Microsoft Entra Zero Trust Updates for AI and Apps
Summary
Microsoft has announced new Microsoft Entra Internet Access and Private Access capabilities to secure AI, web, and private app traffic with Zero Trust controls. The update adds public preview features for network DLP, AI agent controls, and agentic scenarios, while generally available features expand secure access for BYOD, kiosk devices, and MCP traffic visibility.
Introduction
Microsoft is expanding its Zero Trust access story as organizations adopt AI agents, cloud apps, and hybrid work at scale. For IT teams, these updates matter because they extend identity-first security controls beyond traditional users and devices to include AI interactions, unmanaged endpoints, and private applications.
What’s new in public preview
Microsoft introduced several new public preview capabilities across Microsoft Entra Internet Access and Microsoft Entra Private Access:
- Network Data Loss Protection (DLP): Extends Microsoft Purview protections to the network layer. Admins can detect sensitive data in AI and SaaS apps, block unsafe sharing, and apply controls based on identity and activity context.
- AI agent network controls: Entra network controls now support agents, including Microsoft Copilot Studio agents, endpoint-based agents, and local agents. This helps identify unsanctioned AI use, restrict approved destinations, and reduce prompt-based attack risks.
- Custom Acquire and Agentic Acquire: Supports side-by-side deployment of Global Secure Access for AI Gateway and agentic scenarios alongside third-party vendors.
- Windows 365 for Agents integration: Adds enterprise-grade network security for agentic Cloud PCs, including traffic monitoring, web filtering, and threat blocking.
What’s now generally available
Microsoft also moved several capabilities to general availability:
- Browser-based access to internet resources: Secure web access for kiosk and BYOD devices using PAC file-based proxy configuration.
- BYOD with Client in Entra Private Access: Enables secure private app access for unmanaged devices used by employees and contractors.
- Shadow MCP Visibility: Provides visibility into MCP traffic, including which MCP servers are in use, what tools they expose, and how those tools are invoked.
Why this matters for IT admins
These updates help administrators apply Zero Trust principles more consistently across modern access scenarios:
- Extend controls to AI agents and AI-driven workflows
- Protect sensitive data moving through AI and SaaS apps
- Improve secure access for remote users, contractors, and unmanaged devices
- Gain better visibility into emerging AI and MCP traffic patterns
For organizations standardizing on Microsoft security, this also strengthens the connection between Microsoft Entra and Microsoft Purview for policy enforcement and data protection.
Next steps
IT administrators should review which of these capabilities fit current Zero Trust and AI governance plans. Consider testing the public preview features in a controlled environment, validating BYOD and browser-based access scenarios, and assessing whether MCP visibility is needed for AI oversight. Microsoft is also running a webinar series on securing data and access in the era of AI, which may be useful for planning deployments.
Need help with Entra ID?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies