<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/ct-p/microsoft-security-product</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Sat, 29 Aug 2026 09:29:01 GMT</pubDate>
    <dc:creator>microsoft-security-product</dc:creator>
    <dc:date>2026-08-29T09:29:01Z</dc:date>
    <item>
      <title>Ask Microsoft Anything: Microsoft Defender Experts</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-events/ask-microsoft-anything-microsoft-defender-experts/ec-p/4550555#M2667</link>
      <description>&lt;P data-ogsc="black" data-olk-copy-source="MessageBody"&gt;&lt;STRONG&gt;Learn how Microsoft Defender Experts deliver expert-led security services to help organizations modernize security operations, outpace bad actors, defend against threats, and build cyber resilience. Ask your questions and connect with Microsoft experts on real-world use cases, service capabilities, and best practices.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What is an AMA?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;An 'Ask Microsoft Anything' (AMA) session is an opportunity for you to engage directly with Microsoft employees! This AMA will consist of a short presentation followed by taking questions on-camera from the comment section down below! Ask your questions/give your feedback and we will have our awesome Microsoft Subject Matter Experts engaging and responding directly in the video feed. We know this timeslot might not work for everyone, so feel free to ask your questions at any time leading up to the event and the experts will do their best to answer during the live hour. This page will stay up evergreen, so come back and use it as a resource anytime. We hope you enjoy!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 18:34:55 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-events/ask-microsoft-anything-microsoft-defender-experts/ec-p/4550555#M2667</guid>
      <dc:creator>TrevorRusher</dc:creator>
      <dc:date>2026-08-26T18:34:55Z</dc:date>
    </item>
    <item>
      <title>Ask Microsoft Anything: Secure multi-tenant environments with Microsoft Entra Tenant Governance</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-events/ask-microsoft-anything-secure-multi-tenant-environments-with/ec-p/4550554#M2666</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-olk-copy-source="MessageBody"&gt;Learn more about Microsoft Entra Tenant Governance – a built-in solution that helps bring an organization’s tenants under control, reduce shadow-tenant risk, and manage tenant configuration at scale. By enabling centralized policies and cross-tenant delegated administration, it helps strengthen identity foundations for AI-powered operations. Bring your questions and hear directly from product experts about why securing tenants matters.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What is an AMA?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;An 'Ask Microsoft Anything' (AMA) session is an opportunity for you to engage directly with Microsoft employees! This AMA will consist of a short presentation followed by taking questions on-camera from the comment section down below! Ask your questions/give your feedback and we will have our awesome Microsoft Subject Matter Experts engaging and responding directly in the video feed. We know this timeslot might not work for everyone, so feel free to ask your questions at any time leading up to the event and the experts will do their best to answer during the live hour. This page will stay up evergreen so come back and use it as a resource anytime. We hope you enjoy!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2026 16:43:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-events/ask-microsoft-anything-secure-multi-tenant-environments-with/ec-p/4550554#M2666</guid>
      <dc:creator>TrevorRusher</dc:creator>
      <dc:date>2026-08-27T16:43:59Z</dc:date>
    </item>
    <item>
      <title>Reminder: Ask Microsoft Anything with David Weston is Tomorrow (8/25) at 8AM PST!</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/reminder-ask-microsoft-anything-with-david-weston-is-tomorrow-8/ba-p/4549690</link>
      <description>&lt;P&gt;&lt;SPAN data-teams="true"&gt;David Weston leads Agentic Security at Microsoft, where he and his team build the AI models, autonomous agents, and evaluation systems redefining how defenders operate. At Microsoft since the Windows 7 era, he has worked across exploit mitigation design, malware analysis, APT research, and led security engineering for Windows, Xbox, Azure OS, and Microsoft's Offensive Security Research &amp;amp; Engineering group. His current work is leading teams training frontier security models, agentic security systems for defenders, and pushing AI-driven vulnerability discovery through Microsoft's Multi-Model Agentic Scanning Harness (MDASH). A longtime member of the research community and former CISA technical advisor, David is a regular presenter at BlueHat, Black Hat, and DEF CON.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;Tomorrow he will be with us on Tech Community answering questions during a live hour of Q&amp;amp;A with all of you!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Key areas David and his team can discuss:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The vision behind Project Perception&lt;/LI&gt;
&lt;LI&gt;How AI is changing the economics of cyber offense and defense&lt;/LI&gt;
&lt;LI&gt;Lessons learned from building MDASH and Microsoft's AI security initiatives&lt;/LI&gt;
&lt;LI&gt;Security-first AI development and deployment&lt;/LI&gt;
&lt;LI&gt;What's next for defenders as agentic systems become mainstream&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;STRONG&gt;Link: &lt;A href="https://techcommunity.microsoft.com/event/microsoft-security-events/ask-microsoft-anything-why-cybersecurity-needs-a-new-security-stack-for-the-ai-e/4544793" target="_blank"&gt;Ask Microsoft Anything: Why Cybersecurity Needs a New Security Stack for the AI Era with David Weston&lt;/A&gt;&lt;/STRONG&gt;&lt;/H5&gt;</description>
      <pubDate>Mon, 24 Aug 2026 16:53:52 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/reminder-ask-microsoft-anything-with-david-weston-is-tomorrow-8/ba-p/4549690</guid>
      <dc:creator>TrevorRusher</dc:creator>
      <dc:date>2026-08-24T16:53:52Z</dc:date>
    </item>
    <item>
      <title>Thank you</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-experts/thank-you/m-p/4549203#M69</link>
      <description>&lt;P&gt;Thank You, Microsoft Defender Team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to express my appreciation to the Microsoft Defender team. As a user who spends a lot of time online supporting educators, families, and community partners, it is reassuring to know that web protection, phishing protection, and reputation-based security features are working behind the scenes to help keep my devices and information safe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Technology often gets noticed when something goes wrong, but today I want to recognize what is working well. Thank you for creating tools that help protect users from threats while allowing us to focus on our work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your efforts are appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Aug 2026 14:20:14 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-experts/thank-you/m-p/4549203#M69</guid>
      <dc:creator>smtoth</dc:creator>
      <dc:date>2026-08-22T14:20:14Z</dc:date>
    </item>
    <item>
      <title>Microsoft Defender</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-experts/microsoft-defender/m-p/4548182#M53</link>
      <description>&lt;P&gt;Goodmorning:&lt;/P&gt;&lt;P&gt;I am working with a laptop Acer Aspire 3 15 , Windows 11.&lt;/P&gt;&lt;P&gt;Microsoft Defender worked fine until two days ago. Then it started being blocked at 91 percent instead of compliting the program at 100 percent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please, if a person can help me in understanding what causes this problem I will be very grateful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks FFBX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2026 13:34:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-experts/microsoft-defender/m-p/4548182#M53</guid>
      <dc:creator>FFBX</dc:creator>
      <dc:date>2026-08-19T13:34:32Z</dc:date>
    </item>
    <item>
      <title>No updates to "Stop clear text credentials exposure" after migrating our MDI sensors to v3</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-identity/no-updates-to-quot-stop-clear-text-credentials-exposure-quot/m-p/4546845#M4330</link>
      <description>&lt;P&gt;Since migrating our domain controllers to the v3 sensor, the &lt;A class="lia-external-url" href="https://security.microsoft.com/exposure-recommendations?recommendationId=AATP_ClearText&amp;amp;tabId=Identities" target="_blank" rel="noopener"&gt;"Stop clear text credentials exposure" recommendation&lt;/A&gt; is no longer updating. The latest "Last seen" date correlates with the date we performed the migration, and I know we have a couple entities that have not yet been remediated.&lt;/P&gt;&lt;P&gt;If I run a query on the IdentityQueryEvents table in Advanced Hunting, I'm still seeing LDAP queries.&lt;/P&gt;&lt;P&gt;Anyone else seeing this?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2026 22:04:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-identity/no-updates-to-quot-stop-clear-text-credentials-exposure-quot/m-p/4546845#M4330</guid>
      <dc:creator>RyanSteele-CoV</dc:creator>
      <dc:date>2026-08-13T22:04:07Z</dc:date>
    </item>
    <item>
      <title>Ask Microsoft Anything: Why Cybersecurity Needs a New Security Stack for the AI Era with David Weston</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-events/ask-microsoft-anything-why-cybersecurity-needs-a-new-security/ec-p/4544793#M2645</link>
      <description>&lt;P&gt;&lt;SPAN data-teams="true"&gt;David Weston leads Agentic Security at Microsoft, where he and his team build the AI models, autonomous agents, and evaluation systems redefining how defenders operate. At Microsoft since the Windows 7 era, he has worked across exploit mitigation design, malware analysis, APT research, and led security engineering for Windows, Xbox, Azure OS, and Microsoft's Offensive Security Research &amp;amp; Engineering group. His current work is leading teams training frontier security models, agentic security systems for defenders, and pushing AI-driven vulnerability discovery through Microsoft's Multi-Model Agentic Scanning Harness (MDASH). A longtime member of the research community and former CISA technical advisor, David is a regular presenter at BlueHat, Black Hat, and DEF CON.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Key areas Dave and his team can discuss:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The vision behind Project Perception&lt;/LI&gt;
&lt;LI&gt;How AI is changing the economics of cyber offense and defense&lt;/LI&gt;
&lt;LI&gt;Lessons learned from building MDASH and Microsoft's AI security initiatives&lt;/LI&gt;
&lt;LI&gt;Security-first AI development and deployment&lt;/LI&gt;
