﻿1
00:00:03,150 --> 00:00:04,140
How do you make sure

2
00:00:04,140 --> 00:00:07,260
agents don't run unchecked
across your environment?

3
00:00:07,260 --> 00:00:09,810
It starts with the right
level of observability

4
00:00:09,810 --> 00:00:12,720
across security, compliance, and IT,

5
00:00:12,720 --> 00:00:16,620
insights that's tailored to
each team's domain expertise,

6
00:00:16,620 --> 00:00:18,540
yet shared across teams,

7
00:00:18,540 --> 00:00:21,060
so issues can be identified early

8
00:00:21,060 --> 00:00:23,760
and addressed quickly
when something goes wrong.

9
00:00:23,760 --> 00:00:26,580
This is where Agent 365 comes in

10
00:00:26,580 --> 00:00:29,100
to bring together security and IT teams

11
00:00:29,100 --> 00:00:30,930
so they can stay in control

12
00:00:30,930 --> 00:00:33,240
through a unified control plane,

13
00:00:33,240 --> 00:00:36,870
built to work with the
Microsoft tools you already use.

14
00:00:36,870 --> 00:00:38,610
Whether you're viewing agents

15
00:00:38,610 --> 00:00:40,290
along with their configurations

16
00:00:40,290 --> 00:00:44,460
and high-level activities in
the Microsoft 365 Admin Center,

17
00:00:44,460 --> 00:00:46,080
understanding agent activities

18
00:00:46,080 --> 00:00:49,530
and protecting sensitive
information with Microsoft Purview,

19
00:00:49,530 --> 00:00:51,960
managing agent identities and permissions

20
00:00:51,960 --> 00:00:56,100
to apps, data, and resources
with Microsoft Entra,

21
00:00:56,100 --> 00:00:58,440
or investigating and
responding to incidents

22
00:00:58,440 --> 00:01:00,180
in Microsoft Defender,

23
00:01:00,180 --> 00:01:03,180
Agent 365 provides a
common source of truth

24
00:01:03,180 --> 00:01:04,710
for agent activity,

25
00:01:04,710 --> 00:01:07,950
enabling teams to assess
and respond to risks

26
00:01:07,950 --> 00:01:10,230
from their own domain expertise

27
00:01:10,230 --> 00:01:13,890
using the tools and
workflows they know best.

28
00:01:13,890 --> 00:01:16,140
Today is the first episode in a series

29
00:01:16,140 --> 00:01:18,990
where we go deeper on using Agent 365

30
00:01:18,990 --> 00:01:20,760
across your organization,

31
00:01:20,760 --> 00:01:23,130
starting with protecting
your sensitive data.

32
00:01:23,130 --> 00:01:25,350
For example, if data isn't properly

33
00:01:25,350 --> 00:01:27,180
classified and protected,

34
00:01:27,180 --> 00:01:30,150
AI, which uses powerful semantic search,

35
00:01:30,150 --> 00:01:33,690
can quickly surface information
that was once hard to find,

36
00:01:33,690 --> 00:01:35,130
leading to data loss.

37
00:01:35,130 --> 00:01:36,330
At the same time,

38
00:01:36,330 --> 00:01:39,060
it can potentially share
it with the wrong people,

39
00:01:39,060 --> 00:01:42,300
and related other risks
can escalate quickly.

40
00:01:42,300 --> 00:01:45,570
Microsoft Purview now
extends the controls you have

41
00:01:45,570 --> 00:01:48,810
for users in your organization to agents

42
00:01:48,810 --> 00:01:50,280
so they stay aligned

43
00:01:50,280 --> 00:01:52,950
with your organization's data security

44
00:01:52,950 --> 00:01:55,410
and compliance requirements.

45
00:01:55,410 --> 00:01:58,080
Let me show you how IT
and data security teams

46
00:01:58,080 --> 00:02:01,050
can work together using Agent 365.

47
00:02:01,050 --> 00:02:05,310
Starting in Agent 365 in the
Microsoft 365 Admin Center.

48
00:02:05,310 --> 00:02:08,250
As an IT admin, I can
see a comprehensive list

49
00:02:08,250 --> 00:02:10,260
of agents in our organization.

