
Microsoft expands Zero Trust guidance for AI agents and DevSecOps
Microsoft added AI assessment checks and a DevSecOps pillar to its Zero Trust guidance for securing agents and development pipelines.
Microsoft has expanded its Zero Trust for AI program with new assessment checks, workshop guidance and practitioner material aimed at organizations adopting AI agents and AI-assisted software development. The company published the update on August 4, positioning it as a shift from high-level architecture to implementation steps for security, engineering and platform teams.
The announcement matters because agentic systems change where organizations have to draw trust boundaries. AI assistants can generate code, recommend packages, build infrastructure templates and automate testing. Those same workflows can also widen the blast radius of weak permissions, unmanaged dependencies, poor data controls or compromised development pipelines. Microsoft’s answer is to fold AI and developer security into a Zero Trust operating model built around explicit verification, least privilege and an assumption that systems can be breached.
What changed
The Zero Trust Assessment tool now adds coverage for AI, security operations and infrastructure alongside existing identity, device, network and data areas. Microsoft says the assessment evaluates tenant configuration and activity signals, then turns findings into prioritized recommendations. The expanded AI checks are meant to help organizations establish a baseline for agents, Copilots and autonomous workflows before they scale them broadly.
Microsoft also added a dedicated DevSecOps pillar to the Zero Trust Workshop. The new pillar includes 15 control groups and 91 tasks covering source repositories, CI/CD pipelines, dependencies, artifacts, infrastructure-as-code and cloud deployment. Four of those tasks focus directly on AI-assisted development: code governance, tool allowlisting, data protection and AI or machine-learning pipeline supply-chain security.
- The assessment gains AI-focused checks and new reporting for practitioners and executives.
- The workshop adds a DevSecOps pillar for applying Zero Trust from source code to deployment.
- New AI memory guidance treats memory as a governed security boundary with intent, provenance, lifecycle visibility and user control.
The update is not a standalone product launch so much as a control framework around fast-changing AI adoption. Microsoft ties the material to its RSA Conference 2026 Zero Trust for AI strategy and to new guidance for securing AI agents, AI memory, source code access and software supply chains. For enterprises, the practical message is that AI governance cannot sit apart from developer platforms and identity controls. The places where agents read, remember, build and deploy software are becoming part of the security perimeter.
Because the claims come from Microsoft’s own security blog, the details should be read as the company’s description of its platform and guidance rather than independent performance evidence. Even so, the move reflects a broader enterprise concern: AI tools are no longer just applications to approve or block. They increasingly participate in development and operations, which makes policy, provenance and least-privilege design central to how organizations adopt them.
Sources
Cover photo by Mikhail Nilov on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment