TL;DR: Microsoft’s security post argues that the next generation of defence will depend less on alert generation and more on validated corrective action, with blue agents investigating risk and green agents fixing it across a six-layer stack. The implication is clear: security programmes that stop at detection will keep producing backlog, not resilience.
At a glance
What this is: This is Microsoft’s case for an agentic security architecture that separates finding, deciding, and fixing into distinct security functions.
Why it matters: It matters because identity and access teams increasingly need controls that connect detection, context, and remediation across human, NHI, and agentic systems instead of treating them as separate workflows.
👉 Read Senserva's analysis of Microsoft's agentic security architecture
Context
Security programmes break down when findings, context, and remediation live in different systems. In identity and access work, that creates a familiar failure mode: teams can see risk, but cannot act on it quickly enough, with enough context, or in a way that is attributable and reversible. This is now more visible as AI agents enter operational security workflows and begin to participate in decisions that were previously human paced.
Microsoft’s framing is useful because it treats corrective action as part of the security system rather than a downstream ticket queue. That matters for IAM, NHI governance, and agentic AI because the same control plane now has to understand what is risky, what it means, and what can be safely changed without losing accountability.
Key questions
Q: How should security teams separate detection from remediation in AI-assisted security operations?
A: Separate them by design and governance, not just by team name. Detection should identify and rank risk, while remediation should run through a controlled change path with validation, attribution, and rollback. If the same workflow both diagnoses and changes production state, teams lose the ability to prove what happened and why.
Q: Why does context matter so much in agentic security systems?
A: Because agents cannot make reliable decisions from partial telemetry. If configuration, patch, and log data are fragmented, the system sees disconnected symptoms rather than a coherent security state. That leads to misprioritised actions, weak change decisions, and false confidence in automation.
Q: What do security teams get wrong about AI-powered remediation for NHIs?
A: Teams often assume that faster remediation is automatically safer. In reality, the speed gain can hide ownership errors, over-broad tool scopes, and unreviewed script generation. If the same interface can inspect, recommend, and execute, the control model must be stricter than a normal dashboard workflow.
Q: Who is accountable when an AI system changes infrastructure configuration?
A: Accountability should sit with the programme owner responsible for the AI system and the change governance process that approved its operating scope. If the system can alter configuration, then the access model, logging model, and change approval model all need explicit ownership, otherwise responsibility becomes distributed until no one can defend the outcome.
Technical breakdown
Why the blue-green split matters for security operations
The post’s most practical architectural move is the separation of red, blue, and green functions. Red identifies attack paths, blue interprets context and assesses risk, and green executes corrective action. That matters because most security stacks still collapse analysis and remediation into disconnected products or teams, which creates latency and ambiguity. In identity programmes, the gap is especially visible when a finding about permissions, logs, or configuration has no direct path to an enforceable change. Agentic systems can reduce that gap only if every action remains validated, attributable, and reversible.
Practical implication: separate detection from remediation in your operating model, then define which changes can be executed only after explicit validation.
The six-layer stack for context-driven AI security
Microsoft describes a stack of signals and sensors, context, models, harness, agents, and actuators. The key point is that agents are only as trustworthy as the context they receive. A model operating on disconnected configuration, patch, and log data sees three partial pictures, not one security state. For IAM and NHI governance, that means risk scoring based on one source of truth is not enough. Decisions about access, exposure, and remediation require joined-up telemetry, otherwise the system can reason correctly about the wrong world.
Practical implication: unify identity, configuration, and telemetry data before you let AI prioritise or change anything.
Why agentic remediation changes the identity control model
Green-team behaviour changes the identity problem because the system is no longer merely recommending action. It is participating in change. That raises the bar for authorisation, traceability, and rollback across human-operated and machine-operated workflows alike. In IAM terms, this is not just automation. It is delegated security authority that must be bounded by policy, logs, and approval rules strong enough to prove what changed and why. Once an agent can alter the tenant, the control question becomes whether the action was valid in context and recoverable if it was wrong.
Practical implication: treat AI-assisted remediation as a privileged workflow and apply explicit approval, audit, and rollback controls to it.
NHI Mgmt Group analysis
Green-team security is the overdue correction to alert-first security operations. For decades, the industry optimised for discovery and investigation, then pushed remediation into separate queues that rarely had enough context to act quickly. Microsoft’s framing is useful because it recognises that finding risk is not the same as closing it. Practitioners should treat remediation as a first-class security function, not a downstream operational courtesy.
