4.1.6. Monitoring AI Security and Managing Agents
💡 First Principle: With AI risk spread across identity (Agent ID), data exposure (Purview DSPM), and behavior (guardrails, Defender for AI Service), security teams need one consolidated view rather than checking each control's own dashboard separately — otherwise it's too easy to miss how these signals relate to each other.
The Data and AI security dashboard in Defender for Cloud consolidates AI-specific posture and threat signals into a single view, pulling together findings from across the AI security controls covered in this section. Separately, managing agents in the Microsoft 365 admin center covers the administrative lifecycle of Copilot and other M365-integrated agents — which agents exist, who published them, and organizational-level enablement — a governance layer distinct from Entra Agent ID's identity/access governance.
⚠️ Exam Trap: The Microsoft 365 admin center's agent management view and Entra Agent ID access management (4.1.3) answer different questions — admin center management is about the agent's organizational lifecycle and publishing, while Entra Agent ID governs the agent's runtime identity, permissions, and Conditional Access scope. A scenario about "which agents exist in our tenant" points to the admin center; one about "what can this agent's credentials reach" points to Entra Agent ID.
Reflection Question: Why does having AI security signals consolidated in one dashboard matter more for AI workloads specifically than it might for a single traditional workload type?