top of page
attacking and defending

AI Red Team Tactics for M365, Copilot and Enterprise AI [November 2026]

Get started with AI Red Teaming. Learn to attack and defend Copilot, Copilot Studio, Microsoft Foundry in M365 and Azure. Learn to attack Agent Identity in Entra, abuse identity boundaries and evade guardrails using live labs and real-world scenarios. Execute attacks against the Microsoft AI ecosystem to understand the impact on an Enterprise - go beyond prompt injection. Earn the AltSec CAIRTP certification.

Starts:  20th November 2026  Duration: 4 weeks
Recordings of live sessions included!

CAIRTP Certificate Image.jpg

What You Will Learn

This is a 4-week beginner-friendly bootcamp designed to get you started with AI Red Teaming. This course is designed for information security professionals who want to learn how to attack and secure AI across Microsoft 365 and Azure environments.

 

In this course, you will learn attacking the Microsoft AI ecosystem, Copilot, Copilot Studio, Microsoft Foundry, custom agents, built-in agents, abusing authentication flows and Agent identities.

 

You will perform attacks across full kill chains against live labs. Learn agent abuse, jailbreaking and guardrail evasion, agent consent, agent identity abuse, inter-agent flow hijacking, privilege escalation, and lateral movement across tenants and more.

 

The bootcamp goes beyond just prompt injection and teaches the impact of agent identity compromise, AI features abuse and the expanding attack surface created by Microsoft’s rapid integration of AI capabilities with M365, Azure and Entra ID. The course runs on the true cutting-edge of identity security and discusses abuse of the latest AI features by Microsoft.

CAIRTP-Bootcamp.avif

​4 Live Sessions
4 Hrs Per Session
4 Weeks Access
40 Flags To Be Collected
Live Lab Environment
1 CAIRTP Attempt
Recordings Of Live Sessions

Cracked Concrete Wall

Build Your Cybersecurity Credentials

Become Altered Security Certified AI Red Team Professional (AltSec CAIRTP)

Get the AltSec CAIRTP certification! A certificate holder has demonstrated the skills to assess and secure enterprise AI systems and identities across Microsoft 365, Azure and Entra ID. They can understand AI architecture, agent identity issues, expanded attack surface and perform attacks like prompt injection, RAG manipulation, inter-agent flow hijacking, and lateral movement across cloud and hybrid environments. They also know how to bypass guardrails, strengthen defenses, and detect threats, making them capable of protecting modern AI ecosystems.

Bootcamp Completion Certificate

Attendees will also get a course completion certificate after completing Learning Objectives covered during the course.

CAIRTP Certificate Image.jpg

Live Session Schedule

Weekly 4 hours sessions start at 09:00 am ET and end at 01:00 pm ET.

DATE
LIVE SESSIONS
20 November 2026
Introduction to AI Red Team: Microsoft AI Ecosystem, AI Attack Vectors and Initial Access Attacks
27 November 2026
Enterprise Copilot & Semantic Index Abuse
04 December 2026
AI-Driven Lateral Movement & Privilege Escalation
Agent ID Takeover, Multi-Agent workflow Abuse & AI Defense
11 December 2026
Cracked Concrete Wall

Prerequisites

1. Basic understanding of Azure and Azure Red Teaming is required. Check out Cloud Red Team Tactics for Azure - Beginner’s course to learn the basics.
2. Understanding of AI Red Teaming is desired but not mandatory.
3. System with 4 GB RAM and ability to install OpenVPN client and RDP to Windows boxes.
4. Privileges to disable/change any antivirus or firewall.

Bootcamp Syllabus

Bootcamp Syllabus

The course is split in four modules across four weeks:

Image by Gabriella Clare Marino

Module I

Introduction to AI and AI Red Teaming

Exploring Microsoft Copilot, Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry and Agent 365

Deep Dive into Copilot Studio and Microsoft Foundry for Building Low-Code and Enterprise AI Solutions

Exploring Built-in Copilot Agents

Microsoft Copilot Agents Enumeration (Discovery and Analysis of Built-in and Custom Agents)

Reconnaissance and Initial Access Using CoPhish attack

Image by Gabriella Clare Marino

Module II

Automated AI Red Teaming Using Single-Turn, Multi-Turn, and Crescendo Attacks with the PyRIT Framework

Jailbreaking, Prompt and Context Poisoning

Authenticated Enumeration of Microsoft Copilot Agents

Microsoft 365 Copilot and API Abuse

Rogue AI and Cloud Supply Chain Hijacking

Abuse of Microsoft Copilot Chat, Copilot Work and Copilot Cowork (Exploiting Enterprise and Autonomous Agent Capabilities)

