WorkOS
82 Case Studies
A WorkOS Case Study
The customer Microsoft faced the significant challenge of securing its AI agent, Microsoft 365 Copilot, against prompt injection attacks. This vulnerability, as demonstrated by the EchoLeak exploit, allowed attackers to exfiltrate confidential data by embedding hidden instructions in documents and emails. Microsoft needed a robust solution to contain such threats and partnered with the vendor WorkOS for its enterprise security infrastructure.
WorkOS provided a defense-in-depth solution built on its identity and authorization products. By implementing scoped credentials, invocation policies, and supply chain verification with WorkOS, Microsoft was able to contain the blast radius of any successful prompt injection. This layered approach ensured that even if an agent's intent was hijacked, its permissions and policy controls limited the damage, preventing a system-wide compromise and securing the agentic application.