Research Hub > Frontier Firms Need These 3 Security Capabilities

September 02, 2026

Article
3 min

Frontier Firms Need These 3 Security Capabilities

As organizations adopt AI agents, they must take steps to control agents’ identities, govern the data they access and monitor their behavior.

CDW Expert CDW Expert
People reviewing code

Microsoft’s vision of a Frontier Firm assumes that organizations will increasingly operate through human-agent teams. The vendor coined the term in an April 2025 report, noting that Frontier Firms would be “built around intelligence on tap” and making the case that human workers will gradually slip into the role of “agent boss,” managing and delegating to agents to amplify their own impact.

But before organizations can take serious steps toward this agent-forward future, they must first lay the necessary security foundation.

Agents that can autonomously access files and take actions on users’ behalf create fundamentally different risk landscape from a traditional endpoint focused environment.

Fortunately, Microsoft’s own security tools offer capabilities that organizations can use to extend familiar identity, governance and threat-protection controls across their growing agentic environments.

Here are three security capabilities that those tools provide.

1. Control Agentic Identity

Organizations have spent decades building identity and access management policies for human workers. Now, they must extend IAM practices to cover AI agents as well. With Microsoft Entra Agent ID, organizations can give agents their own identities, making it easier to authenticate agents and govern their access to enterprise resources. Agents can also be given permission to operate autonomously or on behalf of a user, and organizations can attribute activity to specific AI agents.

2. Govern Access to Data

Already, AI agents are surfacing data governance problems that many organizations didn’t know they had. For example, an employee might have been given improper permissions to access HR data for years, but no one uncovered the problem because the employee never tried to access the system. AI agents, by contrast, are likely to reach out to every system they’re able to access in search of information.

With Microsoft Purview, organizations can extend data security and compliance controls to agents managed through the Microsoft Agent 365 control plane. This allows organizations to include agents in policies governing sensitivity labels, data loss prevention and data lifecycle management.

3. Monitor Agent Behavior

Agents will always introduce new risks to an organization, even if they are given an appropriate identity and carefully defined data permissions. For example, they may be misconfigured, manipulated through prompt injection or otherwise compromised in ways that turn their legitimate access into new attack paths. Microsoft Defender can detect suspicious agent activity and block malicious behavior in real time, while giving security teams the observability data they need for investigation and threat hunting.

This is an exciting time, but it can also be scary for leaders who want to keep pace with agentic AI and are aware of the risks. Organizations can’t assume that an environment designed around human workers will translate to effective security and governance for AI agents. CDW’s security assessments and envisioning workshops can evaluate existing controls and identify gaps, helping organizations to lay the foundation they need to safely move forward into the next frontier.

microsoft Logo

Your business works best when everything works together. Microsoft 365 and CDW Services bring collaboration, communication and security together.

Learn how to build a seamless ecosystem with help from Microsoft and CDW.