[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffwg64ssyvked":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":58,"categories":60,"source":62,"lang":65,"author":66,"audioState":69,"stats":70,"publishedAt":73,"renderer":74},"6abb995dca21c797c7e9d1f6","build-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d","Build Secure AI Agents with Microsoft Agent Framework and Auth0","A few months ago, I started messing around with Microsoft Agent Framework, and I found it to be very flexible for building AI agents.","news",[10,13,18,23,28,33,38,43,48,53],{"headline":6,"body":11,"imageUrl":12,"sourceImageUrl":12},"A few months ago, I started messing around with Microsoft Agent Framework, and I found it to be very flexible for building AI agents. Like almost everyone, I built a working demo in a short time, but then I stopped and thought, \"wait, what is this thing actually allowed to do?\"","https:\u002F\u002Fmedia2.dev.to\u002Fdynamic\u002Fimage\u002Fwidth=1200,height=627,fit=cover,gravity=auto,format=auto\u002Fhttps%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fihwynszabc5gxifpxplq.png",{"headline":14,"body":15,"imageUrl":16,"images":17},"Most agent tutorials skip that question entirely. You","Most agent tutorials skip that question entirely. You get a smart chatbot that can search your database, send emails, maybe book a meeting, and the identity story is usually an afterthought. This is not how things work in production. You shouldn't implement an AI agent without stopping to ask who the agent is acting as, what it's allowed to see, or who's responsible when it does something wrong.","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F1.webp",{"local":16},{"headline":19,"body":20,"imageUrl":21,"images":22},"To answer these questions, I built a real","To answer these questions, I built a real example around it: an expense-approval agent for a fictional company, using Microsoft Agent Framework on the backend and Auth0 to handle every identity decision along the way. It turned into a four-part series published on the Auth0 blog, and here I want to explain why I think the whole thing is worth your time even if you skim the deep technical parts. What Could Go Wrong with the AI Agent?","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F2.webp",{"local":21},{"headline":24,"body":25,"imageUrl":26,"images":27},"The example app is simple on purpose: a","The example app is simple on purpose: a manager chats with an agent, the agent pulls up expense reports, and eventually the agent can send emails and approve or reject expenses on the manager's behalf. It's built with Microsoft Agent Framework's AIAgent and tool-calling, wired into a Blazor Web App, and it uses Azure AI Foundry.","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F3.webp",{"local":26},{"headline":29,"body":30,"imageUrl":31,"images":32},"Building the AI agent is pretty straightforward and","Building the AI agent is pretty straightforward and you can find plenty of tutorials on that. Actually, the interesting part of the series is what happens when you ask: what's stopping this agent from reading someone else's expense reports? Emailing the wrong person? Approving a $50,000 reimbursement because someone typed \"looks good\" in a chat window?","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F4.webp",{"local":31},{"headline":34,"body":35,"imageUrl":36,"images":37},"Turns out Auth0 has a specific answer to","Turns out Auth0 has a specific answer to each of those, and they're not the same answer. Every capability I added to the agent turned out to need its own identity and authorization decision, with its own failure mode if you skip it. Part 1: Who Is This Agent Even Acting For?","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F5.webp",{"local":36},{"headline":39,"body":40,"imageUrl":41,"images":42},"Before the agent does anything, it needs to","Before the agent does anything, it needs to know who it's working for. That sounds obvious, but a lot of agent demos never actually establish this. The first post walks through wiring up Auth0 Universal Login on the Blazor app, so every action the agent takes is tied to a real, authenticated manager, not an anonymous session.","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F6.webp",{"local":41},{"headline":44,"body":45,"imageUrl":46,"images":47},"This is the part people skip because it's","This is the part people skip because it's \"just login,\" but it's the foundation everything else depends on. If you can't answer \"who is this agent representing,\" none of the authorization questions later even make sense. And once you have that answer, every tool call the agent makes can carry that identity forward instead of acting as some generic service account. Part 2: What Is It Allowed to Retrieve?","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F7.webp",{"local":46},{"headline":49,"body":50,"imageUrl":51,"images":52},"Once the agent knows who's asking, the next","Once the agent knows who's asking, the next problem shows up fast: it needs to search expense reports, and not every manager should see every report. This is where I added Retrieval-Augmented Generation (RAG) support, vector search over the expense data, and paired it with Auth0's Fine-Grained Authorization (FGA).","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F8.webp",{"local":51},{"headline":54,"body":55,"imageUrl":56,"images":57},"The detail I like most from this part","The detail I like most from this part: the filtering happens before the vector search runs, not after. Some RAG-plus-authorization setups fetch everything and filter the results, which means the LLM already saw the data it wasn't supposed to see. Doing the FGA check first, and only searching over the objects the user is actually allowed to read, means unauthorized data never enters the picture at all. Part 3: What Can It Do on My Behalf?","\u002Fapi\u002Fmedia\u002Fposts\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-au-ec0b5d6d\u002F9.webp",{"local":56},[59],"dev",[61],"Technology",{"name":63,"url":64},"Dev.to","https:\u002F\u002Fdev.to\u002Fauth0\u002Fbuild-secure-ai-agents-with-microsoft-agent-framework-and-auth0-1hfa","en",{"handle":67,"displayName":68},"spots","Spots","queued",{"views":71,"likes":72,"saves":72,"shares":72,"completions":72,"opens":72,"skips":72,"depthSum":72},3,0,"2026-09-29T10:56:29.053Z","local"]