Chapter 3 of 6 · Before you start

Red teaming, prompt injection, and Defender

Runtime assurance 4 hours in a non-production POC

Chapter 3 of 6

Confirm these prerequisites:

  • A governed nonproduction agent is ready for authorized testing: the platform inventory identifies immutable baseline and remediated versions, the gateway and tool owners confirm the read-only path and blocked prohibited write, and the quality owner retrieves a passing release-gate result. (The platform, private-networking, model-governance, agent, access-boundary, gateway, inventory, MCP security, and evaluation controls establish these prerequisites.)
  • The approved change record names the exact project, agent, immutable versions, attack scope, synthetic-data boundary, run window, stop contact, and authorization reference.
  • The security owner confirms cloud red-teaming support for the project region on the run date.
  • The project managed identity and operator have Foundry User on the exact Foundry project.
  • The project has the approved judge model and red-teaming budget.
  • Defender for Cloud AI services protection and the approved SOC route are operating.
  • The stable endpoint stays on the previously approved version. Prohibited writes remain absent or independently denied.

Implementation files#

TypeFileConsumer
Runtimeartifacts/red-team/attack-plan.jsonThe red-team runner, comparison process, and security owner
Runtimeartifacts/defender/ai-alert-hunt.kqlThe SOC analyst
Recordartifacts/operations/soc-triage-playbook.mdThe SOC analyst and incident commander

Session 10

Red teaming, prompt injection, and Defender slide deck