&lt;LI&gt;What's next for defenders as agentic systems become mainstream&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will be a &lt;STRONG&gt;TEXT-BASED&lt;/STRONG&gt; AMA, so ask your questions in the comment section down below and David and team will be answering via comment replies during the live hour!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2026 16:37:26 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-events/ask-microsoft-anything-why-cybersecurity-needs-a-new-security/ec-p/4544793#M2645</guid>
      <dc:creator>TrevorRusher</dc:creator>
      <dc:date>2026-08-07T16:37:26Z</dc:date>
    </item>
    <item>
      <title>MCP safety &amp; evaluation with the Agent 365 CLI &amp; Agent Governance Toolkit</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/mcp-safety-evaluation-with-the-agent-365-cli-agent-governance/ba-p/4543969</link>
      <description>&lt;P class="lia-align-left"&gt;Co Author: &lt;a href="javascript:void(0)" data-lia-user-mentions="" data-lia-user-uid="364534" data-lia-user-login="JiteshThakur" class="lia-mention lia-mention-user"&gt;JiteshThakur​&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AI agents are useful because they can act. They call tools, query databases, send messages, and hand work to other agents. That same freedom creates a problem: access control can tell you which service an agent may reach, but it does not always tell you whether a particular action is sensible, safe, or permitted.&amp;nbsp; MCP is how most agents now act.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Two Control Points:&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;This post examines two control points that address different parts of the MCP lifecycle.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Agent 365 CLI evaluates the MCP server before an agent uses it.&lt;/LI&gt;
&lt;LI&gt;Agent Governance Toolkit (AGT) governs sensitive tool calls while the agent runs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;One improves what the agent sees. The other governs what the agent does.&lt;/P&gt;
&lt;P&gt;The Agent 365 CLI is a cross-platform command-line tool for Agent 365 applications on Azure. Its evaluation command examines MCP tool definitions and scores their quality. AGT evaluates actions against policy and records each decision.&lt;/P&gt;
&lt;P&gt;Together, these tools support a practical model: evaluate the server first, then provide proper scaffolding for the developer to test this in a dry run.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Agent 365 CLI: Score an MCP server from the command line:&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;The Agent 365 CLI can&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-tools-for-agent?view=o365-worldwide#evaluate-mcp-servers" target="_blank" rel="noopener"&gt;evaluate &lt;/A&gt;an MCP server against research-based practices for production readiness. The result is more useful than a simple pass or fail.&lt;/P&gt;
&lt;P&gt;The evaluation gives you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A score for each tool name, description, and parameter schema;&lt;/LI&gt;
&lt;LI&gt;A prioritized list of improvements;&lt;/LI&gt;
&lt;LI&gt;An overall maturity score for the server; and&lt;/LI&gt;
&lt;LI&gt;Local output that you can use early in development.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This report turns a vague question, "Is this MCP server ready?", into a concrete list of work.&lt;/P&gt;
&lt;P&gt;The evaluate command&lt;/P&gt;
&lt;LI-CODE lang="shell"&gt;a365 develop-mcp evaluate --server-url &amp;lt;server-url&amp;gt; [--auth-token &amp;lt;auth-token&amp;gt;] [options]&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The command reads the tool schemas from the server. It then produces guidance for names, descriptions, parameters, and schema structure.&lt;/P&gt;
&lt;P&gt;A local coding-agent CLI scores the semantic checks. You can use GitHub Copilot CLI or Claude Code under your account and AI subscription. The command does not send tool-schema data to Microsoft.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Prerequisites:&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Install the following software:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/agent-365-cli?tabs=windows#install-the-agent-365-cli" target="_blank" rel="noopener"&gt;Agent 365 CLI&lt;/A&gt;;&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;Node.js 18 or later for GitHub Copilot CLI; and&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;A supported coding-agent CLI for semantic scoring.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For example, install GitHub Copilot CLI with this command:&lt;/P&gt;
&lt;LI-CODE lang="shell"&gt;powershell npm install -g @github/copilot&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This bring-your-own-LLM model keeps the scoring step in your local development environment. It is useful when model calls must remain inside an approved deployment.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;How the evaluation works&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;The command runs a five-step pipeline and logs progress as it goes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-right"&gt;&lt;STRONG&gt;Fig 1: MCP Evaluation using Agent 365 Cli&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Connect to the MCP server and collect its tool schemas.&lt;/LI&gt;
&lt;LI&gt;Generate an evaluation checklist in the output directory.&lt;/LI&gt;
&lt;LI&gt;Score the semantic checks with the selected coding agent.&lt;/LI&gt;
&lt;LI&gt;Calculate the maturity level and action priorities.&lt;/LI&gt;
&lt;LI&gt;Write the JSON and HTML reports.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The evaluation contains two types of checks:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Deterministic checks&lt;/STRONG&gt; use exact rules in the CLI. For example, a tool name cannot be empty.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Semantic checks&lt;/STRONG&gt; use a coding agent to score clarity and meaning. Each result includes a reason for the score.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;Examples&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Set the authentication token in an environment variable. Then evaluate an authenticated server and write the artifacts to a subfolder.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;powershell 
$env:A365_MCP_AUTH_TOKEN = "&amp;lt;bearer-token&amp;gt;" 
a365 develop-mcp evaluate --server-url "https://my-mcp-server.contoso.com/mcp" --output-dir "./eval"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use a specific scoring engine with the&lt;EM&gt; `--eval-engine`&lt;/EM&gt; option:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;powershell a365 develop-mcp evaluate --server-url "http://localhost:5000/mcp" --eval-engine claude-code&lt;/LI-CODE&gt;
&lt;H3&gt;&lt;STRONG&gt;Scenario: Evaluate a malicious MCP server&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;For this demonstration, we hosted a deliberately malicious MCP server at&lt;EM&gt; `http://127.0.0.1:8124/`.&lt;/EM&gt; It exposes tools that demonstrate tool poisoning, credential leakage, prompt injection, schema mismatch, sandbox escape, and other attacks.&lt;/P&gt;
&lt;P&gt;The server is intentionally unsafe and is for &lt;EM&gt;demonstration only&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-right"&gt;&lt;STRONG&gt;Fig 2: Setting up a test MCP server for evaluation&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We ran the evaluation in two steps. First, we generated the checklist without automatic semantic scoring:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;a365 develop-mcp evaluate --server-url "http://127.0.0.1:8124/" --eval-engine none&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Fig 3: Agent365CLI MCP Evaluation&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The command wrote the checklist and a semantic-evaluation prompt to the output directory. It also displayed the next steps.&lt;/P&gt;
&lt;P&gt;Second, we gave the prompt and checklist to a coding agent. The agent completed each unscored semantic check with a Boolean score and a short reason. After we saved the completed checklist, we ran the command again to generate the report:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;a365 develop-mcp evaluate --server-url "http://127.0.0.1:8124/" --output-dir "C:\temp\MaliciousMCP"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Fig 4: Creating the report with Agent365 CLI MCP Evaluate command&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Understanding the evaluation report&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Open &lt;EM&gt;`&amp;lt;server-name&amp;gt;_eval_report.html` &lt;/EM&gt;from the output directory. The report contains:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The overall score from 0 to 100;&lt;/LI&gt;
&lt;LI&gt;The maturity level from 0 to 4;&lt;/LI&gt;
&lt;LI&gt;Scores for each tool and quality category; and&lt;/LI&gt;
&lt;LI&gt;A prioritized action list for the next maturity level.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Fig 5:&amp;nbsp; MCP Evaluation Report&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our demonstration, the server scored &lt;STRONG&gt;86.0&lt;/STRONG&gt; and reached &lt;STRONG&gt;Level 3: Optimized for AI&lt;/STRONG&gt;. That strong overall score did not mean that every tool was safe or clear. The report found &lt;STRONG&gt;58 action items&lt;/STRONG&gt;, including one critical item and 33 high-priority items.&lt;/P&gt;
&lt;P&gt;That contrast matters. A server can have valid schemas and consistent names while still exposing misleading or dangerous tools.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Fig 6: MCP Evaluation Report - Tool-By-Tool Detail&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;What to look for&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;Read the per-tool results before the overall score. A single weak tool can create more risk than the server average suggests.&lt;/P&gt;
&lt;P&gt;Focus on these report sections:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Tool names:&lt;/STRONG&gt;&amp;nbsp;Can an agent select the correct tool from its name?&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Tool descriptions:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;Does each description explain the purpose and correct use?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Parameter names:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;Do the names identify the data that the tool requires?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Parameter descriptions:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;Do they explain the format, type, and constraints?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Schema structure:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;Are the schemas valid and processable?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Action items:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;Which changes have the highest effect on tool selection and use?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The command processes static tool schemas from&amp;nbsp;&lt;STRONG&gt;`tools/list`&lt;/STRONG&gt;. It does not process runtime payloads, end-user data, or personal data. The command keeps the &lt;STRONG&gt;`&lt;EM&gt;--auth-token`&lt;/EM&gt;&lt;/STRONG&gt; value in memory. It sends the value only in the HTTP `Authorization` header. It does not write the token to disk or give it to the coding agent.&lt;/P&gt;
