メインコンテンツへスキップ

Review and remediate consolidated AI risk with Security Dashboard for AI

Implementation Effort: Low – The dashboard is available at ai.security.microsoft.com with no additional infrastructure deployment; the depth of risk signal depends on which underlying Microsoft Security products (Entra, Defender, Purview) are deployed in the tenant.
User Impact: Low – Security leadership and admin activity only; end users are not affected.

Overview

Organizations deploying AI workloads accumulate risk across identity, data, and cloud infrastructure that no single product dashboard can fully represent. Security leaders need a consolidated view that surfaces where the organization is exposed, which gaps require immediate action, and who is responsible for fixing them — without requiring admin access across every underlying security portal. Without this consolidated view, AI risk assessment depends on manual aggregation across Microsoft Entra, Defender, and Purview, which delays decision-making and creates blind spots between products.

The Overview page of the Security Dashboard for AI provides prioritized security recommendations sourced from Microsoft Entra, Microsoft Defender, and Microsoft Purview. Each recommendation is grouped by product category, shows its current implementation status (such as Not started or Completed), and links to the relevant portal for remediation. A recommendation can be assigned to a specific user or group with a due date and a Teams or email notification — creating a delegated remediation workflow where accountability is explicit without requiring the assignee to hold admin permissions across the underlying portals. Recommendations that are not relevant to the organization can be skipped to keep the dashboard focused on actionable items; skipped recommendations can be restored at any time via Show skipped recommendations. The minimum role required to view all dashboard data and assign recommendations is Security Reader, making this accessible to CISOs and security leaders without tenant-level administrative access.

The AI Risk page provides a consolidated view of identity and access risks, data security risks, and cloud security risks across the organization’s AI workloads. Risk summary cards and trend charts surface immediate priorities and emerging threats at a glance. Each risk category links directly to the relevant Microsoft Security product — View in Microsoft Entra, View in Microsoft Purview, or View in Microsoft Defender — for detailed investigation and remediation, so there is no need to context-switch manually across portals. Microsoft Security Copilot is integrated throughout, providing suggested prompts that help security teams explore complex risk scenarios, generate intelligent risk summaries, and identify remediation priorities without leaving the dashboard.

This supports Assume breach by providing continuous, cross-product risk assessment that surfaces configuration gaps and emerging threats before they are exploited, and by enabling proactive, delegated remediation with clear ownership rather than reactive incident response after the fact. It supports Verify explicitly by consolidating identity, data, and infrastructure risk signals into a single authoritative view that allows security leaders to confirm — at any time — whether the organization’s AI workloads meet its security requirements. Without this step, AI risk decisions are made on incomplete, siloed information and there is no structured mechanism for assigning and tracking remediation across teams.

Reference