Skip to content

According to KuppingerCole Analysts, we’re amongst the leaders in MDR!

ESET named a Market Leader in MDR

We are pleased to announce that our ESET MDR solution was positively evaluated in the latest MDR Leadership Compass by the leading industry analysts KuppingerCole. ESET MDR has received recognition as a MARKET LEADER in the field of Managed Detection & Response.

It makes us proud when ESET solutions are appreciated not only by our customers, but also by leading industry analysts. To gain valuable insights into the MDR market we encourage you to read the full report.

Overall evaluation of ESET PROTECT MDR

What are the strengths of ESET MDR services according to
KuppingerCole Analysts?

  • Fast automated response and containment
  • AI-assisted investigation through ESET AI Advisor
  • Mature threat intelligence and research capability
  • Good customer visibility into incident timelines
  • Built-in SOAR and automated remediation actions
  • Vulnerability and patch management included
  • Ability to discover and monitor shadow IT
  • Multilingual support across many regions
  • Ransomware prevention and rollback technology

ESET Managed Detection and Response

Provides 24/7 cybersecurity protection, combining cutting-edge AI
with human expertise to create a solution that never rests.

Modern Compliance Governance: A Tactical Blueprint for Security & IT Architects

The Engineering Approach to Compliance ManagementA Practical Security and IT Roadmap for Transforming Regulatory Obligations into Continuous Operational Controls

Operational Overview: Enterprise compliance management is no longer an annual check-the-box paperwork exercise. For modern security and engineering teams, it represents the operational framework that translates complex external mandates—from regulators, corporate boards, and enterprise customers—into testable, day-to-day technical configurations and procedural guardrails.

Deconstructing the Compliance Lifecycle

At its core, compliance management is a systematic, repeatable program used to map internal obligations, implement protective controls, automate evidence collection, and programmatically remediate control drift. While a typical point-in-time audit functions as a lagging snapshot of historic posture, a true Compliance Management System (CMS)—as framed by standards like ISO 37301—acts as a continuous, iterative lifecycle designed to constantly evaluate and mature an organization’s defense posture.

Compliance sits at the intersection of corporate governance and active cybersecurity, yet it remains functionally distinct from both:

  • Cybersecurity: Minimizes systemic risk by deploying technical defenses against active threat vectors.
  • Corporate Governance: Defines the organizational hierarchy, authority matrices, and accountability frameworks.
  • Compliance Management: Serves as the verifiable connection point. It generates the auditable data trail that proves to external entities, enterprise clients, and regulators that an organization’s security posture functions as intended.

Why Continuous Compliance Dictates Business Velocity

Modern regulatory environments have linked compliance health directly to operational survival, financial liability, and revenue generation capability:

  • Regulatory Defense: According to the US Department of Justice (DoJ) corporate evaluation guidelines, prosecutors explicitly weigh the proactive design and structural health of a company’s compliance architecture when deciding on corporate resolutions, financial penalties, and ongoing monitoring mandates.
  • Capital Market Mandates: Publicly traded enterprises are bound by strict SEC disclosure rules, requiring material cybersecurity incidents to be detailed on Form 8-K within four business days of materiality determination, complemented by annual risk strategy disclosures on Form 10-K or 20-F.
  • Sales and Vendor Procurement Speed: Enterprise procurement processes demand that B2B vendors present validated control maturity through frameworks like SOC 2 Type II, ISO 27001, PCI DSS, or GDPR. A centralized compliance program allows IT teams to respond to deep security vetting instantly using a single, unified source of truth.
The Real Cost of Shadow Technology: Industry telemetry from IBM indicates that breaches tied to unmanaged “Shadow AI” pipelines add an average of $670,000 in unexpected incident response costs, with 63% of breached organizations lacking an active, formalized AI governance architecture.

