This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
--> Implement security for AI
--> Enable and configure real-time protection for Microsoft Copilot Studio agents
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Introduction
This topic covers how to use Microsoft Defender for Cloud Apps and Microsoft Defender XDR to provide runtime protection for agents created with Microsoft Copilot Studio.
You should understand how to:
- Describe the security risks associated with AI agents.
- Enable real-time protection for Copilot Studio agents.
- Coordinate configuration between Microsoft Defender and Power Platform.
- Configure the required Microsoft Entra application ID.
- Understand how suspicious agent actions are detected and blocked.
- Review agent inventory, alerts, incidents, and Advanced Hunting data.
- Distinguish runtime protection from post-event investigation and governance.
Why Copilot Studio agents require runtime protection
AI agents can do more than generate text. Depending on their configuration, they may:
- Retrieve information from enterprise data sources.
- Invoke connectors and tools.
- Call APIs.
- Execute workflows.
- Send messages.
- Create or update records.
- Perform actions on behalf of users.
- Make decisions based on natural-language instructions.
This introduces risks that are different from those associated with a traditional application. An attacker or malicious user may attempt to manipulate an agent into performing an unsafe action, accessing information it should not use, or disclosing sensitive data.
Examples include:
- Prompt injection.
- Cross-prompt injection attacks.
- Malicious or unexpected tool invocation.
- Attempts to access protected information.
- Data exfiltration.
- Use of an agent to perform unauthorized actions.
- Abuse of excessive agent permissions.
Real-time protection helps reduce these risks by evaluating agent activity during runtime and blocking suspicious actions before they execute. Microsoft Defender for Cloud Apps provides this protection for supported Copilot Studio agent scenarios.
What is real-time protection?
Real-time protection is a security capability that evaluates an AI agent’s activity while the agent is operating.
For Copilot Studio agents, protection evaluates tool invocations before the tools execute. If Microsoft Defender identifies suspicious behavior or a supported attack pattern, the proposed action can be blocked.
The protection process can be summarized as follows:
- A user sends a prompt to an agent.
- The agent interprets the request.
- The agent considers invoking a tool, connector, or action.
- Microsoft Defender evaluates the proposed invocation.
- If the action is considered safe, the agent continues.
- If the action is considered risky, the invocation is blocked.
- Depending on the configuration and integration status, an alert or incident may be created in Microsoft Defender XDR.
This approach is designed to prevent unsafe actions rather than merely report them after they occur.
Microsoft Defender for Cloud Apps and Copilot Studio
The SC-500 learning objective identifies Microsoft Defender for Cloud Apps as the service used to provide runtime protection for Copilot Studio agents.
Microsoft Defender for Cloud Apps supplies the security integration, while Copilot Studio and Power Platform provide the agent runtime and configuration.
The integration requires coordination between:
- A Microsoft Defender administrator.
- A Power Platform administrator.
- The Microsoft Entra application used by the agent integration.
The Defender administrator enables protection and provides configuration information. The Power Platform administrator completes the required onboarding steps in Power Platform. The application ID used during the process must match the application ID associated with the Microsoft Entra application.
Prerequisites
Before enabling protection, verify the following:
Microsoft Defender administration
The administrator should be familiar with:
- The Microsoft Defender portal.
- Microsoft Defender for Cloud Apps.
- Microsoft Defender XDR.
- Security for AI settings.
- Alerts and incidents.
- Advanced Hunting.
Copilot Studio and Power Platform
The organization should have:
- Copilot Studio agents that require protection.
- A Power Platform administrator available to complete onboarding.
- The required agent configuration and application information.
Microsoft Entra application
The integration uses an application ID associated with a Microsoft Entra application. The application ID configured in Power Platform must match the application ID entered in the Defender portal.
Microsoft 365 app connector
The Microsoft 365 app connector should be connected when the organization wants protection outputs, such as alerts and incidents, to appear in Microsoft Defender. If the connector is not connected, runtime blocking may continue, but related alerts and incidents may not appear in the Defender portal.
