Back to insights
September 25, 2026

The AI Platform You Need May Already Be in Your Tenant

AI platform procurement can obscure the real work: turning existing identity, security, and compliance controls into a safe operating capability for redesigned business decisions.

Many enterprises are treating AI adoption as a platform procurement decision when the more urgent problem is operational control. Our view is that an existing Microsoft environment can provide a credible starting point, but only if the organization turns its security, identity, and compliance tools into an operating capability. The decision should change from “Which platform should we buy?” to “Which business decisions can we safely redesign with what we already govern?”

The pattern we keep seeing is deceptively simple: the technology estate is present, but the ownership model is not. Entra can establish who or what is requesting access. Defender can monitor and respond to threats. Purview can apply data protection and compliance rules. That gives an enterprise important control points without introducing another identity store, security boundary, or policy language.

It does not, however, create a useful AI capability by itself. The difficult part is deciding which agent is allowed to act, on whose authority, with what data, and under whose accountability. Microsoft’s own guidance treats agent governance as a combination of identity, lifecycle management, data governance, security, development standards, and observability, rather than as a single product feature.

Consider a claims team building an agent to summarize incoming cases and prepare recommendations for adjusters. The demonstration is easy to make compelling: the agent reads documents and produces a concise assessment. The operating question is harder. Can it access medical information? Can it write back to the claims system? Can an adjuster distinguish its recommendation from an approved decision? What happens when the agent changes, is abandoned, or begins producing suspicious activity?

The AI Platform You Need May Already Be in Your Tenant

If the team builds inside the organization’s existing control plane, those questions become part of the workflow rather than a separate security project. The agent can receive a distinct identity, limited permissions, and an auditable record of its actions. Microsoft describes this separation as a way to distinguish agent activity from human users and conventional application integrations, while supporting least-privilege access and lifecycle management. Purview policies can govern sensitive data, while Defender can provide monitoring and response across agent activity. The immediate benefit is not that the agent becomes autonomous. It is that review work can move faster without making accountability invisible.

The strongest objection is valid: an installed product estate is not an integrated platform. Policies may be inconsistent, licensing may be incomplete, data may sit outside Microsoft systems, and teams may lack the skills to connect controls to real workflows. Treating “we already own it” as “we are ready” would simply move procurement risk into implementation risk.

That changes the argument, but does not defeat it. Buy capabilities where the estate is genuinely weak. Build the control and decision layer where the enterprise already has authoritative ownership. The commercial advantage is less vendor count and more reusable governance: each new agent does not require a new login model, rulebook, and security review from scratch.

AI adoption therefore becomes an organizational design choice. The winners will not be the companies with the most impressive demonstrations. They will be the ones that make useful machine decisions fit naturally inside the boundaries their people already trust.

Originally posted on LinkedIn.