Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and Copilots
    • Innovation & Leadership
    • Cybersecurity
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
  • Ask Copilot
  • Agentic AI Battleground
Twitter Instagram
  • Summit NA
  • Dynamics Communities
  • AI Copilot Summit NA
  • Ask Cloud Wars
Twitter LinkedIn
Cloud Wars
  • Home
  • Top 10
  • CW Minute
  • CW Podcast
  • Categories
    • AI and CopilotsWelcome to the Acceleration Economy AI Index, a weekly segment where we cover the most important recent news in AI innovation, funding, and solutions in under 10 minutes. Our goal is to get you up to speed – the same speed AI innovation is taking place nowadays – and prepare you for that upcoming customer call, board meeting, or conversation with your colleague.
    • Innovation & Leadership
    • CybersecurityThe practice of defending computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
    • Data
  • Member Resources
    • Cloud Wars AI Agent
    • Digital Summits
    • Guidebooks
    • Reports
  • About Us
    • Our Story
    • Tech Analysts
    • Marketing Services
  • Agentic AI Battleground
    • Login / Register
Cloud Wars
    • Login / Register
Home » Microsoft Positions Unified Security as Key to Managing AI’s Expanding Attack Surface
AI and Copilots

Microsoft Positions Unified Security as Key to Managing AI’s Expanding Attack Surface

Kieron AllenBy Kieron AllenFebruary 27, 20264 Mins Read
Facebook Twitter LinkedIn Email
Share
Facebook Twitter LinkedIn Email

As part of the recent Microsoft AI-Powered Work Bootcamp, Herain Oberoi, General Manager of Data Security, Privacy & Compliance at Microsoft, held a session entitled “Securing and Governing Data for the Era of AI.” The session aimed to explore how users can best secure and govern data effectively in the AI Era.

While GenAI and AI agents are becoming increasingly intertwined with business processes and delivering massive strategic gains, it’s also growing and complicating the attack surface.

Top Challenges for the AI Era

Oberoi kicked off his session by illustrating that in the AI Era, there are two key questions when it comes to cybersecurity:

  • Do I trust the data?
  • Is the AI system reliable, safe, and secure?

He explained that AI systems expand the attack surface, and GenAI in particular has introduced new and amplified risks that continue to evolve and are, much like the technology itself, incredibly dynamic. These risks include areas like data leakage, jailbreaks, indirect prompt injection, hallucinations, and model vulnerabilities. Addressing these issues requires purpose-built security measures for AI.

What are the biggest challenges facing enterprises in the age of AI? Oberoi identifies three main issues: data oversharing and leakage, regulatory compliance, and the use of disparate solutions.

Data Oversharing and Leakage: One of the key ways to secure data is to manage access and maintain data hygiene. Oberoi emphasizes that organizations must ensure data sources have the appropriate access controls, actively implement Data Loss Prevention (DLP) policies, and apply sensitivity labels to their data.

In terms of good data hygiene, he suggests that companies focus on deleting outdated data, archiving information appropriately, and keeping their data current. Fundamentally, he believes that good hygiene enables all other data protection measures.

Within Microsoft’s security framework, tools provide visibility into areas where oversharing may occur and help companies understand their oversharing posture. For instance, Microsoft Defender for Cloud Apps now assigns a risk score to AI applications. At the same time, capabilities in Microsoft Purview provide reports that deliver visibility into data with accompanying security risk scores, as well as user risk scores (low vs. high) based on metrics such as the level of access to sensitive information or whether users have access to an AI agent.

Regarding data protection, Purview users can create DLP policies that adapt based on user risk levels and data context. There is also adaptive protection, allowing policies to be applied across multiple platforms, including email, SharePoint sites, Copilot, Foundry, and more.

When it comes to governance, Purview delivers a unified catalog that gives data professionals an easy way to find the data they need, apply data quality rules, and ensure AI produces the right outputs.

AI Agent & Copilot Summit is an AI-first event to define opportunities, impact, and outcomes with Microsoft Copilot and agents. Building on its 2025 success, the 2026 event takes place March 17-19 in San Diego. Get more details.

Regulatory Compliance: Oberoi emphasizes that AI regulations are emerging worldwide, citing the EU AI Act, the AI Action Plan in Australia, and various other data protection frameworks. He says that the key questions organizations must address are:

  • Do I have a data compliance system in place?
  • If an incident happens: what do I do next, and how is it reported?
  • How do I find evidence of what happened?

