ASAI Security ResearchIndependent public-source research
Public reviewread only

Vendor research

Microsoft native AI security beyond Purview DSPM

Review what this vendor says publicly, the security topics those statements may support, what remains unverified, and factual company context. This is not an assessment of product effectiveness or fit.

Company scale

Established
?EstablishedA provider with at least $1B in annual revenue, at least 1,000 employees, or backing from an established owner.This is a company-maturity signal, not a product-quality rating.

A descriptive band derived from retained public revenue, workforce, ownership, or funding signals.

Company scale is separate from product features, effectiveness, and suitability.
  • $281.7B annual revenue (2025-06-30)
  • 1000+ employees
  • Founded 1975

Company context

Public company (Nasdaq: MSFT)

Microsoft positions Foundry as an AI app and agent factory, Security Copilot for Microsoft 365 E5/E7 customers, and Entra Agent ID for agent identity governance

Research coverageCounts describe available public research, not product quality.View details
Vendor statements
18 records
Source-checked records
14
Evaluation requirements
18 in this research model
Unresolved requirements
0

Company intelligence

Who is behind the product

Company facts provide evaluation context. Each signal is kept separate because tenure, workforce, funding, and hiring answer different questions.

Founded1975
HeadquartersRedmond, Washington
OwnershipPublic company (Nasdaq: MSFT)
Employees1000+
Capital and scalePlatform provider

Microsoft

Latest annual company revenue
$281.7B

MICROSOFT CORP · period ended 2025-06-30 · filed 2025-07-30

Operating scale
Microsoft positions Foundry as an AI app and agent factory, Security Copilot for Microsoft 365 E5/E7 customers, and Entra Agent ID for agent identity governance
Backing context
Public company; Microsoft Foundry, Security Copilot, Entra Agent ID, and Microsoft 365 E5/E7 are native Microsoft platform and suite capabilities
Founders and leadershipBackground context

Current leadership and public filings provide more useful context for this company than historical founder information.

Operating signalsRead each signal separately

There is no combined company rating. The company-scale label uses stated size thresholds; product features and effectiveness require separate evidence.

Company tenure
1975
Workforce scale
1000+
Hiring activity
Not displayed

A current count requires a retained, clickable source URL.

Open research questions
  • A current hiring source is not available, so the count is not shown.
Company sources and research limits4 linked public sources

Only company facts supported by retained public sources are shown. Missing values remain unknown, and company scale does not establish product effectiveness.

Company sourceMicrosoft Foundry Control Plane overviewMicrosoft Learn describes Foundry Control Plane as visibility, governance, and control for AI agents, models, and tools.Company sourceMicrosoft Entra Agent ID overviewMicrosoft Learn describes Entra Agent ID, Microsoft Agent 365, and the E7/E5 boundary for extending Entra security features to agents.Company information sourceStored company websiteSupports the company facts shown in this profile.Regulatory filing10-K annual filingMICROSOFT CORP (MSFT) · period ended 2025-06-30

Buyer context

  • Treat this as Microsoft-native context for Foundry, Security Copilot, Entra Agent ID, Agent 365, and E5/E7 suite fit, not as a duplicate of the Purview data security posture management (DSPM) target record.
  • For Microsoft-heavy AI builders, compare Foundry guardrails and agent tracing against independent AI runtime security and agent-security controls.
  • Use the E7 and Agent 365 licensing evidence narrowly: Microsoft says Entra security extensions for agents require E7 or E5 paired with a Microsoft Agent 365 license.

Related frameworks

Where public vendor statements relate to framework requirements

0 related frameworks · expand when needed
These links show related requirements for further review. They do not establish framework compliance or control implementation. Open the full framework crosswalk →

Evaluation questions

What to verify beyond public claims

These questions come from security requirements with some public support. Use them as starting points for demonstrations, documentation review, customer references, or a buyer-observed pilot.

    Detailed security-requirement research0 evaluation items · supporting evidence and open research are shown separatelyExpand
    Security requirementPublic supportRelated frameworksWhat to verify

    Public sources

    Vendor statements and quoted evidence

    Showing the first 6 of 18 source records. Open additional records only when needed.

    Open all vendor evidence →
    Unapproved AI use discoveryNo supporting claim found

    Microsoft Foundry and Agent ID native-control materials reviewed did not provide a public claim for discovering employee use of third-party AI apps.

    No quoted source text is recorded for this claim.
    AI-feature discovery in business applicationsNo supporting claim found

    Microsoft Foundry and Agent ID native-control materials reviewed did not provide a public claim for software as a service (SaaS) AI inventory or embedded third-party software as a service (SaaS) AI discovery.