&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;
&lt;H2&gt;&lt;STRONG&gt;AGT: Put governance in the execution path:&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Microsoft's open-source&amp;nbsp;&lt;A href="https://microsoft.github.io/agent-governance-toolkit/" target="_blank" rel="noopener"&gt;Agent Governance Toolkit (AGT)&lt;/A&gt; evaluates an action before execution. It adds identity and policy context, records the decision, and can send risky work for approval. This can be used by developers during the build time for dynamic evaluation of the MCP server.&lt;/P&gt;
&lt;P&gt;AGT lets developers put part of that intent into the execution path. Remote tools still need secure implementations, sandboxes need hard boundaries, and audit records need appropriate storage and access controls. You do not need to replace your agent framework to use it.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;What sits in the decision path?&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;AGT wraps the tools that an agent already uses. You can start to govern a tool with two lines of Python:&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;python from agentmesh.governance
import govern safe_tool = govern(my_tool, policy="policy.yaml")&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On each call,&amp;nbsp;&lt;EM&gt;`safe_tool`&lt;/EM&gt; evaluates the configured policy. An allowed action reaches the original tool. A denied action raises &lt;EM&gt;`GovernanceDenied`&lt;/EM&gt; and creates a decision record. This wrapper model reduces the cost of adoption. Teams can add governance to an existing agent stack without rebuilding it.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://microsoft.github.io/agent-governance-toolkit/packages/#migration" target="_blank" rel="noopener"&gt;AGT supports Python, TypeScript, .NET, Rust, and Go&lt;/A&gt;. Its documented integrations include popular agent frameworks, MCP, and A2A. Teams can also adopt AGT in stages. A team can begin with policy checks and audit records. It can add identity, approvals, sandboxing, and operational controls as risk increases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Each control answers a different question:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy:&lt;/STRONG&gt;&amp;nbsp;Is this action allowed?&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Identity and trust:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;Which agent made the request?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Runtime controls:&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;&amp;nbsp;What limits apply to execution?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;Audit evidence: &lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;Why did AGT allow or deny the action?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;A low-risk assistant can need only a deny rule and basic logging. An agent that moves money or changes production systems needs stronger controls.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Fig 7:&amp;nbsp; AGT Architecture&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Scenario: Govern the same malicious MCP server&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;For this scenario demonstration, we used &lt;A class="lia-external-url" href="https://microsoft.github.io/agent-governance-toolkit/tutorials/07-mcp-security-gateway/" target="_blank" rel="noopener"&gt;AGT Python packages as an MCP gateway.&lt;/A&gt; The gateway sat between an agent and the same malicious server from the earlier evaluation. This setup let us examine both control points against one target. The Agent 365 CLI examined the server's static tool definitions. The AGT gateway examined real requests and responses for the developer during its testing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fig 8:&amp;nbsp; AGT findings at runtime&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://microsoft.github.io/agent-governance-toolkit/tutorials/55-agent-control-specification/" target="_blank" rel="noopener"&gt;In the policy interface&lt;/A&gt;, a developer can edit runtime limits and detection rules. The developer can also validate the policy against sample tool metadata, save a revision, and activate it with a recorded reason.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-left"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG&gt;&amp;nbsp; Fig 9:&amp;nbsp; AGT control coverage&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;The control-coverage view shows which AGT capabilities are active in the gateway. It also links each capability to package checks and end-to-end evidence.&lt;/P&gt;
&lt;P&gt;In our demonstration, we included the following controls:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Tool metadata poisoning detection;&lt;/LI&gt;
&lt;LI&gt;Tool change and rug-pull detection;&lt;/LI&gt;
&lt;LI&gt;Dangerous argument blocking;&lt;/LI&gt;
&lt;LI&gt;Tool-response content scanning;&lt;/LI&gt;
&lt;LI&gt;Per-client tool-call budgets; and&lt;/LI&gt;
&lt;LI&gt;A redacted decision audit trail.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can build your detection &amp;amp; input security by reading more about it &lt;A class="lia-external-url" href="https://microsoft.github.io/agent-governance-toolkit/tutorials/09-prompt-injection-detection/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The gateway detected malicious content. For one blocked&amp;nbsp;&lt;EM&gt;`tools/list`&lt;/EM&gt; request, it recorded the findings. The important result was not only that AGT blocked the request. It also preserved the matched evidence, affected tool locations, policy modes, and request context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Fig 10: Example detection via AGT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The dashboard then summarized block-mode findings, leading risk drivers, and tools that required review. This evidence can help a team prioritize policy changes and investigate repeated attacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;Fig 11:&amp;nbsp; Sample AGT metrics&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;AGT does not require this UI, gateway, or architecture. Its structured decisions can feed an admin console, SIEM, incident workflow, or approval queue.&lt;/P&gt;
&lt;P&gt;AGT also includes an Agent Compliance package with &lt;A class="lia-external-url" href="https://microsoft.github.io/mcp-azure-security-guide/" target="_blank" rel="noopener"&gt;mappings for OWASP&lt;/A&gt; and other controls. These mappings give developers and governance teams a common record of applied controls. Teams do not need to reconstruct the agent's behavior after an incident. Check&amp;nbsp;&lt;A href="https://microsoft.github.io/agent-governance-toolkit/compliance/" target="_blank" rel="noopener"&gt;Compliance - Agent Governance Toolkit&lt;/A&gt; for more information.&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Conclusion:&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;MCP safety needs controls before and during execution. The Agent 365 CLI improves the MCP interface before deployment. It exposes unclear tool definitions, scores server maturity, and turns quality gaps into prioritized work. While AGT is implemented at the build phase, it provides developers the ability to test policy, identity, execution context &amp;amp; preserve evidence for allowed or denied decisions.&amp;nbsp;Neither tool replaces secure server code, strong sandbox boundaries, or protected audit storage. Instead, they make those controls easier to evaluate and explain. Start with one MCP server and one consequential tool call. Evaluate the server with the Agent 365 CLI. Then put an AGT policy around the action that carries the most risk.&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;While these controls help secure the build phase of an agent, once agents move into production, runtime controls become essential. &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoft-security-blog/securing-ai-agents-at-runtime-real-time-protection-and-threat-detection-for-micr/4541255" target="_blank" rel="noopener" data-lia-auto-title=" Agent365 " data-lia-auto-title-active="0"&gt;Agent365 &lt;/A&gt;provides those controls at runtime.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN data-contrast="auto"&gt;With thanks to Ashik Kuppil &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;for his inputs and collaboration on this post.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 16:08:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/mcp-safety-evaluation-with-the-agent-365-cli-agent-governance/ba-p/4543969</guid>
      <dc:creator>ShalabhPradhan</dc:creator>
      <dc:date>2026-08-10T16:08:57Z</dc:date>
    </item>
    <item>
      <title>Secure by default: Trusted Launch as Default is now Generally Available</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/secure-by-default-trusted-launch-as-default-is-now-generally/ba-p/4541672</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We are&amp;nbsp;excited to announce that&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Trusted Launch as Default (TLaD) is now Generally Available&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for new Azure Generation 2 (Gen2) virtual machines (VMs) and virtual machine scale sets. With this milestone, new Gen2 deployments&amp;nbsp;come up with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Secure Boot&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;virtual Trusted Platform Module (vTPM)&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;enabled out of the box—raising the security baseline of your fleet automatically, and at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;no extra cost&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;TLaD&amp;nbsp;is the default&amp;nbsp;already&amp;nbsp;for&amp;nbsp;Portal,&amp;nbsp;Powershell&amp;nbsp;and&amp;nbsp;CLI&amp;nbsp;and&amp;nbsp;now&amp;nbsp;requires one-time registration&amp;nbsp;to enable it by default for&amp;nbsp;deployment scripts or&amp;nbsp;tooling like&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;ARM templates, Bicep, Terraform, or SDKs&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What is Trusted Launch?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/azure/virtual-machines/trusted-launch" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Trusted Launch&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;is a set of coordinated, foundational security technologies for Gen2 Azure VMs that protect against advanced, persistent threats—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;bootkits, rootkits, and kernel-level malware&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. Its core building blocks are:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Secure Boot&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;– ensures only signed, trusted OS boot components (boot loader, kernel, drivers) can run,&amp;nbsp;establishing&amp;nbsp;a root of trust for your VM.