50
00:02:10,260 --> 00:02:12,660
I can manage agent deployment requests

51
00:02:12,660 --> 00:02:15,480
to review the details
for agent configurations

52
00:02:15,480 --> 00:02:18,480
and even leverage
built-in security defaults

53
00:02:18,480 --> 00:02:22,620
for Agent 365 to quickly
establish policy controls.

54
00:02:22,620 --> 00:02:26,640
That said, as agents are used
inside of your organization,

55
00:02:26,640 --> 00:02:30,660
Microsoft Purview, as part of
the Agent 365 control plane,

56
00:02:30,660 --> 00:02:33,000
provides more granular controls

57
00:02:33,000 --> 00:02:36,060
with deeper visibility over data security.

58
00:02:36,060 --> 00:02:37,920
This includes rich AI

59
00:02:37,920 --> 00:02:41,100
observability, protection, and compliance.

60
00:02:41,100 --> 00:02:42,750
Right from Microsoft Purview,

61
00:02:42,750 --> 00:02:45,480
I can see agents running
in my organization

62
00:02:45,480 --> 00:02:48,330
with the same left-to-right
agent visibility

63
00:02:48,330 --> 00:02:51,930
we saw in the Microsoft 365 Admin Center.

64
00:02:51,930 --> 00:02:55,740
From Data Security Posture
Management, or DSPM, for short,

65
00:02:55,740 --> 00:02:57,930
I can find key agent metrics

66
00:02:57,930 --> 00:03:00,180
and what's important for data security,

67
00:03:00,180 --> 00:03:03,180
like which agents are active
and their risk levels,

68
00:03:03,180 --> 00:03:05,670
whether they're interacting
with sensitive data,

69
00:03:05,670 --> 00:03:08,970
in which ways, along
with interaction trends.

70
00:03:08,970 --> 00:03:11,820
I can also see if their
activities are protected

71
00:03:11,820 --> 00:03:14,250
with sufficient policy coverage.

72
00:03:14,250 --> 00:03:15,570
Let me show you an example

73
00:03:15,570 --> 00:03:18,270
of how this level of oversight
and protection works,

74
00:03:18,270 --> 00:03:20,220
starting from the end user perspective.

75
00:03:21,090 --> 00:03:24,900
This is a custom, in-house-developed
Zava supplier agent.

76
00:03:24,900 --> 00:03:26,910
It's designed to review and summarize

77
00:03:26,910 --> 00:03:28,890
purchase orders for clients.

78
00:03:28,890 --> 00:03:31,230
Here, a member of the procurement team

79
00:03:31,230 --> 00:03:32,880
asks the agent to review

80
00:03:32,880 --> 00:03:36,000
a few linked purchase orders PDF files

81
00:03:36,000 --> 00:03:38,190
and check for delays and impacts.

82
00:03:38,190 --> 00:03:41,310
The reasoning agent gets
to work almost immediately,

83
00:03:41,310 --> 00:03:43,950
providing a summary for the linked files.

84
00:03:43,950 --> 00:03:46,620
It then attempts to access a contract file

85
00:03:46,620 --> 00:03:50,160
to figure out the contractual
impacts of any delays.

86
00:03:50,160 --> 00:03:52,710
Now, because the contract has a label

87
00:03:52,710 --> 00:03:55,230
that the agent is not allowed to process,

88
00:03:55,230 --> 00:03:58,620
it stops and says that it
cannot access the information

89
00:03:58,620 --> 00:04:00,270
contained in that file.

90
00:04:00,270 --> 00:04:02,010
This is Microsoft Purview

91
00:04:02,010 --> 00:04:05,610
enforcing least-privilege
access in real time.

92
00:04:05,610 --> 00:04:08,340
Next, our same user asks the agent

93
00:04:08,340 --> 00:04:11,430
to email the summary to
an external supplier.

94
00:04:11,430 --> 00:04:12,720
The agent tries,

95
00:04:12,720 --> 00:04:15,720
but Purview spots sensitive
data in the message.

96
00:04:15,720 --> 00:04:19,110
In fact, if we move to
Outlook and open the message,

97
00:04:19,110 --> 00:04:21,720
we can see that our sensitive
information policies

98
00:04:21,720 --> 00:04:23,850
have blocked the email from being sent.

