LIVE FEED
HIGH AI Coding Tools Leak Repos as RemControl Trojan Uses AI Dev // HIGH Carbonato Malware Deploys AI Agents to Hijack Docker Hosts // FIRST LOOK Kontext Security Launches AI Agent Runtime Enforcement Platform // FIRST LOOK Microsoft Defender and Purview Add AI Agent Controls in September 2026 // FIRST LOOK AWS Launches AgentCore Gateway for Multi-Account AI Agents via MCP // CRITICAL Rogue AI Agents Exploit urlquery.net to Bypass Restrictions // CRITICAL OpenAI Agents Breach Australian Medicare Portal via SQLi Probes // HIGH AI Chatbots Poisoned via Web Seeding in Disinformation Campaign // FIRST LOOK Outerlimit Launches Decentralized AI Agent Authorization Layer // FIRST LOOK OWASP Flags AI Agent Unbounded Consumption as Top Enterprise Risk //
FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely RELEVANCE ▲ 7.2

Microsoft Defender and Purview Add AI Agent Controls in September 2026

FIRST LOOK MEDIUM ↗ MODERATE
  • What shipped: Microsoft ships network-layer DLP for AI agent traffic, AI email detonation summaries, and Purview auto-labelling at enterprise scale.
  • Who benefits: SOC teams and data security owners who need visibility and policy enforcement over autonomous AI agents operating on behalf of employees gain the most immediate benefit.
  • Next steps: Enable the Purview + Entra Global Secure Access integration and define classification policies for sensitive data categories before enabling blocking mode · Onboard Security Copilot users to the email detonation summary feature and measure reduction in mean time to investigate phishing incidents · Audit existing OBO agent configurations to identify which agents handle sensitive data and validate that network-layer policies cover those traffic paths
Microsoft Defender and Purview Add AI Agent Controls in September 2026

Defender Impact

The expansion of Microsoft Purview data loss prevention to cover on-behalf-of (OBO) agentic traffic closes a governance blind spot that has widened as autonomous AI agents proliferate across enterprise environments. For the first time, defenders can apply consistent, context-aware data classification and blocking at the network layer regardless of whether the actor is a human employee or an AI agent acting on their behalf.

Capability Overview

Microsoft’s September 2026 update delivers three discrete capabilities across the Defender, Purview, and Entra portfolio.

Network-layer DLP for agentic traffic (Generally Available): Microsoft Purview classification and policy enforcement is now applied by Microsoft Entra Global Secure Access at the network layer. This covers both human-initiated data transfers and OBO agentic traffic — the category of actions performed by AI agents acting on behalf of a user, such as uploading files or querying external services. When a policy detects a sensitive file or text string in transit to a risky destination (for example, a consumer AI application or unsanctioned SaaS tool), the transfer is blocked before data egress occurs. This is a meaningful architectural step: policy enforcement moves from the application layer to the network layer, reducing dependence on per-application DLP agent coverage.

AI-generated email detonation summaries in Security Copilot: SOC analysts investigating suspicious emails can now receive an AI-generated narrative summary of URL and file sandboxing (detonation) results, correlated with contextual signals. This reduces the manual effort of correlating raw sandbox telemetry with threat intelligence, compressing investigation workflows. The feature is available to organisations running both Microsoft Defender and Microsoft Security Copilot.

Enterprise-scale auto-labelling in Microsoft Purview: The update includes improvements to labelling automation designed to reduce administrative overhead at scale. This supports the classification accuracy that the network-layer DLP enforcement depends on — accurate labels are a prerequisite for reliable policy decisions.

Defensive Advances

  • Agentic traffic is now a governed surface. Defenders can discover, classify, and block sensitive data movement regardless of whether the initiating actor is human or an autonomous agent. This is the first generally available Microsoft capability to explicitly address OBO agent data flows at the network layer.
  • Faster phishing triage. Email detonation summaries reduce the cognitive load on tier-1 and tier-2 analysts by surfacing correlated sandbox evidence in plain language, accelerating mean-time-to-respond for email-borne threats.
  • Consistent enforcement posture across human and agent actions. A single policy framework now governs both interaction types, reducing the risk of governance gaps where agents are inadvertently exempt from controls designed for human behaviour.

Residual Gaps

  • Third-party agent frameworks. The OBO enforcement model is currently scoped to agents operating within the Microsoft ecosystem and traffic routed through Entra Global Secure Access. Organisations running autonomous agents on non-Microsoft orchestration frameworks or with direct internet egress paths will not automatically inherit these controls. Separate tooling or network policy will be required for those surfaces.
  • Classification policy maturity is a prerequisite. Network-layer blocking is only as reliable as the underlying Purview classification policies. Organisations with immature or incomplete data classification estates risk both false positives (blocking legitimate agent activity) and false negatives (misclassified sensitive data passing undetected). The auto-labelling improvements help, but this remains an organisational readiness question.
  • Detonation summaries require dual-product licensing. The email investigation feature requires both Microsoft Defender and Security Copilot entitlements. Organisations without Security Copilot licensing cannot access this capability, limiting adoption breadth in the near term.

Framework Mapping

FrameworkTechniqueHow this capability helps
MITRE ATLASAML.T0086 — Exfiltration via AI Agent Tool InvocationNetwork-layer blocking prevents sensitive data reaching external destinations via agent-invoked tooling
MITRE ATLASAML.T0057 — LLM Data LeakageClassification and policy enforcement reduces the risk of sensitive data being transmitted through or to LLM services
MITRE ATLASAML.T0080 — AI Agent Context PoisoningAgent governance controls reduce the blast radius of compromised agent configurations
OWASP LLM06Sensitive Information DisclosureDLP enforcement at the network layer directly addresses this risk for agent-driven data flows
OWASP LLM08Excessive AgencyScoping what agents can send externally limits the potential damage from agents operating beyond intended boundaries

Deployment Considerations

Organisations should sequence adoption in three stages. First, complete or accelerate Purview data classification work — the network-layer enforcement depends on accurate labels. Second, deploy Entra Global Secure Access in audit (report-only) mode to baseline agent and human traffic patterns before enabling blocking. Third, enable blocking policies incrementally, starting with highest-sensitivity classifications, to avoid disrupting legitimate agentic workflows.

Teams should also inventory which AI agents in their environment generate OBO traffic and verify that those traffic paths route through Entra Global Secure Access rather than direct egress points.

Defender Checklist

  • Audit current Purview classification coverage and close gaps before enabling network-layer enforcement
  • Deploy Entra Global Secure Access in audit mode and review OBO agent traffic baselines for at least two weeks before enabling blocking
  • Enable blocking policies for the highest-sensitivity classifications first; expand iteratively
  • Identify all AI agents generating OBO traffic and confirm they route through monitored network paths
  • Onboard eligible analysts to the Security Copilot email detonation summary feature and track triage time delta
  • Review auto-labelling configurations in Purview to reduce manual labelling overhead and improve policy accuracy

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.