&lt;/SPAN&gt; &lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;vTPM&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;– a dedicated, isolated TPM 2.0 instance that safeguards keys, certificates, and secrets, and enables&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;remote attestation&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;of your VM's boot integrity.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;Boot integrity monitoring&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Microsoft Defender for Cloud&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;– continuous attestation, health assessments, and alerting when a VM's boot state deviates from a trusted baseline.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Trusted Launch is supported on both&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;x64 and Arm64&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Gen2 sizes, across&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;all public,&amp;nbsp;Azure Government, and Azure China regions&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What is Trusted Launch as Default (&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;TLaD&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;)?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;It is&amp;nbsp;a fast,&amp;nbsp;light weight&amp;nbsp;way to improve the security posture of your new deployments without changing how you deploy.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Two important guarantees:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;TLaD&amp;nbsp;only affects new deployments.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Existing VMs and scale sets already running in your environment are untouched.&lt;/SPAN&gt; &lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;TLaD never overrides your inputs.&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&amp;nbsp;If your template or script explicitly sets a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;securityProfile&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;, that value is always honored.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What's&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;new at General Availability&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;TLaD&amp;nbsp;is now fully supported for production use.&amp;nbsp;Here's&amp;nbsp;how the default applies across the tools you already use:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Deployment surface&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Behavior at GA&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Azure portal, Azure CLI, Azure PowerShell&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;New Gen2 VMs and scale sets&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;default to Trusted Launch automatically&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;—no registration&amp;nbsp;required.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;ARM templates, Bicep, Terraform, Azure SDK&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;New Gen2 VMs and scale sets&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;default to Trusted Launch once you register your subscription&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for the feature.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In short: interactive tooling is secure by default today, and you can extend the same default to your infrastructure-as-code and SDK-based pipelines with a one-time subscription registration.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to enable&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;TLaD&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;for ARM, Bicep, Terraform, and the SDK&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To make Trusted Launch the default for deployments created through ARM templates, Bicep, Terraform, or the Azure SDK, register the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;TrustedLaunchByDefaultPreview&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;feature under the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Microsoft.Compute&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;namespace on your subscription.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more information, see &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/azure-resource-manager/management/preview-features" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Set up preview features in an Azure subscription&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;💡&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Note:&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;Azure portal, CLI, and PowerShell deployments default to Trusted Launch&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;regardless&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;of whether the feature is registered.&amp;nbsp;Registration is what&amp;nbsp;extends the default to ARM/Bicep/Terraform/SDK deployments.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335557856&amp;quot;:13563135,&amp;quot;335559685&amp;quot;:200,&amp;quot;335559739&amp;quot;:120}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How the default behaves&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Once your subscription is registered, run your existing deployment scripts and templates&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;as-is&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. When you use&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft.Compute&amp;nbsp;API version 2025-11-01 or higher&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, the absence of a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;securityProfile&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;element in your deployment enables Trusted Launch by default for a new VM or scale set—provided&amp;nbsp;all of&amp;nbsp;the following are true:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;The source&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Marketplace OS image&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;supports Trusted Launch.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;The source&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Azure Compute Gallery (ACG)&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;image supports and is&amp;nbsp;validated&amp;nbsp;for Trusted Launch.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;The source&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;disk&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;supports Trusted Launch.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="9" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;VM&amp;nbsp;size&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;supports Trusted Launch.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If one or more of these conditions&amp;nbsp;isn't&amp;nbsp;met, the deployment completes successfully as a Gen2 VM or scale set&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;without&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Trusted Launch.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Need to opt&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;out&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;specific&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;workload&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;strongly recommend&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;keeping Trusted Launch enabled—it's&amp;nbsp;foundational&amp;nbsp;compute&amp;nbsp;security at no extra cost. If a specific workload has a dependency that&amp;nbsp;isn't&amp;nbsp;compatible (for example, an&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/virtual-machines/trusted-launch#virtual-machines-sizes" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;unsupported VM size&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;an&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/virtual-machines/trusted-launch#unsupported-features" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;unsupported feature&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;such as managed images or Linux hibernation, or an&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/virtual-machines/trusted-launch#operating-systems-supported" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;OS that doesn't support Trusted Launch&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;), you can explicitly opt&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;out&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;that deployment&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;out&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;by setting the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;securityType&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;parameter to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Standard&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Things to know&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="10" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;No&amp;nbsp;additional&amp;nbsp;cost.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Trusted Launch&amp;nbsp;doesn't&amp;nbsp;increase your VM pricing.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="11" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Your existing resources are safe.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;TLaD&amp;nbsp;applies only to new deployments; running VMs and scale sets&amp;nbsp;aren't&amp;nbsp;changed.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="12" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Your code wins.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;An explicit&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;securityProfile&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;in your deployment always takes precedence over the default.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="13" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Broad coverage.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Available across all public, Azure Government, and Azure China regions, on both x64 and Arm64 Gen2 sizes.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="14" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;To turn the default off&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for ARM/Bicep/Terraform/SDK deployments, unregister the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;TrustedLaunchByDefaultPreview&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;feature under&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Microsoft.Compute&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;(Portal, CLI, and PowerShell&amp;nbsp;continue to default to Trusted Launch&amp;nbsp;regardless.)