This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
--> Implement security for AI
--> Analyze blast radius for security risks related to Entra Agent ID by using Defender XDR
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
AI agents can access data, invoke tools, call APIs, and perform actions across an organization. If an agent identity is compromised, the impact may extend far beyond the agent itself.
For example, an agent might have permission to:
- Read confidential documents.
- Access a customer database.
- Modify records in a business application.
- Call privileged APIs.
- Access other identities or resources.
- Use knowledge sources containing sensitive information.
The blast radius of an agent represents the potential impact of compromising that agent identity. It helps security teams understand what an attacker might be able to reach or control by abusing the agent’s permissions, connected resources, and relationships.
Microsoft Defender XDR provides an AI agent inventory, posture-risk information, and attack-path analysis to help security teams discover agents and assess the consequences of a compromised agent identity.
What Is Microsoft Entra Agent ID?
Microsoft Entra Agent ID provides identity capabilities for AI agents. Instead of treating every agent as an unidentified application process, an organization can represent an agent with a distinct identity that can be:
- Authenticated.
- Assigned permissions.
- Governed.
- Monitored.
- Investigated.
- Disabled or remediated when risky.
An agent identity should be treated as a security principal with a defined owner, purpose, permission set, and lifecycle.
This is important because an AI agent may have more effective access than its name or user interface suggests. The agent’s actual risk depends on what it can access and what actions it can perform—not merely on what the agent was designed to do.
What Is Blast Radius?
The blast radius is the set of resources, identities, applications, data, and systems that could potentially be affected if an agent identity were compromised.
A blast-radius assessment asks questions such as:
- What permissions does the agent have?
- Which applications and APIs can it access?
- Which data sources are available to it?
- Can it read or modify sensitive data?
- Can it invoke tools that perform destructive actions?
- Can it access privileged business systems?
- Can it reach other identities or resources through existing relationships?
- Are there attack paths from the agent to critical assets?
Example
Suppose an AI agent has:
- Read access to a document repository.
- Write access to a purchasing application.
- Permission to call an external API.
- Access to a knowledge source containing confidential business information.
If the agent is compromised, the attacker might be able to:
- Read confidential documents.
- Extract sensitive information.
- Submit unauthorized purchasing requests.
- Use the external API to transfer data.
- Reach additional resources through the agent’s permissions.
The agent’s blast radius is therefore larger than the agent itself.
Why AI Agents Create Unique Blast-Radius Risks
AI agents introduce additional risk because they can dynamically determine which tools to use and which actions to perform.
Traditional applications often follow fixed workflows. Agents may instead:
- Interpret natural-language instructions.
- Retrieve information from multiple sources.
- Select tools dynamically.
- Chain several actions together.
- Act autonomously.
- Use permissions inherited from a user or application.
- Operate without continuous human approval.
A compromised or manipulated agent may therefore use legitimate permissions in unintended ways.
Important AI-related risks include:
- Over-privileged agent identities.
- Excessive access to sensitive data.
- Unrestricted tool invocation.
- Indirect prompt injection.
- Weak or missing authentication.
- Agents that can operate without human approval.
- Privileged access to business systems.
- Active threats or alerts associated with the agent.
Microsoft Defender assesses agent posture using risk indicators derived from configuration, permissions, tools, runtime activity, settings, and associated security alerts.
Microsoft Defender XDR AI Agent Inventory
Microsoft Defender XDR provides a centralized inventory of AI agents in the organization.
Depending on the available integrations and supported platforms, the inventory can include agents built with:
- Microsoft Copilot Studio.
- Microsoft Foundry.
- Microsoft 365.
- Supported non-Microsoft platforms.
- Local AI agents discovered on endpoint devices.
The inventory can provide information about:
- Agent identity.
- Agent type.
- Agent configuration.
- Connected tools.
- Knowledge sources.
- Risk level.
- Risk indicators.
- Security recommendations.
- Related alerts.
- Security context.
To review agents in the Microsoft Defender portal, navigate to:
Assets → AI agents → Agents
The exact portal experience may change as Microsoft’s AI security capabilities evolve.
Agent Risk Level Versus Blast Radius
These concepts are related but are not identical.
