Video summary
Secure the age of AI: Redefining trust, data and access
Main summary
Key takeaways
Summary
Core theme
Organizations must “secure data and access in the AI era.” Traditional security models—mainly designed around applications/files and human users—are insufficient for AI workloads that include prompts, agents, connectors, and data flows that existing controls can’t reliably see or govern.
New security drivers (scale + risk)
- Exponential growth of identities and endpoints
- Includes both human users and non-human entities/AI agents.
- Explosion in enterprise data
- Claim: 90% of the world’s data was created in the last 2 years.
- Attack surface expands
- Every identity/endpoint becomes a potential entry point and a “cache of enterprise data.”
- AI-related incidents are common
- 70% of organizations report AI incidents.
- Non-human identities will dominate access requests
- By 2029, 60% of secure access requests are expected to come from non-human identities (AI agents), requiring access enforcement that goes beyond people.
Why access control must change
- Access can’t be granted/denied only at the application layer
- AI requires controls spanning prompts and granular workflows.
- Access can’t be limited to human identities
- Agents must be governed similarly to employees.
- Data protection must be real-time while data is moving
- Not only “at rest.”
Proposed model: Unified, adaptive “access fabric” (Zero Trust)
The approach moves beyond siloed identity/network security into an “access fabric” that secures every digital interaction.
Three Zero Trust–driven principles
- Contextual access
- Continuous evaluation
- Connected real-time protections
How it works conceptually
- Identity determines who/what should have access.
- Network access continuously validates trust/session security based on identity signals.
- The goal is zero-trust, continuous evaluation across interactions involving humans, machines, and agents, with adaptive governance and enforcement.
Microsoft Entra + Microsoft Purview integration
Entra (identity/access)
- Provides the identity/access side, including:
- Identity
- Conditional access
- Insider risk context
Purview (data security)
- Provides data security controls that protect data in real time as it travels, not just while stored.
Together: connect access decisions to data protection
- Access decisions are informed by data sensitivity.
- Enforcement adapts based on context at the speed and scale AI operates.
“One home” concept
- Entra manages access policies tied to identity/network/session trust.
- Purview manages how data is secured across the digital estate and where it travels (endpoints, apps, third parties).
Data movement scenarios driving tighter protections
- Data accessed via enterprise apps (e.g., Microsoft 365) and third-party apps (Workday, Salesforce, line-of-business apps).
- Data can be:
- Downloaded
- Copied to removable media
- Printed
- In the AI era, data may be shared to:
- Unmanaged browsers
- Consumer-grade AI apps
- This can send “crown jewel” data to risky third parties.
Therefore: the emphasis is on network-level data protections integrated with Entra.
New / announced capabilities for AI and data-in-motion
Network data security integration (public preview)
- Secures data in motion when shared to:
- Shadow AI
- Unmanaged SaaS apps
- Personal cloud storage over the network
- Goal: prevent sensitive data leakage
Future direction (planned deeper demos)
- Entra + Purview walkthroughs showing the integration end-to-end.
- Expanded protections for AI agents, including:
- Agents running locally on devices
- Agents running in the cloud
Packaging / availability
- These capabilities are stated as available in Microsoft 365 E7:
- Advanced data security via Purview
- Identity/access via Entra
Main speakers / sources
- Diana Visar — Product Marketing Manager, Microsoft Entra (host)
- Chenade Odonovan — Microsoft Entra Vice President of Product
- Matili Dandich — Microsoft Purview General Manager of Product