top of page


The Security Bridge™️- Identity Threat Protection in Microsoft 365 - Part 2: Your Tenant Has More Identities Than Employees
Machine identities outnumber humans 109 to 1 in the average Microsoft 365 tenant, and most are ungoverned. Part 2 of The Security Bridge series breaks down why service principal ownership, not directory roles alone, is the real takeover path: how a stolen credential inherits every permission an app holds, and why 99% of tenants already have at least one privileged service principal exposed. Includes 3 real examples and a validation checklist for security architects, engineers

Derek Morgan
Jul 225 min read


Part 2 of 3: Your Pro-Code Agent Has an Identity Too. Here Is How Conditional Access Governs It
Publishing a Copilot Studio agent creates an Entra identity in the same minute. As of March 18, 2026, every Copilot Studio agent in a default-on tenant gets a Microsoft Entra Agent ID: a service principal with the 'Agent' subtype, governable through the same Entra admin center and Microsoft 365 admin center your IAM team already operates. A walkthrough of what the Agent ID is, how Agent 365 governs it, the connected dual-agent pattern from a defensive SecOps PoC, and a 7-step

Derek Morgan
Jun 197 min read


Part 1 of 3: Your Copilot Studio Agent Has An Identity. Here Is How To Govern It
Publishing a Copilot Studio agent creates an Entra identity in the same minute. As of March 18, 2026, every Copilot Studio agent in a default-on tenant gets a Microsoft Entra Agent ID: a service principal with the 'Agent' subtype, governable through the same Entra admin center and Microsoft 365 admin center your IAM team already operates. A walkthrough of what the Agent ID is, how Agent 365 governs it, the connected dual-agent pattern from a defensive SecOps PoC, and a 7-step

Derek Morgan
May 268 min read
Start Your Cloud Journey
bottom of page