Agent risk level
The risk level represents the overall security risk associated with an agent. Microsoft Defender combines active risk indicators to determine an overall risk level.
Possible risk levels include:
- High
- Medium
- Low
- No known risk
- Not evaluated
Risk indicators may include:
- Weak instructions.
- Indirect prompt-injection exposure.
- Privileged business-system access.
- High usage.
- Active threats.
- Lack of human approval.
- Access to sensitive data.
The risk level is influenced by both the severity and combination of active indicators.
Blast radius
Blast radius focuses on the potential impact if the agent is compromised.
An agent could have a high blast radius even if no active threat has been detected. For example, an agent may be operating as designed but have broad permissions to critical systems.
Conversely, an agent may have a low blast radius but still be actively compromised.
Therefore:
Risk level describes the likelihood and seriousness of the agent’s security exposure. Blast radius describes what could be affected if the agent were compromised.
Security teams should evaluate both.
Key Risk Indicators
Microsoft Defender uses risk indicators to provide context about an agent’s exposure.
Privileged business-system access
This indicates that an agent has write access to important business systems.
Examples include:
- Creating or modifying financial transactions.
- Changing customer records.
- Updating inventory.
- Modifying business-critical configurations.
- Accessing administrative APIs.
An agent with write access generally has a greater blast radius than an agent with read-only access.
Indirect prompt-injection exposure
An agent may retrieve content containing hidden instructions from:
- Email.
- Documents.
- Web pages.
- Knowledge bases.
- External data sources.
The content may attempt to manipulate the agent into performing unintended actions.
This risk is especially important when the agent can access sensitive data or invoke powerful tools.
Weak instructions
Weak or incomplete instructions may fail to establish safe operating boundaries for the agent.
For example, an agent may not be clearly instructed to:
- Refuse unauthorized requests.
- Avoid exposing secrets.
- Request approval before destructive actions.
- Validate tool parameters.
- Restrict access to approved resources.
High-usage agent
An agent used by many people may be important to business operations. A compromise could affect a large number of users or business processes.
High usage does not necessarily mean the agent is insecure, but it increases the importance of careful review.
Active threat
An active threat indicator means that security alerts are associated with the agent.
An agent with both an active threat and privileged access should receive immediate attention because the likelihood and potential impact of compromise may both be significant.
Understanding Attack Paths
An attack path is a possible sequence of relationships or permissions that could allow an attacker to move from a compromised entity to a target resource.
For an agent, an attack path might look like:
Compromised agent identity → application permission → sensitive database → confidential data
Another example could be:
Compromised agent → privileged API → business application → administrative action
Attack-path analysis helps identify indirect exposure that may not be obvious when reviewing the agent’s permissions individually.
A single permission may appear harmless, but a sequence of permissions and relationships may create a significant route to a critical asset.
Microsoft Defender graphs use nodes and edges to represent entities and relationships. Attack-path analysis can show potential routes between a source entity and a target asset.
How to Analyze an Agent’s Blast Radius
Step 1: Discover the agent
Open the Microsoft Defender portal and review the AI agent inventory.
Identify:
- The agent name.
- The agent type.
- Its associated identity.
- Its owner.
- Its environment.
- Its connected tools.
- Its knowledge sources.
- Its risk level.
The inventory is the starting point for understanding which agents exist and which require further investigation.
Step 2: Review the agent’s configuration
Examine how the agent is configured.
Important questions include:
- Is the agent autonomous?
- Does it act on behalf of a user?
- Can it operate without human approval?
- Which tools can it invoke?
- Which applications can it access?
- Does it have write or administrative capabilities?
- Does it use external services?
- Does it retrieve content from untrusted sources?
Configuration weaknesses can increase the likelihood that an agent will be manipulated or misused.
Step 3: Review permissions and identities
Determine the permissions assigned to the agent identity.
Review:
- Microsoft Entra roles.
- Application permissions.
- Delegated permissions.
- API scopes.
- Resource access.
- Group memberships.
- Access packages.
- Privileged assignments.
- Permissions inherited through applications or users.
The goal is to determine what the agent can actually do, not merely what it is intended to do.
