# Microsoft frames its Ignite security week around AI agents with real access

By MarketScale Newsroom · Published 2026-10-01 · Software & Technology on MarketScale
Canonical: https://www.marketscale.com/industries/software-and-technology/microsoft-frames-its-ignite-security-week-around-ai-agents-with-real-access

> A Security Pre-Day and four security themes: at Ignite, Microsoft treats every decision to adopt an AI agent as a trust decision.

## Key points

- Deciding what each agent is allowed to see is where the work sits when governance is missing; CDW research cited by BizTech found 51% of respondents have an established data governance framework.
- The Nov. 17 keynote is the signal to watch: data-level Agent 365 controls would suggest Microsoft is tackling the governance gap; mostly new SOC agents would leave it with customers.

The company's event guide, posted September 30 on the Microsoft Security blog, invites attendees to start a day early. A Security Pre-Day runs Monday, November 16, from 1:00 to 5:00 PM PT, before the main event begins. That's four hours of presentations, roundtables and ask-me-anything sessions with Microsoft Security leaders and outside industry voices. The main event follows from November 17 to 20 in San Francisco, with an online option.

For a conference brochure, the framing is unusually blunt. Microsoft argues that AI agents now act with real access to identities, data and cloud resources, so every decision to adopt one is a trust decision. That idea shapes the whole week, with four security themes running across all four days.

For operators who track Microsoft's direction, this year's security-led program could suggest that the company now treats agent governance as a security question. A CISO or identity architect deciding who to send to San Francisco needs to know how far agent governance has moved in twelve months, and where the open work still sits.

## What Agent 365 set up a year ago

Joy Chik, Microsoft's president of identity and network access, told attendees that Agent 365 takes the infrastructure companies already trust for managing and securing people and extends it to agents. The first layer is a registry meant to show every agent in an organization. That includes agents with identities in Entra Agent ID, agents the organization registered itself, and shadow agents.

Access control comes next. Chik said Agent 365 enforces least privilege and applies conditional access policies that take context and risk into account. A visualization layer maps how agents, people and data connect, so teams can watch behavior and performance in real time.

The order is familiar: inventory first, then permissions, then monitoring. Identity teams already work through those steps for human accounts. For agents, that puts more weight on the context-aware conditional access policies Chik described.

## The data question behind the agent count

Microsoft keeps coming back to governance, and the scale of agent adoption it expects could explain why.

The more useful number is closer to home. CDW research cited by BizTech found that only 51% of respondents said their organization has an established data governance framework. If only 51% of organizations have a data governance framework, then an agent registry is the easy part; deciding what each agent is allowed to see is where the work sits. BizTech also reported that several Ignite 2025 sessions treated data governance as a first step before deploying agentic AI.

Block Field

For organizations that already have data governance in place, the registry and the conditional access policies could be the missing piece, and the Agent 365 material at Ignite may be most useful to them. Teams without a governance framework could get more from the week by bringing questions about data-level policy than about agent discovery.

## Planning four days at Moscone

A security team going to Ignite needs a plan. Microsoft says technical breakouts run from level 200 to level 400, alongside instructor-led labs and onsite certifications.

## What the November 17 keynote will settle

The first real signal comes on Tuesday morning, when the opening keynote sets the direction for the week.

Announcements that push Agent 365's registry and least-privilege controls down to the data level would suggest Microsoft is going after the governance gap the CDW figure points to. If the news mostly brings new agents for the security operations center, that gap stays with customers for another cycle. Either way, the people who'll judge the answer are the ones who walk in on November 16 knowing how many agents they already run.

## Sources

- [​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026](https://www.microsoft.com/en-us/security/blog/2026/09/30/secure-whats-next-your-guide-to-microsoft-security-at-microsoft-ignite-2026/)
- [Your complete guide to Microsoft experiences at RSAC™ 2026 ...](https://www.microsoft.com/en-us/security/blog/2026/02/12/your-complete-guide-to-microsoft-experiences-at-rsac-2026-conference/)
- [Microsoft Ignite 2025: How Microsoft Purview Drives Data Security in the ...](https://biztechmagazine.com/article/2025/11/microsoft-ignite-2025-how-microsoft-purview-drives-data-security-ai-era) (BizTech Magazine)
- [Microsoft Ignite 2026: Attendee travel guide - Navan Edge](https://navan.com/blog/edge/microsoft-ignite-guide)
- [Microsoft Ignite San Francisco 2026 - Conference - Reworked](https://www.reworked.co/events/conference/microsoft-ignite-san-francisco-2026/)

Tags: Microsoft, Microsoft Ignite 2026, Microsoft Security, Agent 365, Microsoft Entra Agent ID, AI agents, agentic AI, identity and access management, data governance, CISO, security operations, IT conferences, enterprise IT

---
Source: MarketScale, https://www.marketscale.com/industries/software-and-technology/microsoft-frames-its-ignite-security-week-around-ai-agents-with-real-access. Published for AI indexing and citation; cite the canonical URL. Site guide for agents: https://www.marketscale.com/llms.txt
