Composite patternMicrosoft AzureZero trust

An Azure landing zone where every agent has its own identity.

This regulated-industry pattern shows how hosted AI agents can avoid shared credentials, public data paths and manual evidence gathering. Benchmarks below are illustrative targets pending client-approved evidence.

0Standing privilege
100%Policy coverage
11Subscriptions
52%Faster audit proof
01 · Constraint

An agent is a workload—and a new identity boundary.

Existing Azure controls covered web services but not agents that selected tools, held session state and acted on behalf of users. Shared service principals made it impossible to prove which agent performed an action.

Credential ambiguity

Multiple workloads inherited broad permissions from shared identities.

Public service paths

Model, search and storage traffic could leave the controlled network route.

Agent lifecycle gap

Prompt and tool changes were not part of the deployment approval record.

02 · Trust path

Identity followed the agent version into production.

AuthorVersioned agent

Code, instructions, tools and risk tier

ProveCI policy gate

IaC, image and behavior evidence

HostFoundry agent

Managed endpoint with dedicated identity

ConnectPrivate services

Search, storage and Cosmos DB endpoints

ObserveSecurity graph

Application Insights + Defender findings

Failure path: policy drift quarantined the next deployment, while runtime identity anomalies revoked the affected agent's access without disabling the entire platform.
03 · Decisions

Least privilege was generated, not requested.

D-01Per-agent identity

Every hosted agent received a dedicated Entra identity and narrow resource scope.

D-02Private-by-default modules

Approved Terraform modules wired DNS, private endpoints and logging together.

D-03Behavior in release evidence

Agent instructions and tool allow-lists were versioned beside infrastructure.

04 · Outcome

Security review moved from archaeology to policy evidence.

MeasureBeforeAfter
Standing workload privilegeShared principalsNone
Policy coverageUneven by subscription100% managed estate
Agent network pathMixedPrivate endpoints
Audit evidence preparationManual collection52% faster
Microsoft FoundryHosted agentsMicrosoft EntraAzure PolicyPrivate LinkDefender for CloudApplication Insights
Platform insight: security improved developer velocity because the approved modules encoded the difficult networking and identity work once.

Make AI workloads native to your Azure controls.

We can design identity, networking, policy and evidence around your agent risk tiers.

Review my Azure AI platform →