99
00:04:23,850 --> 00:04:26,220
Back in Teams, we can
see that the same user

100
00:04:26,220 --> 00:04:29,430
is attempting to use the
agent to draft an email

101
00:04:29,430 --> 00:04:32,490
that promises an exclusive gift incentive

102
00:04:32,490 --> 00:04:34,830
to fast track the PO approval.

103
00:04:34,830 --> 00:04:36,180
The agent stops again.

104
00:04:36,180 --> 00:04:37,650
It recognizes the request

105
00:04:37,650 --> 00:04:39,690
crosses ethical and compliance lines

106
00:04:39,690 --> 00:04:42,093
and explains why to our user.

107
00:04:43,080 --> 00:04:45,390
Importantly, behind the scenes,

108
00:04:45,390 --> 00:04:48,300
Purview logs all activity as it happens

109
00:04:48,300 --> 00:04:50,670
and flags the interaction for review.

110
00:04:50,670 --> 00:04:52,380
In fact, let's switch perspectives

111
00:04:52,380 --> 00:04:55,200
to the data security admin
in the Purview portal

112
00:04:55,200 --> 00:04:57,720
after these activities have taken place.

113
00:04:57,720 --> 00:05:00,720
I'm back in DSPM under AI Observability

114
00:05:00,720 --> 00:05:03,060
with a view of my running agents.

115
00:05:03,060 --> 00:05:04,650
And on top of my list,

116
00:05:04,650 --> 00:05:07,470
Purview has flagged the
supplier agent as high risk.

117
00:05:07,470 --> 00:05:08,910
Let's drill into it.

118
00:05:08,910 --> 00:05:11,550
For that, I'm in insider
risk management view

119
00:05:11,550 --> 00:05:12,900
for this activity.

120
00:05:12,900 --> 00:05:14,940
It maps out the sequence of events

121
00:05:14,940 --> 00:05:17,940
that our user and agent
attempted to carry out,

122
00:05:17,940 --> 00:05:20,880
starting with sensitive
file access in SharePoint,

123
00:05:20,880 --> 00:05:23,100
including the contract I mentioned.

124
00:05:23,100 --> 00:05:25,110
Then the DLP policy block,

125
00:05:25,110 --> 00:05:26,580
which stopped the email summary

126
00:05:26,580 --> 00:05:28,860
from being sent to the external supplier.

127
00:05:28,860 --> 00:05:31,620
And, finally, the unethical behavior block

128
00:05:31,620 --> 00:05:34,080
when a user attempted to offer a gift

129
00:05:34,080 --> 00:05:37,440
in exchange for faster contract approval.

130
00:05:37,440 --> 00:05:40,830
All these activities raise
the risk level of the agent,

131
00:05:40,830 --> 00:05:44,070
and each action is clearly outlined.

132
00:05:44,070 --> 00:05:47,460
To get more detailed context
about the agent's behavior,

133
00:05:47,460 --> 00:05:49,680
I can view the activity timeline,

134
00:05:49,680 --> 00:05:53,730
which links me directly into
Activity Explorer in DSPM

135
00:05:53,730 --> 00:05:56,490
to see other interactions with this agent.

136
00:05:56,490 --> 00:05:58,680
It looks like there's a
mix of benign activity

137
00:05:58,680 --> 00:06:00,000
at the bottom of the list,

138
00:06:00,000 --> 00:06:03,363
and the higher risk activities
for our user are at the top.

139
00:06:04,440 --> 00:06:06,960
All prompts and responses are evaluated

140
00:06:06,960 --> 00:06:09,720
against compliance
policies and classifiers,

141
00:06:09,720 --> 00:06:11,520
and any matches are surfaced

142
00:06:11,520 --> 00:06:15,060
using the same investigation
and remediation workflows

143
00:06:15,060 --> 00:06:16,800
you already use today.

144
00:06:16,800 --> 00:06:18,330
In fact, you can find the details

145
00:06:18,330 --> 00:06:20,370
for agent policy violations

146
00:06:20,370 --> 00:06:23,040
across solutions in Microsoft Purview.

