Microsoft AI security: audit Copilot and AI agents before they audit you

Microsoft 365 Copilot and the new agent identities are already in tenants, and they inherit permissions, reach data, and act on behalf of users. Senserva scans that surface as part of every tenant scan, so the AI your organization runs is governed with the same rigor as the rest of Microsoft 365.

This page describes what the scanner actually inspects today: agent identity blueprints, the permissions they inherit, the high-risk Graph scopes they hold, and the governance controls around how AI is used.

The Microsoft AI surface Senserva scans

Microsoft's agent model has a three-level hierarchy: an agent identity blueprint defines a permission template, agent identities (service principals) run under it, and users are bound to those identities. Permissions inherit down the chain, which is exactly where risk hides. Senserva walks all three levels.

Agent identity blueprints
Senserva enumerates every agent identity blueprint in the tenant and reads its inheritable permissions, so you know what any agent built on it can do.
Agent identities and users
The service principals running as agents, and the user accounts bound to them, are detected and reported with the scopes they have been granted.
High-risk Graph scopes
Inherited and granted scopes are checked against a list of high-risk Microsoft Graph permissions, so an over-privileged agent is flagged, not buried.
Copilot usage signal
Copilot usage reporting is checked as a monitoring signal, so a gap in AI telemetry shows up as a finding rather than a blind spot.

Deterministic agent auditing, from real tenant data

These checks read live configuration from Microsoft Graph and report exactly what is there. This is the core of Microsoft AI security: knowing precisely what your agents can reach.

Check What it inspects Severity
Least privilege for agent functionsInheritable scopes on agent blueprints, flagged when an agent can do more than its job needs.High
High-risk scopes on agent blueprintsInherited scopes checked against high-risk Graph permissions such as Directory.ReadWrite.All and RoleManagement.ReadWrite.Directory.High
Agent identity blueprints discoveredEvery blueprint in the tenant, with its display name and inherited scopes.Medium
Inheritable permissions on blueprintsThe presence and content of inheritable permissions that propagate to every agent and user under a blueprint.Medium
Agent identities (service principals)The service principals running as agents under each blueprint, with their granted OAuth scopes.Medium
Agent usersUser accounts bound to an agent identity, inheriting its permissions.Medium

High-risk scopes Senserva flags include Directory.ReadWrite.All, RoleManagement.ReadWrite.Directory, Application.ReadWrite.All, Mail.Send, Files.ReadWrite.All, Sites.ReadWrite.All, Policy.ReadWrite.ConditionalAccess, and PrivilegedAccess.ReadWrite.AzureAD, among others.

AI governance controls Senserva tracks

Beyond permissions, Senserva tracks the governance controls that keep AI safe to use. Where Microsoft Graph exposes the setting, the check is deterministic. Where it does not yet, Senserva raises the control as a finding to verify, so it stays on the radar instead of being forgotten.

Control What it covers Severity
Use of approved modelsOnly vetted AI models in use, to limit data leakage and unsafe generations.Medium
Multi-layered content filteringFiltering on AI inputs and outputs to blunt jailbreaks and prompt injection.Medium
Safety meta-prompts on agentsSystem prompts that keep agents from following adversarial instructions.Medium
Human in the loopApproval gates before high-impact AI-driven actions are carried out.Medium
Monitoring and detectionTelemetry on AI workloads so unsafe behavior can be seen and reviewed.Medium
Continuous red teamingOngoing adversarial testing of AI deployments against new bypass techniques.Informational

Why this matters

An AI agent is an identity with permissions and an instruction-following brain. If it is over-privileged, a single prompt-injection can turn it into a path to read mail, change roles, or move data, with no human in the loop. The defense is the same discipline Senserva already applies to the rest of the tenant: least privilege, visibility, and proof.

  • See every agent identity and exactly what it can reach, ranked by risk.
  • Catch high-risk Graph scopes on agents before an attacker does.
  • Keep the governance controls visible, so AI use stays reviewable and audit-ready.

Govern the AI you run, prove the AI you ship

Microsoft AI security is one half of AI governance. The other is running your own AI responsibly, which is how every Senserva AI feature is built. For the standards view, see how this maps to ISO/IEC 42001, and for the model and data posture, see Senserva Trustworthy AI.

Scan your tenant free ISO/IEC 42001 All security checks

Explore the AI Enhanced suite

Agentic AI for Microsoft 365 security, end to end. Each piece works with the AI of your choice.

Works with any AIChatGPT, Claude, Gemini, Copilot, or a local model, with a built-in prompt builder. Claude & MCPRun Microsoft 365 security agentically from Claude through the Senserva MCP. AI security reportsSix AI-enhanced report types generated from one scan. AI remediationValidated, approve-before-apply fixes for every finding. AI complianceMap and close gaps against CISA SCuBA, MCSB, and more.