Entra ID

Microsoft Entra Zero Trust Updates for AI and Apps

3 min read

Summary

Microsoft has announced new Microsoft Entra Internet Access and Private Access capabilities to secure AI, web, and private app traffic with Zero Trust controls. The update adds public preview features for network DLP, AI agent controls, and agentic scenarios, while generally available features expand secure access for BYOD, kiosk devices, and MCP traffic visibility.

Need help with Entra ID?Talk to an Expert

Introduction

Microsoft is expanding its Zero Trust access story as organizations adopt AI agents, cloud apps, and hybrid work at scale. For IT teams, these updates matter because they extend identity-first security controls beyond traditional users and devices to include AI interactions, unmanaged endpoints, and private applications.

What’s new in public preview

Microsoft introduced several new public preview capabilities across Microsoft Entra Internet Access and Microsoft Entra Private Access:

  • Network Data Loss Protection (DLP): Extends Microsoft Purview protections to the network layer. Admins can detect sensitive data in AI and SaaS apps, block unsafe sharing, and apply controls based on identity and activity context.
  • AI agent network controls: Entra network controls now support agents, including Microsoft Copilot Studio agents, endpoint-based agents, and local agents. This helps identify unsanctioned AI use, restrict approved destinations, and reduce prompt-based attack risks.
  • Custom Acquire and Agentic Acquire: Supports side-by-side deployment of Global Secure Access for AI Gateway and agentic scenarios alongside third-party vendors.
  • Windows 365 for Agents integration: Adds enterprise-grade network security for agentic Cloud PCs, including traffic monitoring, web filtering, and threat blocking.

What’s now generally available

Microsoft also moved several capabilities to general availability:

  • Browser-based access to internet resources: Secure web access for kiosk and BYOD devices using PAC file-based proxy configuration.
  • BYOD with Client in Entra Private Access: Enables secure private app access for unmanaged devices used by employees and contractors.
  • Shadow MCP Visibility: Provides visibility into MCP traffic, including which MCP servers are in use, what tools they expose, and how those tools are invoked.

Why this matters for IT admins

These updates help administrators apply Zero Trust principles more consistently across modern access scenarios:

  • Extend controls to AI agents and AI-driven workflows
  • Protect sensitive data moving through AI and SaaS apps
  • Improve secure access for remote users, contractors, and unmanaged devices
  • Gain better visibility into emerging AI and MCP traffic patterns

For organizations standardizing on Microsoft security, this also strengthens the connection between Microsoft Entra and Microsoft Purview for policy enforcement and data protection.

Next steps

IT administrators should review which of these capabilities fit current Zero Trust and AI governance plans. Consider testing the public preview features in a controlled environment, validating BYOD and browser-based access scenarios, and assessing whether MCP visibility is needed for AI oversight. Microsoft is also running a webinar series on securing data and access in the era of AI, which may be useful for planning deployments.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft EntraZero TrustAI securityBYODPrivate Access

Related Posts

Entra ID

Azure AD B2C Migration Policy Analyzer Now GA

Microsoft has made the Migration Policy Analyzer generally available to help organizations assess Azure AD B2C custom policies before moving to Microsoft Entra External ID. The tool generates a structured migration assessment, helping IT teams understand current implementations, identify gaps, and prioritize migration work faster.

Entra ID

Microsoft Entra Agent ID: Secure AI Agent Access

Microsoft is urging organizations to treat AI agent governance as an immediate identity and access problem, not a future concern. Based on feedback from identity professionals at Identiverse 2026, the company highlights unmanaged agent sprawl, orphaned agents, and weak agent-to-agent controls, while positioning Microsoft Entra Agent ID and Agent 365 as the foundation for inventory, ownership, and policy enforcement.

Entra ID

Microsoft Entra Agent ID Adds AI Agent Governance

Microsoft has announced general availability of agent identity governance capabilities in Microsoft Entra as part of Microsoft Agent 365. The update helps organizations govern AI agents with dedicated identities, named sponsors, access packages, and lifecycle workflows to reduce overprivileged access and improve accountability.

Entra ID

Microsoft Purview and Entra Add Real-Time AI DLP

Microsoft has announced a public preview that extends data protection to the network layer using Microsoft Purview and Microsoft Entra. The integration helps organizations detect and block sensitive data moving to unmanaged SaaS, personal cloud storage, and generative AI apps in real time, reducing data leakage risk before exposure occurs.

Entra ID

Entra PIM Custom Extensions Preview for Role Activation

Microsoft has introduced preview support for custom extensions in Microsoft Entra Privileged Identity Management, allowing organizations to call a REST API during role activation to enforce business-specific rules. This helps IT teams automate checks such as ticket validation, HR status, compliance gates, and on-call logic while improving auditability and reducing manual approval gaps.

Entra ID

Microsoft Entra Backup and Recovery GA Now Available

Microsoft Entra Backup and Recovery is now generally available for customers with Entra ID P1 or P2, bringing built-in recovery for critical identity objects across workforce tenants. The release extends retention from 5 to 7 days and adds more flexibility for snapshots, difference reports, and recovery jobs, helping IT teams respond faster to accidental or malicious changes.