AI Security: The Basics Everyone Misses
Most prompt injection attempts never get to your prompt if you filter input properly. Use managed identities. Always.
127 articles
Most prompt injection attempts never get to your prompt if you filter input properly. Use managed identities. Always.
Zero-trust isn't optional for AI workloads handling sensitive data. Implement these patterns from day one to avoid costly retrofitting.
AI security is not optional. Implement these measures before going to production, and review them quarterly as threats evolve.
AI applications face unique security concerns: protecting training data, controlling model access, securing inference endpoints, and preventing prompt…
Zero-Trust security ensures AI applications remain protected while enabling legitimate business use cases.
Maintain comprehensive logs of all content filtering decisions for compliance and incident investigation. Every blocked request should be logged with…
Prompt injection occurs when user input is interpreted as instructions rather than data. Attackers can attempt to override system prompts, extract…
A well-designed gateway enables enterprise-wide AI adoption while maintaining security, compliance, and cost control.
Filter and sanitize user inputs before they reach the LLM. Verify AI responses before returning them to users.
Comprehensive security protects AI systems from emerging threats.
Defense in depth with multiple layers provides the best protection against prompt injection.
Comprehensive guardrails are essential for responsible AI deployment.
Enterprise agents require these patterns to ensure security, compliance, and reliable operation at scale. Implement them from the start rather than…
Comprehensive audit logging is essential for AI agents in production. It enables debugging, ensures compliance, and provides the visibility needed to build…
Permission models for AI agents must be flexible yet secure. Combine RBAC for broad access patterns with capabilities for fine-grained, time-limited access.
Sandboxing is your last line of defense. Even trusted agents can behave unexpectedly - proper isolation ensures that unexpected behavior doesn't become a…
Safety in AI agents is not optional - it's foundational. Build safety in from the start, and your agents will be both powerful and trustworthy.
Network security provides defense in depth for your data platform. Today I'm exploring network security options in Microsoft Fabric.
Conditional Access enables Zero Trust security by controlling access based on conditions. Today I'm exploring how to implement Conditional Access for…
Data Loss Prevention (DLP) helps prevent accidental data exposure and ensures compliance. Today I'm exploring DLP implementation in Microsoft Fabric.
Security is foundational to any data platform. Today I'm exploring the security architecture and best practices in Microsoft Fabric.
Data sharing enables collaboration while maintaining security. Today I'm exploring data sharing patterns in Microsoft Fabric.
Tenant settings control what users can do in your Fabric environment. Today I'm covering the essential settings every admin should configure.
Fabric administration has matured significantly. Today I'm covering the latest admin capabilities for managing your Fabric environment effectively.
Code execution is one of the most powerful capabilities for AI agents - and one of the most dangerous. Today I'm exploring how to implement it safely.
AI introduces risks that cut across data, models, operations and people. Over the past year I've helped teams map those risks to concrete controls — from…
Fabric governance is where the platform's SaaS architecture creates both an advantage and a complication for enterprise security teams. The advantage…
Implementing comprehensive PII detection and protection strategies for AI applications.
Comprehensive input validation strategies for securing LLM applications against malicious inputs.
Comprehensive strategies for defending against prompt injection attacks in LLM applications.
Essential AI safety concepts and practices for building responsible LLM applications.
RLS provides essential data security for multi-tenant and sensitive data scenarios. Tomorrow, I will cover Azure OpenAI function calling patterns.
Item permissions provide the flexibility to share specific artifacts securely. Tomorrow, I will cover Row-Level Security in Fabric.
Proper role management is essential for secure and efficient collaboration. Tomorrow, I will cover Item Permissions in more detail.
Security is an ongoing responsibility. Tomorrow, I will cover Workspace Roles in more detail.
Security Copilot addresses the security skills gap by augmenting analysts with AI-powered investigation and response capabilities.
1. Set appropriate thresholds : Adjust based on your use case 2. Use blocklists : For domain specific terms 3. Check both input and output : For AI…
Each category has severity levels: safe, low, medium, high.
The question I kept hearing from enterprise clients in January 2023 was some variation of: "We've seen what ChatGPT can do—how do we get that capability…
2022 brought significant security advancements in Azure, from Defender for Cloud improvements to enhanced Zero Trust capabilities. As we move into 2023,…
Rate limiting protects your application by: Preventing denial of service attacks Ensuring fair usage among clients Protecting downstream services Managing…
Secure Files protect sensitive credentials while enabling automated pipelines.
Service connections provide secure, manageable access to external resources.
Checks provide automated validation gates for enterprise deployments.
OIDC eliminates the need for long-lived cloud credentials, improving security posture.
Required workflows ensure consistent security and quality standards across the enterprise.
