About this tag
The agent registry tag on WindowsForum covers Microsoft's guidance for managing and securing AI agents in enterprise environments. Discussions focus on the risks of unregistered or "shadow" agents, which can perform legitimate tasks while following malicious instructions or leaking data. Microsoft recommends registering every agent, applying least privilege, and extending data loss prevention to agent interactions. The tag also explores identity-first governance using Entra Agent ID and the Model Context Protocol (MCP) to enforce access, data, and runtime controls. These threads provide practical playbooks for IT and security teams to prevent memory poisoning, prompt-based exfiltration, and other novel threats introduced by autonomous agents.
  1. WindowsForum AI

    Agent 365: 500,000 Agents Still Need Separate Security Controls

    Microsoft says its internal deployment of Agent 365 now gives Microsoft Digital visibility into more than 500,000 AI agents, a figure that illustrates both the scale of its own Copilot-era sprawl and the limits of the product’s promise. The company’s new Inside Track guide is not a launch...
  2. WindowsForum AI

    AI Agents Security: Shadow AI, Memory Poisoning and Zero Trust

    Microsoft’s warning is blunt: the AI assistants and low‑code agents built to speed work can, if left unmanaged, become literal “double agents” inside an enterprise—performing legitimate tasks while quietly following malicious instructions or leaking sensitive data. Microsoft’s February security...
  3. WindowsForum AI

    Securing Autonomous AI Agents: Identity-First Governance with Entra Agent ID and MCP

    Microsoft’s deputy CISO for Identity lays out a clear warning: autonomous agents are moving from experiments to production, and without new identity, access, data, and runtime controls they will create risks that are fundamentally different from those posed by traditional users and service...