{"id":59670,"date":"2026-06-02T19:51:14","date_gmt":"2026-06-02T19:51:14","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/59670\/"},"modified":"2026-06-02T19:51:14","modified_gmt":"2026-06-02T19:51:14","slug":"microsofts-vasu-jakkal-on-why-ai-agents-need-human-level-security-controls","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/59670\/","title":{"rendered":"Microsoft\u2019s Vasu Jakkal On Why AI Agents Need Human-Level Security Controls"},"content":{"rendered":"<p>As Microsoft expands its Agent 365 offering, Jakkal tells CRN that in \u2018just the way we have been protecting humans for eons, we need to extend the same protection from a security standpoint to agents.\u2019<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_159d6e71c7e808911ecb887149efdde62904bea11.png?width=750&amp;format=png&amp;optimize=medium\" width=\"611\" height=\"472\"\/><\/p>\n<p>Microsoft is doubling down on its efforts to uniquely provide comprehensive control for securing the adoption of AI agents with the expansion of its Agent 365 offering, top Microsoft security executive Vasu Jakkal told CRN.<\/p>\n<p>In connection with Microsoft Build 2026, the tech giant announced Tuesday that it has expanded Agent 365\u2014which provides observability, governance and security for agents\u2014to now include local AI agents in addition to cloud-based agents. The capabilities for surfacing locally based agents, via Microsoft\u2019s Agent Registry in Agent 365, are now in preview, Microsoft said.<\/p>\n<p>[Related: <a href=\"https:\/\/www.crn.com\/news\/cover-story\/microsoft-s-judson-althoff-to-partners-managed-services-are-your-ai-superpower\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft\u2019s Althoff To Partners: Managed Services Are Your AI Superpower<\/a>]<\/p>\n<p>It\u2019s the latest move from Microsoft to enable partners and customers to avoid the potentially major security risks of using powerful AI agents without robust security and governance, according to Jakkal, corporate vice president for Microsoft Security.<\/p>\n<p>\u201cOur philosophy always has been that we want to comprehensively protect organizations, no matter what you do, what you\u2019re using,\u201d she said in an interview. \u201cSo that\u2019s why we\u2019re expanding this to local agents\u2014because as agents really proliferate across environments, we believe gaining visibility and control over them becomes critical.\u201d<\/p>\n<p>Ultimately, in \u201cjust the way we have been protecting humans for eons, we need to extend the same protection from a security standpoint to agents,\u201d Jakkal said. \u201cAnd it starts with great observability, it starts with great security, and it starts with great governance.\u201d<\/p>\n<p>Jakkal also discussed why identity security is so critical when it comes to protecting agents, as well as the importance of Agent 365 for solution and service provider partners. Without a doubt, partners \u201chave been joined to the hip with us on making sure we can deploy the solution to our customers,\u201d she said.<\/p>\n<p>What follows is more of CRN\u2019s interview with Jakkal.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_1a80144e7eb9ec5ffc3728ed5f47773db4a7c3da2.png?width=750&amp;format=png&amp;optimize=medium\" width=\"612\" height=\"461\"\/><\/p>\n<p>What has prompted Microsoft to focus so heavily on providing security for AI agents? And what are the major Build announcements around Agent 365?<\/p>\n<p>Just at the highest level, what we\u2019re seeing now is this incredible momentum on how organizations are building, deploying and using agents. Agents are moving from prototype to production. And as they do that, the challenge isn\u2019t about using agents. Customers want to use agents. It\u2019s not about building them. They want to build them. But the challenge really is about security, observability and governance. Just to give you a few stats, IDC had projected 1.3 billion agents by 2028. And while that\u2019s theoretical, what we have seen in our own first-party research data is 80 percent of Fortune 500 are already using and deploying agents, especially as low-code, no-code tools become easily available to them. People are excited about it. They want to use it. And agents are becoming more and more autonomous\u2014from assistive to autonomous. They\u2019re no longer side projects. They\u2019re part of just the operational fabric of many of these organizations. And as that happens, and as they become a part of our workforce, we have to think about security differently.<\/p>\n<p>That was the reason behind Agent 365, which we first announced at Ignite last year. The philosophy and idea behind it was, just the way we have been protecting humans for eons, we need to extend the same protection from a security standpoint to agents. And it starts with great observability, it starts with great security, and it starts with great governance. Those are the three pillars behind Agent 365, where we are helping organizations start with discovering what agents they have.<\/p>\n<p>Our registry brings that to life. You turn it on, and you can see all of the agents in your environment\u2014whether they are on Microsoft platforms or they are on third-party platforms. It helps you bring the same tried-and-tested security controls of Microsoft Security that we have used for securing organizations and people and infrastructure to agents. Defender brings threat protection capabilities, protects agents from novel attacks so they don\u2019t become \u201cdouble agents.