Anatomy of a Modern Compliance Architecture

An enterprise compliance engine relies on eleven core structural pillars to maintain systemic visibility across cloud networks:

The Baseline Architecture

  1. Governance Model: Appoints formalized program owners, establishes reporting structures straight to executive leadership, and documents decision-making rights.
  2. Obligation Register: A comprehensive, dynamic index of all statutory laws, external security frameworks, regional privacy mandates, and customer-facing service level agreements (SLAs).
  3. Risk Assessment Engine: A formalized methodology to prioritize software assets, internal directories, and data pools by threat exposure, sensitivity, and business impact.
  4. Unified Control Library: A centralized repository of internal policies that maps to multiple external compliance frameworks simultaneously.
  5. Policies & Written Procedures: Formally documented behavioral rules that translate compliance intent into specific operational realities for engineering teams.
  6. Automated Evidence Pipelines: Systematic capture mechanisms that continuously ingest configuration baselines, database logs, IAM snapshots, and operational tickets.
  7. Role-Based Training: Target-specific educational programs covering regional privacy laws, code of conduct parameters, and secure coding practices.
  8. Third-Party Risk Management (TPRM): Structured lifecycle oversight governing vendor evaluation, security posture checks, data processing agreements (DPAs), and safe offboarding loops.
  9. Exception & Issue Registers: A transparent log tracking control gaps, temporary policy waivers, compensating controls, and executive risk acceptances.
  10. Continuous Monitoring: Real-time validation engines designed to flag control drift, configuration changes, and missing evidence blocks instantly.
  11. Executive Reporting Matrices: Actionable telemetry dashboards optimized for internal executives, external auditors, and client compliance teams.

Navigating the Global Framework Landscape

Security and IT teams must frequently design defenses to satisfy multiple, overlapping domestic and global standards at the same time:

Regulatory CategoryCore Global FrameworksPrimary Technical Mandate
Data Privacy & ProtectionGDPR (Art. 32), CCPA / CPRARequires risk-based technical controls including end-to-end encryption, pseudonymization, continuous resilience testing, and rapid data restoration workflows.
Financial & TransactionalPCI DSS v4.0, FTC Safeguards RuleMandates multi-factor authentication everywhere, secure development lifecycles, structured access logging, immutable audit trails, and formalized board-level security reports.
Critical Infrastructure & SovereigntyNIS2, DORA (EU Financial Sector)Enforces strict systemic ICT risk management frameworks, mandatory supply chain security checking, and highly accelerated incident reporting windows.
Enterprise Security AttestationSOC 2 (Trust Services Criteria), ISO/IEC 27001Requires detailed operational validation of corporate data security, availability, processing integrity, and processing confidentiality.
Artificial Intelligence & Emerging TechEU AI Act, NIST AI RMF, ISO/IEC 42001Demands strict AI model inventories, usage risk classification, data ingestion logging, and continuous monitoring for shadow AI workloads.

The Operational Lifecycle: Step-by-Step Execution

Modern compliance operations function as an ongoing loop, closely mirroring structured risk methodologies like the NIST Risk Management Framework (RMF):

  1. Scope Definition: Establish clear operational boundaries by isolating the business infrastructure, network assets, user directories, vendors, and codebases subject to tracking.
  2. Mandate Identification: Populate the Obligation Register with relevant legal requirements and client contract clauses.
  3. Asset Risk Ranking: Evaluate internal systems against data classification tiering, accessibility levels, and business criticality metrics.
  4. Cross-Framework Control Mapping: Connect specific technical configurations to overlapping requirements in the unified library. For example, routing all system login requests through an Identity Provider (IdP) satisfies access control mandates across SOC 2, ISO 27001, and PCI DSS at the same time.
  5. Ownership Assignment: Pair every single control requirement, evidence source, and open exception ticket with an individual technical owner and an enforceable due date.
  6. Control Implementation: Enforce explicit system settings, configure code pipelines, and establish documented standard operating procedures (SOPs).
  7. Evidence Generation & Testing: Schedule regular access validation reviews, infrastructure scans, backup restoration tests, and configuration snapshots.
  8. Exception Logging: Document unexpected control drops, map out compensating safeguards, track time-bound remediations, and secure official manager sign-offs.
  9. Telemetry Reporting: Provide clear compliance dashboards for management and auditors.
  10. Continuous Reassessment: Update the global control map whenever infrastructure code changes, new microservices launch, external laws evolve, or threat intelligence landscapes shift. Guidance from NIST SP 800-137 supports this final step by providing continuous visibility into asset health and control efficacy.

