← All topics

# Topic

AI Security

13 articles on this subject.

01 2 min read

Agentic Defense-in-Depth: A Tri-Cloud Reference Architecture for AI Agents

Seven defense layers from network edge to data plane for agents on Azure AI Foundry, AWS Bedrock AgentCore, or GCP Vertex AI — native + best-of-breed controls, A2A and MCP protection, deployment gates, and a crosswalk to OWASP, MITRE ATLAS, NIST AI RMF, and DASF 3.0.

02 5 min read

Your Non-Human Identities Have Owners. Half of Them Quit.

A recorded owner who left the company. A dormant identity nobody measures. A directory-role admin that reads as "scoped." Non-human identity assessment keeps mistaking a value being present for a control being satisfied — and a false green is worse than a red.

03 4 min read

What 614 Non-Human Identities Taught Me — and the False Positive That Almost Cried Wolf

I pointed nhi-scan at a real Entra tenant with 614 non-human identities. The 80:1 ratio became a worklist — and the top finding was a false positive: 53 "long-lived secrets" that were really 1. What a real NHI scan reveals, and why context beats raw counts.

04 3 min read

Making an NHI Scanner Production-Ready: What a 600-Identity Run Taught the Tool

Running my NHI tool against a real 600+ identity Entra tenant exposed three things unit tests missed: it didn't run on Windows, the enriched scan took 40 minutes, and it mistook managed identities for stored secrets. The fixes — including a 20x speedup — and why dogfooding matters.

05 5 min read

What an AI Agent Must Never Be Allowed to Do

Buried in a Microsoft Graph reference is a list of permissions that cannot be granted to an AI agent identity at all. Read backwards, it's the first enforced authority model for agents — six prohibitions worth applying to every agent platform you run, not just Entra.

06 5 min read

MCP Triage: Turning Scanner Noise Into a Six-Item To-Do List

MCP security scanners are smoke alarms that go off every time you make toast — one audit found 21 of 27 alerts were false. mcp-triage is the layer that sits on top of any scanner and sorts the noise into the handful that matter, then governs the fleet against the OWASP MCP Top 10.

07 3 min read

Drift Detection for Agent Identities: When Reach Grows and the Tier Doesn't Move

An AI agent's reach is the one thing that can grow without anyone touching the identity — give it a new tool or connector and its blast radius expands while privilege, credential age, and owner all look unchanged. Here's why point-in-time posture scans miss it, and how to close the gap.

08 13 min read

A Control Framework for Non-Human & Agentic Identity

A practitioner control framework for governing non-human and agentic identities: eight principles, a four-tier risk model, thirty-five controls across eight domains, an agentic threat model, and a maturity model — mapped to OWASP NHI Top 10, NIST AI RMF, CSF 2.0, and 800-53.

09 3 min read

The Non-Human Identity Reckoning — and Why Agents Make It Urgent

Non-human identities are the enterprise's largest and least-governed identity population, and AI agents just added autonomy to the problem. Here is why the next identity crisis is already here — and the discipline that answers it.

10 9 min read

Understanding Azure AI Foundry Agent Identities, Blueprints, and Entra ID Object Relationships

A practical identity architecture guide for security, governance, and troubleshooting

11 24 min read

AI Red Teaming: A Risk-Based Methodology for When, Why, and How

AI red teaming has emerged as a foundational security control for organizations deploying artificial intelligence — analogous to penetration testing for traditional applications, but distinct in scope, technique, and risk profile. Unlike standard security assessments, AI red teaming…

12 2 min read

Securing Enterprise AI: An Identity-First Approach

As enterprises move from AI pilots to agentic systems that act on their behalf, identity becomes the control plane. Here is how I think about securing AI agents with the same rigor we apply to human and workload identities.

13 2 min read

Using AI to Optimize SOC Operations

Security Operations Centers are drowning in alerts while the metrics that matter — mean time to detect and respond — barely move. Here is how AI-driven automation and analytics change the operational math.