Microsoft users can leverage Compliance Manager in Purview to perform self-assessments of their security posture, receive recommendations, solutions, and implementation steps, and govern GenAI projects to ensure regulatory compliance. While AI reports give details of model security configuration, safety configurations, and more.

Disparate Solutions: Oberoi highlights the core challenge of managing a fragmented AI ecosystem, which is complex and costly to support when solutions are siloed. Fragmented systems lead to inconsistent outcomes, higher costs, and greater implementation complexity, making security in the AI Era especially challenging.

Microsoft has addressed this issue by expanding Purview to include data security, data governance, and compliance through a single pane of glass. These integrated solutions work seamlessly across the technology stack.

In one of the final slides of the presentation, Oberoi positioned Microsoft as the first security provider to deliver comprehensive solutions across data security and governance, security posture management, threat protection, safety systems, and governance. This applies not only to Copilot and Microsoft agents but also to other enterprise, consumer, and custom-built AI.


Ask Cloud Wars AI Agent about this analysis

ai ai agent Compliance Cyber Security data featured framework governance security
Share. Facebook Twitter LinkedIn Email
Analystuser

Kieron Allen

Cloud, AI, Innovation
Cloud Wars analyst

Areas of Expertise
  • Business Apps
  • Cloud
  • Cybersecurity
  • Data
  • LinkedIn

Kieron Allen is a Cloud Wars Analyst examining innovations in, and the future impact of, the latest AI, cloud, cybersecurity, and data technology developments. In his ongoing analyses and video reports, Allen focuses on the platforms, applications, people, and ideas that will mold our digital future. After serving as the Online Editor for BBC Sky at Night Magazine and as the Editorial Assistant for BBC Focus Magazine, Kieron became a freelance journalist in 2015 where his focus on the business technology market became a key passion. Kieron partners with technology start-ups and organizations that share his interests in science, social affairs, non-profit work, fashion and the arts.

  Contact Kieron Allen ...

Related Posts

AI Agent & Copilot Podcast: Summit Highlights — Orchestration, MCP, and AI Workforce Transformation

March 20, 2026

Google Cloud Expands Healthcare Leadership with CVS Health Partnership

March 20, 2026

OpenAI Faces 5 Big Questions, Starting Here: $140 Billion Enterprise Revenue by 2030?

March 19, 2026
copilot summit

AI Agent & Copilot Summit Day Two: How Copilot Studio and Agent Design Are Redefining Enterprise AI

March 19, 2026
Add A Comment

Comments are closed.

Recent Posts
  • AI Agent & Copilot Podcast: Summit Highlights — Orchestration, MCP, and AI Workforce Transformation
  • Google Cloud Expands Healthcare Leadership with CVS Health Partnership
  • OpenAI Faces 5 Big Questions, Starting Here: $140 Billion Enterprise Revenue by 2030?
  • AI Agent & Copilot Summit Day Two: How Copilot Studio and Agent Design Are Redefining Enterprise AI
  • Microsoft Exec Shares Roadmap To Drive AI Success — and Cast Aside the Hype

  • Ask Cloud Wars AI Agent
  • Tech Guidebooks
  • Industry Reports
  • Newsletters

Join Today

Most Popular Guidebooks and Reports

elevaite365 Test Automation: Turning Software Testing into a Strategic Asset with AI

March 6, 2026

Driving Business Transformation with Agentic AI and ServiceNow

January 9, 2026

The Agentic Enterprise: How Microsoft and Industry Leaders Are Redefining Work Through AI

September 2, 2025

SAP Business Network: A B2B Trading Partner Platform for Resilient Supply Chains

July 10, 2025

Advertisement
Cloud Wars
Twitter LinkedIn
  • Home
  • About Us
  • Privacy Policy
  • Get In Touch
  • Marketing Services
  • Do not sell my information
© 2026 Cloud Wars.

Type above and press Enter to search. Press Esc to cancel.

  • Login
Forgot Password?
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.
body::-webkit-scrollbar { width: 7px; } body::-webkit-scrollbar-track { border-radius: 10px; background: #f0f0f0; } body::-webkit-scrollbar-thumb { border-radius: 50px; background: #dfdbdb }