AI is changing the cyber security conversation. The opportunity is significant, but so is the pressure to move quickly. Business leaders want productivity gains, employees are already experimenting with new tools, and technology teams are being asked to enable adoption without introducing unnecessary risk.
For many organisations, this discussion naturally involves Microsoft. Microsoft 365 already supports everyday communication, collaboration and information sharing, while Azure may host important applications and data. As Copilot and other AI capabilities become part of this environment, the same Microsoft ecosystem also provides tools for managing identity, protecting endpoints and data, and coordinating security operations.
This does not mean that adding more products is automatically the answer. Organisations need to understand which capabilities they already have, where genuine gaps remain and how their Microsoft environment fits alongside other security technologies and operational processes.
The answer is not to treat AI as a separate security project. It is to strengthen the foundations that determine what AI systems, applications and people can see and do.
Three areas deserve particular attention: identity, data and integration.
1. Identity has become the control plane
The traditional network boundary has become less useful as a complete picture of organisational access. People work across offices, homes and customer sites. They use cloud services and multiple devices. Applications interact with other applications, and automated agents are beginning to perform tasks that previously required a person.
In that environment, identity is often the point at which access decisions come together.
That means identity security is about more than requiring multi-factor authentication. Leaders should be asking:
- Do we know which human and non-human identities exist?
- Are privileges proportionate to what each identity needs to do?
- Can we identify unusual or risky sign-in behaviour?
- Are joiner, mover and leaver processes working consistently?
- Are identity signals connected to endpoint, cloud and security operations decisions?
Microsoft Entra, Defender and related controls can support this work, but technology alone does not resolve unclear ownership or excessive access. The first step is understanding the identity estate and deciding how risk should change an access decision.
2. AI can amplify existing data-access problems
Generative AI does not create every data-security weakness, but it can make existing weaknesses more visible and more consequential.
If information is poorly classified, broadly shared or retained without clear ownership, AI can help an authorised user find and combine it more quickly. That may be useful, but it can also expose oversharing that has accumulated quietly across Microsoft 365.
This is why safe AI adoption needs to start with questions about the data itself:
- What sensitive information does the organisation hold?
- Where is it stored?
- Who can access it today?
- Which sharing links, groups or permissions are broader than intended?
- Are sensitivity labels and data-loss prevention policies aligned with real business use?
- Can the organisation monitor and investigate risky interaction with AI applications?
Microsoft Purview brings together capabilities including information protection, data loss prevention, Insider Risk Management and Data Security Posture Management. These can help organisations understand sensitive-data exposure, identify oversharing and prioritise action. The important point is not to enable every possible feature at once. It is to start with the business's most important data and its most credible risk scenarios.
3. Integration matters more than product count
Many organisations already own more security capability than they actively use. The challenge is often not the absence of another tool, but fragmented configuration, disconnected signals and unclear operational processes.
An identity alert, an endpoint event and unusual access to sensitive data may each appear manageable in isolation. Seen together, they can tell a very different story.
Microsoft's security ecosystem spans identity, endpoints, email, cloud workloads, data and security operations. Integration across Entra, Defender, Sentinel, Purview and Security Copilot can help teams bring relevant context together. However, value depends on how the environment is designed and operated:
- Which signals matter most?
- Who is responsible for responding?
- Are alerts enriched with enough context to support a decision?
- Can existing processes cope with additional automation?
- Are licences and capabilities being used deliberately, or simply accumulated?
- Can security investment be related to risk reduction and operational outcomes?
Consolidation can reduce complexity, but only where it improves visibility, ownership and response. Replacing several disconnected tools with one poorly configured platform will not produce the intended result.
A connected conversation
Identity, data security and operational integration should not be separate discussions. They shape one another.
AI adoption depends on appropriate access. Appropriate access depends on reliable identity and data governance. Effective response depends on signals from those controls being connected to people who can act.
There is no universal configuration that suits every organisation. The right approach depends on the existing Microsoft environment, the organisation's data, its operating model and the outcomes leadership expects.
That is why peer discussion is valuable. Organisations need space to compare what is working, what is proving difficult and where security investment is producing a meaningful return.
On Wednesday 30 September, Positiv Technology will host an invite-only Cyber Security Executive Roundtable at Microsoft Reading Campus. James Butler will be joined by Joseph Boland-Scott, Security PSS at Microsoft, and Darren Roberts, Microsoft Security Lead UK&I at Infinigate Cloud.
The session will bring together a small group of senior technology and business leaders to discuss identity, endpoint and data security, safe AI adoption, Microsoft's security roadmap and the practical reality of security integration.