Loading...
Loading...
Guidance for Microsoft Defender for Cloud — AI workload protection (AI-SPM and runtime threat detection for generative AI). Covers AI Security Posture Management (discovery of Azure OpenAI / Azure AI Foundry / Amazon Bedrock / Google Vertex AI resources, identification of grounding data exposure, model deployment posture), runtime threat detection on Azure OpenAI (prompt injection / jailbreak attempts, sensitive data leakage in prompts/responses, wallet abuse, credential leakage), integration with Azure AI Content Safety Prompt Shields, attack path analysis for AI workloads, alert investigation in Defender XDR, and pairing with Purview DSPM for AI (user side) and Azure AI Content Safety (model side). WHEN: Defender for Cloud AI, AI-SPM, AI workload protection, Azure OpenAI threat detection, prompt injection alert, jailbreak alert Azure OpenAI, AI wallet abuse, AI workload posture, Amazon Bedrock posture, Vertex AI posture, generative AI security Azure. DO NOT USE for end-user AI usage governance (use purview-ai-hub), content moderation API (use azure-ai-content-safety), or M365 Copilot rollout (use copilot-for-m365-readiness).
npx skill4agent add vinayaklatthe/microsoft-security-skills defender-for-cloud-aipurview-ai-hubazure-ai-content-safetycopilot-for-m365-readiness| Capability | Scope |
|---|---|
| Multicloud AI discovery | Azure (OpenAI, Foundry), AWS Bedrock, GCP Vertex AI (via existing multicloud connectors) |
| Sensitive grounding data exposure | Identifies grounding storage with sensitive data + public/over-permissive access |
| Attack path analysis | "Internet-exposed AI endpoint with sensitive grounding + over-privileged identity" |
| Runtime detections (Azure OpenAI) | Prompt injection, jailbreak, sensitive data leakage in prompts/responses, suspicious access patterns, wallet abuse |
| Prompt Shields integration | Detections leverage Content Safety prompt-shield signals |
| Alerts in Defender XDR | Correlated incidents alongside cloud and identity signals |
Enable Defender for Cloud AI plan across 12 subscriptions with Azure OpenAI and AI Foundry deployments.Inventory AI workloads and grounding stores; identify top-10 attack paths.Build runbook for "Prompt injection detected" alerts: triage, containment, hunt.Integrate Azure AI Content Safety Prompt Shields with our Foundry chat app and enable Defender runtime detection.Posture pipeline: Azure Policy to require private endpoint + Entra auth on all Azure OpenAI resources.Connect AWS Bedrock and GCP Vertex AI usage into Defender AI-SPM.Sentinel detection correlating Defender AI wallet-abuse alert with sign-in risk on the calling identity.