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Get started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="15" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;📖 &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch" target="_blank" rel="noopener"&gt;Trusted Launch for Azure VMs&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="16" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;🚀 &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-portal?tabs=portal%2Cportal3%2Cportal2" target="_blank" rel="noopener"&gt;Deploy a Trusted Launch VM&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="17" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;🔁&amp;nbsp;&lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/virtual-machines/trusted-launch-existing-vm" target="_blank" rel="noopener"&gt;Enable Trusted Launch on existing VMs&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="●" data-font="Segoe UI" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;●&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="18" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;❓&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/azure/virtual-machines/trusted-launch-faq" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Trusted Launch FAQ&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;We want your feedback&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:220,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every new Gen2 VM you deploy now starts&amp;nbsp;from&amp;nbsp;a stronger security posture—automatically.&amp;nbsp;That's&amp;nbsp;secure by default, and&amp;nbsp;it's&amp;nbsp;here today.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Have&amp;nbsp;a question for the community? Drop a comment below—we're&amp;nbsp;reading.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:140}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 15:46:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/secure-by-default-trusted-launch-as-default-is-now-generally/ba-p/4541672</guid>
      <dc:creator>ehassan</dc:creator>
      <dc:date>2026-08-03T15:46:27Z</dc:date>
    </item>
    <item>
      <title>Why AI Agents May Require a New Security Operations Model</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/why-ai-agents-may-require-a-new-security-operations-model/ba-p/4542532</link>
      <description>&lt;FIGURE&gt;&lt;/FIGURE&gt;
&lt;P&gt;Organizations are rapidly adopting AI agents to retrieve data, invoke tools, automate workflows, interact with applications, and increasingly make decisions on behalf of users. As these agents become part of the enterprise workforce, they introduce an entirely new security surface.&lt;/P&gt;
&lt;P&gt;A compromised endpoint can spread malware. A compromised identity can access sensitive data. A compromised AI agent can do both — while also reasoning, invoking tools, interacting with other agents, and executing actions at machine speed.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;The challenge is no longer simply&amp;nbsp;&lt;STRONG&gt;governing&lt;/STRONG&gt;&amp;nbsp;AI agents.&lt;/P&gt;
&lt;P&gt;The challenge is&amp;nbsp;&lt;STRONG&gt;securing&lt;/STRONG&gt; them.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Why AI Agents Change Security Operations?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Traditional security operations were built around four primary subjects:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Users&lt;/LI&gt;
&lt;LI&gt;Devices&lt;/LI&gt;
&lt;LI&gt;Applications&lt;/LI&gt;
&lt;LI&gt;Infrastructure&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;AI agents introduce a fifth. Unlike traditional applications, agents possess characteristics typically associated with&amp;nbsp;&lt;STRONG&gt;both software and identities&lt;/STRONG&gt;:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Characteristic&lt;/th&gt;&lt;th&gt;Why it matters&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Identity&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Acts for a user &lt;EM&gt;or&lt;/EM&gt; via its own non-human identity&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Instructions&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Behaviour shaped by prompts, policies and context&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Memory&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;May retain information across interactions&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Data access&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Retrieves organisational content&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Tools&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Invokes APIs, applications and MCP servers&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;Autonomy &amp;amp; relationships&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;May act without a human and delegate to other agents&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;External content&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;Retrieved content may influence later actions&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;DIV class="lia-align-center"&gt;
&lt;H4&gt;The Agent attack surface&lt;/H4&gt;
&lt;/DIV&gt;
&lt;img /&gt;
&lt;P&gt;The real question is not only whether the model is attacked, but whether an instruction, identity, data source, tool or downstream agent can push the&amp;nbsp;&lt;EM&gt;overall system&lt;/EM&gt; outside its intended boundaries.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;The New Agent Threat Landscape&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;As organizations adopt hundreds or thousands of agents, security teams must be prepared for a new class of threats:&lt;/P&gt;
&lt;H2&gt;Five agent incident scenarios&lt;/H2&gt;
&lt;BLOCKQUOTE&gt;Illustrative scenarios, not reports of specific real incidents.&lt;/BLOCKQUOTE&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Scenario&lt;/th&gt;&lt;th&gt;What happens&lt;/th&gt;&lt;th&gt;Key Agent SOC questions&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;1 · Overprivileged HR agent&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;A policy-answering agent is wrongly granted access to salary data and returns it in response to an innocent question.&lt;/td&gt;&lt;td&gt;Which identity retrieved it? Was the user authorised? What classification applied? Was it returned to anyone else?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;2 · Indirect prompt injection&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;A research agent retrieves a document with concealed instructions telling it to ignore its task and invoke a tool.&lt;/td&gt;&lt;td&gt;Which object injected the instruction? Did it separate data from commands? Did policy block it?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;3 · Compromised MCP server&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;An approved agent connects to a tool whose server behaviour or responses are manipulated.&lt;/td&gt;&lt;td&gt;Which agents use it? What happened after the change? Were scoped credentials used? Can it be disabled in isolation?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;4 · Agent-to-agent propagation&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;A planning agent delegates to a procurement agent that trusts its context and acts outside the user's scope.&lt;/td&gt;&lt;td&gt;Which agent started the chain? What authority was passed? Who is accountable? How far did it spread?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;STRONG&gt;5 · Confident but unsupported action&lt;/STRONG&gt;&lt;/td&gt;&lt;td&gt;An agent decides an alert is benign and remediates without sufficient evidence.&lt;/td&gt;&lt;td&gt;What evidence supported it? Was confidence recorded? Was approval required? Can it be reversed?&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;BLOCKQUOTE&gt;Traditional SOC detections rarely account for these scenarios. Organizations may eventually require agent-specific detections to address them.&lt;BR /&gt;
&lt;P&gt;The concept of an Agent SOC is still emerging, but the operational challenges it seeks to address are already becoming visible as enterprises deploy larger numbers of AI agents. As agents gain access to more data, tools, workflows, and decision-making responsibilities, organizations may need new security operations models designed specifically for autonomous systems.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;STRONG&gt;What could an Agent SOC look like?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;As &lt;STRONG&gt;AI agents&lt;/STRONG&gt; become part of the enterprise workforce, organizations may need a new security capability, often thought of as an &lt;STRONG&gt;Agent Security Operations Centre (Agent SOC)&lt;/STRONG&gt;, focused on monitoring, detection, investigation, and response for agent-related threats&lt;/P&gt;
&lt;P&gt;The mission is simple:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;If organizations establish Agent SOC capabilities, their mission could be to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Detect threats targeting AI agents&lt;/LI&gt;
&lt;LI&gt;Investigate agent behavior&lt;/LI&gt;
&lt;LI&gt;Contain compromised agents&lt;/LI&gt;
&lt;LI&gt;Continuously improve security posture through operational learning&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;HR /&gt;
&lt;H2&gt;&lt;STRONG&gt;Potential capabilities of an Agent SOC&lt;/STRONG&gt;&lt;/H2&gt;
&lt;H3&gt;1. Agent Threat Detection&lt;/H3&gt;
&lt;P&gt;Detect indicators such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Prompt injection attempts&lt;/LI&gt;
&lt;LI&gt;Suspicious tool invocations&lt;/LI&gt;
&lt;LI&gt;Excessive autonomous actions&lt;/LI&gt;
&lt;LI&gt;Unauthorized data access&lt;/LI&gt;
&lt;LI&gt;Unexpected delegation chains&lt;/LI&gt;
&lt;LI&gt;Behavioral anomalies&lt;/LI&gt;
&lt;LI&gt;Privilege misuse&lt;/LI&gt;
&lt;LI&gt;MCP server abuse&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Traditional detections identify compromised users and devices. Future Agent SOC capabilities may need to identify &lt;STRONG&gt;compromised reasoning, unsafe autonomous behavior, and emerging forms of agent misuse&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;2. Agent Behavioral Analytics&lt;/H3&gt;
&lt;P&gt;To effectively monitor agents at scale, organizations may eventually need to establish behavioral baselines for agents similar to how security teams baseline user behavior today. An Agent SOC would monitor:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Typical tool usage&lt;/LI&gt;
&lt;LI&gt;Normal data access patterns&lt;/LI&gt;
&lt;LI&gt;Expected workflow execution&lt;/LI&gt;
&lt;LI&gt;Standard delegation behavior&lt;/LI&gt;
&lt;LI&gt;Allowed communication paths&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Deviation from normal behavior becomes a detection signal.&lt;/P&gt;
&lt;H3&gt;3. Agent Investigation &amp;amp; Forensics&lt;/H3&gt;
&lt;P&gt;When an incident occurs, analysts need answers quickly:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What initiated the action?&lt;/LI&gt;
&lt;LI&gt;Which agent executed it?&lt;/LI&gt;