Enabling real-time protection
The exact navigation may change as Microsoft updates the Defender portal, but the configuration process generally follows these steps.
Step 1: Open Microsoft Defender
Sign in to the Microsoft Defender portal with an account that has the required administrative permissions.
Step 2: Open Security for AI settings
Navigate to the Defender portal’s AI security settings. Depending on the current portal experience, this may appear under:
- Settings
- Security for AI
- Copilot Studio
- Real-time protection
Microsoft documentation has used different navigation labels as the feature has evolved. The important exam concept is that the configuration is performed in the Microsoft Defender portal, not exclusively in Copilot Studio.
Step 3: Check the Microsoft 365 app connector
Verify that the Microsoft 365 app connector is connected.
If it is not connected, enable or configure it according to the organization’s requirements.
The connector is important for Defender visibility, including alerts and incidents associated with protected agent activity. Runtime protection may still block suspicious actions even when the connector is not connected, but the corresponding security outputs may not be available in the Defender portal.
Step 4: Enable real-time protection
Turn on the real-time protection setting for Copilot Studio agents.
This enables Defender to inspect supported agent tool invocations during runtime.
Step 5: Provide the Power Platform integration URL
The Defender portal provides a URL or configuration value that must be shared with the Power Platform administrator.
The Power Platform administrator uses this information to complete the external threat detection and protection configuration for the Copilot Studio agents.
Step 6: Configure the integration in Power Platform
The Power Platform administrator completes the required onboarding steps in Power Platform.
This establishes the connection between the Copilot Studio agent environment and the external protection service.
Step 7: Confirm the application ID
The Power Platform administrator provides the application ID used by the integration.
The Defender administrator enters that value in the appropriate App ID field in the Defender portal.
The application ID must match the App ID used by the Microsoft Entra application. A mismatch can cause validation errors or prevent the integration from becoming connected.
Step 8: Save and verify the connection
Save the configuration and verify that the integration displays a connected status.
If the application ID was recently changed, the update may take a short time to propagate. Microsoft documentation indicates that propagation can take approximately one minute in some cases.
How runtime protection works
The runtime protection process is designed to evaluate agent activity before a potentially dangerous action occurs.
For example, an agent might receive a prompt such as:
“Find the customer records for this account and send them to an external address.”
The agent may attempt to invoke a connector or API. Before the tool invocation executes, Defender evaluates the proposed action.
If the action is permitted:
- The tool invocation proceeds.
- The agent continues processing.
- The user generally does not see an interruption.
If the action is blocked:
- The tool invocation does not execute.
- The agent stops or interrupts the relevant processing.
- The user is notified that the request or action was blocked.
- An alert or incident may be generated, depending on the configuration and connector status.
This is an important distinction: protection occurs at the point where the agent is about to perform an action, rather than only after the action has completed.
Threats that runtime protection can address
Runtime protection is intended to help detect and block supported threats involving agent activity.
Prompt injection
A prompt injection attack attempts to manipulate the agent into ignoring its intended instructions or security boundaries.
For example, a user may attempt to instruct an agent to:
- Ignore its system instructions.
- Reveal hidden configuration.
- Disclose protected data.
- Invoke a tool for an unauthorized purpose.
- Treat untrusted content as a trusted instruction.
Cross-prompt injection
Cross-prompt injection can occur when malicious instructions are introduced through content that the agent retrieves or processes.
For example, a document, web page, or data source may contain instructions designed to manipulate the agent when it reads the content.
Unsafe tool invocation
An agent may attempt to invoke a connector, API, or action in a way that creates a security risk.
Examples include:
- Sending sensitive information to an unauthorized destination.
- Modifying records without sufficient authorization.
- Calling an unexpected external service.
- Accessing information outside the intended business purpose.
Data exfiltration
Data exfiltration occurs when an agent is manipulated into transferring sensitive information to an unauthorized person, application, or destination.
Runtime protection can help prevent certain exfiltration attempts by blocking the tool invocation responsible for the transfer.
However, runtime protection should not be treated as the only security control. Organizations should also use least-privilege access, data policies, DLP, sensitivity labels, authentication controls, and appropriate agent design.
Reviewing protection outputs
After enabling protection, administrators should verify that the expected security information is available in Microsoft Defender XDR.
Important outputs include:
AI agent inventory
The AI agent inventory helps administrators discover and review agents operating in the environment.
Depending on the available experience, inventory information may include:
- Agent name.
- Agent type.
- Agent owner.
- Agent environment.
- Security posture.
- Protection status.
- Related recommendations.
Alerts and incidents
When suspicious activity is detected, Defender may generate alerts or incidents.
These can help administrators investigate:
- The affected agent.
- The user or activity involved.
- The type of detected threat.
- The action that was blocked.
- The related evidence.
- The recommended response.
Advanced Hunting
Advanced Hunting can be used to search and analyze security telemetry associated with AI agents.
This supports activities such as:
- Identifying repeated attacks.
- Finding agents that frequently trigger detections.
- Detecting patterns across users or environments.
- Correlating agent activity with other security events.
- Creating custom detections and investigations.
The SC-500 objective specifically expects administrators to verify that agent inventory, alerts, and Advanced Hunting data appear in Microsoft Defender XDR.
Runtime protection versus agent governance
Runtime protection is only one layer of AI security.
Runtime protection
Runtime protection focuses on what an agent is attempting to do while it is operating.
It can help:
- Inspect tool invocations.
- Detect suspicious behavior.
- Block risky actions.
- Generate security alerts.
Agent governance
Agent governance focuses on how agents are created, configured, published, owned, and managed.
Governance activities include:
- Reviewing agent ownership.
- Controlling who can create agents.
- Reviewing agent permissions.
- Applying data policies.
- Managing environments.
- Reviewing authentication.
- Monitoring agent lifecycle.
- Removing unused agents.
Data protection
Data protection focuses on the information that agents can access or process.
Relevant controls include:
- Microsoft Purview sensitivity labels.
- Data Loss Prevention.
- Microsoft Purview auditing.
- Insider Risk Management.
- SharePoint permissions.
- Microsoft Entra Conditional Access.
- Least-privilege permissions.
- Data classification.
A secure agent deployment requires all three layers:
- Secure agent design and governance.
- Protected data and controlled access.
- Runtime detection and blocking.
Copilot Studio built-in protection versus Defender protection
Copilot Studio includes built-in protections against certain threats, including prompt-injection-related attacks. External threat detection provides an additional layer of runtime monitoring and enforcement.
The external protection service evaluates proposed tool invocations and can return an allow or block decision.
The distinction is important:
- Copilot Studio built-in protections are part of the agent platform.
- Microsoft Defender protection provides an additional security and monitoring integration.
- Microsoft Purview focuses on data security, compliance, classification, auditing, and information protection.
- Microsoft Entra controls identity and access.
- Microsoft Defender XDR provides centralized detection, investigation, and hunting experiences.
Protection status in Copilot Studio
Copilot Studio can display an agent-level protection status for published agents.
Possible statuses include:
- Protected
- Needs review
- Unknown
The protection status can summarize categories such as:
- Authentication.
- Policies.
- Content moderation.
A status of Needs review may indicate that the agent violates a policy or has an authentication issue. A status of Unknown means that the protection state cannot be confidently determined.
This status helps makers identify potential issues, but it does not replace centralized security monitoring in Microsoft Defender.
Operational best practices
Use least privilege
Give agents only the permissions and tools required for their intended business purpose.
Avoid granting broad access to:
- SharePoint sites.
- Dataverse tables.
- Customer records.
- Financial systems.
- Administrative APIs.
- External communication services.
Limit tool access
An agent should not have access to every connector or action available in its environment.
Use narrowly scoped tools and actions, and review them periodically.
Require appropriate authentication
Ensure that the agent’s authentication configuration is appropriate for the sensitivity of the data and actions involved.
Review agent ownership
Every production agent should have:
- A business owner.
- A technical owner.
- A support contact.
- A defined purpose.
- A review schedule.
Monitor alerts and incidents
Do not enable protection and then ignore the resulting alerts. Repeated detections may indicate:
- A malicious user.
- A poorly designed agent.
- An overly permissive connector.
- A compromised account.
- A legitimate workflow that requires adjustment.
Test before production deployment
Test agents with:
- Normal business prompts.
- Unexpected prompts.
- Prompt injection attempts.
- Requests for sensitive information.
- Unauthorized tool requests.
- Attempts to send information externally.
Keep protection enabled
Disabling runtime protection removes an important security layer. If protection must be disabled for troubleshooting, document the reason and re-enable it as soon as possible.
Troubleshooting considerations
The integration does not show Connected
Check:
- Whether the Power Platform onboarding steps were completed.
- Whether the correct App ID was entered.
- Whether the App ID matches the Microsoft Entra application.
- Whether the configuration has had enough time to propagate.
- Whether the required administrators completed their respective tasks.
Alerts are not appearing
Check:
- Whether the Microsoft 365 app connector is connected.
- Whether the activity generated an alertable detection.
- Whether the administrator has the required permissions.
- Whether the agent is within the supported protection scope.
- Whether the alert is available in the relevant Defender experience.
Runtime blocking may still occur even if alerts and incidents are not visible because the connector is not connected.
A legitimate action is blocked
Investigate:
- The detection type.
- The tool being invoked.
- The data being accessed.
- The user’s request.
- The agent’s instructions.
- The agent’s permissions.
- Whether the workflow can be redesigned more safely.
Do not simply disable protection without understanding the cause.
Protection is not available for an agent
Verify:
- The agent type is supported.
- The agent is configured for the relevant runtime.
- The required integration is enabled.
- The tenant has the required licensing.
- The agent is not a classic agent outside the supported external threat-detection scope.
Microsoft documentation states that the external threat detection integration applies to generative agents using generative orchestration and is skipped for classic agents.
Important exam distinctions
Defender for Cloud Apps versus Defender for Cloud
For this topic, runtime protection for Copilot Studio agents is associated with Microsoft Defender for Cloud Apps.
Do not confuse it with Microsoft Defender for Cloud capabilities used to protect Azure resources, AI services, containers, virtual machines, and cloud workloads.
Runtime protection versus investigation
Runtime protection attempts to block unsafe actions before execution.
Advanced Hunting and alert investigation are used to analyze activity and investigate threats.
Power Platform configuration versus Defender configuration
The integration requires work in both environments:
- Defender enables and configures protection.
- Power Platform completes the agent-side onboarding.
- The Microsoft Entra App ID must match across the configuration.
Blocking versus auditing
A security system may be configured to observe or audit activity, or it may be configured to block specific detected actions.
Auditing provides visibility. Blocking provides preventive enforcement.
Protection versus data classification
Runtime protection evaluates agent behavior and tool invocations.
Data classification identifies sensitive information. The two capabilities address different parts of the security problem and should be used together.
Summary
To enable and configure real-time protection for Microsoft Copilot Studio agents:
- Open the Microsoft Defender portal.
- Navigate to the Security for AI settings.
- Verify the Microsoft 365 app connector.
- Enable real-time protection for Copilot Studio agents.
- Share the provided integration URL with the Power Platform administrator.
- Have the Power Platform administrator complete the onboarding process.
- Obtain the correct Microsoft Entra application ID.
- Enter the matching App ID in Defender.
- Save the configuration.
- Confirm the integration shows a connected status.
- Verify agent inventory, alerts, incidents, and Advanced Hunting data.
- Investigate and remediate blocked or suspicious activity.
The central exam concept is that Microsoft Defender for Cloud Apps can inspect supported Copilot Studio agent tool invocations during runtime and block suspicious actions before they execute.
Practice Exam Questions
Question 1
Which Microsoft service provides runtime protection for supported Microsoft Copilot Studio agents?
A. Microsoft Defender for Cloud Apps
B. Azure Backup
C. Microsoft Defender for Containers
D. Microsoft Purview Records Management
Answer: A
Explanation: Microsoft Defender for Cloud Apps provides the runtime protection integration for supported Copilot Studio agents. It evaluates agent activity and can block suspicious tool invocations.
