Select a theme from the list.
Insights

From our experts

Latest
Microsoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password Collector
Security Insight

Microsoft Pushes Data-Loss Prevention Into the Path of Shadow AI

Microsoft Pushes Data-Loss Prevention Into the Path of Shadow AI
Photo by Pavel Danilyuk on Pexels

Microsoft has made new network-level controls generally available for blocking sensitive information from being uploaded to unsanctioned AI services. The integration combines Microsoft Purview classification with Entra Global Secure Access and applies policies to both human activity and traffic generated by agents acting on users' behalf.

News Date: 2026-09-24

Microsoft is extending enterprise data protection beyond managed applications by using the network as an enforcement point for sensitive information moving toward unsanctioned AI services. The generally available capability combines Microsoft Purview data classification with Microsoft Entra Global Secure Access.

The system can inspect files and text in real time, apply organizational policies and stop a transfer before protected information leaves the environment. Importantly, the controls cover conventional user activity as well as on-behalf-of traffic generated by AI agents operating with delegated authority.

Shadow AI Becomes a Data Movement Problem

Organizations have traditionally approached shadow IT by discovering unapproved applications and blocking access to risky domains. Generative AI complicates that model because the browser destination may be legitimate while the uploaded content is highly sensitive.

An employee might paste source code, customer records or contract information into a consumer chatbot without malicious intent. An automated agent could create the same exposure at greater speed while processing documents or performing a delegated research task.

Microsoft's approach connects content awareness with network enforcement. Instead of relying exclusively on user training or application-specific integrations, policies can evaluate the sensitivity of the information and the destination together.

Additional Security Changes

The September update also introduced AI-generated summaries of email detonation results for organizations using Microsoft Defender with Security Copilot. These summaries are designed to help analysts understand file and URL sandbox evidence without manually correlating every event.

Microsoft also expanded Purview auto-labeling simulations to cover as many as 20 million items and 50,000 sites. Other changes improve the investigation, retention and deletion of content produced through Copilot Pages, Loop and related Microsoft 365 experiences.

Implementation Priorities

  • Identify which AI services are approved for business data.
  • Classify sensitive information before enabling broad blocking policies.
  • Test rules in monitoring mode to detect operational conflicts.
  • Apply controls to delegated agents as well as interactive users.
  • Define an exception process for legitimate AI workflows.

I believe network-level enforcement is an important step, but it should not become the only control. Organizations still need endpoint visibility, strong identity governance and clear inventories of autonomous agents. Blocking a sensitive upload is useful, but understanding which person or agent attempted it, why it happened and what other systems were accessed is essential for meaningful risk management.

Talk to our team →

Latest

Microsoft Pushes Data-Loss Prevention Into the Path of Shadow AISep 26, 2026Dormant GitHub Actions Reawakened With Their Malicious Payloads IntactSep 26, 2026Kiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksSep 26, 2026Unpatched OnePlus Chain Gives Permissionless Android Apps Root ControlSep 25, 2026MacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelSep 25, 2026Storm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookSep 25, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3IDScan Lawsuits Put Mass Identity Collection Under the Microscope4French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning5Windows LegacyHive Flaw Leaves Administrators Weighing Unofficial Protection6COLDCARD Randomness Failure Exposes Bitcoin Wallets to an $88 Million Sweep