An ambitious Customer Zero effort across Microsoft showed us how to secure our AI agents.

Securing AI agents in the enterprise: Learnings from our journey at Microsoft

As AI agents become more sophisticated and autonomous, large enterprises like ours face a fundamental challenge: How do you enable powerful new AI experiences among your employees without compromising security, governance, or operational control?

That was the guiding mantra behind an ambitious cross-company effort involving our team in Microsoft Digital—the company’s IT organization—and a number of our product teams. The effort, internally referred to as the Securing AI Agents initiative, brought together teams from Microsoft Digital, Windows, Entra, Intune, Defender, Purview, and Microsoft Security to validate secure AI agent scenarios inside Microsoft’s corporate tenant.

Together, we set out to prove that AI agents could operate safely inside a real enterprise environment, not just in a controlled demonstration.

A photo of Singh.

“Securing AI in the enterprise at pace requires an integrated, full-stack approach. By validating these capabilities together at enterprise scale, we’re generating the real-world learning to strengthen Microsoft’s products and give customers a trusted blueprint for secure AI adoption.”

Ragini Singh, partner group engineering manager, Microsoft Digital

As part of our role as the company’s Customer Zero, this work was recently showcased by Samantha Song and Scott Hanselman at the Microsoft Build 2026 conference.

“Securing AI in the enterprise at pace requires an integrated, full-stack approach,” says Ragini Singh, a partner group engineering manager in Microsoft Digital. “By validating these capabilities together at enterprise scale, we’re generating the real-world learning to strengthen Microsoft’s products and give customers a trusted blueprint for secure AI adoption. Looking ahead, our vision is to make this integrated security foundation the standard for every enterprise, so organizations can scale autonomous agents with speed, confidence, and trust.”

The Secure AI Agents initiative was the result of an all-hands-on-deck project behind the scenes here at Microsoft: Months of testing, coordination, validation, and refinement that transformed an emerging concept into a governable enterprise pattern.

A photo of Gogi.

“All of these teams came together and not only enabled the environment in our IT tenant but also ensured that all the right policies were deployed to make it so that these agents can run safely. That meant not bypassing any of the security parameters that we’ve already deployed.”

Shyam Sunder Gogi, technical program manager, Microsoft Digital

Shyam Sunder Gogi, a technical program manager in Microsoft Digital, served as the organizer of the effort, which initially began with a two-week sprint to get ready for Microsoft Build 2026. The project eventually involved more than 70 stakeholders representing different product and business groups.

“All of these teams came together and not only enabled the environment in our IT tenant but also ensured that all the right policies were deployed to make it so that these agents can run safely,” Gogi says. “That meant not bypassing any of the security parameters that we’ve already deployed.”

Testing in real-world scenarios

Rather than validating solutions in an isolated sandbox, we ran a pilot inside Microsoft Digital, standing up a dedicated Windows 365 Cloud PC environment for roughly 100 internal users.

Pilot participants put the solution through its paces across common developer scenarios. These included:

  • Windows OS images with Copilot CLI and OpenClaw pre-installed
  • Windows 365 Cloud PC provisioning
  • Entra Agent IDs to distinguish human and agent identities
  • Defender runtime protection and Purview data loss prevention policies
  • Intune device and agent configuration policies
  • Microsoft Entra Global Secure Access (GSA) network security controls at runtime

Our goal was to pressure-test a full stack of security guardrails, and to do it the way an actual customer would: with real users and real workloads.

“Customer Zero only works if you’re willing to be the first to hit the rough edges,” says Tom McCleery, a principal group cloud network engineering manager on the Microsoft Infrastructure, Network and Tenant (MINT) team here in Microsoft Digital. “We took the agent scenarios into a live tenant with real users, found the issues product teams couldn’t have surfaced in a lab, and fed every one of them back to the team to address before this ever reached broader enterprise readiness.”

The decision to use Windows 365 Cloud PCs in the pilot proved important.

“We want these device agents to run on our employees’ primary machines, and when necessary, to run on a secondary machine that can be easily isolated and reset if needed,” says Dave Rodriguez, a principal product manager for the Endpoint Experience (EE) team in Microsoft Digital. “That’s why we chose to go with Windows 365 Cloud PCs as a corporate-bound, non-primary environment, where we could have our end users work with those machines as they would with any other device.”

The approach created a safe environment for experimentation while giving teams realistic deployment conditions.

“With Windows 365, there’s no real impact to the devices that we’re using,” says Harshitha Digumarthi, a senior product manager on the EE team. “I really love how we leveraged Windows 365 for piloting this, iterating each time there was a change.”

Digumarthi and her team helped to establish and validate all administrative controls and policies, confirm that they function as expected, and execute a phased rollout strategy—starting with pilots and expanding incrementally while proactively monitoring for risks and user impact.

Identity, data, and network controls under load

Much of the runtime security work fell to our Microsoft Digital team, which validated how the controls behaved once agents were actually operating. A foundational aspect was telling humans and agents apart, so that rules and governance can be more clearly defined based on who is overseeing a process.

“Entra Agent IDs let us give an agent its own distinct identity, instead of having it borrow a person’s,” says Joshua Green, principal software engineering manager on the Microsoft Digital team. “Once you can cleanly separate human and agent identities, everything downstream—access decisions, auditing, runtime protection—gets dramatically more trustworthy.”