Question 2
An administrator enables real-time protection in Microsoft Defender but does not complete the Power Platform configuration. What is the most likely result?
A. All Copilot Studio agents are automatically deleted.
B. The integration may not become connected or provide the expected protection outputs.
C. Microsoft Entra ID is disabled for the tenant.
D. All SharePoint permissions are removed.
Answer: B
Explanation: The onboarding process requires coordination between Defender and Power Platform. Enabling the Defender setting alone does not complete the integration.
Question 3
What must match between the Power Platform configuration and the Defender configuration?
A. The Azure subscription name
B. The SharePoint site URL
C. The Microsoft Entra application ID
D. The Microsoft Sentinel workspace name
Answer: C
Explanation: The App ID used by the Power Platform integration must match the App ID associated with the Microsoft Entra application and entered in the Defender portal.
Question 4
What does runtime protection primarily evaluate for Copilot Studio agents?
A. Azure virtual machine disk encryption
B. SharePoint retention labels
C. Tool invocations during agent execution
D. Microsoft Entra password expiration settings
Answer: C
Explanation: Runtime protection evaluates proposed agent tool invocations before they execute, helping detect and block suspicious actions.
Question 5
What happens when Defender identifies a suspicious tool invocation covered by a blocking protection rule?
A. The tool invocation is blocked before it executes.
B. The tool invocation always executes and is reviewed later.
C. The agent is permanently deleted.
D. The user is automatically assigned the Global Administrator role.
Answer: A
Explanation: The purpose of runtime protection is preventive enforcement. A suspicious action can be blocked before the tool executes.
Question 6
Which Microsoft Defender capability is useful for investigating patterns in AI agent security telemetry?
A. Azure Cost Management
B. Advanced Hunting
C. Azure Resource Locks
D. Microsoft Purview Data Lifecycle Management
Answer: B
Explanation: Advanced Hunting allows security teams to query and analyze security telemetry, identify repeated activity patterns, and investigate AI agent behavior.
Question 7
An organization wants alerts and incidents associated with protected Copilot Studio agent activity to appear in Microsoft Defender. Which component should the administrator verify?
A. Azure Bastion
B. Microsoft 365 app connector
C. Azure VPN Gateway
D. Microsoft Defender for Storage
Answer: B
Explanation: The Microsoft 365 app connector is important for Defender visibility. If it is not connected, runtime blocking may continue, but related alerts and incidents may not appear in the Defender portal.
Question 8
Which scenario is an example of prompt injection against an AI agent?
A. A user changes their Microsoft Entra password.
B. An administrator enables a resource lock.
C. A user attempts to manipulate the agent into ignoring its instructions and revealing protected information.
D. A security analyst exports an alert to a CSV file.
Answer: C
Explanation: Prompt injection attempts to manipulate an AI agent’s behavior by introducing instructions that conflict with its intended system instructions or security boundaries.
Question 9
Which statement best describes the relationship between runtime protection and Microsoft Purview?
A. Runtime protection and Microsoft Purview are identical services.
B. Runtime protection evaluates agent behavior, while Purview provides data security and compliance capabilities.
C. Microsoft Purview replaces all agent authentication controls.
D. Runtime protection is used only for Azure virtual machines.
Answer: B
Explanation: Runtime protection focuses on agent actions and tool invocations. Microsoft Purview supports data classification, sensitivity labels, DLP, auditing, Insider Risk Management, and other data-security and compliance capabilities.
Question 10
A Copilot Studio agent is configured as a classic agent rather than a generative agent using generative orchestration. What should the administrator understand about the external threat-detection integration?
A. It automatically converts the agent into a generative agent.
B. It applies only after the agent is deleted and recreated.
C. It is skipped for classic agents.
D. It requires Azure Bastion to be installed.
Answer: C
Explanation: Microsoft documentation states that the external threat-detection integration is called for generative agents using generative orchestration and is skipped for classic agents.
Go to the SC-500 Exam Prep Hub main page
