Explore the latest Microsoft Entra capabilities to secure AI traffic, protect sensitive data, and extend identity-first Zero Trust controls across web and private applications.
Today's threats don't respect boundaries. As AI agents proliferate across enterprise workflows, employees work from everywhere, and organizations adopt cloud-first architectures, the attack surface has fundamentally shifted. Traditional perimeter security can no longer keep pace with how work actually happens.
Microsoft Entra Internet Access and Microsoft Entra Private Access extend Zero Trust principles to all traffic, ensuring that every access request is verified against identity, device, and risk context, whether it originates from a user, a device, or an AI agent.
Today, we're building on our recent announcement, where we introduced a significant wave of new capabilities across both public preview and general availability. These updates span AI security, data protection, private access, and connectivity resilience, bringing the breadth of our SASE platform to meet the security demands of the AI era.
Now in public preview: deeper controls for AI, data, and access
Microsoft Entra Internet Access and Microsoft Entra Private Access
This July, we’re introducing new capabilities in public preview to help you secure AI interactions, protect sensitive data, strengthen access controls, and improve operational resilience—all through an identity-first approach to security. These capabilities bring deeper visibility and policy enforcement across users, AI agents, devices, locations, and applications, helping you innovate with confidence while maintaining Zero Trust principles.
- Network Data Loss Protection (DLP) extends Microsoft Purview data security to the network layer with Microsoft Entra Internet Access. Discover sensitive content in risky AI and cloud apps, block unsafe sharing (including file uploads, prompts, and responses), and apply context-aware controls based on identity and activity.
- Microsoft Entra network controls are now available for agents, including Microsoft Copilot Studio agents and those running on user endpoint devices, and local agents such as OpenClaw. These controls can help identify unsanctioned AI usage, restrict connections to only approved web destinations, filter risky file movement, and help block malicious prompt-based attacks before they lead to harmful actions.
- Custom Acquire and Agentic Acquire on Entra Internet Access traffic profile enables side by side deployment of Global Secure Access for AI Gateway and Agentic scenarios with other vendors.
- Windows 365 for Agents integrates with Global Secure Access platform to provide enterprise-grade network security to agentic Cloud PCs with traffic monitoring, web filtering and threat blocking on agentic sessions.
Figure 1: Demo of Network data security
Now generally available: broader coverage and stronger controls for users, applications, and AI
As secure access becomes foundational to every AI, cloud, and hybrid work initiative, organizations need solutions that are both powerful and operationally simple. The latest generally available capabilities for Microsoft Entra Internet Access and Microsoft Entra Private Access help organizations accelerate Zero Trust adoption, extend protection to unmanaged and remote environments, and gain greater visibility into how users, applications, and AI services interact with enterprise resources. The following capabilities are now GA and ready for organizations to deploy:
- Browser-based access to internet resources for Microsoft Entra Internet Access extends secure web access to kiosk and BYOD devices using PAC file-based proxy configuration.
- BYOD with Client in Microsoft Entra Private Access lets you enforce Zero Trust for unmanaged devices, so employees and contractors can securely access private apps without compromising security or user experience.
- Shadow MCP Visibility provides advanced monitoring and analysis capabilities for MCP traffic between client MCP on devices and remote MCP servers. This feature provides thorough visibility into which MCP servers are being used, what tools and resources they expose, and how those tools are invoked.
Want to Learn More?
Join our three-part webinar series, Securing Data and Access in the Era of AI (July 21–23, 9:00 AM PDT), where Microsoft Entra and Microsoft Purview product leaders will share practical guidance for securing data, governing access, and scaling AI adoption with confidence. Save the dates and register to attend.
-Sinead O’Donovan | VP of Product Management, Identity and Network Access
Additional resources
- Protect sensitive data in motion across SaaS and AI apps with Microsoft Purview and Microsoft Entra
- Secure AI at scale: Join the Microsoft Entra + Purview webinar series | Microsoft Community Hub
- Lock down AI, web, and private apps: what’s new in Internet Access and Private Access
- Microsoft Entra Private Access | Microsoft Security
- Microsoft Entra Internet Access | Microsoft Security
Learn more about Microsoft Entra
Prevent identity attacks, ensure least privilege access, unify access controls, and improve the experience for users with comprehensive identity and network access solutions across on-premises and clouds.
- Microsoft Entra News and Insights | Microsoft Security Blog
- Microsoft Entra blog | Tech Community
- Microsoft Entra documentation | Microsoft Learn
- Microsoft Entra discussions | Microsoft Community