Code Signing is verifying that you (or an entity) developed and owns the application. The way it works is by creating a “signature” on to the application to…
RLS uses security policies with predicate functions to filter rows transparently. Users see only the rows they're authorized to access without any…
DDM is a policy-based security feature that hides sensitive data in query results. The data in the database is not modified, making it ideal for scenarios…
Always Encrypted uses column encryption keys (CEKs) protected by column master keys (CMKs) to encrypt sensitive columns. The database engine never has…
Ledger tables maintain a complete history of all changes with cryptographic hashes, making it possible to verify that data hasn't been tampered with.
Implementing these security best practices creates a defense-in-depth approach for your IoT solutions.
DPS is essential for deploying and managing IoT devices at scale across multiple regions and IoT Hubs.
Network Policies provide essential microsegmentation for Kubernetes clusters. Enable a CNI that supports policies (like Azure CNI or Calico) to enforce them.
Three built in levels: Privileged : Unrestricted (equivalent to no PSP) Baseline : Prevents known privilege escalations Restricted : Heavily restricted,…
Seccomp (Secure Computing Mode) limits which system calls a process can make, reducing the attack surface.
Object Level Security provides an additional security layer: Protect sensitive columns from unauthorized access Hide entire tables from roles Complement RLS…
Row Level Security is essential for: Multi tenant applications Regional data access Hierarchical visibility Regulatory compliance Combined with proper…
Private Endpoint : Consume services privately (you're the client) Private Link Service : Expose services privately (you're the provider) 1. SaaS providers :…
A private endpoint: Creates a network interface with a private IP in your VNet Maps to a specific Azure resource (or sub resource) Enables DNS resolution to…
Data Flows automatically use the managed VNet when connected to private endpoints.
A complete governance framework addresses: Access Control : Who can access what data Data Quality : Ensuring data accuracy and completeness Data Lineage :…
Comprehensive Windows Event collection is essential for security monitoring and compliance.
Azure Confidential Ledger provides cryptographically verifiable, tamper-proof record keeping for compliance-critical scenarios.
Category Example Recommended Approach Azure Services Storage, SQL Managed Identity External APIs Third party APIs Key Vault Certificates TLS, Auth Key Vault…
Certificate-less authentication dramatically simplifies operations while improving security posture.
Keyless Authentication: The Future of Cloud Security
OIDC for GitHub Actions is the modern, secure approach to Azure authentication in CI/CD pipelines.
Instead of client secrets: 1. External identity provider issues a token 2. Token is exchanged for an Azure AD token 3. Application uses Azure AD token to…
Managed identities are the foundation of a zero-secrets architecture in Azure.
Dependabot is an essential tool for maintaining secure and up-to-date dependencies.
GitHub partners with service providers to detect over 100 types of secrets. When a secret is detected, both you and the provider are notified, allowing for…
Code scanning uses CodeQL, a semantic code analysis engine, to find security vulnerabilities, bugs, and other errors in your codebase.
GitHub Advanced Security transforms security from a gate to a continuous process integrated into your development workflow.
Differential privacy ensures that the output of a computation doesn't reveal whether any individual's data was included. The key insight: add calibrated…
Identity-first security in 2021 meant rethinking how we control access. The tools are mature; the challenge is implementation discipline.
1. Verify Explicitly : Always authenticate and authorize based on all available data points 2. Least Privilege Access : Limit user access with just in time…
Azure Service Connector eliminates the boilerplate of connecting services while implementing security best practices. It's a significant productivity boost…
Azure AD Workload Identity is the architecture-level improvement over AAD Pod Identity that removes the NMI DaemonSet and uses Kubernetes native service…
AAD Pod Identity was the original mechanism for giving Kubernetes pods an Azure AD identity so they could access Azure resources—Key Vault secrets, Storage…
Content protection with DRM ensures your premium content remains secure while providing a seamless viewing experience across all platforms.
Speaker Recognition enables secure, frictionless authentication and personalized experiences based on voice identity.
