An agent is a workload—and a new identity boundary.
Existing Azure controls covered web services but not agents that selected tools, held session state and acted on behalf of users. Shared service principals made it impossible to prove which agent performed an action.
Multiple workloads inherited broad permissions from shared identities.
Model, search and storage traffic could leave the controlled network route.
Prompt and tool changes were not part of the deployment approval record.
Identity followed the agent version into production.
Code, instructions, tools and risk tier
IaC, image and behavior evidence
Managed endpoint with dedicated identity
Search, storage and Cosmos DB endpoints
Application Insights + Defender findings
Least privilege was generated, not requested.
Every hosted agent received a dedicated Entra identity and narrow resource scope.
Approved Terraform modules wired DNS, private endpoints and logging together.
Agent instructions and tool allow-lists were versioned beside infrastructure.
Security review moved from archaeology to policy evidence.
| Measure | Before | After |
|---|---|---|
| Standing workload privilege | Shared principals | None |
| Policy coverage | Uneven by subscription | 100% managed estate |
| Agent network path | Mixed | Private endpoints |
| Audit evidence preparation | Manual collection | 52% faster |
Make AI workloads native to your Azure controls.
We can design identity, networking, policy and evidence around your agent risk tiers.