Root Causes of Compliance Failure

Engineering teams frequently run into several persistent roadblocks that can undermine an otherwise healthy compliance program:

  • The Screenshot & Evidence Trap: IT specialists often lose hundreds of hours manually extracting configurations, building spreadsheet reports, and taking configuration screenshots. This repetitive collection process leads to operational burnout and distracts teams from active threat mitigation.
  • Point-in-Time Blindspots: Mandiant’s historical security telemetry reveals that initial access exploits can transition to downstream attacker lateral movement in as little as 22 seconds, with median attacker dwell times hovering around two weeks. Static annual audits fail to detect these live risks; keeping pace requires continuous validation.
  • SaaS and Identity Sprawl: The explosive growth of cloud accounts, privileged administration keys, automated API webhooks, workload identities, and autonomous AI agents creates complex, unmonitored access vectors that can easily slip past traditional directory audits.

Tactical Best Practices for Security Engineers

To scale compliance without adding friction to development velocities, enterprise security leaders should prioritize these four tactical design principles:

1. Implement a Single-Control, Multi-Framework Mapping Strategy

Never implement separate, isolated processes for individual compliance checklists. Instead, build a single robust control—such as a phishing-resistant Multi-Factor Authentication policy or a standardized code review pipeline—and map that single technical artifact to every overlapping requirement in your regulatory catalog.

2. Decouple and Automate the Evidence Ingestion Architecture

Integrate compliance automation platforms directly into your core systems via native APIs. Connect your compliance workflows to your Identity Providers (IdPs), Cloud Security Posture Management (CSPM) tools, continuous deployment (CI/CD) pipelines, vulnerability scanners, and ticketing engines to capture configuration evidence silently and continuously.

3. Anchor Compliance directly to Root Access & Password Controls

Access control forms the bedrock of almost every compliance standard. Organizations should align their infrastructure rules with modern, risk-aware authentication frameworks like NIST SP 800-63B:

  • Enforce a minimum length of 15 characters for single-factor values, and 8 characters when used alongside multi-factor layers.
  • Discard traditional, arbitrary character composition rules (such as forcing a mix of symbols and case variations) and eliminate arbitrary periodic rotation policies, which often lead to weaker user-generated choices.
  • Enforce continuous screening to block common, weak, or historically compromised credentials, and deploy strict authentication rate-limiting.

To achieve this at scale, enterprise teams leverage dedicated password protection suites like NordPass. NordPass consolidates corporate vaulting, secure cross-team sharing, live data breach scanning, and robust MFA integration into a single platform. By generating deep, audit-ready access logs and automating password health metrics across the workforce, it satisfies strict credential management requirements in ISO 27001, SOC 2, HIPAA, and the FTC Safeguards Rule natively, eliminating the need for manual screenshot collection.

4. Enforce Phishing-Resistant MFA and Secure Workload Identities

Traditional factor mechanisms like SMS notifications and basic push approvals remain highly vulnerable to modern adversary-in-the-middle (AiTM) phishing loops and prompt fatigue attacks. Security teams should transition administrative portals and high-privilege workflows toward phishing-resistant authentication methods, such as FIDO2 passkeys, hardware security keys, or device-bound certificate architectures.

Furthermore, because legacy user-based automation accounts cannot complete interactive MFA challenges without breaking functionality, administrators must aggressively migrate automated scripts and background code routines over to dedicated Entra Workload Identities or Managed Identities.

Looking Ahead: The Shift to Continuous, Real-Time Attestation

The traditional concept of compliance as a static, annual project is quickly coming to an end. Driven by rapid cloud deployment cycles and evolving global mandates, compliance management is transforming into a live, continuous system that runs alongside everyday business activities.

Future-ready IT organizations are moving away from manual evidence gathering and adopting real-time compliance dashboards. By centering their programs around a unified control library, automated API data collection, strict non-human identity management, and clear, individual ownership, security teams can confidently satisfy changing regulatory expectations while building a measurable, auditable, and resilient enterprise defense posture.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About NordPass
NordPass is developed by Nord Security, a company leading the global market of cybersecurity products.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Enterprise Security: Decoupling the Technical Architecture of Microsoft Entra Agent ID

The Anatomy of Entra Agent ID

Deconstructing Microsoft’s Hierarchical Identity Model for Autonomous and Assistive AI Systems

Strategic Briefing: As autonomous AI systems move from simple text generation to executing business logic across enterprise networks, traditional service principals are no longer sufficient. Securing these workloads requires a completely new identity paradigm. Microsoft Entra Agent ID introduces a hierarchical, delegated authentication framework explicitly engineered to handle the scale, fluid permissions, and blast-radius challenges of enterprise AI workers.

