Identity on the network
Entra Agent ID + SPIFFE SVIDs become first‑class network primitives. Every packet is tied to a verifiable workload identity — not an IP.
Azure AgentFabric is the agent‑aware network built into Azure — the fabric where every hop (agent ↔ agent, agent ↔ LLM, agent ↔ MCP tool, agent ↔ data) is identity‑authenticated, mTLS‑encrypted, policy‑enforced, and semantically inspected. Identity, security, and policy converge on the wire — no sidecars, no agent code changes.
A walkthrough of identity-aware, mTLS-secured, policy-enforced agent traffic on Azure — end to end.
AgentFabric is an Azure‑native network capability. It binds every agent, tool, and MCP server to a verifiable identity, then carries every interaction over a fabric that authenticates, encrypts, segments, and inspects traffic at line rate — transparently. Identity from Entra. Policy as identity. Security and inspection delivered by the network itself. One fabric. Every agentic hop.
Entra Agent ID + SPIFFE SVIDs become first‑class network primitives. Every packet is tied to a verifiable workload identity — not an IP.
mTLS, segmentation, and threat protection live in the Azure networking data path (eBPF + Envoy) — not in your agent, not in a sidecar. If it's on Azure, it is SECURE by default!
Allow / Block / Inspect — written in identities, enforced inline. Compose rich policy groups per agentic hop, with semantic guardrails (Prompt Shield, Purview DLP, MCP Network Filtering and Security) applied on the same wire.
Agent traffic is the new network. A dense, dynamic, runtime‑generated east–west conversation graph across LLMs, tools, MCP servers, PaaS, and SaaS — with sensitive context flowing on every turn. Identity lives in Entra. Policy lives in firewalls. Security lives in apps. They never meet on the wire — and that's exactly where agents talk.
Hundreds of short‑lived flows per user outcome — agents, LLMs, tools, MCP, data — created at runtime.
Entra owns identity, firewalls own policy, apps own security — they never converge on the wire where agents actually talk.
Agents span Serverless, AKS/ACA, IaaS, and PaaS. Bolt‑on meshes and sidecars don't cover them all.
Prompt injection, indirect prompt injection, data exfiltration via tools, MCP/tool poisoning, A2A misuse.
AgentFabric collapses three historically separate planes — identity, security, and policy — into a single, agent‑aware network. Developers keep building. The network quietly enforces zero trust on every hop.
Every flow carries a SPIFFE SVID + Entra Agent ID. Policy is written in identities — not subnets, not IPs. Lateral movement collapses.
FIPS‑compliant mTLS, ALTS‑grade encryption, and L7 inspection — delivered by the network, line‑rate, transparent.
Allow / Block / Inspect at every hop. Add semantic guardrails — Prompt Shield, Purview DLP, MCP integrity — to the same wire.
Same identity model, same policy surface, same telemetry — across Serverless, AKS/ACA, IaaS, and PaaS.
“Identity tells you who. Security tells you how safe. Policy tells you what's allowed. Until now they lived in three different planes. AgentFabric brings them together — on the network.”
Wherever agents run on Azure, AgentFabric is the same security fabric underneath.
Light up identity‑based segmentation and prompt‑injection blocking for AI Foundry workloads — the lighthouse scenario.
Phase 0 — first to GAOrchestrator/specialist patterns where agents delegate over A2A — every hand‑off authenticated, every message inspectable.
Copilot Studio · pro‑codeBind every MCP server to an identity. Allow only the right tools to the right agents. Stop poisoning and tool drift.
Azure Functions · customStorage, Cosmos, Key Vault, Search, ticketing, CRM — secure egress with identity, intent, and data‑class context.
Cross‑boundaryInline detection of prompt injection, jailbreaks, data exfil, and tool mutation — without slowing down the agent.
Phase 2 differentiationEvery flow is identity‑tagged and protocol‑aware. Streamed to Sentinel for hunting, detection, and audit.
Sentinel · DefenderA lightweight component near the workload, a regional control plane, and an elastic data plane — all working as one agent‑aware network where identity, security, and policy converge on every hop.
Sits transparently next to the workload. Embeds the SPIRE client, terminates mTLS, applies allow/block/inspect policy — with no agent code changes.
Regional control plane: Resource Manager, SPIRE Server federated to Entra, Policy Manager, and Dataplane Manager.
Elastic services for deep packet inspection, traffic shaping, and semantic protections — Prompt Shield, Purview‑aware DLP, MCP/tool integrity.
A small, senior team across leadership, product, and engineering — shipping AgentFabric for every Azure customer.
Where identity, security & policy converge — on the wire.