147
00:06:23,040 --> 00:06:26,760
For example, if your focus is
on communication compliance,

148
00:06:26,760 --> 00:06:29,190
you can find the details
for the agent interaction

149
00:06:29,190 --> 00:06:30,990
that was flagged as unethical.

150
00:06:30,990 --> 00:06:32,370
In this case, it matched

151
00:06:32,370 --> 00:06:34,410
the gifts and entertainment condition.

152
00:06:34,410 --> 00:06:35,310
And clicking in,

153
00:06:35,310 --> 00:06:38,073
you can see related matches
for other sources too.

154
00:06:39,090 --> 00:06:42,810
And Purview Audit also captures
every agent interaction,

155
00:06:42,810 --> 00:06:45,780
which you'll find using an audit search.

156
00:06:45,780 --> 00:06:48,300
Here we've searched
across agent interactions

157
00:06:48,300 --> 00:06:49,410
that occurred between

158
00:06:49,410 --> 00:06:52,680
February 1st and March 1st for our agent,

159
00:06:52,680 --> 00:06:56,010
and you can see the exportable
details for each interaction,

160
00:06:56,010 --> 00:07:01,010
including IP, user, agent,
record, and activity details.

161
00:07:01,170 --> 00:07:03,900
So when a regulator asks:
"How did this happen?"

162
00:07:03,900 --> 00:07:06,990
You can trace it instantly
using Purview Audit.

163
00:07:06,990 --> 00:07:10,380
Of course, with Agent
365 at the foundation,

164
00:07:10,380 --> 00:07:12,360
everything is connected and integrated

165
00:07:12,360 --> 00:07:13,950
across the control plane.

166
00:07:13,950 --> 00:07:15,510
So now as an IT admin

167
00:07:15,510 --> 00:07:18,450
working in the Microsoft 365 Admin Center,

168
00:07:18,450 --> 00:07:21,390
I can see the agents
running in our environment

169
00:07:21,390 --> 00:07:22,830
filtered by high risk,

170
00:07:22,830 --> 00:07:24,870
and there's our supplier agent.

171
00:07:24,870 --> 00:07:27,330
In its details, under
Security and Compliance,

172
00:07:27,330 --> 00:07:31,020
I can see it has performed
a few risky activities.

173
00:07:31,020 --> 00:07:32,250
This is all signal

174
00:07:32,250 --> 00:07:34,470
that has been pulled in
from Microsoft Purview

175
00:07:34,470 --> 00:07:36,720
as part of Agent 365.

176
00:07:36,720 --> 00:07:39,720
From here, I can tune
the agent configurations,

177
00:07:39,720 --> 00:07:41,400
including its permissions,

178
00:07:41,400 --> 00:07:44,130
or even block it all together from use.

179
00:07:44,130 --> 00:07:46,020
AI agents move fast,

180
00:07:46,020 --> 00:07:48,060
and without the right level of visibility

181
00:07:48,060 --> 00:07:49,560
and guardrails in place,

182
00:07:49,560 --> 00:07:52,890
they can easily access data
they shouldn't overshare,

183
00:07:52,890 --> 00:07:56,070
and even work against
your company's ethics.

184
00:07:56,070 --> 00:07:58,650
Agent 365 with Microsoft Purview

185
00:07:58,650 --> 00:08:00,360
keeps your agents in line,

186
00:08:00,360 --> 00:08:02,310
spots trouble before it happens,

187
00:08:02,310 --> 00:08:05,490
and makes sure that actions are recorded.

188
00:08:05,490 --> 00:08:09,963
To learn more, check out
aka.ms/Agent365DataSecurity.

189
00:08:11,684 --> 00:08:13,230
In the next episode of the series,

190
00:08:13,230 --> 00:08:16,860
we'll explore Agent 365
with Microsoft Defender

191
00:08:16,860 --> 00:08:20,190
to investigate and respond
to security incidents

192
00:08:20,190 --> 00:08:22,290
involving agentic activity.

193
00:08:22,290 --> 00:08:25,020
Subscribe to Microsoft Mechanics
if you haven't already,

194
00:08:25,020 --> 00:08:27,020
and thanks for watching.

