Azure Networking · The agentic network for AI

Where identity, security & policy
meet on the network.

Azure AgentFabric is the agent‑aware network built into Azure — the fabric where every hop (agent ↔ agent, agent ↔ LLM, agent ↔ MCP tool, agent ↔ data) is identity‑authenticated, mTLS‑encrypted, policy‑enforced, and semantically inspected. Identity, security, and policy converge on the wire — no sidecars, no agent code changes.

Networkwhere it all converges
0code changes for agents
100%hops, identity‑bound
L3 → L7defense in depth
Built on and integrated with
▶ See it in action

AgentFabric, live.

A walkthrough of identity-aware, mTLS-secured, policy-enforced agent traffic on Azure — end to end.

01 · What it is

The agentic network for Azure — where identity, security & policy meet on the wire.

AgentFabric is an Azure‑native network capability. It binds every agent, tool, and MCP server to a verifiable identity, then carries every interaction over a fabric that authenticates, encrypts, segments, and inspects traffic at line rate — transparently. Identity from Entra. Policy as identity. Security and inspection delivered by the network itself. One fabric. Every agentic hop.

Identity on the network

Entra Agent ID + SPIFFE SVIDs become first‑class network primitives. Every packet is tied to a verifiable workload identity — not an IP.

Security in the fabric

mTLS, segmentation, and threat protection live in the Azure networking data path (eBPF + Envoy) — not in your agent, not in a sidecar. If it's on Azure, it is SECURE by default!

Policy as the wire

Allow / Block / Inspect — written in identities, enforced inline. Compose rich policy groups per agentic hop, with semantic guardrails (Prompt Shield, Purview DLP, MCP Network Filtering and Security) applied on the same wire.

One network. Every agentic hop. Identity, security, and policy converge on the wire — by default.
02 · The problem

Agents broke the network.

Agent traffic is the new network. A dense, dynamic, runtime‑generated east–west conversation graph across LLMs, tools, MCP servers, PaaS, and SaaS — with sensitive context flowing on every turn. Identity lives in Entra. Policy lives in firewalls. Security lives in apps. They never meet on the wire — and that's exactly where agents talk.

01

Combinatorial east–west traffic

Hundreds of short‑lived flows per user outcome — agents, LLMs, tools, MCP, data — created at runtime.

02

Identity, security & policy are siloed

Entra owns identity, firewalls own policy, apps own security — they never converge on the wire where agents actually talk.

03

No consistent posture across compute

Agents span Serverless, AKS/ACA, IaaS, and PaaS. Bolt‑on meshes and sidecars don't cover them all.

04

New, semantic threats

Prompt injection, indirect prompt injection, data exfiltration via tools, MCP/tool poisoning, A2A misuse.

From a few predictable flows → to a runtime‑generated graph of hundreds of interactions.
03 · The value

One network. Identity. Security. Policy. Converged.

AgentFabric collapses three historically separate planes — identity, security, and policy — into a single, agent‑aware network. Developers keep building. The network quietly enforces zero trust on every hop.

AgentFabric secure connectivity fabric across Azure
Identity-based micro-segmentation for all workloads on Azure across any resource.
Compose policy groups for every agentic hop — source × destination, applied immediately at the wire.

Identity becomes the network

Every flow carries a SPIFFE SVID + Entra Agent ID. Policy is written in identities — not subnets, not IPs. Lateral movement collapses.

  • Default‑deny micro‑segmentation
  • Agent‑to‑agent / agent‑to‑tool
  • Cryptographic, hop‑by‑hop

Security in the data path

FIPS‑compliant mTLS, ALTS‑grade encryption, and L7 inspection — delivered by the network, line‑rate, transparent.

  • Cilium eBPF data plane
  • Envoy for L7 inspection
  • No sidecars to operate

Policy on the wire

Allow / Block / Inspect at every hop. Add semantic guardrails — Prompt Shield, Purview DLP, MCP integrity — to the same wire.

  • Identity‑driven policy
  • Protocol‑aware (A2A, MCP, OpenAI)
  • Inline runtime threat blocking

One network, every compute

Same identity model, same policy surface, same telemetry — across Serverless, AKS/ACA, IaaS, and PaaS.

  • Framework‑agnostic
  • Protocol‑agnostic
  • Hosting‑agnostic

“Identity tells you who. Security tells you how safe. Policy tells you what's allowed. Until now they lived in three different planes. AgentFabric brings them together — on the network.

04 · Scenarios

Real agentic systems. Real protection.

Wherever agents run on Azure, AgentFabric is the same security fabric underneath.

Foundry agents at enterprise scale

Light up identity‑based segmentation and prompt‑injection blocking for AI Foundry workloads — the lighthouse scenario.

Phase 0 — first to GA

Multi‑agent collaboration (A2A)

Orchestrator/specialist patterns where agents delegate over A2A — every hand‑off authenticated, every message inspectable.

Copilot Studio · pro‑code

MCP tools and tool servers

Bind every MCP server to an identity. Allow only the right tools to the right agents. Stop poisoning and tool drift.

Azure Functions · custom

Agents → Azure PaaS & SaaS

Storage, Cosmos, Key Vault, Search, ticketing, CRM — secure egress with identity, intent, and data‑class context.

Cross‑boundary

Runtime threat protection

Inline detection of prompt injection, jailbreaks, data exfil, and tool mutation — without slowing down the agent.

Phase 2 differentiation

SOC‑grade observability

Every flow is identity‑tagged and protocol‑aware. Streamed to Sentinel for hunting, detection, and audit.

Sentinel · Defender
05 · High‑level architecture

Three layers. One network.

A lightweight component near the workload, a regional control plane, and an elastic data plane — all working as one agent‑aware network where identity, security, and policy converge on every hop.

Zoom into a single hop — Entra-issued identity, mutual mTLS tunnel, deep inspection in the data path.
01

AgentFabric Shim

Sits transparently next to the workload. Embeds the SPIRE client, terminates mTLS, applies allow/block/inspect policy — with no agent code changes.

02

AgentFabric Controller

Regional control plane: Resource Manager, SPIRE Server federated to Entra, Policy Manager, and Dataplane Manager.

03

AgentFabric Dataplane

Elastic services for deep packet inspection, traffic shaping, and semantic protections — Prompt Shield, Purview‑aware DLP, MCP/tool integrity.

Plays well with the Microsoft ecosystem and open standards

Entra Agent IDIssuance & governance
SPIFFE / SPIREWorkload identity
Cilium · eBPFKernel‑level data path
EnvoyL7 inspection
Azure AI Content SafetyPrompt Shield inline
Microsoft PurviewData classification
Microsoft SentinelDetections & audit
Prometheus / OTelOpen telemetry
06 · The team

Built by Azure Networking.

A small, senior team across leadership, product, and engineering — shipping AgentFabric for every Azure customer.

The Team

The agentic network for Azure.

Where identity, security & policy converge — on the wire.