Context collapse is the real failure mode in AI-assisted security. If configuration, patch state, and logs are not joined, no agent can reason reliably about what matters. This is the same structural problem that weakens IAM programmes when identity data is fragmented across tools and teams. The practitioner lesson is that AI does not compensate for missing context; it amplifies whatever the control plane already knows.
Validated, attributable, reversible action is the new baseline for agentic remediation. Microsoft’s architecture implies that the next control challenge is not whether an agent can propose a fix, but whether the fix can be trusted in production. That shifts emphasis toward change control, rollback, and evidence generation across identity operations. Teams should assume that every autonomous or semi-autonomous action now needs a governance wrapper.
Identity governance will increasingly be measured by closure, not just detection. Security programmes that can generate findings but cannot reliably reduce exposure will look mature on paper and weak in practice. That is true for human access, NHI credentials, and AI-driven security operations. Practitioners should expect board-level scrutiny to move from “how many issues did we find?” to “how many did we actually close safely?”
What this signals
Security teams should expect the control conversation to shift from alert reduction to action governance. As AI begins to participate in prioritisation and remediation, the programme question becomes whether the environment can prove that changes were valid, attributable, and reversible before they touch production.
A useful concept here is remediation authority drift: the point at which a tool that was designed to recommend changes starts to behave like a change executor without the corresponding governance model. Teams should watch for this in identity operations first, because IAM and NHI controls carry direct blast-radius implications.
For practitioners
- Define a green-team approval model Map which remediation actions can be executed only after human validation, which can be pre-authorised, and which must always remain manual. Start with identity-impacting changes such as role assignment, conditional access, token handling, and configuration changes that affect authentication paths.
- Unify the context sources your security decisions depend on Join identity configuration, patch state, vulnerability data, and logs before feeding prioritisation or remediation logic. If these signals remain in separate tools, any AI layer above them will inherit partial truth and produce unreliable actions.
- Treat remediation as a privileged workflow Apply auditability, rollback, and change control to every automated or AI-assisted fix. Make sure each action can be attributed to a policy, a reason, and a final state that can be independently verified after execution.
- Measure closure, not just discovery Track how many findings are actually remediated, how long corrections remain open, and how often fixes are reversed or re-opened. Use those metrics to identify where security operations are still acting as a triage function rather than a control function.
Key takeaways
- The central issue is not whether security tools can find more problems, but whether they can close them safely inside the control plane.
- AI-assisted remediation changes the identity model because change authority, auditability, and rollback now matter as much as detection quality.
- Practitioners should prioritise context integration and approval boundaries before allowing AI to influence production security changes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | The article is about agentic security architecture and agent-like remediation behaviour. | |
| NIST AI RMF | GOVERN | Governance and accountability are central to AI-assisted security actions. |
| NIST CSF 2.0 | PR.IP-1 | The piece emphasises operational processes for corrective action and evidence. |
| NIST SP 800-53 Rev 5 | CM-3 | Controlled change management fits AI-assisted remediation workflows. |
| NIST Zero Trust (SP 800-207) | The architecture depends on continuous verification before actions are taken. |
Assess agent actions, tool boundaries, and approval paths before allowing autonomous remediation.
Key terms
- Green Team: A green team is the security function responsible for corrective action, not just detection or analysis. In this context, it means the controls, people, and automation that change the environment safely, with validation, attribution, and rollback so remediation becomes part of the security system.
- Agentic security: The practice of governing software actors that can choose actions, tools, and timing in production workflows. It extends identity, authorization, logging, and lifecycle control to agents so their behaviour is tied to a verifiable principal and a revocable permission set.
- Contextual layer: An intermediate governance layer that adds visibility and control across systems not fully covered by the primary IGA stack. It matters when organisations need immediate insight into drift, exceptions, and coverage gaps while they work toward a more mature governance architecture.
What's in the full article
Senserva's full post covers the operational detail this post intentionally leaves for the source:
- Microsoft’s direct quotations on the red, blue, and green team definitions
- The six-layer stack description linking signals, context, models, harness, agents, and actuators
- Senserva’s own implementation perspective on how blue and green functions share one operational model
- The source article’s mapping of remediation output to Microsoft security benchmarks, NIST, CIS, SOC 2, and HIPAA
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on July 28, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org