Microsoft, “Least privilege for AI agents: Identity, access, and tool binding”
Microsoft warns that organizations are deploying autonomous, multi-tool agents faster than their identity and authorization systems are evolving to constrain them. Broad permissions and combinations of individually reasonable access rights can allow agents to correlate information across email, files, tickets, and code repositories, creating risks of unauthorized data access, unintended modification or deletion, privilege escalation, and forensic ambiguity about who authorized an action.
Microsoft warns that organizations are deploying autonomous, multi-tool agents faster than their identity and authorization systems are evolving to constrain them.
Why it matters
Microsoft recommends treating every agent as a first-class security principal with a dedicated identity, named human owner, task-scoped permissions, approved-tool manifests, just-in-time elevation, downstream authorization checks, and tested revocation mechanisms—while emphasizing that prompt-level instructions are not substitutes for enforceable access boundaries.
Primary trail
Go to the source
Read the evidence behind this analysis. External links open in a new tab.