Step 4: Review knowledge sources
Knowledge sources can significantly increase an agent’s blast radius.
Review whether the agent can access:
- Confidential documents.
- Customer information.
- Financial data.
- Internal policies.
- Credentials or secrets.
- Sensitive databases.
- External content.
- Data belonging to multiple departments.
An agent with read access to a broad knowledge source may expose more information than expected, even if it cannot modify the underlying data.
Step 5: Review connected tools
Tools determine what actions the agent can perform.
Examples include tools that:
- Query databases.
- Send email.
- Create support tickets.
- Modify records.
- Call external APIs.
- Execute workflows.
- Access storage.
- Provision resources.
A tool with write, delete, or administrative capability can substantially increase the agent’s potential impact.
Step 6: Review blueprint configuration
Agent identity blueprints can provide a consistent way to create and manage agent identities.
Review blueprint configuration to determine whether it establishes:
- Appropriate identity settings.
- Required governance.
- Permission boundaries.
- Consistent security controls.
- Appropriate ownership.
- Secure defaults.
A poorly configured blueprint may create multiple agents with the same excessive permissions or weak security settings.
Step 7: Review risk indicators and recommendations
Review the agent’s active risk indicators and any available security recommendations.
Risk indicators describe the agent’s exposure. Recommendations identify actionable changes that may reduce that exposure.
A high-risk agent may not always have an available recommendation, and a lower-risk agent may still have a recommendation that should be implemented. Therefore, review the risk level and recommendations together.
Step 8: Analyze attack paths
Use the available Defender graph and attack-path capabilities to investigate possible routes from the agent to sensitive resources.
Look for paths involving:
- Privileged identities.
- Sensitive applications.
- Critical databases.
- Storage accounts.
- Administrative roles.
- High-value business systems.
- External access.
- Lateral movement.
The objective is to identify not only direct access but also indirect routes that could lead to compromise of critical assets.
Step 9: Prioritize remediation
Prioritize agents that combine several high-impact characteristics, such as:
- High risk.
- Privileged access.
- Access to sensitive data.
- Autonomous operation.
- External exposure.
- Active security alerts.
- Write access to critical systems.
- Multiple attack paths to important assets.
Defender Blast-Radius Graphs
Microsoft Defender can display graph-based views of entities and potential attack paths.
A graph generally contains:
- Nodes, representing entities or assets.
- Edges, representing relationships or connections.
- Paths, representing possible routes between entities.
For an incident, investigators can select an entity and choose View blast radius when the capability is available. The graph can show highly rated attack paths and a list of reachable targets. Investigators can select a target to inspect the potential path leading to it.
What the graph can help identify
The graph may reveal:
- A compromised identity’s reachable resources.
- Indirect paths to critical assets.
- Relationships between identities and applications.
- Potential lateral movement.
- Privilege-escalation routes.
- Access to sensitive data.
- Connections between an agent and other entities.
Important limitations
Blast-radius graphs are an approximation of possible attack reach.
They may be limited by:
- The number of hops analyzed.
- Data freshness.
- The attack techniques modeled.
- The viewer’s RBAC scope.
- Missing or incomplete relationships.
- Changes in the environment that have not yet been reflected.
The graph shows possible paths. It does not guarantee that an attacker will use every path shown.
Interpreting the Blast Radius Correctly
A blast-radius graph should not be interpreted as proof that a compromise has occurred.
Instead, it answers:
“If this identity were compromised, what resources might be reachable through known relationships and permissions?”
The graph is useful for:
- Prioritizing remediation.
- Identifying excessive permissions.
- Understanding lateral movement.
- Finding critical assets exposed through an agent.
- Supporting incident investigation.
- Designing Conditional Access policies.
- Improving agent architecture.
It should be combined with:
- Actual sign-in and activity logs.
- Security alerts.
- Agent configuration.
- Permission reviews.
- Data classification.
- Business criticality.
- Incident-response procedures.
Example Scenario
A company deploys an autonomous finance agent.
The agent can:
- Read invoices.
- Query a financial database.
- Submit payment requests.
- Access a shared document repository.
- Call a payment-processing API.
Defender identifies the following risk indicators:
- Privileged business-system access.
