A Purview Insider Risk Management policy, in preview and on by default, that keeps watch over agents made with Copilot Studio or Microsoft Foundry. It flags things like dangerous prompts, replies containing sensitive data, opening sensitive files or unsafe sites, and external file sharing.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Risky Agents in context, with comparison tables and the common traps.
Terms in this definition
- Insider Risk Management
A Microsoft Purview solution that scores risky user activity, such as leaking or stealing data, from activity indicators and raises alerts. DLP policies are not edited here.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Copilot Studio
Microsoft's low-code tool for building workflows and AI agents. Its generative agents may hand each tool call they intend to make to an external threat detection service, Microsoft Defender for example, for checking.
- Microsoft Foundry
Formerly called Azure AI Foundry, the Azure platform where AI models and agents are built, evaluated and run within one resource, with evaluations, guardrails and AI red teaming.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- External
API Management virtual network mode in which the gateway stays public but can call private back ends inside the VNet.