Set up Update Management for your VMs: Onboard VMs to Update Management: Schedule update deployments: Create maintenance scripts: Query update compliance…
Activity Logs include several categories: Administrative : Resource management operations (create, update, delete) Security : Security Center alerts and…
Traditional NSG rules use IP addresses, which creates challenges: IP addresses change when VMs are recreated Rules become hard to read with many IP ranges…
NSG rules are evaluated by priority (100 4096, lower = higher priority): Direction : Inbound or Outbound Priority : 100 4096 (lower numbers processed first)…
Azure Firewall rules are the configuration work that determines whether your network security posture is genuinely restrictive or accidentally permissive.…
NAT Gateway solves several problems: SNAT Port Exhaustion : Each NAT Gateway supports up to 64,000 concurrent connections per public IP Simplified…
Application Gateway v2 is where the regional Layer 7 load balancer story became production-serious for enterprise workloads. Autoscaling means you don't…
Platform Use Case Global/Regional Application Gateway Regional apps, traditional Regional Front Door Global apps, edge protection Global CDN Static content…
Basic (Free) Always on traffic monitoring Automatic mitigation Protection for Azure infrastructure No SLA or customization Standard (Paid) All Basic…
Feature Key Vault Premium Managed HSM HSM Type Multi tenant Single tenant FIPS Level 140 2 Level 2 140 2 Level 3 Admin Control Azure managed Customer…
Key Vault stores certificates as: Certificate : The X.509 certificate (public) Key : The private key (protected) Secret : The combined certificate + private…
Flow Use Case User Interaction Authorization Code Web apps, mobile Yes Authorization Code + PKCE SPAs, mobile, desktop Yes Client Credentials Daemon/service…
User Flows: Pre-built, configurable through portal Custom Policies: XML-based, fully customizable
Conditional Access is where the "never trust, always verify" principle of Zero Trust actually gets operationalised. Every sign-in to every app goes through…
The service identifies: Reconnaissance : Attackers gathering information about your environment Compromised credentials : Pass the hash, pass the ticket,…
Microsoft Defender for Cloud includes: CSPM (Cloud Security Posture Management): Free tier with security recommendations CWP (Cloud Workload Protection):…
In Sentinel, SOAR is implemented through Playbooks (Logic Apps) and Automation Rules.
Azure Dedicated Host is the offering I typically reach for when a client's security or compliance team says "I can't be on shared hardware." The use cases…
Confidential Computing addresses the attack surface that most cloud encryption doesn't touch: data while it's actively being processed in memory. Encryption…
Both work together - a user needs both RBAC permission to access the storage account AND appropriate ACL permissions on the specific path.
1. Azure Sphere MCU : Secured silicon with hardware based security 2. Azure Sphere OS : Linux based secured operating system 3. Azure Sphere Security…
Databricks workspace governance was the problem nobody thought about until there were thirty workspaces, fifteen clusters running overnight, and six teams…
Azure Firewall Manager provides: Hierarchical policy management Parent and child policies for inheritance Global deployment Manage firewalls across regions…
I keep writing about Bastion because I keep finding jump boxes I have to replace. VM with a public IP, port 3389 open, "admin" password in a sticky note in…
Private Link provides several key benefits: Private connectivity Access services over private IP addresses Data exfiltration protection Service endpoints…
Azure Defender extends the capabilities of Azure Security Center by adding: Advanced threat detection using machine learning and behavioral analytics…
"Put it in Key Vault" is the easy advice. The advanced game is rotation, lifecycle, and access patterns that don't break under pressure. Managed identity…
I revisit APIM policies on this blog roughly every six months because the patterns are how the service earns its keep. Rate limiting per subscription, JWT…
SQL Ledger: trust through cryptographic verification.
Storage accounts are deceptively easy to deploy and easy to misconfigure into a leak. Public blob containers are still the most common "how did this get…
DDoS Protection Standard provides cost credits for attack-related scaling. Azure DDoS Protection: resilience against the largest attacks.
Jump boxes are one of those legacy patterns I keep finding in environments I inherit. A Windows VM with RDP open to the internet, "for admin access only,"…
Azure Firewall: cloud-native network security without the complexity.
"It can't be processed if it can't be decrypted, but you can't process encrypted data." That truism quietly stopped being true. Confidential Computing uses…
A WAF in front of every public app is no longer a nice-to-have. Bots scan you within minutes of going live, and "we'll add WAF later" is how breaches…
SIEM used to mean a rack of appliances, a forwarder per data source, and a six-figure annual licence. Sentinel rewrites that economics. It's a SIEM that…
API Management is one of those services I underestimated for years. "It's a proxy, right?" The penny drops when you realise policies are the product. Rate…
Azure Defender: security visibility across your entire estate.
Encrypt sensitive columns—keys never exposed to SQL Server. Azure SQL security is comprehensive—use all layers for maximum protection.
In Desktop: Modeling → View as Roles → Select role → Enter email to test RLS enables true multi-tenancy in Power BI, where one dataset serves many users…
The extra cost of Bastion is worth the security posture improvement.
By default, Azure PaaS services (Storage, SQL, Cosmos DB) have public endpoints. Even with firewall rules, data transits the public internet.
Three years ago a client asked me to "put a gateway in front of my APIs." It turned into a six-month conversation about rate limiting, OAuth, partner…
A confession to start: I've shipped connection strings in appsettings.json more times than I'm proud of. The reasons are always the same — "it's only dev"…