Buried in a Microsoft Graph reference is a list of permissions that cannot be granted to an AI agent identity at all. Read backwards, it's the first enforced authority model for agents — six prohibitions worth applying to every agent platform you run, not just Entra.
A visual blueprint of MDASH — Microsoft's Multi-Model Agentic Scanning Harness — an autonomous system that discovers, validates, and proves software vulnerabilities at AI speed. The system, not the model, is the product.
AI Red Teaming: A Risk-Based Methodology for When, Why, and How
AI red teaming has emerged as a foundational security control for organizations deploying artificial intelligence — analogous to penetration testing for traditional applications, but distinct in scope, technique, and risk profile. Unlike standard security assessments, AI red teaming…
Securing Enterprise AI: An Identity-First Approach
As enterprises move from AI pilots to agentic systems that act on their behalf, identity becomes the control plane. Here is how I think about securing AI agents with the same rigor we apply to human and workload identities.
Security Operations Centers are drowning in alerts while the metrics that matter — mean time to detect and respond — barely move. Here is how AI-driven automation and analytics change the operational math.