Defender Impact
The expansion of Microsoft Purview data loss prevention to cover on-behalf-of (OBO) agentic traffic closes a governance blind spot that has widened as autonomous AI agents proliferate across enterprise environments. For the first time, defenders can apply consistent, context-aware data classification and blocking at the network layer regardless of whether the actor is a human employee or an AI agent acting on their behalf.
Capability Overview
Microsoft’s September 2026 update delivers three discrete capabilities across the Defender, Purview, and Entra portfolio.
Network-layer DLP for agentic traffic (Generally Available): Microsoft Purview classification and policy enforcement is now applied by Microsoft Entra Global Secure Access at the network layer. This covers both human-initiated data transfers and OBO agentic traffic — the category of actions performed by AI agents acting on behalf of a user, such as uploading files or querying external services. When a policy detects a sensitive file or text string in transit to a risky destination (for example, a consumer AI application or unsanctioned SaaS tool), the transfer is blocked before data egress occurs. This is a meaningful architectural step: policy enforcement moves from the application layer to the network layer, reducing dependence on per-application DLP agent coverage.
AI-generated email detonation summaries in Security Copilot: SOC analysts investigating suspicious emails can now receive an AI-generated narrative summary of URL and file sandboxing (detonation) results, correlated with contextual signals. This reduces the manual effort of correlating raw sandbox telemetry with threat intelligence, compressing investigation workflows. The feature is available to organisations running both Microsoft Defender and Microsoft Security Copilot.
Enterprise-scale auto-labelling in Microsoft Purview: The update includes improvements to labelling automation designed to reduce administrative overhead at scale. This supports the classification accuracy that the network-layer DLP enforcement depends on — accurate labels are a prerequisite for reliable policy decisions.
Defensive Advances
- Agentic traffic is now a governed surface. Defenders can discover, classify, and block sensitive data movement regardless of whether the initiating actor is human or an autonomous agent. This is the first generally available Microsoft capability to explicitly address OBO agent data flows at the network layer.
- Faster phishing triage. Email detonation summaries reduce the cognitive load on tier-1 and tier-2 analysts by surfacing correlated sandbox evidence in plain language, accelerating mean-time-to-respond for email-borne threats.
- Consistent enforcement posture across human and agent actions. A single policy framework now governs both interaction types, reducing the risk of governance gaps where agents are inadvertently exempt from controls designed for human behaviour.
Residual Gaps
- Third-party agent frameworks. The OBO enforcement model is currently scoped to agents operating within the Microsoft ecosystem and traffic routed through Entra Global Secure Access. Organisations running autonomous agents on non-Microsoft orchestration frameworks or with direct internet egress paths will not automatically inherit these controls. Separate tooling or network policy will be required for those surfaces.
- Classification policy maturity is a prerequisite. Network-layer blocking is only as reliable as the underlying Purview classification policies. Organisations with immature or incomplete data classification estates risk both false positives (blocking legitimate agent activity) and false negatives (misclassified sensitive data passing undetected). The auto-labelling improvements help, but this remains an organisational readiness question.
- Detonation summaries require dual-product licensing. The email investigation feature requires both Microsoft Defender and Security Copilot entitlements. Organisations without Security Copilot licensing cannot access this capability, limiting adoption breadth in the near term.
Framework Mapping
| Framework | Technique | How this capability helps |
|---|---|---|
| MITRE ATLAS | AML.T0086 — Exfiltration via AI Agent Tool Invocation | Network-layer blocking prevents sensitive data reaching external destinations via agent-invoked tooling |
| MITRE ATLAS | AML.T0057 — LLM Data Leakage | Classification and policy enforcement reduces the risk of sensitive data being transmitted through or to LLM services |
| MITRE ATLAS | AML.T0080 — AI Agent Context Poisoning | Agent governance controls reduce the blast radius of compromised agent configurations |
| OWASP LLM06 | Sensitive Information Disclosure | DLP enforcement at the network layer directly addresses this risk for agent-driven data flows |
| OWASP LLM08 | Excessive Agency | Scoping what agents can send externally limits the potential damage from agents operating beyond intended boundaries |
Deployment Considerations
Organisations should sequence adoption in three stages. First, complete or accelerate Purview data classification work — the network-layer enforcement depends on accurate labels. Second, deploy Entra Global Secure Access in audit (report-only) mode to baseline agent and human traffic patterns before enabling blocking. Third, enable blocking policies incrementally, starting with highest-sensitivity classifications, to avoid disrupting legitimate agentic workflows.
Teams should also inventory which AI agents in their environment generate OBO traffic and verify that those traffic paths route through Entra Global Secure Access rather than direct egress points.
Defender Checklist
- Audit current Purview classification coverage and close gaps before enabling network-layer enforcement
- Deploy Entra Global Secure Access in audit mode and review OBO agent traffic baselines for at least two weeks before enabling blocking
- Enable blocking policies for the highest-sensitivity classifications first; expand iteratively
- Identify all AI agents generating OBO traffic and confirm they route through monitored network paths
- Onboard eligible analysts to the Security Copilot email detonation summary feature and track triage time delta
- Review auto-labelling configurations in Purview to reduce manual labelling overhead and improve policy accuracy