Azure AI Security Updates 2025: Agent 365 & DSPM
New Azure AI security updates for 2025: Agent 365, Entra Agent ID, Integrated HSM, Confidential Computing and AI-driven DSPM extend Zero Trust to AI agents.
Ziv
YouCC Technologies
Azure AI Security Updates 2025: From Agent 365 to AI-Driven DSPM
Microsoft's latest wave of Azure AI security updates for 2025 marks a clear shift: protection is no longer only about users and devices, but about the AI agents and data flowing through the cloud itself. The headline theme is extending Zero Trust principles to autonomous AI, while hardening data both at rest and, crucially, in use.
What's new
Agent 365 — managing AI agents at scale. A platform for governing enterprise AI agents end to end: registration, access control, interaction monitoring and risk assessment. An organization building internal bots for Microsoft Teams can now register every agent in Agent 365, apply Conditional Access policies such as MFA, and watch for anomalous behavior to prevent unauthorized use.
Entra Agent ID — Zero Trust identities for AI agents. Every AI agent receives a unique identity in Azure AD with a managed lifecycle and Zero Trust access policy. An agent that touches HR data can be granted only temporary permissions through PIM, with access revoked automatically if it performs an abnormal action.
Azure Integrated HSM — hardware-level key protection. A dedicated security chip built into servers delivering FIPS 140-3 Level 3 protection. Financial firms can store critical encryption keys in the local HSM, with no dependency on an external service, to meet strict regulatory requirements.
Azure Confidential Computing — protecting data in use. This includes Confidential VMs running AMD EPYC processors with NVIDIA H100 GPUs, Confidential Clean Rooms for joint analysis of sensitive data, and Confidential Containers in AKS. A healthcare company collaborating on research with other institutions can use Clean Rooms to analyze patient data in encrypted form without exposing personal information.
DSPM with AI. Data Security Posture Management gains AI capabilities for detecting data exposure, analyzing risk and generating automated remediation recommendations. An organization with thousands of documents in SharePoint can run DSPM to flag files containing personal data exposed to external users, and receive concrete fixes.
Why it matters
The common thread is that threats now target the AI layer directly, not just endpoints and identities. Protecting data while it is being processed, assigning managed identities to non-human agents, and embedding dedicated hardware for isolation together represent a meaningful expansion of the Zero Trust model. Automated, AI-driven risk analysis closes the gap between configuration drift and real exposure.
What to do
- Inventory and register your AI agents, and apply Conditional Access and lifecycle policies through Agent 365 and Entra Agent ID.
- Grant agents temporary, scoped permissions via PIM rather than standing access.
- Evaluate Confidential Computing for workloads that handle regulated or highly sensitive data in use.
- Run DSPM across SharePoint and cloud data stores to surface exposed PII and act on the prioritized recommendations.
Shared from the CSC - Cloud Security Community community, by Ziv.
Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community