Copilot Cowork Plugin and Skill Poisoning

Abusing Copilot Cowork to Establish C2 Infrastructure (Automated Webhook Beacons for Data Exfiltration)

Image by Gabriella Clare Marino

Module III

Introduction to Agent Identity and Agent Identity Blueprint

Agent Identity Authentication and Authorization Architecture

Abusing Multi-Tenant Identity Blueprints to Inherit Elevate Application Execution Roles

Privilege Escalation (Agent Tool Hijacking and Confused Deputy Attacks)

Autogen Multi-Agent Workflow Abuse (RCE, Data Exfiltration)

Lateral Movement through AI Agents

Cross-Tenant Agent Abuse

Image by Gabriella Clare Marino

Module IV

Agent Supply Chain, Indexing and Semantic Index Abuse

AI Agent and Copilot Security Defenses (Implementing Purview Sensitivity Labels and Custom Guardrail)

Prompt Injection, Jailbreak and Guardrails Bypass Defenses

Data Mining and Credentials Exposure

AI Security Monitoring and Detection

Image by Stepan Sargsyan

Purchase Options

Bootcamp

30 DAYS LAB ACCESS
+
BOOTCAMP
+
LIFE TIME ACCESS TO COURSE MATERIAL
+
​ONE CERTIFICATION EXAM ATTEMPT

$549

Extension

30 DAYS
LAB EXTENSION
+
ONE COMPLEMENTARY EXAM ATTEMPT

$399

Bootcamp

​60 DAYS LAB ACCESS
+
BOOTCAMP
+
LIFE TIME ACCESS TO COURSE MATERIAL
+
​ONE CERTIFICATION EXAM ATTEMPT

$749

Bootcamp

​90 DAYS LAB ACCESS
+
BOOTCAMP
+
LIFE TIME ACCESS TO COURSE MATERIAL
+
​ONE CERTIFICATION EXAM ATTEMPT

$949

Exam Reattempt is only for existing or past students of this course who have already purchased this course in the past.

Reattempt


EXAM
REATTEMPT


 

$99

Anchor 1

Add to cart

.

Purchase includes : 30 days lab access + course material + one certification exam attempt

Terms of Purchase and Use:

  • The Course materials and lab portal access are typically shared a few days before the scheduled bootcamp start date.

  • For all users enrolled in a bootcamp, lab access begins on the first day of the scheduled bootcamp.

  • You can use your registered email address to access the lab portal enterprisesecurity.io.

  • One Certification Exam attempt is included in the pricing. Additional exam attempts will be $99 each.

  • Once connected over VPN, consider the lab to be a hostile environment and you are responsible for your computer's security.

  • The above lab is a shared environment and certain pre-specified machines will be off-limits.

  • If you want a dedicated lab just for yourself at extra cost, please use the form in the Contact tab.

MEET THE INSTRUCTORS

Nikhil Mittal

Red Team Lab, Red Team Certifications, Red Team Trainings, Azure Pentesting, Azure Security

Nikhil Mittal is a hacker, infosec researcher, speaker and enthusiast. His area of interest includes red teaming, Azure and active directory security, attack research, defense strategies and post exploitation research. He has 15+ years of experience in red teaming.

He specializes in assessing security risks at secure environments that require novel attack vectors and "out of the box" approach. He has worked extensively on Azure Red Team, Active Directory attacks, defense and bypassing detection mechanisms. 

Nikhil has trained more than 15000 security professionals in private trainings and at the world’s top information security conferences.


He has spoken/trained at conferences like DEF CON, BlackHat, BruCON and more. 

He is the founder of Altered Security - a company focusing on hands-on enterprise security learning - https://www.alteredsecurity.com/

Vishal Raj

Vishal Raj.avif

Vishal Raj is a security researcher at Altered Security specializing in cloud security, red teaming, and network security. With a strong focus on identifying and exploiting misconfiguration in modern cloud environments, Vishal is passionate about enhancing enterprise security by simulating real-world attack scenarios and providing actionable defense strategies. Vishal extensively conducts research on Microsoft Entra ID, contributing to the understanding of identity and access management vulnerabilities in cloud environments.

 

In addition to his technical expertise, Vishal actively contributes to the cybersecurity community by writing insightful blogs on a variety of security topics. His writings aim to bridge the gap between theoretical concepts and practical application, empowering others in the field.

Can't attend this bootcamp?
Get informed about future bootcamps!

Thanks for subscribing!

bottom of page