- Indirect prompt-injection exposure.
- Ability to operate without human approval.
- Access to sensitive financial data.
An attack-path analysis shows:
Agent identity → payment API → financial system
It also shows:
Agent identity → shared repository → confidential financial documents
The security team should consider:
- Removing unnecessary write permissions.
- Requiring human approval for payment actions.
- Restricting the agent to approved APIs.
- Limiting access to financial documents.
- Reviewing prompt-injection protections.
- Applying Conditional Access to high-risk agent identities.
- Monitoring related alerts and activity.
- Reassessing the blast radius after remediation.
Relationship to Conditional Access
Conditional Access and blast-radius analysis work together.
Blast-radius analysis helps answer:
- Which agents are high impact?
- Which agents have privileged access?
- Which resources should be protected?
- Which agents should be restricted or blocked?
Conditional Access can then enforce policies such as:
- Block high-risk agent identities.
- Restrict selected agents from sensitive applications.
- Separate development and production agents.
- Apply policies based on agent attributes.
- Restrict access to selected resources.
Microsoft Entra ID Protection can detect risky agent behavior. When an agent is confirmed as compromised, its risk can be set to High, allowing a Conditional Access policy configured to block high agent risk to prevent access to resources.
Relationship to Microsoft Defender for Cloud and Microsoft Purview
Blast-radius analysis is not the same as every other security capability.
Microsoft Defender XDR
Used for:
- AI agent inventory.
- Agent risk assessment.
- Identity investigation.
- Attack-path analysis.
- Security alerts.
- Incident investigation.
Microsoft Defender for Cloud
Used more broadly for:
- Cloud security posture management.
- Workload protection.
- Security recommendations.
- Cloud resource security.
- AI workload protection.
Microsoft Purview
Used for:
- Data classification.
- Sensitivity labels.
- Data security posture management.
- Data-loss prevention.
- Compliance and information protection.
Microsoft Entra Conditional Access
Used for:
- Evaluating access conditions.
- Blocking risky agent identities.
- Restricting access to selected resources.
- Enforcing identity-based access policies.
These capabilities complement one another. No single control provides complete protection for AI agents.
Best Practices
Use dedicated agent identities
Avoid sharing a broad identity across unrelated agents. Separate identities improve accountability and reduce the impact of a single compromise.
Apply least privilege
Grant only the permissions required for the agent’s purpose.
Minimize write and administrative permissions
Read-only access generally creates a smaller blast radius than the ability to modify or delete data.
Restrict tools
Every connected tool expands the agent’s potential attack surface. Remove tools that are not required.
Use approval gates
Require human approval for:
- Financial transactions.
- Data deletion.
- Permission changes.
- External communications.
- Production changes.
- Other high-impact actions.
Protect knowledge sources
Limit the data available to the agent and ensure that sensitive sources are properly secured.
Separate environments
Development and test agents should not automatically have access to production resources.
Review blueprints
Ensure that agent identity blueprints do not create agents with excessive or inconsistent permissions.
Monitor active threats
An agent with active alerts and privileged access should be investigated immediately.
Reassess after changes
Recalculate or review the agent’s exposure after changing:
- Permissions.
- Tools.
- Knowledge sources.
- Identity configuration.
- Resource access.
- Blueprint settings.
Treat graphs as possible paths
Do not assume that every path shown is an active attack or that every possible path is displayed.
Common Exam Traps
Blast radius is not the same as risk level
Risk level describes the agent’s overall security exposure. Blast radius describes the potential impact of compromise.
An agent does not need to be compromised to have a large blast radius
An agent may be configured with excessive permissions even when no threat has been detected.
Read access and write access are different
Write access to critical business systems generally creates a greater potential impact than read-only access.
Attack paths show possibilities
A graph shows possible routes based on known relationships and data. It does not prove that an attacker has used the route.
Conditional Access does not remove permissions
Conditional Access controls whether access is allowed under specified conditions. It does not replace least-privilege authorization.
Risk indicators and recommendations are different
Risk indicators contribute to the agent’s risk assessment. Recommendations identify available actions that may improve security posture.
A high-risk agent may not have a recommendation
Risk level and available recommendations are calculated separately.
