Skip to main content

Plan your security journey with us.

André Kraemer

New Business | Project Manager

Schedule a free consulation

Zero Trust for AI: Why Agents Are Getting Their Own Pillar — and What That Means for You

AI has firmly arrived in everyday enterprise life: chatbots for customers, agents for internal processes, a copilot in every department. With every new agent instance, the same questions come up:

Who deployed this agent?
What is it allowed to do?
… and who notices when it gets compromised?

Microsoft is addressing this with Zero Trust for AI (ZT4AI), unveiled at RSAC in late March 2026: the Zero Trust framework now has a dedicated AI pillar — a standalone building block in the new reference architecture, complete with its own workshop track and expanded assessment tooling. In our latest webcast, we looked at the whole picture from two angles: cybersecurity/SOC and data security.

The Problem: Agents Are Identities – But Were Never Treated as Such

The three core Zero Trust principles remain unchanged:

•  Verify explicitly now also applies to agents. In the identity section of the framework, the agent shows up as its own identity type, complete with an Agent ID.
•  Least privilege: access to models, prompts, plugins, and data sources only to the extent necessary.
 Assume breach across the entire AI lifecycle: Is the model clean? Where does the LLM come from, and how was it trained? Was something planted during development that could be exploited later?

What's new is the attack surface: prompt injection, tampered models in the supply chain, and so-called double agents — misconfigured or compromised agents working against their own organization. This is still rarely exploited in the wild. But the risks are foreseeable, and now is exactly the moment to get ahead of them.

Two factors dramatically increase the blast radius of a compromised agent:

1. Speed — agents act many times faster than human attackers, and
2. Data access — agents with elevated privileges and connections to sensitive data sources make the perfect target.

On top of that comes Shadow AI. Departments build their own chatbots and deploy agents for internal work without an agent identity and without an owner. The security implications rarely get a second thought. Then, when an incident hits, exactly the knowledge needed for response actions is missing: Am I allowed to disable it? Is what it's doing even sanctioned in the first place?

What Microsoft Has Released

The ZT4AI announcement shipped with four building blocks. Together, they map out a path from strategy through assessment to implementation:

Component
What's New

Zero Trust Workshop

A dedicated AI pillar, now totaling 700 security controls across 116 logical groups and 33 swim lanes. The workshop now runs on a web platform instead of an Excel spreadsheet.

Zero Trust Assessment

Data and Network added as new automated assessment pillars alongside Identity and Devices

Zero Trust Reference Architecture

Extended for AI: Resources as a new area, Agents represented as an identity type
with an Agent ID

Patterns & Practices

Practical guidance covering threat modeling for AI, AI observability, securing agentic systems, and XPIA defense

The New AI Pillar in the Workshop

The AI pillar covers seven implementation areas:

•  Map and assess AI risk: discover, inventory, and prioritize risk across AI agents, applications, and services organization-wide
•  Register agents: capture, classify, and assign ownership to every agent in a central registry
 Secure AI authentication and access: apply conditional access, risk-based policies, and identity governance to AI systems
•  Secure AI network access: control, filter, and inspect traffic for AI interactions, including protection against prompt injection
•  Secure AI data access: classify, label, and apply DLP to data in prompts, grounding, and outputs; monitor for oversharing
•  Build agents securely: secure development and deployment, including content-safety controls, validation, and red teaming
 Detect and respond for AI: integrate AI signals into security operations, detect misuse and prompt-based attacks

Every task is rated by implementation effort and user impact (high/medium/low) – a useful lens for deciding where to start: quick wins with low effort and high payoff, obviously, come first. The report also breaks down measures into 30-, 60-, and 90+-day actions, giving you an immediate roadmap and a way to report progress and next steps at any time.

Results can be exported and shared as JSON or CSV, imported into project management tools like ADO or Jira. No more Excel file circulating through the organization by email.

Practical tip from our workshops:

At first glance, the sheer scope can feel overwhelming. Approach it in a structured way and divide up the work – each pillar typically has different owners anyway. That's the reliable path to results, rather than getting lost in the details.

The Assessment: A Look at the Current State

The Zero Trust Assessment automates the review of hundreds of security configurations across Identity, Devices, and now also Data and Network. Doing this manually would be time-consuming and error-prone. The checks draw on industry standards such as NIST, CISA, and the CIS Benchmarks, on Microsoft's own learnings from the Secure Future Initiative (SFI), and on customer insights gathered from thousands of security implementations.
Getting started is deliberately simple: install PowerShell 7, install the module, connect, invoke. The first run requires Global Admin (for consent); after that, Global Reader is sufficient. In our test tenant, generation took around 40 minutes; according to Microsoft's documentation, an assessment in large environments can take up to 24 hours. So start it on a machine that can run uninterrupted.

The report's first page delivers general tenant information: users, authentication methods, devices — data that today is scattered across various portals, now consolidated on a single page. The findings follow, sortable by risk and status. Each finding comes with concrete remediation steps, so you also get the path to resolution right away.

One more thing: It's worth running the assessment repeatedly, to check whether configurations still match the target state, whether anything has changed, and whether Microsoft has added new checks. The effort is manageable, and the insight gained is substantial.
At the time of our recording, the AI pillar was not yet included in the automated assessment and was slated for summer 2026. Microsoft has since delivered the first AI checks, focused on agent identities: authentication, permissions, and ownership. For the full AI component, the workshop remains the foundation.

Agent 365 and the SOC Perspective

For detection and response, Agent 365 is the critical building block: the central collection point for all agents, with registration, ownership, and permissions. Only on this governance foundation can the SOC meaningfully process signals. Agent information flows into the Defender ecosystem and can be enriched with security data.
From a data security standpoint, there's more: an agent can be treated like a human identity, including insider risk scoring. That provides triage context – should I rate this action higher or lower? Do I deal with the agent first, or the user?

On top of that, Entra Internet Access with Shadow AI detection closes a gap at the network level: traffic inspection reveals which AI applications are running in the environment that IT and security don't know about. That said, this space is still young. Many workflows don't exist yet; it takes tuning and simply experience working with the data. The expectation “I now have AI, so it needs to be monitored” is correct. But getting there takes time – nothing happens here at the push of a button.

The EU AI Act: An Important Disclaimer

The workshop and assessment are aligned with regulatory requirements and provide a solid foundation for the technical, and in part procedural, measures involved. But running the tools does not automatically make you compliant. A significant portion of the regulatory and legal work required for AI Act compliance is still missing — particularly given the demanding regulatory landscape in the DACH region.

What does hold true: everything you document in the tool helps you demonstrate that you engaged with these topics in a structured way. From a compliance standpoint, that's becoming increasingly important.

Important to understand: this is a Microsoft-only view — the data comes from the Microsoft universe. For other platforms, the framework at least offers a starting point for the question: what's our equivalent in that world?

How to Get Started – Today, Ideally Yesterday

The path is always the same, whether you go it alone or work with us:

1. Run the assessment: pull an unvarnished picture of the current state of your environment, automated, with prioritized findings.
2. Run the workshop: focus on the relevant pillars based on your maturity level. If you've already completed the Zero Trust Workshop, now's the time to tackle the new AI pillar specifically.
3. Build a project plan: bring together the results from the report and the workshop into a concrete, prioritized 30/60/90-day project plan.

Nearly every organization already has agents in use — deployed and running in production, often without governance. The framework, workshop, and assessment offer a structured approach to this for the first time. Our key recommendation: start today, if not yesterday. We've spent significant time working with this tooling and are happy to show you the right path for your organization, from assessment through to implementation.

Back to all blogs

Featured blogs

water surf Newsletter