\u201d With Entra, [we\u2019re] giving every agent an agent ID and conditional access so that you can manage access [and use] very classical principles of zero trust on managing privileged access and verifying explicitly. Intune helps manage policies, especially as you have more local agents\u2014which [are part] some of the new announcements we are making at Build\u2014like OpenClaw. You can use Intune to manage those policies and block agents where you want to. And Purview helps you bring those data security controls [around] really understanding what\u2019s the data that agents are accessing? How do you make sure you have the right sensitivity labeling, the right policies? That\u2019s what Agent 365 does. It brings those security and governance principles right to the very beginning, preventing agent sprawl, reducing data oversharing, protecting against novel techniques and also helping you with compliance.<\/p>\n<p>We had all these capabilities for cloud agents. We\u2019re now expanding that to local agents because we\u2019ve seen a proliferation of local agents. And you can now use Defender and Entra and Intune and Purview to help you protect those local agents on your machine or in your tenant. So that\u2019s really the big theme. And then lastly, we also have Agent 365 SDK that we were building, so that now developers anywhere can use Agent 365 through the SDK\u2014so as they develop agents, they have these controls.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_14ba7f4555920785ce95bda7721ef9090cbfda652.png?width=750&amp;format=png&amp;optimize=medium\" width=\"690\" height=\"458\"\/><\/p>\n<p>Are you seeing a lot more usage of local agents?<\/p>\n<p>Yes, we are, with OpenClaw and all of those agents that were introduced. So we are seeing [more] local agents. Our philosophy always has been that we want to comprehensively protect organizations, no matter what you do, what you\u2019re using. So that\u2019s why we\u2019re expanding this to local agents\u2014because as agents really proliferate across environments, we believe gaining visibility and control over them becomes critical. And that\u2019s why our registry now supports more than 20 types of local agents, like coding agents, desktop agents, remote MCP servers. And we are also using policy, especially through Intune, to block common execution methods for the local agents, like OpenClaw.<\/p>\n<p>If you talk to a CISO, they\u2019re worried. What we know is that 29 percent of organizations that we talked to and surveyed said that their employees are using unsanctioned AI tools. So that creates a lot of risk for them. And so they want to make sure they understand what [agents are being used]. And now the Agent 365 Registry surfaces unmanaged local agents discovered by Defender, Entra and Intune, all working together. So it gives them that scanning [capability] and helps them understand and manage that risk.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_135b68fb55c1f6216dfb42d44d147a0cd5bee272a.png?width=750&amp;format=png&amp;optimize=medium\" width=\"610\" height=\"458\"\/><\/p>\n<p>Is this a unique approach from Microsoft, given that you have such a broad security platform with tools such as Defender, Entra, Intune and Purview?<\/p>\n<p>Absolutely. Our basic principle has been that security practitioners want to manage their tool fragmentation. There\u2019s so much tool fragmentation. They\u2019re not looking for another thing. And so we used our [existing] tools that they use. We have 1.6 million customers who use Microsoft Security today, and 1 million of those customers use four or more of our tools. So we just want to expand those tools so that they can now protect agents the same way they have been doing. And that\u2019s why Agent 365 uses all the familiar names\u2014Defender, Purview, Entra, Intune. And we\u2019re expanding the capabilities\u2014first to cloud agents, now to local agents. So I think it brings that simplicity, that easy button to the organizations, as well. And so our philosophy has been that we want to give unified solutions to our security organizations that can protect them comprehensively, to secure agents, to secure people, to secure foundations and we want to use agentic security. So it\u2019s really that paradigm of security for AI and AI for security. Agent 365 is security for AI, along with the rest of our portfolio, which also brings those agentic capabilities.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_1132cebf2081f195aa284afc19d0acc7aef72db55.png?width=750&amp;format=png&amp;optimize=medium\" width=\"627\" height=\"458\"\/><\/p>\n<p>What are the major partner opportunities with Agent 365?<\/p>\n<p>We have 20,000 partners in our ecosystem. We are partner-first. We always have been. We need our partners to scale. With Agent 365, our GSIs and other partners have been joined at the hip with us on making sure we can deploy the solution to our customers. Agent 365 is also part of [Microsoft 365] E7, which is now our overall frontier transformation solution. And organizations will continue to use that. And we look forward to scaling that with our partners.<\/p>\n<p>No company can do this alone. Security has always been a team sport, and our partners are so important to us. They are really our co-creators on so many of these technologies, from the get-go, of helping understand the customer problems and helping understand how to manage change. How do you deploy and how do you use [the technology]? They bring that scale. And I\u2019m excited about what we can do with them.