Microsoft Dives into AI Agent Governance at Ignite Security Event
Microsoft's upcoming Ignite security event is centered around AI agents with real access to identities, data, and cloud resources. The company argues that every decision to adopt an agent is a trust decision, and this idea shapes the entire week-long event. Four security themes will run across all four days of the conference.
The main focus of Microsoft's Agent 365 is on extending the infrastructure companies already use for managing and securing people to agents. Joy Chik, Microsoft's president of identity and network access, said that Agent 365 takes this infrastructure and extends it to agents, including a registry to show every agent in an organization.
The sequence of steps outlined by Chik is inventory first, then permissions, and finally monitoring. For human accounts, identity teams already work through these steps, but for agents, more weight will be put on context-aware conditional access policies. Microsoft keeps coming back to governance, and the scale of agent adoption it expects could explain why.
The CDW research cited by BizTech found that only 51% of respondents said their organization has an established data governance framework. This suggests that deciding what each agent is allowed to see is where the work sits. Chik's sequence starts with the registry, then moves to access control, which implies that an inventory of registered and shadow agents could be the first step.