AI agents on corporate laptops create a basic security problem: IT cannot govern software it cannot see. Microsoft is pairing new visibility into those agents with network-level controls designed to keep sensitive corporate data from reaching risky AI destinations.
Defender for Endpoint can discover supported local AI agents and their Model Context Protocol (MCP) configurations, while Purview policies enforced through Entra Global Secure Access can block sensitive data headed to untrusted cloud services. The latter protection is now generally available, including for on-behalf-of agent traffic.
Microsoft's Sept. 24 security update places those capabilities within a broader effort to secure human and agent-driven activity.
Defender maps local AI agents and access
Microsoft's local-agent discovery documentation lists the capability as preview. Defender automatically detects supported agents on onboarded Windows and macOS endpoints, including command-line tools, desktop apps, agentic IDEs, and VS Code extensions such as Claude Code, Codex CLI, Gemini CLI, ChatGPT Desktop, Cursor, and GitHub Copilot.
The inventory can associate agents with users and devices, identify configured MCP servers, and map relationships to resources those identities can access. That visibility has practical value when autonomous software exceeds intended permissions: Spain's data protection authority is reviewing the country's first reported AI-agent data breach after an organization said an agent accessed internal systems and personal data.
Licensing limits the available detail. Microsoft's licensing documentation says Defender for Endpoint Plan 2 covers discovery, inventory, and Advanced Hunting, while risk levels, risk indicators, and security recommendations require Microsoft 365 E7 or Microsoft Agent 365 with Defender for Endpoint Plan 2.
Discovery does not automatically block agent actions. Microsoft's runtime protection documentation describes a separate preview capability that can audit or block supported prompt-injection activity, with coverage varying by agent and inspection method. Recent UK testing of tool-enabled agents likewise showed how internet access, credentials, and execution permissions can widen an agent's reach.
Purview blocks sensitive data headed to shadow AI
Purview's integration with Entra Global Secure Access reached general availability in September 2026. Microsoft's Purview release notes say organizations can apply DLP policies to text, files, and AI interactions moving through browsers, apps, APIs, and add-ins, including generative AI platforms.
Entra enforces those Purview policies at the network layer. Microsoft's Sept. 24 example describes an employee or on-behalf-of agent attempting to upload a sensitive document to an unsanctioned AI tool, with the policy stopping the transfer before the data leaves the organization.
The broader governance problem extends beyond Microsoft. OpenAI recently tightened controls around autonomous agents after internal cyber evaluations exposed failures involving sandbox boundaries and access to external systems.
What eWeek Found: Microsoft's AI controls still span three security layers
Microsoft's documentation describes three separate control points: Defender discovers supported local agents and maps their access, runtime protection can intervene in supported prompt-injection scenarios, and Purview with Entra governs covered outbound data flows.
The three controls differ in maturity and licensing. Purview and Entra network DLP is generally available, while local-agent discovery and runtime protection remain in preview. Defender for Endpoint Plan 2 supplies basic discovery, but richer posture information requires additional licensing.
Enterprises therefore need to assess visibility, runtime coverage, and outbound-data enforcement separately. Detecting an agent does not establish that all of its actions or traffic are protected.
Want to learn more AI tips, tricks, and prompting techniques? Let us teach you How to Talk to AI for free! Try our six-minute course at The Neuron Academy, our practical learning platform designed to help professionals use AI more confidently at work.
Learn a few simple ways to write better prompts and get more useful results from AI, or browse our other AI course for free for seven days. eWeek readers get free 7-day access. Check out all the lessons here →


