AI SECURITY / AGENTS ON AZURE + MICROSOFT 365
AI security consultant for agents that act.
AI agents read your data and take actions on your behalf. I help you design, test and monitor Microsoft Foundry and Copilot Studio agents so access, data and actions stay under control.
01 / THE RISKS
Where agents go wrong.
Most agent incidents are not exotic. They come from ordinary gaps in access, data handling and oversight that an agent can exploit at speed.
- Prompt injection: instructions hidden in documents, emails or web content that hijack an agent
- Data oversharing: agents surface whatever a user can technically access, including badly permissioned files
- Excessive agency: broad tools, connectors and actions with no approval step
- Weak identity: shared credentials, over-privileged service accounts and unmanaged secrets
- Blind spots: no logging, no detections and no way to investigate an agent incident
- Shadow AI: unapproved agents and tools outside security review
02 / HOW I SECURE THEM
Identity, data, guardrails.
I start from the architecture and a threat model, then apply controls in layers.
- Identity first: Microsoft Entra ID, Conditional Access, least-privilege access and managed identities for agents
- Data first: permissions cleanup, Microsoft Purview sensitivity labels and DLP before agents see content
- Guardrails: content filtering, grounding and human approval for high-impact actions
- Adversarial testing: scenarios informed by the OWASP Top 10 for LLM Applications and MITRE ATLAS
- Monitoring: logging and detections in Microsoft Defender and Microsoft Sentinel, plus an agent incident playbook
- Governance: NIST AI RMF and ISO/IEC 42001-informed policies, ownership and evidence
03 / WHAT YOU CAN BOOK
Focused engagements.
- AI agent security review: architecture and threat model
- Copilot readiness and data oversharing assessment
- Secure design for a Microsoft Foundry or Copilot Studio rollout
- Monitoring and AI incident response design
My background is in Microsoft 365 and cloud security, which is why I begin with identity and data rather than the model. You can read more about me.
Discuss your agents04 / COMMON QUESTIONS
AI security,
answered.
What is prompt injection?
It is an attack where text the agent reads, such as a document, email or web page, contains instructions that override the agent's intended behavior. Defenses combine limited permissions, approval steps for risky actions, input and output controls, and monitoring.
Is my data exposed through Microsoft 365 Copilot?
Copilot works within the permissions of the signed-in user, so the larger risk is often existing oversharing in SharePoint and other repositories. A readiness assessment finds and fixes this before agents amplify it.
Do you test agents against attacks?
Yes. I run adversarial scenarios against your agent design as part of a security review. It reduces risk and improves your controls, but it is not a guarantee that an agent is free of vulnerabilities.
Where does ISO 42001 fit?
Security controls are one part of an AI management system. I can align them with ISO/IEC 42001 so security work also produces governance evidence.
SECURE IT BEFORE IT SCALES