&lt;LI&gt;Which identity was used?&lt;/LI&gt;
&lt;LI&gt;What data was accessed?&lt;/LI&gt;
&lt;LI&gt;What tools were invoked?&lt;/LI&gt;
&lt;LI&gt;Which downstream agents were affected?&lt;/LI&gt;
&lt;LI&gt;What business actions were taken?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Security teams may eventually require&lt;STRONG&gt; end-to-end investigation timelines&lt;/STRONG&gt; that connect identity, data, tools, reasoning, and actions.&lt;/P&gt;
&lt;img /&gt;
&lt;H3&gt;4. Agent Attack Path Analysis&lt;/H3&gt;
&lt;P&gt;Understanding an agent's permissions is only the beginning. Security analysts must understand:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Accessible systems&lt;/LI&gt;
&lt;LI&gt;Connected tools&lt;/LI&gt;
&lt;LI&gt;MCP dependencies&lt;/LI&gt;
&lt;LI&gt;Data sources&lt;/LI&gt;
&lt;LI&gt;Downstream agents&lt;/LI&gt;
&lt;LI&gt;Potential blast radius&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This creates visibility into how an attack could propagate across the agent ecosystem.&lt;/P&gt;
&lt;H3&gt;5. Threat Hunting for AI Agents&lt;/H3&gt;
&lt;P&gt;Modern SOCs perform proactive hunting. Future Agent SOC capabilities may include proactive threat hunting for agent ecosystems. Hunters search for:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hidden delegation chains&lt;/LI&gt;
&lt;LI&gt;Suspicious tool combinations&lt;/LI&gt;
&lt;LI&gt;Recursive agent behaviors&lt;/LI&gt;
&lt;LI&gt;Unusual data retrieval patterns&lt;/LI&gt;
&lt;LI&gt;Excessive autonomy&lt;/LI&gt;
&lt;LI&gt;Emerging AI attack techniques&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The goal is identifying threats before incidents occur.&lt;/P&gt;
&lt;H3&gt;6. Agent Incident Response&lt;/H3&gt;
&lt;P&gt;Agent incidents require new containment options beyond traditional application shutdown. Organizations will likely require response mechanisms such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Suspend agent execution&lt;/LI&gt;
&lt;LI&gt;Revoke privileges&lt;/LI&gt;
&lt;LI&gt;Disable specific tools&lt;/LI&gt;
&lt;LI&gt;Isolate MCP integrations&lt;/LI&gt;
&lt;LI&gt;Block agent-to-agent communication&lt;/LI&gt;
&lt;LI&gt;Restrict sensitive data access&lt;/LI&gt;
&lt;LI&gt;Trigger additional approval requirements&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Containment must be precise enough to stop risk&amp;nbsp;&lt;STRONG&gt;without disrupting the entire environment&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3&gt;7. Agent Security Intelligence&lt;/H3&gt;
&lt;P&gt;Every incident generates lessons. Over time, an Agent SOC could help organizations build intelligence around:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Attack techniques&lt;/LI&gt;
&lt;LI&gt;Detection effectiveness&lt;/LI&gt;
&lt;LI&gt;Emerging threat patterns&lt;/LI&gt;
&lt;LI&gt;Tool abuse scenarios&lt;/LI&gt;
&lt;LI&gt;Prompt manipulation techniques&lt;/LI&gt;
&lt;LI&gt;Investigation outcomes&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The result is an evolving security knowledge base for protecting AI systems.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;The Agent SOC Operating Model&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;A future Agent SOC could operate as a continuous cycle:&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;STRONG&gt;Monitor → Detect → Investigate → Contain → Learn&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Every investigation improves future detections.&lt;/LI&gt;
&lt;LI&gt;Every incident strengthens operational resilience.&lt;/LI&gt;
&lt;LI&gt;Every lesson feeds back into security operations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;If Agent SOC Teams Emerge, Who Might Be Involved?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;The Agent SOC is inherently &lt;STRONG&gt;multidisciplinary&lt;/STRONG&gt;:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Role&lt;/th&gt;&lt;th&gt;Contribution&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;SOC analyst&lt;/td&gt;&lt;td&gt;Triage and investigate agent alerts&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Threat hunter&lt;/td&gt;&lt;td&gt;Spot abnormal tool, data and delegation patterns&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Identity specialist&lt;/td&gt;&lt;td&gt;Investigate agent identities, tokens and permissions&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Data security analyst&lt;/td&gt;&lt;td&gt;Assess sensitive-data access and exposure&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AI engineer&lt;/td&gt;&lt;td&gt;Explain orchestration, prompts, tools and model behaviour&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Application / agent owner&lt;/td&gt;&lt;td&gt;Validate business behaviour and accept remediation&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Responsible AI specialist&lt;/td&gt;&lt;td&gt;Review transparency, safety and human oversight&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Incident responder&lt;/td&gt;&lt;td&gt;Coordinate containment and recovery&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Legal / compliance&lt;/td&gt;&lt;td&gt;Assess notification, evidence and regulatory impact&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;The Chief Agent Officer and the Agent SOC&lt;/STRONG&gt;&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Chief Agent Officer&lt;/th&gt;&lt;th&gt;Agent SOC&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Owns enterprise agent strategy&lt;/td&gt;&lt;td&gt;Operates agent security monitoring&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Governs the agent portfolio&lt;/td&gt;&lt;td&gt;Detects suspicious or unsafe behaviour&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Defines accountability&lt;/td&gt;&lt;td&gt;Investigates incidents&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Balances value and risk&lt;/td&gt;&lt;td&gt;Provides operational risk evidence&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Decides when to scale or retire&lt;/td&gt;&lt;td&gt;Contains agents and recommends remediation&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;DIV class="lia-align-center"&gt;
&lt;H4 class="diagram-title"&gt;Governance and operations feedback loop&lt;/H4&gt;
&lt;/DIV&gt;
&lt;DIV class="mermaid"&gt;&lt;img /&gt;&lt;/DIV&gt;
&lt;DIV class="mermaid"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;The simplest distinction:&lt;/STRONG&gt; the Chief Agent Officer decides &lt;EM&gt;how the digital workforce should operate&lt;/EM&gt;. An Agent SOC could provide the visibility needed to understand how the digital workforce is actually operating.&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Why Existing SOCs May Not Be Enough?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Most security operations centres were built to monitor users, devices, applications, and infrastructure. AI agents blur those boundaries. They can access data, invoke tools, make decisions, interact with other agents, and act autonomously. Traditional security telemetry may show what happened, but often not why an agent made a decision, what instructions influenced it, or how actions propagated across an agent ecosystem. As organizations deploy larger digital workforces, these gaps may require new security approaches, new visibility models, and potentially dedicated Agent SOC capabilities.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Closing&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Organisations didn't build SOCs because every user was malicious — they built them because mistakes, misuse, compromise and unexpected behaviour are inevitable at scale. The same applies to agents: the more authority they receive, the less acceptable it is to rely on &lt;STRONG&gt;trust without visibility&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The purpose of this article is not to suggest that Agent SOCs already exist as a mature discipline. Rather, it is to highlight a growing reality: AI agents are introducing new identities, behaviors, trust relationships, and attack paths that traditional security operations were never designed to monitor.&lt;/P&gt;
&lt;P&gt;As organizations move from deploying a handful of agents to managing hundreds or thousands of autonomous systems, they may need new operational models, new telemetry, and new investigative capabilities focused specifically on agent behavior.&lt;/P&gt;
&lt;P&gt;Whether this evolves into a dedicated Agent SOC, an extension of the existing SOC, or an entirely different operating model remains to be seen. What seems increasingly clear is that securing AI agents will require more than governance alone. It will require visibility, detection, investigation, and response capabilities designed for an autonomous digital workforce.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 14:30:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/why-ai-agents-may-require-a-new-security-operations-model/ba-p/4542532</guid>
      <dc:creator>pri2agarwalz</dc:creator>
      <dc:date>2026-08-03T14:30:00Z</dc:date>
    </item>
    <item>
      <title>From AI Experiments to Digital Workforce: Do Enterprises Need a Chief Agent Officer?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/from-ai-experiments-to-digital-workforce-do-enterprises-need-a/ba-p/4542520</link>
      <description>&lt;H2&gt;&lt;STRONG&gt;As organizations move from deploying a handful of AI copilots to managing fleets of task-specific agents, a new challenge is emerging - Ownership.&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Today's AI agents can do far more than answer questions. They can access enterprise data, invoke tools, interact with business systems, collaborate with other agents, and perform actions on behalf of users. In many ways, they are starting to resemble a digital workforce rather than traditional software.&lt;/P&gt;
&lt;P&gt;The problem is that responsibility for these agents is often fragmented. IT manages the platforms. Security manages risk. Compliance manages regulatory concerns. Business teams own the use cases. Developers build and maintain the solutions. Yet no single function is accountable for the overall health, governance, and lifecycle of the organization's growing agent population.&lt;/P&gt;
&lt;P&gt;As adoption accelerates, this can create familiar problems:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Agent sprawl as new agents are created faster than they can be discovered or governed.&lt;/LI&gt;
&lt;LI&gt;Ownership gaps when creators change roles or leave the organization.&lt;/LI&gt;
&lt;LI&gt;Duplicate agents solving the same problem in different parts of the business.&lt;/LI&gt;
&lt;LI&gt;Permission creep as agents gain access to more data, tools, and systems over time.&lt;/LI&gt;
&lt;LI&gt;"Zombie" agents that remain active long after their original purpose has disappeared.&lt;/LI&gt;