    No quoted source text is recorded for this claim.
    Approved AI usage monitoringSource checkedStrong public support for this requirement

    Microsoft claims Foundry Control Plane provides visibility, governance, and control for AI agents, models, and tools across a Foundry enterprise.

    provides visibility, governance, and control for AI agents, models, and tools across your Foundry enterprise.
    Controls for unapproved AI useNo supporting claim found

    Microsoft Foundry and Agent ID native-control materials reviewed did not provide a public claim for blocking arbitrary unapproved employee AI app use.

    No quoted source text is recorded for this claim.
    Sensitive-data protection for generative AISource checkedStrong public support for this requirement

    Microsoft claims Foundry guardrail controls cover protected material and personally identifiable information for models and agents.

    Protected material for code ✅ ✅ Protected material for text ✅ ✅ Groundedness (Preview) ✅ ❌ Personally identifiable information (Preview) ✅ ✅
    Browser and business-application controlsNo supporting claim found

    Microsoft Foundry and Agent ID native-control materials reviewed did not provide a public claim for browser or software as a service (SaaS) user-activity protection.

    No quoted source text is recorded for this claim.
    Show 12 additional evidence records
    Generative AI application securitySource checkedStrong public support for this requirement

    Microsoft claims Prompt Shields are Foundry guardrail controls for model deployments and agents.

    Prompt Shields are part of the Foundry guardrails and controls system
    Action-taking agent monitoringSource checkedStrong public support for this requirement

    Microsoft claims Foundry tracing captures agent inputs, outputs, tool usage, retries, latencies, and costs during an agent run.

    It captures key details during an agent run, such as inputs, outputs, tool usage, retries, latencies, and costs.
    Agent-to-agent communication securitySource checkedStrong public support for this requirement

    Microsoft claims Entra Agent ID supports OAuth 2.0, Model Context Protocol (MCP), and agent-to-agent (A2A) for authentication and agent-to-agent communication.

    supports standard protocols such as OAuth 2.0, MCP, and A2A for authentication and agent-to-agent communication.
    Non-human identity and service-account securitySource checkedStrong public support for this requirement

    Microsoft claims Entra Agent ID provides a platform for creating and managing agent identities and agent identity blueprints.

    provides the platform for creating and managing agent identities and agent identity blueprints.
    AI cost and usage controlsSource checkedLimited public support for this requirement

    Microsoft claims Foundry AI Gateway uses Azure application programming interface (API) Management to apply token limits, quotas, and governance to model deployments.

    AI Gateway uses Azure API Management behind the scenes to provide token limits, quotas, and governance for model deployments.
    Licensing modelSource checkedStrong public support for this requirement

    Microsoft says extending Entra security features to agents requires Microsoft 365 E7 or Microsoft 365 E5 paired with a Microsoft Agent 365 license.

    Extending Microsoft Entra security features to agents requires Microsoft 365 E7 (includes Agent 365 and Microsoft Entra Suite) or Microsoft 365 E5 paired with a Microsoft Agent 365 license.
    AI governance, risk, and complianceSource checkedStrong public support for this requirement

    Microsoft claims Agent 365 provides a centralized control plane to discover, manage, govern, and secure Microsoft and third-party AI agents.

    Microsoft Agent 365 is a Microsoft 365 service that provides a centralized control plane for AI agents.
    AI assurance and adversarial testingSource checkedStrong public support for this requirement

    Microsoft provides open-source RAMPART and PyRIT tooling for repeatable adversarial and regression testing of agent and generative-AI systems.

    RAMPART is an open-source testing framework that brings red teaming techniques directly into the development workflow.
    AI model and supply-chain securitySource checkedLimited public support for this requirement

    Microsoft Defender for Cloud claims preview scanning of registered Azure Machine Learning models for embedded malware, unsafe operators, and exposed secrets before production.

    AI model scanning provides proactive detection of unsafe or malicious artifacts and continuously monitors models for risk throughout the AI lifecycle.
    AI gateway, tool-connection, and runtime controlsSource checkedStrong public support for this requirement

    Microsoft Foundry claims preview Model Context Protocol (MCP) governance by routing eligible tool traffic through an AI Gateway where Azure application programming interface (API) Management policies enforce authentication, rate limits, IP restrictions, and audit logging.

    An AI gateway provides a single, governed entry point where you can enforce authentication, rate limits, IP restrictions, and audit logging
    AI agent identity and permissionsSource checkedStrong public support for this requirement

    Microsoft Foundry claims automatic provisioning and lifecycle management of Entra agent identities, with Azure RBAC and token-based access for agent tool calls.

    Microsoft Foundry automatically provisions and manages agent identities throughout the agent lifecycle.
    AI coding-agent and workstation securitySource checkedLimited public support for this requirement

    Microsoft Defender for Endpoint claims runtime protection that can detect prompt injection and audit or block actions by supported local AI agents, including coding and CLI agents.

    AI agent runtime protection helps you detect prompt injection at the device level and block or audit the agent's action