What the 2026 Microsoft Digital Defense Report reveals about AI, identity, and the future of cybersecurity
Key Takeaways
- Identity is the common thread. The Microsoft Digital Defense Report 2026 shows identity sprawl, non-human identities, and AI agents driving interconnected risk. Cloud identity abuse was the most observed technique against critical infrastructure, at 78%.
- A graph shows real reach. Microsoft states that “an inventory is not enough and a graph is essential.” Mapping the relationships between identities, permissions, and resources shows what an identity can reach directly, through automation, and through downstream connections.
- AI agents join the existing attack graph. 88% of enterprises are experimenting with AI agents, and Microsoft names ungoverned agent proliferation and overprivileged access as top risks. Agents accumulate access the same way service accounts always have, so they belong in the same attack graph as every other identity.
- AI speeds up attack path discovery. Most attack paths come from long-standing technical debt. AI cuts the time needed to find and chain them, and adversaries already used AzureHound to map cloud attack paths (12% of the observed tool mix against critical infrastructure).
- Fix choke points to close many paths at once. Attack path management maps every path and finds the relationships that thousands of paths share. Removing one choke point closes all the paths that run through it.
The recently released 2026 Microsoft Digital Defense Report describes a security landscape shaped by interconnected risk, identity sprawl, and AI-driven acceleration. One theme runs through much of the report: environments are expanding, and attackers benefit from the increasingly complex relationships between identities, permissions, applications, infrastructure, and cloud services.
An infrastructure weakness becomes more consequential when it connects to other systems, privileges, or identities that extend what an attacker can reach.
Years of traditional identity technical debt, combined with the rapid addition of cloud services, non-human identities, automation, and AI agents, create relationships that may be difficult to see when security teams audit individual systems or findings. Attack Path Management makes those relationships visible and shows where they lead, providing a insight into how exposure accumulates across an environment and the potential impact.
Learn more about the intersection of AI and Attack Path Management. Watch our webinar, “Securing the AI Era: The Next Evolution of Identity Attack Path Management.”
Interconnected risk changes how exposure should be measured
Microsoft describes modern cyber risk as “a continuous business condition shaped by persistent adversary pressure, machine-speed operations, and systemic interdependence.” Cloud services, automation, non-human identities, and AI agents are adding to the number of identities organizations need to govern and creating more dependencies between them.
Many security programs naturally divide their environment into manageable pieces: identities, endpoints, vulnerabilities, entitlements, applications, cloud resources, and configurations. An attacker’s path through the environment may cross several of those categories. A compromised identity might provide access to an application that exposes a credential tied to a cloud identity with access to sensitive infrastructure. An attacker never sees those silos, only the route through them. Flaws within specific platforms can seem benign if viewed within a silo, but the picture becomes critical when we view as an attack path that cuts through the hybrid enterprise. It takes looking at these relationships holistically to piece together the attack paths that connect identities to critical assets across the environment, regardless of where those paths originate.
Attackers don’t need advanced exploits or tradecraft to escalate from a foothold and move on to riper targets. They merely leverage the almost inevitable tech debt that plagues nearly every enterprise.
A graph is essential
Microsoft makes obvious the need for a graph in its discussion of developer environments. Developers increasingly work with source-code access, cloud permissions, credentials, tokens, automation, pipelines, and AI coding interfaces. Each access grant may make sense on its own, while the combination creates a much larger effective blast radius that no one (nor any tool) is tracking.
Microsoft writes that “an inventory is not enough and a graph is essential.” The report recommends understanding what a developer can reach directly, what automation can access on their behalf, what pipelines can trigger, and what becomes reachable through downstream relationships.
The same concept applies beyond developers. An inventory identifies users, applications, permissions, workloads, and resources. Graph analysis adds the relationships between them and makes it possible to see how control can propagate through an environment. This foundation of BloodHound and Attack Path Management: the significance of a permission often depends on where that permission leads.
This is what sets BloodHound Enterprise apart from most “graph” solutions, which show what can accessed directly but do not represent how an attacker could take over a succession of accounts to ultimately reach one with legitimate, IGA-approved access. The initial identity is often uninteresting, it’s the snowball of privilege and further identities attackers can take over that represents true risk. To protect the critical assets that could be accessed, altered, destroyed, or exfiltrated, defenders need to understand and defend with the perspective of an attacker who is determined to reach them.
