Category Archives: Security

From Guardrails to Controls: Getting Started with Azure AI Content Safety

In my previous article, “From Prompt to Privilege Practical Guardrails for Securing Agentic AI and MCP,” we looked at Agentic AI security from a broader architectural perspective.
The key takeaway was simple: securing AI systems cannot rely on a single control.
As AI applications evolve from answering questions to retrieving enterprise data, calling tools, interacting with APIs and eventually performing actions on behalf of users, the security model also needs to evolve. Identity, authorization, data protection, prompt protection, content filtering, monitoring and agent behaviour controls all become part of the same security story.

But architecture diagrams are only the beginning.

The next question is:

What do these guardrails actually look like when we implement them?
That is what I want to explore in this series.
Rather than trying to cover every AI security control in one large article, I will take them one at a time, deploy them, test them and document what happens.

For the first control, I am starting with Azure AI Content Safety.
Microsoft describes Azure AI Content Safety as a service for detecting harmful user-generated and AI-generated content.
Its capabilities include text and image analysis, Prompt Shields, groundedness detection, protected material detection, custom categories and Task Adherence.

Why start with Azure AI Content Safety?
When we think about securing a traditional application, we normally place controls around identities, networks, applications and data.

Generative AI introduces an additional trust boundary:

Natural language input itself.

A user prompt might simply ask a valid business question.
But the same interface can also be used to attempt to manipulate the model, override system instructions, inject hidden instructions or push the model towards unsafe responses.
So before we move deeper into areas such as agent permissions, tool invocation and MCP controls, it makes sense to first look at what is entering the AI system.
Microsoft’s Azure AI security guidance similarly recommends a layered approach, including analyzing input for malicious content and prompt injection attempts alongside output filtering and other application controls.

For this first hands on exercise, I therefore kept the scope deliberately small:

Text moderation : Can Azure identify potentially harmful text?
Prompt Shields : Can Azure recognize a prompt attempting to manipulate the model?

Continue reading →

Designing Safe and Actionable Agents in the New Azure Foundry Portal

In this blog we will go through the Azure AI foundry Portal and its capabilities .The new Azure AI Foundry portal brings model experimentation, agent building, data grounding, and safety controls into a single, coherent workspace. It’s designed so builders can move from idea to prototype to hardened agent without context switching.

The first thing when we login is we need to switch on the toggle new foundry and it totally brings altogether a new interface and lands us to the dashboard.

This dashboard is the Foundry project home for a developer or team building AI agents. It surfaces the project endpoint and API key for integration, shows the project region, and highlights recent model and tooling updates so teams can stay current. The page also lists recent projects and provides quick links to documentation and community resources, making it a practical launchpad for both prototyping and production work.

In the coding quick start we have the option coding quick start. We can open in vs code for the web.

Continue reading →

The Future of Account Recovery: Microsoft Entra Verified ID Powered by AU10TIX for Account Recovery (Preview)

Introduction

Microsoft Entra Verified ID transforms identity verification by enabling secure, privacy‑preserving, verifiable credentials. Whether you’re implementing Account Recovery (Preview) or integrating a trusted identity verification partner like AU10TIX, the onboarding process requires a few key steps: enabling the provider, provisioning resources, activating the integration, and validating the recovery flow.

This blog walks through the full, end‑to‑end Verified ID setup using AU10TIX as the identity verification provider. You’ll find prerequisites, detailed configuration steps, screenshots, and a summary to help you complete the setup smoothly

Prerequisites

Before you begin, ensure the following:

  1. Verified ID Setup :

You need to have the Verified ID setup properly configured in your tenant first and the foremost thing to do before proceeding to any steps. If this one is not setup then the account recovery (Preview) is not going to work . Especially your domain needs to be a verified domain here.

Also in the Authentication method you must have the Temproary Access Pass Enabled

Continue reading →

Exploring Microsoft Entra Agent ID (Preview): Identity, Governance & Zero‑Trust for AI Agents

Note: Features are in Preview and may change.

As organizations lean into AI assistants and autonomous workflows, one challenge keeps coming up in every SOC and IAM conversation: agent sprawl. Agents show up in multiple teams and builder platforms, and before you know it, you’ve got non‑human actors touching sensitive data without a clear inventory, lifecycle, or policy boundary.