The Structural Identity Shift

Unlike legacy machine identities built for predictable scripts, a modern AI agent acts as a dynamic entity capable of calling APIs, utilizing toolkits, and impersonating human users. Instead of treating an agent as a simple static credential tied to an application registration, the Entra Agent ID framework decouples credential maintenance from permission enforcement. This structure defines an agent’s operational blueprint, regulates how it acts on behalf of others, and enforces human-level administrative accountability.

This deep dive examines both the functional building blocks of an AI agent and the specialized identity architecture that governs these non-human systems within the corporate directory.


1. The Functional Building Blocks of an Agent

Before an agent can interact with Microsoft Entra ID, its internal code architecture dictates how it perceives data and executes tasks. This functional loop relies on four foundational components:

  • Reasoning Engine (Model): The underlying large language model (LLM) that processes intent, parses instructions, and makes systemic decisions.
  • Orchestration Layer: The cyclical control loop that manages data intake, prompts the model, and determines when a multi-step objective has been achieved.
  • Contextual Memory: Dynamic storage arrays that supply real-time state and historical interactions, eliminating the need for constant model retraining.
  • Extensible Interfaces (Tools): The connection points—such as web scrapers, local file systems, and external APIs—that allow the agent to read and modify its environment.

2. Deconstructing the Entra Agent ID Hierarchy

Because autonomous workflows introduce unpredictable access patterns, Microsoft uses a multi-tiered identity structure rather than standalone service principal definitions. This model cleanly isolates master configuration settings from individual running instances.

The Blueprint Tier (Templates & Core Security)

Agent Identity Blueprint: Serving as the master operational template (analogous to an App Registration), the blueprint is the sole credential vault for the agent family. It stores certificates, client secrets, or Federated Identity Credentials (FIC). Individual running instances never manage their own passwords; all credentials live exclusively at this root level. The blueprint also defines baseline configuration data and inheritable permissions that flow down to all child instances.

Agent Identity Blueprint Principal: The tenant-specific runtime representation of the blueprint (analogous to an Enterprise Application). Upon deployment, this object automatically receives the AgentIdentity.CreateAsManager role, giving it authorization to provision and manage the lifecycle of localized child agent identities. When a blueprint requests tokens inside a tenant, the audit logs track the object ID of this principal to maintain accountability.

The Instance Tier (Acting Personas)

Agent Identity: A specialized service principal subtype that serves as the unique account individual agents use to authenticate. While the blueprint holds the cryptographic keys, the Agent Identity houses the actual privilege set (Microsoft Graph scopes, Azure RBAC roles, and Entra permissions). It registers as the acting client in sign-in logs, mapping every automated action to a specific instance. Non-Microsoft platforms are capped at spawning 250 agent identities per tenant under app-only models.

Agent User Account (Agent User): An optional, secondary Entra user account paired precisely one-to-one with a specific agent identity. This is provisioned exclusively when an agent must interact with human-centric collaboration tools that strictly require user-object structures—such as Microsoft Teams channels, Exchange mailboxes, or shared calendars. These objects return an idtyp=user token claim but completely bypass human authentication paths (like MFA or passwords), relying instead on identity federation through their parent agent identity.

Critical Security Boundary: Because child agent identities do not maintain individual passwords, compromising an Agent Identity Blueprint’s root credentials instantly compromises every associated child agent identity deployed across the entire enterprise tenant.

3. Token Exchange and Authentication Mechanics

Authentication within this architecture shifts from traditional secret verification to a strict, multi-step token-exchange model driven entirely by industry-standard protocols like OpenID Connect (OIDC) and OAuth 2.0.

When an active agent identity needs to query a resource, the process unfolds through a delegated impersonation flow:

  1. The parent agent identity blueprint uses its root credentials (such as an FIC or a certificate) to authenticate directly with Microsoft Entra ID.
  2. Entra ID verifies the blueprint and issues an intermediate exchange token targeted at a specific child agent identity.
  3. The agent identity uses this exchange token as its client assertion to pull the final access token required to query the destination API.

As a result of this exchange, the access token lists the specific agent identity instance as the primary client actor, ensuring deep historical traceability in corporate SIEM platforms.

