Microsoft is introducing new security measures and features to address the growing use of AI agents within enterprise environments. The company announced Entra Agent ID, which extends Microsoft Entra's identity and access management (IAM) capabilities to AI agents, treating them with the same governance and controls as human users. This includes assigning unique identities to agents and applying conditional access, identity governance, and protection policies. The move is in response to the anticipated proliferation of both sanctioned and unsanctioned AI agents within organizations, aiming to mitigate risks associated with shadow IT and unauthorized agent activity. Additionally, Microsoft is rolling out a strengthened Content Security Policy for Entra ID sign-ins, restricting script execution to trusted Microsoft domains to prevent external script injection and cross-site scripting attacks during authentication processes.
Alongside these IAM enhancements, Microsoft is experimenting with new features such as the Agent Workspace for Copilot, which allows AI agents to access and manipulate files in isolated environments on Windows systems. While this feature is designed to improve productivity, it comes with significant security warnings. Microsoft documentation highlights risks such as cross-prompt injection, where malicious instructions embedded in files or applications could trick AI agents into performing unauthorized actions, including data exfiltration. To address these concerns, Microsoft emphasizes user supervision, least privilege access for agent accounts, and explicit user approval for sensitive actions. These developments reflect Microsoft's broader strategy to secure the expanding role of AI agents in enterprise IT while acknowledging the unique security challenges they introduce.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced it will enforce a stricter Content Security Policy for browser-based Entra ID sign-ins at login.microsoftonline.com in mid-to-late October 2026. The change will block external script injection and unsupported browser extensions or tools that inject scripts into sign-in pages.
Microsoft said Entra Agent ID, after its public preview, is expected to become commercially available in 2026. Pricing had not yet been finalized at the time of the announcement.
Microsoft introduced Entra Agent ID within Entra IAM to assign managed identities to AI agents and apply controls such as conditional access, governance, and protection. The feature is intended to help enterprises monitor and restrict agent behavior and is available in public preview.
In documentation accompanying Agent Workspace, Microsoft warned that agentic AI features create notable risks from cross-prompt and indirect prompt injection, including possible data exfiltration. Researchers also noted that access to folders like Downloads increases exposure to untrusted third-party content, while Copilot Actions can retain desktop screenshots for up to 30 days.
Microsoft introduced an experimental Windows feature for Windows Insiders that lets Copilot agents access local files through a separate Agent Workspace account. The feature is disabled by default and supports background tasks such as resizing photos, renaming files, and filling out forms.
PromptArmor recently published a proof of concept showing that hidden instructions in a spreadsheet could indirectly prompt-inject Anthropic's Claude for Excel. The demonstration highlighted how malicious file content can manipulate AI agents into unintended actions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
semperis.com
Open sourcezdnet.com
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.