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_19acfd5121967f169235388d36109201a3b76980c.png?width=750&amp;format=png&amp;optimize=medium\" width=\"610\" height=\"458\"\/><\/p>\n<p>You\u2019ve touched on Entra and identity here\u2014why is that so pivotal to securing AI agents?<\/p>\n<p>It\u2019s the first step toward securing agents. And it\u2019s even the first step in Agent 365 because it starts with a registry and it starts with an Agent ID. When you and I come to work, we log in and the system recognizes [us]\u2014we have a unique identifier, which then gives us the permissions that we need to access the things we need. If we didn\u2019t have that, it would be chaos. And for agents as well, with Agent ID, that is what we\u2019re trying to solve\u2014how do you manage an agent if it doesn\u2019t have an identifier? Whose permissions does the agent take? If you have an agent that you\u2019re sharing with me, does it have your permissions? And do I automatically get them? And what if you have more privileges than I need to have? And that becomes really complicated as agents start generating agents themselves. That\u2019s why agent identity is such a critical part of that. And not only just Agent ID. For us it\u2019s the first step\u2014assign an agent ID so you know who the agent is. Second step, make sure that you check and audit the permissions that they have, and you\u2019re very thoughtful about that. Third step, use policies like conditional access\u2014which is what we have extended, so that automatically you can say, \u2018This agent has this access.\u2019 And it\u2019s role-based and it\u2019s real time. So when you finish doing something, verifying explicitly [is key]\u2014you don\u2019t get access forever. So Entra helps us extend all of this to the agent world, and it really helps us enforce that zero trust for AI. And identity is going to be even more critical, and data security with Purview, because this notion of \u2018double agents\u2019 has really come into the [picture] now.<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"\" src=\".\/media_1f038486c9cdf62e0e66621d2cd956b9221e82271.png?width=750&amp;format=png&amp;optimize=medium\" width=\"611\" height=\"458\"\/><\/p>\n<p>Do you have any sense about whether customers are focusing more on security before allowing agents to be used in their environments, perhaps as compared to prior technology shifts?<\/p>\n<p>Yes, and that\u2019s the heartening part for me. Because the question organizations are not asking is whether I should use AI. What they are asking is, \u2018How do I use AI securely\u2019\u201d And the secure-by-design and the secure-by-default principles that we\u2019ve talked about are coming to bear even more. That\u2019s why capabilities like Agent 365, where you can bring those controls right in the beginning of the development cycle, are super important.<\/p>\n<p>We\u2019re definitely seeing that conversation shift, where security is not a bolt-on anymore. It\u2019s built in. And it\u2019s not a source of friction, but they are turning it into a catalyst for innovation.<\/p>\n<p>A few years back, even getting organizations to adopt [multifactor authentication] felt like it was a big mountain to climb. The great news is that people are using AI and frontier transformation as the moment to drive security transformation. And they\u2019re not just saying, \u2018Hey, how do I secure my AI?\u2019 But they\u2019re going and asking, \u2018How do I secure my foundation and address all the hygiene? How do I make sure that my data and my identity, and the things I need for threat protection, are all updated?\u2019<\/p>\n<p>So this moment is creating an opportunity for organizations to do security the right way\u2014not just for AI, but [for] all the foundations that they\u2019ve needed to put in place. And because AI brings this unprecedented speed, scale and sophistication, there is an urgency to do that. And that\u2019s why we\u2019re seeing this high interest in technologies like Agent 365. The organizations are so open now to try different things to secure themselves. It\u2019s really exciting.<\/p>\n","protected":false},"excerpt":{"rendered":"As Microsoft expands its Agent 365 offering, Jakkal tells CRN that in \u2018just the way we have been&hellip;\n","protected":false},"author":2,"featured_media":59671,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[24,405,10395,399,25,7537,8916,12722,313,400,401,414],"class_list":["post-59670","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai","tag-ai-agents","tag-api-security","tag-application-and-platform-security","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-cloud-security","tag-cyberattacks","tag-cybersecurity","tag-managed-security","tag-managed-service-providers","tag-security-operations"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/59670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=59670"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/59670\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/59671"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=59670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=59670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=59670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}