GregLab | Exam Prep

Secure compute

Security for AI Workloads and Agents

Core

Secure AI data, identities, runtime actions, model traffic, safety behavior, workload telemetry, and tenant agent inventory with controls matched to each layer.

Aligned to the live SC-500 guide, which publishes no skills-measured date; guide and product behavior verified September 23, 2026.

Why this matters

AI agents connect data, identities, tools, models, and actions. A single control cannot cover overshared grounding data, overprivileged agent identities, unsafe runtime calls, ungoverned model endpoints, harmful content, or weak operational visibility.

Must Know

  • Purview DSPM for AI surfaces overshared SharePoint data and risky AI interactions; a finding must be remediated at the data, sharing, labeling, or policy layer that caused it.
  • Defender real-time protection can evaluate supported agent tool invocations and block configured risky actions; coverage depends on agent type, connection, and supported invocation path.
  • Conditional Access applies when Microsoft Entra issues or refreshes tokens. API-key access bypasses that token pipeline and is outside Conditional Access enforcement.
  • Defender XDR AI agent inventory and blast-radius views use permissions, knowledge sources, blueprint configuration, and attack paths to prioritize risky agent identities.
  • Entra Agent ID lifecycle controls can disable an individual agent, a blueprint, or broader authentication; choose the narrowest action that contains the risk.
  • AI Gateway uses API Management capabilities to centralize access, quotas, policy, monitoring, and private connectivity for supported Foundry model traffic.
  • Defender for AI Services detects supported runtime threats; Foundry guardrails evaluate prompts and responses with controls such as content filters, blocklists, and Prompt Shields.
  • The Data and AI security dashboard summarizes asset, posture, protection, recommendation, attack-path, and alert signals; Microsoft 365 admin center governs agent inventory, availability, owners, permissions, and lifecycle.

Compare and Distinguish

  • DSPM for AI addresses data exposure and interaction risk; Defender runtime protection addresses unsafe or malicious agent activity.
  • AI Gateway governs traffic and access; Foundry guardrails evaluate input and output safety; Defender for AI Services detects threats.
  • Entra Agent ID governs authentication and access; Microsoft 365 agent management governs tenant inventory, availability, ownership, and rollout.

Scenario examples

  • Scenario: Copilot can summarize a broadly shared sensitive site. Think: use DSPM evidence and remediate sharing or content controls rather than merely blocking one prompt.
  • Scenario: An autonomous agent reaches an API with its own Entra token. Think: target the agent identity and resource in Conditional Access; an API key would not be covered.
  • Scenario: Model traffic needs shared quotas and logging while harmful content must be blocked. Think: combine AI Gateway policy with an assigned and tested Foundry guardrail.

Exam traps

  • A dashboard finding does not itself change SharePoint permissions or contain an agent.
  • Conditional Access cannot govern a resource reached only with an API key.
  • A guardrail is not a substitute for authentication, least privilege, private networking, or runtime threat detection.
  • Buying a Security Store agent, installing it, granting permissions, and ending its subscription are separate lifecycle actions.

Key takeaways

  • Map each AI risk to data, identity, runtime, gateway, safety, workload, posture, or governance layers.
  • Constrain agent blast radius before enabling autonomous actions.
  • Reverify preview and newly launched AI surfaces every 30 days.
How it works
  • An agent authenticates, retrieves grounding data, calls tools or models through supported paths, and emits activity that security products can inspect.
  • Preventive controls act at each hop while posture and threat products correlate exposures and observed behavior.
Objects and administrative surfaces
  • Microsoft Purview portal for DSPM for AI assessments, recommendations, and risky interactions.
  • Microsoft Defender portal for Security for AI settings, agent inventory, blast radius, alerts, and Advanced Hunting evidence.
  • Microsoft Entra admin center, Foundry portal, API Management, Defender for Cloud Data and AI dashboard, and Microsoft 365 admin center agent registry.
When to use it
  • Use DSPM before and during AI rollout to reduce data exposure; use runtime protection and Defender plans for active behavior.
  • Use AI Gateway and guardrails when central traffic policy and prompt or response safety must be enforced independently.
Security and governance implications
  • Require named owners, least-privileged identities, reviewed tools, protected data sources, monitored activity, and a disable path for every agent.
  • Record preview status, license prerequisites, supported agent types, and coverage gaps without implying broader protection.
Troubleshooting signals
  • For missing real-time protection, verify agent support, connector onboarding, policy scope, and the actual tool invocation path.
  • For agent access, inspect subject and audience, token flow, Conditional Access result, resource authorization, and whether the call used an API key.
More detail
  • Use Purview DSPM for AI to find overexposed data and risky interactions.
  • Protect supported Copilot Studio actions and Entra Agent ID token flows.
  • Configure AI Gateway, Defender for AI Services, and Foundry guardrails for their distinct boundaries.
  • Monitor AI posture and govern agents through Defender for Cloud and Microsoft 365 admin surfaces.

Ready for the quiz?

  • Which layer should remediate a sensitive SharePoint site available to Copilot?
  • Why does an API-key call evade Conditional Access?
  • How do AI Gateway, guardrails, and Defender for AI Services complement one another?

Related objectives

  • D3.1.S1 — Identify overexposure of data in SharePoint
  • D3.1.S2 — Identify risks related to Microsoft Copilot and AI apps by using Microsoft Purview Data Security Posture Management (DSPM)
  • D3.1.S3 — Enable and configure real-time protection for Microsoft Copilot Studio agents
  • D3.1.S4 — Implement conditional access for Microsoft Entra Agent ID
  • D3.1.S5 — Analyze blast radius for security risks related to Entra Agent ID by using Defender XDR
  • D3.1.S6 — Manage Entra Agent ID access
  • D3.1.S7 — Configure and deploy AI Gateway in Azure API Management for Microsoft Foundry
  • D3.1.S8 — Enable Defender for AI Service in Cloud Workload Protection in Defender for Cloud
  • D3.1.S9 — Configure guardrails for agent security in Foundry
  • D3.1.S10 — Monitor AI security by using the Data and AI security dashboard in Defender for Cloud
  • D3.1.S11 — Manage agents in Microsoft 365 admin center

Learn more

Free Microsoft Certified: Cloud and AI Security Engineer Associate prep

Build focused SC-500 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-500 at a glance

Level
Intermediate / Associate
Duration
120 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-500. This lane contains multiple-choice and multiple-response exam-style practice. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Intermediate Associate-level cloud and AI security-engineering complexity rather than a Microsoft-published question rating.

Reference

SC-500 topics and reference map

Study links

SC-500 resources