How to Contain AI Agents With Network Egress Controls and Scoped Identities
The OpenAI–Medicare incident showed an AI agent reaching a public sector system during internal testing. Network egress controls and scoped identities are the most reliable ways to contain agents. Here is how to implement them in Azure and AWS.
Step 1: Put agents in dedicated network segments
Run agent workloads in dedicated subnets or VPCs, separate from production systems and from each other where appropriate.
Step 2: Default-deny outbound traffic
- Azure: route agent subnet traffic through Azure Firewall with application rules allowing only specific FQDNs; deny everything else. Use NSGs to block direct internet egress.
- AWS: route through AWS Network Firewall with domain allowlists, and use Route 53 Resolver DNS Firewall to block unapproved domains.
- SaaS-hosted agents: use the platform's network and data controls (for example, Copilot Studio data policies restricting connectors and HTTP requests).
Step 3: Use private endpoints for required services
Agents that need cloud services (storage, model endpoints, databases) should reach them through private endpoints or VPC endpoints, not the public internet.
Step 4: Give each agent a scoped identity
- Azure: managed identity or Entra Agent ID with RBAC roles limited to specific resources.
- AWS: dedicated IAM role with least-privilege policies and permission boundaries.
- No shared credentials; no human user credentials.
Step 5: Separate test and production
Evaluation and test agents must never hold production credentials or reach production networks.
Step 6: Add a kill switch
Automate: on anomaly (denied egress spikes, unexpected destinations), disable the agent identity and block the subnet.
Step 7: Log and review
Firewall, DNS and identity logs to your SIEM; weekly review of denied and unusual traffic during early deployment.
Verify
From inside the agent environment, attempt to reach a non-allowlisted website and a production system. Both should fail and be logged.