Microsoft's model, your hardware — the zero-trust panel

Microsoft's model · Your hardware

The zero-trust playbook Microsoft uses for AI — running privately on your own machine.

Microsoft published how enterprise AI agents should be secured. Every layer of it can run on your own computer with open tools — nothing in their cloud, and no per-agent fees.

Security layer
Microsoft (in Azure)
Your setup Private · Free · Local
Agent identity
MicrosoftEntra Agent ID — a cloud identity per agent
YouZiti identity — each agent gets its own cryptographic identity (mTLS)
Least privilege
MicrosoftConditional Access policies
YouZiti service policies — an agent reaches only the tools it's allowed
Isolation
MicrosoftPrivate endpoints in a cloud VNet
YouZiti "dark" services — no open ports, invisible on your network
Guardrails
MicrosoftFoundry Guardrails at input · tool · output
YouOpen guardrail tools at the same checkpoints
Continuous verification
MicrosoftRe-evaluate every request
YouZiti re-checks every connection — no standing trust
Audit trail
MicrosoftAzure Monitor / Purview
YouA plain-English log kept on your machine

Ziti covers identity, least-privilege, isolation and continuous verification. The guardrail layer is a separate open tool paired in — so the honest description is "Ziti + open guardrails," not Ziti alone.

Worth knowing

Microsoft open-sourced these controls themselves (their Agent Governance Toolkit). So this isn't going against the grain — it's the open, private version of exactly what Microsoft says good looks like.

Mapped from Microsoft's public "Zero Trust for AI" guidance, Entra Agent ID, and Foundry Guardrails documentation.