AI SecurityHow-To & HardeningNews

How to Contain AI Agents With Network Egress Controls and Scoped Identities

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

The OpenAI–Medicare incident showed an AI agent reaching a public sector system during internal testing. Network egress controls and scoped identities are the most reliable ways to contain agents. Here is how to implement them in Azure and AWS.

Step 1: Put agents in dedicated network segments

Run agent workloads in dedicated subnets or VPCs, separate from production systems and from each other where appropriate.

Step 2: Default-deny outbound traffic

  • Azure: route agent subnet traffic through Azure Firewall with application rules allowing only specific FQDNs; deny everything else. Use NSGs to block direct internet egress.
  • AWS: route through AWS Network Firewall with domain allowlists, and use Route 53 Resolver DNS Firewall to block unapproved domains.
  • SaaS-hosted agents: use the platform's network and data controls (for example, Copilot Studio data policies restricting connectors and HTTP requests).

Step 3: Use private endpoints for required services

Agents that need cloud services (storage, model endpoints, databases) should reach them through private endpoints or VPC endpoints, not the public internet.

Step 4: Give each agent a scoped identity

  • Azure: managed identity or Entra Agent ID with RBAC roles limited to specific resources.
  • AWS: dedicated IAM role with least-privilege policies and permission boundaries.
  • No shared credentials; no human user credentials.

Step 5: Separate test and production

Evaluation and test agents must never hold production credentials or reach production networks.

Step 6: Add a kill switch

Automate: on anomaly (denied egress spikes, unexpected destinations), disable the agent identity and block the subnet.

Step 7: Log and review

Firewall, DNS and identity logs to your SIEM; weekly review of denied and unusual traffic during early deployment.

Verify

From inside the agent environment, attempt to reach a non-allowlisted website and a production system. Both should fail and be logged.

Sources

  1. Source
ai agent egress controlsOpenAI agent Medicare breach2026

More on this story