Securing and Governing AI Agents with Microsoft Purview: Best Practices and Architecture
Explore AI security risks, governance strategies, and how Microsoft Purview enables data protection, compliance, and monitoring for AI agents in multi-cloud environments.
Securing and Governing AI Agents with Microsoft Purview: Best Practices and Architecture
2.
About Me
Emad AdelTadros
Senior Cloud Architect
• Microsoft MVP (2025–2027)
• Microsoft Certified Trainer (MCT) since 2012
• 18+ years of IT & Cloud experience
• Founder, Egypt Azure Community
• Multi-Cloud: Azure, AWS, Google Cloud
• AI, Microsoft AI Foundry, Purview, Security & Governance
3.
Agenda
What we’ll cover:
•Key AI security risks
• Governing and securing AI agents
• Agent governance and security architecture
• What is Microsoft Purview?
• Purview for AI agents and compliance
4.
Key AI
security risks
Manyorganizations lack visibility into:
• Who is using AI tools
• What data is being shared
• How AI-generated content is used or stored
AI agent controlplane
Microsoft Entra
Microsoft Purview
Microsoft Defender
Azure Monitor
Microsoft Entra for AI agent identity.
Microsoft Purview for data governance and compliance for AI agents.
Microsoft Defender for AI agent security monitoring
Azure Monitor for centralized monitoring of Microsoft Foundry and Copilot
Studio agents.
14.
DEFINITION
What is MicrosoftPurview?
Microsoft Purview is a unified data governance, security, and compliance platform that helps
organizations manage and protect their data across environments.
17.
Understand data classificationand protection
To protect data effectively, organizations need to understand what they have and how sensitive it is.
Data classification: Detect sensitive content using sensitive information types and trainable
classifiers.
Sensitivity labels: Apply consistent rules to classify and protect data.
Encryption: Enforce access control for files and emails.
DLP and retention: Reduce exposure and preserve important information.
Together, these capabilities help organizations protect sensitive data while supporting productive work.
18.
Secure AI interactionswith Microsoft Purview
Securing AI interactions requires a clear process that helps you understand usage, protect sensitive
content, and apply consistent controls.
Identify AI usage
See which AI tools
are used and how
they handle sensitive
data.
Protect sensitive
content
Apply labeling, DLP,
and access controls
during AI interactions.
Govern AI-generated
content
Manage prompts,
responses, and
generated outputs.
Detect unsafe activity
Find risky or
noncompliant AI
behavior.
Protect AI
environments
Apply consistent
policies across AI
experiences.
20.
Review AI appand agent activity
The Apps and agents (preview) page shows activity patterns for each AI app and agent so you can see
where sensitive interactions are happening.
• Review usage trends for each app or agent to
see how often they’re used and whether
activity is increasing.
• Filter by protection status to see which apps are
protected by policies and which might need
attention.
• Select an app or agent to view details such as
alerts, risk distribution, prompts, or response
activity.
• Run the agent report to identify the most active,
most risky, or least-used agents.
• DSPM andDSPM for AI (classic)
• Auditing
• Data classification
• Sensitivity labels
• Data loss prevention
• Insider Risk Management
• Communication compliance
• eDiscovery
• Data Lifecycle Management
• Compliance Manager
Capability or solution in Microsoft Purview