On the protection and data-governance side, MINT exercised Defender and Purview against agent activity.

“We validated Defender runtime protection and Purview data loss prevention against live agent behavior,” says Diego Baccino, a principal software engineering manager on the MINT team. “It’s one thing to write a DLP policy; it’s another to confirm that it actually catches what an autonomous agent might try to move. That testing is exactly the kind of value that Customer Zero adds.”

Network-layer controls rounded out the stack.

A photo of Kunjunny.

“Entra Agent IDs let us give an agent its own distinct identity, instead of having it borrow a person’s. Once you can cleanly separate human and agent identities, everything downstream—access decisions, auditing, runtime protection—gets dramatically more trustworthy.”

Pradeep Kunjunny, principal PM manager, Microsoft Digital

This was the advantage of using Global Secure Access, showing that the effort worked with traffic loads generated by a real agent.

“Entra Agent IDs let us give an agent its own distinct identity, instead of having it borrow a person’s,” says Pradeep Kunjunny, a principal PM manager in Microsoft Digital. “Once you can cleanly separate human and agent identities, everything downstream—access decisions, auditing, runtime protection—gets dramatically more trustworthy.”

From pilot to platform

Across the initiative, Microsoft Digital drove coordination and execution across multiple organizations.

A photo of Nair.

“Our close collaboration with Microsoft Digital demonstrates the power of validating security capabilities for AI agents in one of the world’s largest and most complex enterprise environments. The insights we gain from real users and workloads help us strengthen our products and give customers greater confidence as they adopt AI agents securely.”

Aakarsh Nair, partner director of engineering, Microsoft Security

Pilot onboarding, validation of Intune-managed control rollouts, and rapid issue-triage loops improved decision confidence before it was demonstrated at Build, and it shaped the product to prepare it for broader enterprise use.

“Our close collaboration with Microsoft Digital demonstrates the power of validating security capabilities for AI agents in one of the world’s largest and most complex enterprise environments,” says Aakarsh Nair, a partner director of engineering in Microsoft Security. “The insights we gain from real users and workloads help us strengthen our products and give customers greater confidence as they adopt AI agents securely.”

The result is a validated blueprint—endpoint, identity, data, and network controls working together—that our customers can now look to as they bring AI agents to their own tenants.

A photo of Makinde.

“The winners in enterprise AI won’t just be the teams with the best model experience. They’ll be the teams that make AI operationally trustworthy within the enterprise.”

Tunde Makinde, senior service engineer, Microsoft Digital

It was an initiative that was all about proving that secure AI agent scenarios could work in a real enterprise environment, not just in a demo or a lab setup.

“The winners in enterprise AI won’t just be the teams with the best model experience,” says Tunde Makinde, a senior service engineer for tenant integration and management engineering in Microsoft Digital. “They’ll be the teams that make AI operationally trustworthy within the enterprise.”

Our Secure AI Agents initiative is reinforcing a lesson we’ve learned repeatedly as Customer Zero for the company: Successfully deploying AI in the enterprise isn’t just about delivering innovative capabilities, it’s about ensuring that identity, endpoint, network, runtime, and data protections work together as a cohesive system, enabling employees to use new technologies with confidence while maintaining the governance and security standards that organizations expect.

“By validating these capabilities together at enterprise scale, we’re generating real-world learning to strengthen our products and give customers a trusted blueprint for secure AI adoption.”

Ragini Singh, partner group engineering manager, Microsoft Digital

By bringing together teams from across Microsoft and validating these capabilities in a live enterprise environment, we were able to test how AI agents perform under real-world conditions. The result was more than a successful Build demonstration. It was a practical blueprint that informs how we build our products and provides valuable guidance for companies preparing to adopt agents at scale.

“Securing AI in the enterprise at pace requires an integrated, full-stack approach,” Singh says. “That’s why our team in Microsoft Digital brought together Microsoft Agent 365, Windows 365, Intune, Entra Agent ID and Global Secure Access, Defender, and Purview to secure our agents.”

Working in concert across endpoint, identity, network, runtime, and data, our partnership helped establish the layered security model needed to secure our AI agents.

“By validating these capabilities together at enterprise scale, we’re generating real-world learning to strengthen our products and give customers a trusted blueprint for secure AI adoption,” she says.

Looking ahead, our vision is to make this integrated security foundation the standard for every enterprise, so organizations can scale autonomous agents with speed, confidence, and trust.

Key takeaways

Keep these tips in mind as you consider deploying AI agents within your own enterprise organization:

  • Don’t miss an opportunity to think big. A two-week sprint for the Build 2026 conference turned into a much bigger cross-company effort to test secure AI agents in the enterprise.
  • Find the balance between controlled testing environments and real-world scenarios. Windows 365 Cloud PCs provided a safe environment for experimentation while creating real conditions that users will experience.
  • Differentiate between humans and agents. Access, security, and decision making gets easier when there are clearly defined roles for humans and agents.
  • Think about operational reality for AI in the enterprise. There’s a difference between a promising capability and a governable enterprise pattern. Create tests that will help you understand the opportunities in real tenant conditions.

Try it out

Related links