certslothcertsloth
SC-500/Topic 10

Azure / Associate

AI Data Exposure and Agent Security

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: An agent can combine every permission it receives; constrain its identity, context and tools.

Must remember

  • Review overexposed SharePoint data and source permissions before deploying search/assistant experiences. Retrieval can make existing oversharing easier to exploit. Purview DSPM for AI helps discover/classify relevant risk and data-use patterns; remediation still needs ownership and access changes.
  • Agent identities require lifecycle, owners, least privilege and access reviews. Entra Agent ID and supported Conditional Access controls help govern agent access; inspect blast radius and related signals through Defender XDR where supported. Do not share a broad human administrator identity with agents.
  • Copilot Studio agents need supported real-time protection and controlled connectors/actions. Manage deployed agents through relevant administration surfaces, including Microsoft 365 admin centre where applicable. A published agent can expose tools even when its chat interface looks harmless.
  • API Management AI Gateway can centralise supported model access policies, token/rate controls and observability. It does not make every downstream tool action authorised. Foundry guardrails and tool-access constraints should be tested against direct/indirect prompt injection and sensitive-data leakage.
  • Enable appropriate Defender for AI service/workload protection and inspect the Data and AI security dashboard. Correlate risky data, identity and runtime signals rather than treating a single filter as a complete defence.
  • Log AI interactions with minimisation/redaction, provenance and retention controls. Validate outputs before commands/queries/actions; require approvals for consequential operations. Test tenant separation, revoked access, poisoned retrieval and tool-result injection, not only offensive user prompts.

Choose under exam pressure

Requirement Choice and reason
Assistant exposes documents too broadly Repair source permissions and retrieval authorisation.
Agent needs one business operation A scoped agent identity/tool permission.
Need central model API policy and usage controls A supported API Management AI Gateway design.

Traps

  • Existing document oversharing becomes an AI risk.
  • A model refusal is not a substitute for denied tool permission.
  • Agent identity governance must continue after initial deployment.

Active recall

1. Why inspect SharePoint permissions before rollout?

An assistant can surface data users technically can access but should not have been granted.

2. What is an agent's blast radius?

The data and actions reachable through its combined identities, tools and dependencies.

3. Why separate model API policy from tool policy?

Calling a model and changing a business system are different operations with different permissions.

4. What should happen when a user loses document access?

Retrieval/index/cache controls must stop exposing that content according to the design.

5. Why test tool-output injection?

An external tool can return hostile instructions that the model must not treat as trusted policy.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.