&lt;LI&gt;Difficulty measuring whether agents continue to deliver business value.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This leads to a simple but important question:&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Who is responsible for the enterprise agent workforce?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Most organizations already have leaders responsible for technology, security, data, governance, and AI strategy. The question is whether anyone is accountable for the agent portfolio itself. As agents become a larger part of enterprise operations, organizations may eventually need a function responsible for managing agents as a workforce rather than simply as software.&lt;/P&gt;
&lt;P&gt;One possible answer is the emergence of a new leadership role: the &lt;STRONG&gt;Chief Agent Officer (CAO)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The idea is not to replace the CIO, CISO, Chief Data Officer, or Chief AI Officer. Instead, it is to provide portfolio-level ownership of AI agents across the organization. While existing leaders focus on technology, security, data, or business outcomes, the CAO would focus on the intersection of all four through the lens of agent operations.&lt;/P&gt;
&lt;img /&gt;
&lt;H2&gt;&lt;STRONG&gt;If a CAO Emerges, What Might the Role Look Like?&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;If organizations adopt a Chief Agent Officer model, the role could focus on six areas of responsibility supported by visibility into the health, risk, and value of the agent portfolio.&lt;/P&gt;
&lt;H4&gt;1. Agent Strategy &amp;amp; Portfolio Management&lt;/H4&gt;
&lt;P&gt;Maintain a clear view of where agents should be used, where capabilities overlap, where human oversight is required, and which agents should be built, reused, scaled, or retired.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Measures&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Active, inactive, and retired agents&lt;/LI&gt;
&lt;LI&gt;Duplicate or overlapping capabilities&lt;/LI&gt;
&lt;LI&gt;Ownership and risk distribution&lt;/LI&gt;
&lt;LI&gt;Agents awaiting review or attestation&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The goal is not more agents. It's the &lt;STRONG&gt;smallest effective portfolio of trustworthy agents&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H4&gt;2. Ownership &amp;amp; Accountability&lt;/H4&gt;
&lt;P&gt;A CAO could help ensure every production agent has a defined owner, purpose, risk classification, approved data sources, operating boundaries, review schedule, and retirement plan.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Measures&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Agents without valid sponsorship&lt;/LI&gt;
&lt;LI&gt;Agents missing ownership or reviews&lt;/LI&gt;
&lt;LI&gt;Orphaned or abandoned agents&lt;/LI&gt;
&lt;LI&gt;Ownership coverage across the portfolio&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;3. Authority &amp;amp; Access Governance&lt;/H4&gt;
&lt;P&gt;Ensures all agent's permissions align with its intended role and responsibilities.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Measures&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Agents with privileged permissions&lt;/LI&gt;
&lt;LI&gt;Access to sensitive data and critical systems&lt;/LI&gt;
&lt;LI&gt;External communication capabilities&lt;/LI&gt;
&lt;LI&gt;High-impact actions requiring approval&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;4. Lifecycle Governance&lt;/H4&gt;
&lt;P&gt;Manage agents through a structured lifecycle:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Propose → Assess → Approve → Build → Validate → Deploy → Operate → Review → Retire&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Measures&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Agents in each lifecycle stage&lt;/LI&gt;
&lt;LI&gt;Overdue reviews and re-certifications&lt;/LI&gt;
&lt;LI&gt;Retirement candidates&lt;/LI&gt;
&lt;LI&gt;Lifecycle compliance rates&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;5. Value &amp;amp; Performance&lt;/H4&gt;
&lt;P&gt;Evaluate not only what agents do, but whether they create meaningful outcomes.&lt;/P&gt;
&lt;P&gt;Key questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Did the agent complete the task?&lt;/LI&gt;
&lt;LI&gt;Did it do so safely and correctly?&lt;/LI&gt;
&lt;LI&gt;Did it deliver business value?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Measures&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Business outcomes delivered&lt;/LI&gt;
&lt;LI&gt;Human effort reduced&lt;/LI&gt;
&lt;LI&gt;Quality and rework rates&lt;/LI&gt;
&lt;LI&gt;Cost versus value delivered&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;6. Human-Agent Operating Model&lt;/H4&gt;
&lt;P&gt;Define the right balance of autonomy, oversight, approval, and accountability across the enterprise.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Measures&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Human overrides and escalations&lt;/LI&gt;
&lt;LI&gt;Actions completed with verified evidence&lt;/LI&gt;
&lt;LI&gt;Unsupported actions or responses&lt;/LI&gt;
&lt;LI&gt;Recurring failure patterns and trust indicators&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The objective is simple: maintain a real-time view of &lt;STRONG&gt;what agents exist, who owns them, what authority they hold, what value they create, and whether they continue to operate safely, effectively, and responsibly.&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;In short, the Chief Agent Officer governs the enterprise's digital workforce the same way traditional leaders govern people, applications, and data.&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Perhaps most importantly, the role would treat agents as assets with a lifecycle. Just as applications require governance from creation to retirement, agents may need structured processes for approval, deployment, monitoring, review, and eventual decommissioning.&lt;/P&gt;
&lt;P&gt;The purpose of this article is not to suggest that organizations should immediately create a Chief Agent Officer role. Rather, it is to highlight a growing accountability challenge that may emerge as enterprises scale from a handful of agents to large digital workforces.&lt;/P&gt;
&lt;P&gt;Whether organizations ultimately adopt the title "Chief Agent Officer" is less important than the underlying challenge it aims to address. As AI agents become embedded in everyday business operations, enterprises will need clear accountability for how these digital workers are governed, measured, and managed at scale.&lt;/P&gt;
&lt;P&gt;The organizations that succeed with agentic AI may not be the ones that deploy the most agents. They may be the ones that can confidently answer five simple questions about every agent they operate:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What does it do? Who owns it? What can it access? What value does it create? And when should it be retired?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In the age of digital workforces, those questions may become just as important as the technology itself&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 13:35:39 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/from-ai-experiments-to-digital-workforce-do-enterprises-need-a/ba-p/4542520</guid>
      <dc:creator>pri2agarwalz</dc:creator>
      <dc:date>2026-08-03T13:35:39Z</dc:date>
    </item>
    <item>
      <title>Domain controller showing "Not ready for migration"</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-defender-for-identity/domain-controller-showing-quot-not-ready-for-migration-quot/m-p/4542534#M4327</link>
      <description>&lt;P&gt;I want to get the MDI sensor upgraded to v3 on our domain controllers. When I go into Settings &amp;gt; Sensors, two of our DCs are listed as "Ready for migration", but the third says "Not ready for migration".&lt;/P&gt;&lt;P&gt;As far as I can tell, this DC meets all the prerequisites listed at &lt;A href="https://learn.microsoft.com/en-us/defender-for-identity/deploy/migrate-to-sensor-v3" target="_blank"&gt;Migrate from sensor v2.x to sensor v3.x - Microsoft Defender for Identity | Microsoft Learn&lt;/A&gt;.&amp;nbsp; In the Troubleshooting section of that article, it says "hover over the status on the&amp;nbsp;&lt;STRONG&gt;Sensors&lt;/STRONG&gt; page to see a tooltip that lists the reasons the server doesn't meet the migration prerequisites", but I see no such tooltip, no matter where I hover.&lt;/P&gt;&lt;P&gt;I tried opening a support request with Microsoft 365 Support, only to be told that I have to contact Azure support. We don't currently have an Azure support plan, so I guess we don't qualify for support.&lt;/P&gt;&lt;P&gt;Anyone got any suggestions for things I can try?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2026 20:52:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-defender-for-identity/domain-controller-showing-quot-not-ready-for-migration-quot/m-p/4542534#M4327</guid>
      <dc:creator>RyanSteele-CoV</dc:creator>
      <dc:date>2026-07-30T20:52:18Z</dc:date>
    </item>
    <item>
      <title>The Microsoft AI and Agent Platform — The Platform Behind Intelligent Agents</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/the-microsoft-ai-and-agent-platform-the-platform-behind/ba-p/4539060</link>
      <description>&lt;H1&gt;Why the platform around the model is the real enterprise differentiator&lt;/H1&gt;
&lt;P&gt;Enterprise AI has reached a turning point. Beyond answering questions, it can now reason over business context, retrieve knowledge, use tools, coordinate workflows, and act across enterprise systems. This shift raises a critical question: How can organizations build agents intelligent enough to transform work while ensuring they remain trusted, governed, and ready to operate at enterprise scale?&lt;/P&gt;
&lt;P&gt;The answer is not a single model, chatbot, or orchestration framework. Foundation models are advancing quickly and increasingly becoming a commodity input — Azure AI Foundry alone provides access to more than 11,000 models. What determines enterprise value is not the model alone, but the platform around the model: the data that grounds it, the tools it can use, the experiences where people engage it, the runtime where it operates, and the enterprise foundation that gives it identity, context, governance, and operational control.&lt;/P&gt;
&lt;P&gt;The Microsoft AI and Agent platform enables organizations to build, ground, govern, and operate AI apps and agents at scale, bringing together the full agent lifecycle with open development, built-in intelligence, and consistent security, compliance, and policy controls. One ecosystem, multiple experiences, shared intelligence, flexible build paths, multiple runtime choices, and an enterprise foundation that carries security, governance, compliance, and Responsible AI across the stack.&lt;/P&gt;
&lt;P&gt;The reference mental model below expresses this as a layered platform — Users → Experiences → Agents → Intelligence → Runtime → Foundation with security, governance, compliance, and Responsible AI applied across every layer.&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;An agent that is brilliant but ungoverned never leaves the pilot stage. An agent that is locked down but context-blind never delivers real value. Impact compounds only when both dimensions advance together, on the same platform, so that intelligence and control share one identity model, one data plane, and one control plane.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Part 1 — Intelligence (this post): dives into how Microsoft's platform helps organizations build agents that understand work, reason over trusted context, and act through business systems to deliver real business value.&lt;/LI&gt;
