Lesson 7/7
Microsoft Security Summit 2025: the AI agent era and its new threats
Back from the Microsoft Security Summit 2025: the explosion of AI agents, the new threats (prompt injection), unified solutions (Defender, Sentinel, Purview), and the Agent ID revolution for securing the era of autonomous AI.
☰
Contents
32
▾
0:00 Introduction to the Microsoft Security Summit 0:18 The era of AI agents: an exploding market 0:42 New attack surfaces and prompt injection 0:57 Complexity vs security: today's challenge 1:08 Microsoft's unified platform (Defender, Sentinel, Purview) 1:38 Purview: confidentiality and data protection 1:50 Entra: modern identity management and MFA 2:02 Copilot: the risk of exposing sensitive data 2:28 Rolling out Copilot: a staged strategy 2:43 Cleaning up dormant data (80% never used) 3:13 Consolidating governance and industrialising it 3:27 Securing SharePoint and Teams: the first 100 sites 3:54 SharePoint administration policy 4:14 The data life cycle with Copilot 4:31 Purview: automatic detection and classification 4:52 Securing the foundations: 5 days vs 58 days 5:05 Mapping the attack surface 5:18 Security Exposure Management: the attacker's view 5:36 A unified platform approach (firewall, DNS, endpoints) 6:00 How attackers move through a graph 6:21 Autonomous security agents in a few clicks 6:48 The SOC: from manual work to autonomous AI 7:00 Microsoft Security Store: a marketplace of agents 7:09 Building Copilot agents with an MCP server 7:24 MCP: an API for artificial intelligence 7:36 Types of agent: triage, sorting, hunting 8:00 Vibe Coding and Vibe Hunting: a workflow revolution 8:27 Entra Agent ID: managing agents as identities 8:37 Three kinds of AI agent (assistant, autonomous, colleague) 9:10 Human accountability and least privilege 9:39 Zero Trust and conditional access for agents 9:54 Conclusion and thanks to Microsoft