Microsoft Entra Agent ID and the Agent Registry (Preview) are designed to solve exactly that bringing identities, governance, and Zero Trust controls to AI agents, so you can securely discover, organize, and manage them easily in your directory.


What Agent Registry Adds (and Why You’ll Care)

Agent Registry is an Microsoft Entra integrated metadata repository that gives you a unified view of agents built on Microsoft platforms (e.g., Copilot Studio, Azure AI Foundry) and those from other ecosystems. It separates operational records (Agent Instances) from discoverability metadata (Agent Card Manifests) and introduces Collections to govern which agents can discover and collaborate with each other. Think discovery before access a crucial shift for reducing exposure.


A Quick Look at the Tenant Experience

Agent ID Overview (Preview) dashboard showing agent counts, status, types, and blueprints: high-level posture of agents, identities, blueprints, and collections

Continue reading →

Top 10 Browser Security Controls that can be Enforced with Microsoft Intune

In today’s enterprise landscape, most applications are accessed through modern browsers like Microsoft Edge and Google Chrome, especially on Windows devices. While these browsers come with built-in security features, organizations must go a step further to enforce consistent and robust browser security policies across all endpoints.

If your organization uses Microsoft Intune, you have powerful tools at your disposal to configure and enforce browser security settings. In this blog, we’ll walk through 10 essential browser security controls you can implement using Intune’s Settings Catalog to enhance protection against web-based threats.

1. Enable Windows Defender SmartScreen

SmartScreen helps protect users from phishing attacks and malicious websites or downloads.

Recommended Settings:

  • Enable Windows Defender SmartScreen
  • Don’t allow SmartScreen warning overrides for unverified files
  • Don’t allow SmartScreen warning overrides
Continue reading →

What’s New in Azure Firewall: Draft & Deploy, Selective Logging, Explicit Proxy, Security Copilot & More

Azure Firewall continues to evolve with powerful new features that enhance security, governance, and operational efficiency.

Whether you’re managing complex enterprise environments or hybrid architectures, these updates offer greater control, visibility, and automation.

Here’s an overview into the latest innovations:

Draft and Deploy – Azure Firewall Policy Changes (Preview)

Managing firewall policies just got smarter.

With the Draft and Deploy feature, administrators can now:

  • Clone active policies to create editable drafts.
  • Collaborate on bulk changes without impacting live environments.
  • Stage deployments to minimize disruption.
  • Apply all changes at once, improving governance and reducing human error.

This is a game changer for environments requiring frequent policy updates, such as dynamic cloud workloads or multi team operations.

Continue reading →

First Look at Microsoft AI Hub: What You Need to Know

Prioritize comprehensive security and compliance measures before integrating AI into your IT ecosystem. This video showcases what the Microsoft AI Hub (preview) brings to the table in this context.

Regards
Sathish Veerapandian

Getting started with securing AI with Microsoft CSPM, AI Threat protection and Purview

Protecting Gen AI apps requires a comprehensive strategy that encompasses data privacy, input validation, API security, and monitoring for malicious use of the outputs. Take a look at this video to get started with the options available to explore within the Microsoft Ecosystem

Take a look at this video to know more about the same.

Regards
Sathish Veerapandian

Utilize the Azure WAF to secure your applications from Cyber Attacks

Azure WAF is a critical security service that safeguards web application from common threats and vulnerabilities. Take a look at this video to know more about its features and utilize them in your environment.

Hope you enjoyed this video.

Regards
Sathish Veerapandian

Microsoft Entra Global Secure Access Preview – Secure Access Service Edge (SASE)

An identity-aware, cloud-based security infrastructure is becoming increasingly necessary for today’s workforce as more and more data and apps move to the cloud. Security Service Edge (SSE) is a new class of network security solutions that is a stand-alone subset of Secure Access Service Edge (SASE).

SASE architecture’s main goal is to provide a seamless and secure user experience while maintaining optimal connectivity.

Take a look at this video to learn more about it.

I hope you enjoyed this video!

Regards

Sathish Veerapandian