An AI agent needs its own identity, but a human sponsor must remain accountable for its purpose and actions. A practical look at ownership, oversight, and responsibility.
I've been breaking down Microsoft's security stack since before Entra ID was even called Entra ID. No fluff, no paywalls — just technical depth on Entra, Sentinel, Defender, Purview, and Azure Security that the official docs rarely give you.

Discussion on technical topics and MVP path exploration. Pick the intensity that fits your timeline. Only for Individuals.
An AI agent needs its own identity, but a human sponsor must remain accountable for its purpose and actions. A practical look at ownership, oversight, and responsibility.
Secure AI agents beyond the prompt: enforce tool authorization, control retrieval and memory, test side effects, and recover a critical workflow without compromised identities.
A practical reading of Microsoft's 2026 report: follow phishing and stolen sessions into application identities, software builds, and business data, then test containment.
Azure Container Apps Sandboxes are generally available. This is what the new portal, microVM isolation, egress policy, managed identity injection, VNet integration, IaC, and observability mean for agent platforms.
Microsoft Sentinel's September 2026 update unifies data lake onboarding, retention, Advanced Hunting, Fabric compute, and Incident Cases. Here is what changes for SOC architecture and agent-assisted response.
Copilot Studio can delegate work to Foundry, A2A, and Microsoft 365 Agents SDK agents. This security architecture guide maps identity, context, tool, network, and audit controls across every hop.
The second part of the series looks at policy as code, drift reconciliation, security scanning, GitHub environments, and how AI can participate in remediation without undermining the trust boundary.