Skip to content

Fixed-scope engagement

Agentic AI Security Assessment

Every agent in your tenant, what each one can read and do, and whether your assurance panel should sign off the deployment.

Typical duration: 2–3 weeks

What you get

  • Agent inventory across the tenant with a named owner per agent: Copilot Studio, Foundry Agent Service, and third-party agents holding Microsoft Graph or API access
  • Injection surface map per agent: what untrusted content it reads, what data it can reach, and what actions it can take
  • Identity and permission review across Microsoft Entra ID: agent identities, service principals, delegated versus application permissions, and RBAC on grounding data
  • Data flow review for assurance: where inference runs, what prompts are logged and retained, and the inputs your DPIA and Algorithmic Transparency Recording Standard record need
  • Controls verification: seeded prompt injection payloads run against deployed agents in an agreed window, with each control's response recorded
  • Findings register mapped to the NCSC Cyber Assessment Framework and the OWASP Top 10 for LLM Applications, with remediation expressed as deployed controls, pipeline gates, or scheduled reviews with named owners

Outcome

A deployment your assurance panel can sign off, or a written reason it should not.

Which of your agents can read untrusted content and act on what it reads?

If nobody holds the list of agents, nobody can answer that. Book a 30-minute call and we will scope which parts of the estate the assessment should cover first.