Operational Authentication Flows

Depending on the business objective, agents authenticate using one of three dedicated OAuth profiles:

Authentication ProfileTechnical Flow TriggerAuthorization Bounds
Interactive / AssistiveTriggers via On-Behalf-Of (OBO) flows in response to a live, signed-in human user prompt.Utilizes delegated scopes; the agent can never exceed the permissions of the interacting human.
Autonomous BackgroundRuns independently without human context via scheduled actions or system event hooks.Utilizes the Client Credentials flow; acts strictly on application permissions directly assigned to the agent identity.
Agent User ProfileTriggers when interacting directly with user-object silos like Exchange or Teams channels.Bypasses standard human interactive prompts, authenticating purely via parent identity federation.

4. Governance, Authorization, and Shadow Access Vectors

To prevent unmanaged “agent sprawl,” Microsoft establishes strict administrative lines that separate structural configuration from business lifecycle ownership:

  • Sponsors: A mandatory human user or group holding absolute business accountability for the agent’s lifecycle. Sponsors approve access extensions, review usage metrics, and authorize immediate isolation during an incident. Without an assigned sponsor, an identity becomes “governance-invisible” and is blocked from routine access reviews.
  • Owners: Human personnel responsible for technical adjustments, integration configurations, and immediate incident response for the blueprint or agent instance.
  • Managers: Technicians specifically designated to handle the operational configuration of secondary Agent User accounts.

The Threat Model: Inheritable Permissions and Permitted Dangerous Scopes

To ease administration across large environments, Entra ID allows administrators to configure inheritable permissions directly on the root Agent Identity Blueprint. Once consented to on the Blueprint Principal, these permissions automatically cascade to all child agent identities.

While operationally efficient, this architecture introduces a severe Shadow Access Risk. Because inherited permissions are injected dynamically during token issuance, checking the individual agent identity object directly will reveal a completely clean, zero-privilege profile. Security teams auditing single instances will miss active, high-privilege scopes entirely unless they evaluate the root blueprint’s configuration matrix.

“While Microsoft explicitly blocks agents from holding top-tier directory roles like Global Administrator and high-risk API permissions like RoleManagement.ReadWrite.All, several Tier-0 equivalent capabilities remain assignable. For example, an agent holding the permitted Application.ReadUpdate.All scope can be abused by an attacker to inject malicious credentials into existing enterprise applications.”


5. Generational Distinctions and the Evolution of the Registry

As organizations run asset discovery audits across their directories, security teams must distinguish between two architectural eras of agents currently coexisting in Entra ID:

  • Classic Agents: Legacy automation objects—such as those provisioned in early iterations of Copilot Studio—that run on traditional application service principals. These are flagged in the directory as Has Agent ID: No. They are completely incompatible with modern, agent-specific security layers like Agent Conditional Access or Agent Identity Protection.
  • Modern Agents: Non-human identities fully native to the new framework. They are backed by a master blueprint, possess a distinct Agent ID, utilize the token-exchange impersonation engine, and support risk-based Conditional Access.

To streamline this management overhead, Microsoft is introducing Agent 365 (Generally Available May 2026). This unified control plane replaces older Agent Registry blades in the Entra admin center, acting as the singular source of truth for tracking, auditing, and managing both classic and modern agent models across the enterprise.

The Paradigm Shift in Non-Human Workloads

The evolution of non-human directory objects marks a distinct shift in security priorities:

  • Standard Service Principals: Engineered for predictable scripts. The primary defensive focus is preventing secret leakage.
  • Managed Identities: Engineered for cloud resources, removing visible credentials entirely. The primary defensive focus is mitigating permission sprawl caused by over-provisioned RBAC roles.
  • Agent Identities: Engineered for non-deterministic, autonomous LLM workflows. The primary defensive focus is managing inherited access and the blueprint blast radius. Defenders must audit not only what an identity is configured to do on day one, but what it can dynamically become as it navigates across connected tools, users, and enterprise applications.

About Guardz
Guardz is on a mission to create a safer digital world by empowering Managed Service Providers (MSPs). Their goal is to proactively secure and insure Small and Medium Enterprises (SMEs) against ever-evolving threats while simultaneously creating new revenue streams, all on one unified platform.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.