Why it matters

Microsoft recommends treating every agent as a first-class security principal with a dedicated identity, named human owner, task-scoped permissions, approved-tool manifests, just-in-time elevation, downstream authorization checks, and tested revocation mechanisms—while emphasizing that prompt-level instructions are not substitutes for enforceable access boundaries.

Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

Microsoft