A&M kept a Microsoft/Azure backbone for identity, endpoints and security, but chose a non-Microsoft AI layer — Anthropic's Claude, Claude Code and Claude Cowork — instead of defaulting to Copilot. That best-of-breed choice opens a control gap that Microsoft's native tooling doesn't fully cover. Harmonic is the seam that closes it. Understanding that seam is the highest-value thing you can walk into this meeting with.
Click any component for detail. Solid dots are confirmed in A&M's own job specifications; hollow dots are standard-for-Azure inferences you should treat as hypotheses to test in the room, not facts to assert.
A&M's AI Security Engineer specification asks for “proficiency in cloud security across Microsoft Azure, including cloud-native security controls, CSPM tooling, and secure API gateway configuration,” plus enterprise IAM with “zero-trust architectures, role-based access control (RBAC), and privileged access management (PAM).” The certifications it names — AZ-500 and SC-100 — are both Microsoft. This is an Azure-first shop: identity in Entra, devices under Intune, posture managed with CSPM, telemetry into a SIEM. That's the “Azure-centric estate.”
The same document names the AI applications to be secured: “Claude, Claude Code, Claude Cowork.” Not Copilot. For a Microsoft-shop this is a deliberate, best-of-breed decision, and it fits A&M's operator culture — pick the tool that does the job rather than the one that comes bundled. It also means the AI layer sits outside the Microsoft trust boundary, reached over the public internet through a third-party API.
Microsoft's native data-protection stack is deepest where Microsoft owns both ends — M365 content and Copilot. When the AI layer is a third-party desktop app, a CLI running in a developer's terminal, and an agent making tool calls to MCP servers, the Microsoft control plane sees the device and the network egress, but not the prompt, not the tool call, and not the agent's intent. Harmonic Security — an AI governance and control platform whose CEO Alastair Paterson co-founded Digital Shadows — closes exactly that gap by sitting on the device rather than on the network: a browser extension, a desktop hook for Claude Desktop and Cursor, and a local MCP gateway. It deploys through the same MDM A&M already runs (Intune), which is why it slots into an Azure estate without friction.
A&M's commercial model is selling to clients what it has proven on itself. It is, right now, building the reference implementation of governed enterprise agentic AI — and staffing it: A&M's current search results date the Harmonic/Claude security role to 27 July 2026. If you can speak fluently about this seam, you are not pitching generic capability. You are describing the thing they are currently building and will need to sell.
Harmonic's own practitioner guide to Claude Cowork states that Cowork activity is excluded from Anthropic's Audit Logs, Compliance API and Data Exports, and advises against using Cowork for any workflow requiring a regulatory audit trail until that closes. OpenTelemetry gives partial visibility but needs custom plumbing into a SIEM. For a firm doing restructuring, disputes and regulated-client work, that is a live constraint on how far agentic deployment can go.
Raise it — carefully, as an architecture question you have already thought about, never as a criticism of their choices. “How are you handling the Cowork audit-trail gap for regulated engagements — OTel into Sentinel, or scoping Cowork away from those workflows?” is the single highest-signal sentence available to you in that room. It proves you have operated this stack, not just read about it.
managed-mcp.json pushed via MDM is the mature answer. The answer tells you how far along they actually are versus how far along the press release sounds.