Architecture-specific review
Microsoft Foundry Agent security review
Foundry Agent Service hosts your agent with per-session hypervisor isolation and an auto-provisioned Entra Agent ID. That substrate is strong, but the boundary sits at what your agent's identity is scoped to reach, what a customer VNet exposes, and — if the agent is published into Microsoft 365 — what permissions it inherits into Outlook, SharePoint, OneDrive and Teams.
Start an AI security review →Review scope
What the reviewer needs to establish
Scope the hosted agent and its application services: the Entra Agent ID grants, any customer-provided VNet and the internal resources it exposes, the persistent per-session file system, the OpenTelemetry traces, and — where the agent is published as a Copilot-integrated agent — its inherited Microsoft 365 permission scope. Foundry's hypervisor isolation and per-agent identity are strong building blocks; the permission boundary, network scope and approval design are still your application's job.
Entra Agent ID scope
What is each hosted agent's Entra Agent ID actually scoped to access — verified against the agent's real tool set, or copied from a broad template?
Evidence to request: Per-agent Entra Agent ID role assignments, the tool set each identity backs, least-privilege review notes, and negative permission tests.
VNet-exposed blast radius
If deployed with a customer-provided VNet for outbound traffic, which internal resources does that VNet actually expose to the agent, and is that inventory current as the network evolves?
Evidence to request: VNet configuration, the list of reachable internal databases and APIs, and a re-review record showing the exposure was revisited, not configured once and forgotten.
Tracing coverage
Is OpenTelemetry tracing enabled and actually reviewed for every model call, tool invocation and handoff — or only collected and spot-checked?
Evidence to request: Tracing pipeline configuration, coverage across model and tool events, and evidence that traces are reviewed, since collection is not review.
Persistent file system
What sensitive data gets written to the per-session persistent file system, and is it cleaned or rotated across a long-running session?
Evidence to request: File system retention and cleanup policy, sensitive-data handling for anything written during a session, and rotation tests.
Published-agent inheritance and decision
If any agent is published into Microsoft 365 as a Copilot-integrated agent, is the tenant confirmed past the CVE-2026-35435 fix, and has its inherited permission scope been reviewed independently of its Foundry-side identity?
Evidence to request: Tenant version confirmation past CVE-2026-35435, the reviewed inheritance scope into Outlook/SharePoint/OneDrive/Teams, open controls with owners, and the signed review decision.
Architecture example
Follow authority and data end to end
A model endpoint is one component. The security decision also depends on the identity that calls it, the data it receives, the actions it can trigger, and who accepts the remaining risk.
For a hosted agent that answers HR questions: employee query → Entra-scoped tool call to an HR system → context assembled → response, with traces flowing to OpenTelemetry. Check that the Entra Agent ID reaches only that HR system, that a customer VNet does not quietly expose adjacent finance databases, and that if the agent is also published into Microsoft 365 its inherited SharePoint scope was reviewed on its own, not assumed from the Foundry identity.
From review to decision
Describe the system, confirm its architecture, examine threats and required controls, attach evidence, and record a human clearance decision. Unknown or missing evidence remains visible; it is not treated as a passed control.
Read the review methodology →