Case Study: Microsoft strengthens AI agent security and contains prompt injection with WorkOS

A WorkOS Case Study

Preview of the Microsoft Case Study

Microsoft secures Copilot against 85%+ prompt injection attacks with WorkOS

The customer Microsoft faced the significant challenge of securing its AI agent, Microsoft 365 Copilot, against prompt injection attacks. This vulnerability, as demonstrated by the EchoLeak exploit, allowed attackers to exfiltrate confidential data by embedding hidden instructions in documents and emails. Microsoft needed a robust solution to contain such threats and partnered with the vendor WorkOS for its enterprise security infrastructure.

WorkOS provided a defense-in-depth solution built on its identity and authorization products. By implementing scoped credentials, invocation policies, and supply chain verification with WorkOS, Microsoft was able to contain the blast radius of any successful prompt injection. This layered approach ensured that even if an agent's intent was hijacked, its permissions and policy controls limited the damage, preventing a system-wide compromise and securing the agentic application.


View this case study…

WorkOS

82 Case Studies