Action is the most beautiful form of speech

Category Security

License to Assist: Bringing AI Agents to Entra ID

AI agents are no longer a future concept in identity and security—they are already becoming first‑class citizens in Microsoft Entra. I had session in Experts Live Denmark 2026 and in session “License to Assist – Bringing AI Agents to Entra ID”, Jan… Continue Reading →

Blueprint for a Modern Defense Stack

Why the Future of Security Is Graph‑Powered, AI‑Driven, and Relentlessly Adaptive At this year’s keynote in Experts Live Denmark 2026, Raviv Tamir, Vice President and Chief Product Strategy for SIEM & XDR at Microsoft, laid out a clear and candid vision… Continue Reading →

Power Platform Governance & Security Architecture

I attended CollabDays Bremen last weekend. Session led by Stalin Ponnusamy, MVP provided a comprehensive and practical deep dive into Power Platform governance, breaking down the layered security model that organizations must understand to protect sensitive data in a world… Continue Reading →

Fixing Prompt Injection Vulnerability

I’ve been building agents a while and after CollabDays Portugal I had the idea of hacking my own Copilot Studio agent. Other MVPs discussed how important and hot topic security is and I had an idea. I realised that if… Continue Reading →

Copilot Studio Agent Security

Below are the mitigations that significantly reduce exfiltration risk. These should be in place before deploying any Copilot Studio agent to a production environment. 1. Apply Least‑Privilege Access Only grant the agent permissions it absolutely needs — nothing more.If the… Continue Reading →

Obfuscated request patterns and rapid‑fire multi‑turn scripts

There was still couple tests to run for my agent before thinking how to fix problems. Like in any testing, it is important to run all tests, then analyse before starting to fix anything when first bug is revealed. Many… Continue Reading →

Copilot Studio Agent Data Exfiltration

I wanted to test how easy it was hacking my own agent created in July. I seems prompt injection was quite easy. I did not know how to hack the agent other means, I needed to ring my old pall… Continue Reading →

Hacking my Job Application Agent was easy

I created Job Application agent in July and felt that I need something more in my demos. I felt that security is now quite hot topic and I was thinking that how easy it would be hacking my own agent…. Continue Reading →

From Agent Quality to Power Platform Governance – Practical Tool Demos

In a session at CollabDays Finland 2025, Microsoft MVP Terho Antila and Arto Niemi from Locoda tackled one of the most complex challenges facing Power Platform professionals today: how to bring structure, visibility, and automation to sprawling environments powered by AI and Copilot… Continue Reading →

Mastering Copilot Agent Governance: Strategies for Secure and Efficient Deployment

At CollabDays Finland 2025, Microsoft MVP Mikko Koskinen delivered a session that tackled one of the most pressing challenges in the Power Platform ecosystem: how to govern, deploy, and scale Copilot Studio agents responsibly (session slides). With a background in enterprise architecture and hands-on… Continue Reading →

« Older posts

© 2026 Karl-Johan Spiik, Microsoft MVP — Powered by WordPress

Theme by Anders NorenUp ↑