📊 Key Data
  • $300 billion investment firm successfully deployed AI assistants after implementing Aembit's security platform.
  • Gartner predicts over half of enterprises will adopt dedicated AI security platforms by 2028.
  • Aembit's solution eliminates persistent credentials by issuing ephemeral, task-specific tokens.
🎯 Expert Consensus

Experts would likely conclude that Aembit's integration for Microsoft Copilot Studio addresses critical security gaps in AI agent deployments, enabling safer and more controlled enterprise adoption of AI technologies.

about 1 month ago
Taming the AI Workforce: Aembit Plugs a Critical Security Hole for Copilot

Taming the AI Workforce: Aembit Plugs a Critical Security Hole for Copilot

LAS VEGAS, NV – June 17, 2026 – The enterprise AI revolution is moving at a breakneck pace, but its security scaffolding is struggling to keep up. At the Identiverse 2026 conference this week, identity security firm Aembit unveiled a solution aimed directly at one of the most significant and overlooked risks in modern IT: the autonomous AI agent. The company announced a new integration for Microsoft Copilot Studio, a platform that has supercharged the ability of businesses to create their own AI assistants.

The move addresses a growing anxiety in cybersecurity circles. As business units rapidly deploy custom AI agents to interact with sensitive data, query internal systems, and execute commands, they are often doing so with static credentials and a startling lack of oversight. Aembit’s integration promises to give security teams the reins, providing granular control over what these AI agents can access, ensuring their actions are auditable, and fundamentally rethinking how we manage the identity of this emerging non-human workforce.

The 'Shadow AI' Problem: Unpacking the Enterprise Agent Risk

Microsoft Copilot Studio has been a game-changer for enterprise innovation, democratizing the creation of custom AI agents. Business teams can now, with minimal technical expertise, build and deploy agents that connect to internal databases, external APIs, and critical enterprise systems through what are known as Model Context Protocol (MCP) servers. An agent can be built to triage support tickets, another to analyze financial data, and a third to modify cloud configurations.

While this accelerates productivity, it has inadvertently created a vast and largely unmonitored security frontier. The core issue is that these agents are often granted access using static, long-lived credentials—like API keys or service principal secrets—that are frequently over-privileged to ensure the agent simply "works." This creates a landscape ripe for what some are calling "Shadow AI," where agents operate outside of formal security governance, their actions lost in a sea of generic log files.

The risks are not theoretical. A significant vulnerability known as the "confused deputy problem" arises when an agent acts on behalf of a user but uses the credentials of its creator. For example, an agent built by a system administrator with broad permissions could inadvertently grant any user who interacts with it access to sensitive systems they are not authorized to see. Furthermore, traditional Identity and Access Management (IAM) systems, designed to manage human employees, are ill-equipped to handle the explosion of these non-human identities, making it nearly impossible to enforce principles of least privilege or attribute actions during a security incident.

Forging a Digital Identity: How Aembit Secures the Agent

Aembit's solution injects a modern security model directly into this chaotic environment by acting as a sophisticated identity broker between the Copilot Studio agents and the resources they access. Instead of relying on flawed, static secrets, the platform establishes a verifiable identity for every agent and every request.

The technical linchpin of this approach is what Aembit calls a "blended identity." When an AI agent is instructed by a human user, the platform dynamically creates a composite identity that combines the agent's own cryptographically verified workload identity with the user's identity, pulled from the company’s existing identity provider like Okta or Azure AD. This allows for incredibly granular policy enforcement. Security teams can now create rules that distinguish between an agent acting autonomously and an agent acting on behalf of a specific user, ensuring that the combined entity never has more access than the lesser of the two.

This blended identity is then used to issue "ephemeral credentials"—short-lived, just-in-time tokens scoped only to the specific task at hand. Once the task is complete, the credential expires, eliminating the risk of standing access that plagues systems using persistent API keys. Every access decision, from identity verification to credential issuance, is meticulously logged with rich context, providing a complete, tamper-proof audit trail for compliance and incident response.

"Enterprises want to move fast with agentic AI, and Copilot Studio makes that easy on the deployment side," said David Goldschlag, co-founder and CEO of Aembit, in the announcement. "What's been missing is a security model that keeps pace – one where agents carry verified identities, hold no persistent credentials, and operate under access policies that security teams can actually manage centrally. That's what this integration provides."

From Blocker to Enabler: Security's Role in the AI Revolution

This shift towards robust agent identity management reframes security from a potential blocker of innovation to a critical enabler. Many organizations, wary of the risks, have been forced to either slow their AI rollouts or prohibit access to sensitive systems altogether. Aembit’s case studies suggest a different path is possible. For instance, a $300 billion investment firm, initially blocking the use of the AI model Claude due to security concerns, was able to deploy AI assistants across its entire analyst and executive workforce after implementing Aembit’s platform to secure access to financial data, calendars, and other sensitive information.

This underscores a broader industry trend. Gartner predicts that by 2028, over half of enterprises will adopt dedicated AI security platforms. The rapid growth of non-human identities (NHIs) has become a primary attack surface, and solutions that can inventory, manage, and secure them are moving from niche to necessity.

For developers and IT teams, the integration is designed for minimal friction. "Organizations deploying Copilot Studio have been asking us how to bring their agents under the same access model as the rest of their infrastructure," noted Kevin Sapp, Aembit’s co-founder and CTO. "This integration makes that possible without requiring changes to the agent build or to the enterprise systems the agents connect to." By abstracting away the complexity of authentication and authorization, it allows development teams to focus on building valuable AI capabilities.

A Growing Ecosystem: Strengthening the Foundation for Enterprise AI

Aembit’s announcement is more than just a new product feature; it’s a sign of a maturing enterprise AI ecosystem. Major platforms like Microsoft’s are powerful, but their true enterprise-readiness is often solidified by a robust network of third-party partners who provide specialized capabilities, particularly in stringent areas like security and compliance. While other major cybersecurity players like Palo Alto Networks are also targeting the AI security space, Aembit's laser focus on the identity and access management piece for workloads and agents carves out a critical, specialized role.

By providing a solution that hardens the security posture of Copilot Studio deployments, Aembit not only makes the platform more attractive to large organizations with strict security mandates but also helps build a more resilient foundation for the next wave of AI-driven transformation. To help organizations navigate this new terrain, the company also released an interactive Agentic AI Deployment Checklist, a practical tool designed to help security teams identify and prioritize gaps in their agent rollouts before they become critical vulnerabilities. This focus on both technology and best-practice education highlights the dual approach needed to responsibly harness the power of agentic AI.

Topics & Related

Theme:
Cybersecurity & Privacy
Agentic AI
Metric:
Financial Performance
Event:
Industry Conference
Product Launch
Sector:
AI & Machine Learning
Cybersecurity
Wealth Management
Product:
Claude
UAID: 36552