Missing graph paths do not prove that no risk exists
Graphs have scope, freshness, and modeling limitations.
Practice Exam Questions
Question 1
What does the blast radius of a Microsoft Entra agent identity primarily describe?
A. The number of users who have interacted with the agent
B. The amount of compute capacity assigned to the agent
C. The potential resources and systems affected if the agent identity is compromised
D. The number of prompts processed by the agent
Correct answer: C
Explanation: Blast radius describes the potential impact of compromising the agent, including reachable data, applications, identities, and systems.
Question 2
Which Microsoft Defender capability provides a centralized view of AI agents and their security context?
A. Azure Cost Management
B. Azure Resource Graph only
C. Microsoft Purview retention management
D. AI agent inventory
Correct answer: D
Explanation: The AI agent inventory in Microsoft Defender provides visibility into agents, configuration, identities, risk indicators, tools, and related security information.
Question 3
An agent has no active security alerts but can modify a critical financial system. What should the security team conclude?
A. The agent has no security risk
B. The agent has a potentially large blast radius even though no compromise has been detected
C. The agent must be deleted immediately
D. The agent cannot be protected by Conditional Access
Correct answer: B
Explanation: Blast radius is based on potential impact. Privileged access can create significant exposure even when no active threat has been detected.
Question 4
Which risk indicator most directly suggests that an agent can affect important business operations?
A. High usage
B. Weak instructions
C. Indirect prompt-injection exposure
D. Privileged business-system access
Correct answer: D
Explanation: Privileged business-system access indicates that the agent can write to or otherwise affect important business systems.
Question 5
What is the purpose of analyzing attack paths for an agent identity?
A. To determine the model’s response quality
B. To identify possible routes from the agent to other resources or critical assets
C. To calculate the agent’s monthly operating cost
D. To configure the agent’s natural-language instructions
Correct answer: B
Explanation: Attack-path analysis identifies possible relationships and permission chains that could allow access to additional resources or critical assets.
Question 6
Which statement best distinguishes an agent’s risk level from its blast radius?
A. Risk level measures potential impact only, while blast radius measures prompt quality
B. Risk level applies only to human users, while blast radius applies only to applications
C. Risk level reflects overall security exposure, while blast radius reflects potential impact if compromised
D. They are two names for exactly the same measurement
Correct answer: C
Explanation: Risk level combines active risk indicators. Blast radius focuses on what could be affected if the agent identity were compromised.
Question 7
A Defender blast-radius graph displays a path from an agent to a sensitive database. What does this mean?
A. The agent has definitely been compromised
B. The database has already been accessed
C. The graph identifies a possible route based on known relationships and permissions
D. The agent must be assigned a database administrator role
Correct answer: C
Explanation: A blast-radius graph shows possible attack paths. It does not prove that compromise or access has occurred.
Question 8
Which change would most directly reduce an agent’s blast radius?
A. Remove unnecessary write permissions and restrict the agent to required resources
B. Increase the agent’s model size
C. Add more knowledge sources
D. Allow the agent to use additional administrative APIs
Correct answer: A
Explanation: Reducing permissions and limiting resource access directly reduces what the agent could affect if compromised.
Question 9
Why should security teams review an agent’s knowledge sources during blast-radius analysis?
A. Knowledge sources determine the agent’s compute pricing
B. Knowledge sources may expose confidential or sensitive information to the agent
C. Knowledge sources automatically grant Global Administrator access
D. Knowledge sources eliminate the need for identity protection
Correct answer: B
Explanation: Knowledge sources may contain sensitive information. The agent’s access to those sources can significantly increase the impact of compromise or misuse.
Question 10
Which statement about Microsoft Defender blast-radius graphs is accurate?
A. They show every possible attack path with complete certainty
B. They prove that all displayed paths have been exploited
C. They replace permission reviews and incident investigation
D. They show possible paths and may be limited by data freshness, scope, and modeled attack techniques
Correct answer: D
Explanation: Blast-radius graphs are useful approximations, but they have limitations involving data freshness, RBAC scope, hop limits, and known attack vectors.
Go to the SC-500 Exam Prep Hub main page
