Microsoft Unifies Entra and Purview to Block Shadow AI Leaks Across Agentic Network Traffic
Microsoft announced the general availability of native data security enforcement at the network layer, achieved through deep integration between Microsoft Purview and Microsoft Entra Global Secure Access. The integrated capability applies Purview's context-aware data classification directly within the network inspection path, identifying and blocking sensitive files and text payloads from being transferred to unsanctioned external destinations in real time. Crucially, this policy enforcement covers both direct human browser sessions and on-behalf-of (OBO) agentic traffic generated by background AI workloads.
Why it matters: The rapid adoption of autonomous and semi-autonomous AI agents across cloud platforms and developer workstations has created an acute security blind spot. AI agents routinely operate with delegated user privileges, querying internal knowledge repositories and formatting data to complete downstream tasks. When these agents or individual users route enterprise data to external, unapproved AI platforms, traditional endpoint-centric Data Loss Prevention (DLP) tools frequently fail to intercept fast-moving API requests. By marrying identity-aware Zero Trust network access with continuous data classification, security teams gain the mechanism needed to halt unauthorized data transfer before packets leave their governed boundary.
Context: This capability highlights the broader convergence of Secure Access Service Edge (SASE) networking with Data Security Posture Management (DSPM) and Identity and Access Management (IAM). As enterprise infrastructure shifts from static perimeters to distributed ecosystems powered by agentic tools, model context protocols, and cloud APIs, defensive controls cannot remain isolated in silos. Decoupled network firewalls and standalone DLP agents are incapable of reasoning over identity context and payload sensitivity simultaneously. Bringing policy evaluation directly into the secure access fabric represents the industry's response to securing non-deterministic, agent-driven cloud environments.
What it means in practice: For security practitioners and cloud architects, this development requires modernizing network egress architectures and identity governance rules. Teams should begin by ensuring Microsoft Purview auto-labeling and classification schemes are properly applied to sensitive cloud data repositories. Next, organizations must configure Entra Global Secure Access forward-proxy policies to inspect outbound traffic destined for untrusted AI endpoints, specifically evaluating the risk posture of on-behalf-of token requests. Finally, security operations teams should leverage these unified network-layer signals to establish baseline telemetry for legitimate agent communications, allowing them to detect anomalous egress without disrupting valid automated workflows.
Read original source