IT BEFORE IT SCALES

Let's look at your
agents together.

Book a free session