Recent CISA red team findings offer another example of the same issue. In A Tale of Two SOCs, CISA used BloodHound collectors SharpHound and, later AzureHound, to understand Active Directory and Azure Entra ID relationships and identify access to sensitive systems. CISA also referenced SpecterOps’ “Certified Pre-Owned” research while discussing ADCS ESC1 misconfigurations. Both are examples of looking beyond an individual configuration to understand how permissions and technical debt can contribute to greater control. Attack Path Management applies that perspective continuously so organizations can find and reduce those conditions before they are used in an attack.
Agentic AI expands the attack graph
AI agents add another, and exceedingly convoluted, identity type to this already complicated environment. Microsoft also identifies that 88% of enterprises are experimenting with agents, and 82% of leaders plan broader deployments within 12 to 18 months. Those agents require access to business systems and resources, which introduce additional identities, permissions, dependencies, and governance requirements. Microsoft also identifies ungoverned agent proliferation and overprivileged access among the major risks, including the possibility that agent identities accumulate permissions as their responsibilities change.
There is a lot here that will feel familiar to identity teams. Organizations have spent years dealing with service accounts that accumulate permissions, access that outlives its original purpose, and privileges that become difficult to trace back to a business need. Agentic identities introduce similar concerns, potentially at much greater scale, and without a clear picture of the effects of their cascading relationships. They become part of the same web of users, applications, workloads, data, APIs, and infrastructure that organizations already need to understand.
The solution to this problem is not to look at agents and assess their security in yet another silo. You must understand how these connect to every other identity and resource in the larger attack graph.
AI changes how quickly attack paths can be found
AI also reduces the effort involved in understanding complicated environments. The underlying attack paths may have existed for years (or decades…). What changes is the economics; the speed and scale at which someone can discover them. AI can help analyze permissions, identities, configurations, and relationships that would have taken a human operator weeks or more to work through. Technical debt that once benefited from obscurity becomes easier to surface and connect.
Where attackers once had to find a needle in a haystack, and defenders could take some comfort in how difficult that was, AI changes the equation. Today’s attackers can find a million needles without risking a sneeze.
Microsoft’s critical-infrastructure data gives this issue additional context. AzureHound, the data collection engine for BloodHound, designed to map relationships and potential privilege escalation paths within Microsoft Entra ID (formerly Azure AD) and Azure Resource Manager (AzureRM), appeared in 12% of the observed tool mix used against critical infrastructure, specifically for mapping cloud attack paths. Cloud identity abuse appeared in 78% of observed critical-infrastructure activity. Those findings show that understanding identity relationships and cloud attack paths already has practical value for adversaries. AI increases the amount of complexity they can work through and the speed at which they can do it.
Reducing the conditions that make attack paths possible
Mapping these relationships can expose a large number of potential paths. Mapping paths one by one is pointless and leaves security teams with another prioritization problem. The more useful application of Attack Path Management is to map every path and identify where large concentrations of thousands or millions of paths share common relationships and where a focused remediation can shut them down at once.
This is where the connection to technical debt becomes especially important. Removing an unnecessary permission, correcting a trust relationship, restructuring privilege, or eliminating standing access can affect far more than the individual configuration being changed. If several attack paths depend on the same relationship, addressing that relationship removes multiple opportunities for an attacker at once.
Microsoft’s report ultimately describes many familiar security problems operating at greater scale and speed. Least privilege, identity governance, blast-radius analysis, unnecessary access, and trusted relationships have mattered for years. Today those issues extend across on-premises identity, cloud infrastructure, SaaS, developer platforms, automation, non-human identities, and AI agents.
That makes Microsoft’s observation that “an inventory is not enough and a graph is essential” particularly relevant. CISA’s recent findings provide a practical example of the same principle.
Microsoft and CISA’s recent highlighting of this problem makes it clearer than ever that, as environments become more interconnected and AI makes complex relationships easier to analyze, reducing the technical debt behind attack paths becomes an essential to manage identity risk.
Understand the paths; reduce the risk
As AI accelerates the ability to discover and exploit existing attack paths, organizations need to understand their exposure and address the conditions that make those paths possible. BloodHound Enterprise provides continuous visibility into identity attack paths and helps prioritize the technical debt that creates them. SpecterOps AI Adversary Operations brings the adversary perspective to AI systems through red teaming, testing, and enablement.
See where attackers can go. Eliminate the paths. Test what comes next.