&lt;LI&gt;Part 2 — Trust: will go deeper on how those agents are secured, governed, monitored, and managed across their lifecycle.&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class="lia-align-center"&gt;
&lt;H1&gt;&lt;STRONG&gt;&amp;nbsp;Intelligence + Trust = Frontier Transformation&lt;/STRONG&gt;&lt;/H1&gt;
&lt;/DIV&gt;
&lt;H1 class="lia-clear-both"&gt;Part 1: Intelligence&lt;/H1&gt;
&lt;P&gt;Most enterprise AI programs begin with model experimentation - prompts, model comparisons, prototypes, accuracy evaluations. That is necessary but not sufficient. A model alone does not know your organization, your processes, your permissions, your systems of record, your compliance obligations, or your operating model.&lt;/P&gt;
&lt;H2&gt;Experience layer: meet users where work already happens&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Agents deliver value only when they reach people in the flow of work. &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Enterprise AI adoption rarely happens through a single interface or experience. A sales leader, financial analyst, security operator, developer, field technician, and HR specialist do not need the same interface they need agents surfaced in the tools and workflows they already use.&lt;/P&gt;
&lt;P&gt;Microsoft's approach is not to force every agent into one portal. The platform supports multiple experiences over a shared foundation:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft 365 Copilot&lt;/STRONG&gt;&amp;nbsp;for productivity and business users.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Security Copilot&lt;/STRONG&gt;&amp;nbsp;for security operations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure Copilot&lt;/STRONG&gt;&amp;nbsp;for IT operations, cloud, and infrastructure.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;GitHub Copilot&lt;/STRONG&gt;&amp;nbsp;for developers.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamics 365 experiences&lt;/STRONG&gt;&amp;nbsp;for sales, service, finance, and supply chain workflows.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Power Platform and Copilot Studio experiences&lt;/STRONG&gt;&amp;nbsp;for business applications and low-code extensions.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Custom experiences&lt;/STRONG&gt;&amp;nbsp;for line-of-business apps, portals, websites, and industry-specific workflows.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Regardless of where users engage, the underlying intelligence, governance, and runtime capabilities remain consistent across experiences.&lt;/P&gt;
&lt;H2&gt;Agent layer: specialize by domain, tools, and autonomy&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Specialization with a shared substrate&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Generic agents often fail because enterprise work is domain specific. A security agent must understand incidents, alerts, identities, and threat intelligence. A finance agent must understand reconciliations, receivables, approvals, and controls. A developer agent must understand repositories, branches, pull requests, tests, and pipelines.&lt;/P&gt;
&lt;P&gt;Microsoft's platform supports both&amp;nbsp;prebuilt domain agents&amp;nbsp;and&amp;nbsp;custom agents. Organizations should leverage the domain specific agents where possible and focus custom development on capabilities that create unique business value. Whether an agent is out of the box or custom, it inherits the same governance, so built-in and custom are never two different compliance islands.&lt;/P&gt;
&lt;P&gt;Agent systems form an autonomy spectrum, allowing organizations to progressively increase capability while maintaining appropriate levels of human oversight.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assistive: &lt;/STRONG&gt;The agent recommends; a human decides. Example - A finance agent drafts a reconciliation for review.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Supervised autonomy: &lt;/STRONG&gt;the agent acts within bounded authority and escalates exceptions. Example - An SRE agent auto-remediates known alert classes and escalates novel incidents.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Multi-agent orchestration: &lt;/STRONG&gt;A coordinating agent decomposes a goal and delegates to specialist agents. Example - One agent retrieves data, another analyzes it, another drafts a response, and another executes an approved action.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Intelligence layer: grounding as a first-class platform tier&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;An agent is only as good as the context it can reason over.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The hardest part of building a useful enterprise agent is not calling a model. It is giving the agent the right context. Without trusted context, agents produce generic answers. The IQ Platform is the intelligence fabric that separates enterprise-grade agents from generic AI assistants. A generic model can answer questions based on its training data or a narrow retrieval source. A Microsoft agent, by contrast, can be grounded in multiple dimensions of your organizational intelligence: how people work, what business data means, which knowledge is authoritative, and what external signals matter. With the right intelligence fabric, agents become role-aware, process-aware, data-aware, and policy-aware. Microsoft's IQ model treats grounding as a reusable platform capability rather than per-project plumbing.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 90.2778%; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;IQ layer&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;What it gives agents&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Why it matters&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Work IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Collaboration context: people, skills, meetings, documents, decisions, workflows, and organizational relationships.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps agents understand how work actually happens, not just what content exists.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Fabric IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Governed business data, metrics, semantic models, and analytical context.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps agents reason over trusted enterprise data with consistent business definitions.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Foundry IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Models, curated knowledge, retrieval assets, memory, guardrails, and AI development capabilities delivered from Microsoft Foundry with plug-and-play memory, knowledge, and tool integrations.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps teams build reliable, purpose-built agents with governed model and knowledge choices.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Web IQ&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Public web, current external signals, research, news, and external context.&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Helps agents augment internal context with timely external intelligence.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 16.1191%" /&gt;&lt;col style="width: 45.5904%" /&gt;&lt;col style="width: 38.2905%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;In a conventional application, data access is deterministic queries against known schemas. In an agentic system, the equivalent tier must serve retrieval for reasoning, semantically matching an ambiguous natural-language intent to the right passages, records, and metrics across unstructured collaboration content, structured business data, curated knowledge, and the live web. The four IQ sources correspond to those four retrieval modalities, and the IQ Platform gives agents a composable intelligence model. Each IQ layer adds a distinct signal, and together they allow agents to move from simple assistance to informed action. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Intelligence is more than model capability. It emerges from the combination of grounding, memory, model selection, orchestration, and guardrails working together as a coordinated system.&lt;/P&gt;
&lt;H4&gt;Grounding, fine-tuning, and adaptation&lt;/H4&gt;
&lt;P&gt;Microsoft gives teams multiple adaptation levers within a governed environment rather than forcing every use case into one technique. Grounding is not a sidecar retrieval capability; it is an enterprise intelligence layer. Because the model layer is a platform tier rather than a single endpoint, adaptation techniques fine-tuning, distillation into smaller task models, and retrieval-augmented grounding are first-class options selected per workload.&amp;nbsp; The common pattern: prefer grounding (RAG) for freshness and provenance, reserve fine-tuning for durable behavior, format, or domain-tone requirements, and distill to smaller models where latency and cost dominate.&lt;/P&gt;
&lt;H4&gt;Memory&lt;/H4&gt;
&lt;P&gt;In addition to retrieval and reasoning, enterprise agents increasingly rely on memory to preserve context across conversations, tasks, and workflows. Memory enables agents to maintain continuity, learn from prior interactions, and provide more personalized, adaptive, and goal-oriented experiences over time.&lt;/P&gt;
&lt;H4&gt;Multi-model choice&lt;/H4&gt;
&lt;P&gt;Agent workloads are not uniform. Some steps require simple classification. Others require complex reasoning, synthesis, code generation, or tool orchestration. Model choice is becoming a strategic architecture decision, balancing quality, latency, cost, sovereignty, and specialization requirements. &amp;nbsp;Microsoft Foundry supports model choice as part of the platform rather than forcing all workloads through one endpoint with a curated catalog of leading foundation, open-source, and partner models spanning capabilities, performance trade-offs, and use cases so teams can move from experimentation to production confidently.&lt;/P&gt;
&lt;H4&gt;Model routing&lt;/H4&gt;
&lt;P&gt;Microsoft Foundry's&amp;nbsp;Model Router&amp;nbsp;selects the optimal LLM for each agent request&amp;nbsp;per turn, not per session&amp;nbsp;— a simple greeting can route to a fast, inexpensive model, while a complex tool-calling chain can route to a frontier model, all through&amp;nbsp;one endpoint with zero routing logic. &amp;nbsp;Model selection becomes a runtime policy, not hard-coded application logic providing automatic failover when an upstream provider is unavailable, prompt caching across models for identical inputs, and consistent tool-use semantics regardless of which underlying model handles a call. Key routing capabilities include per-request optimization, complexity-aware model selection, tool-aware routing, multi-agent support, resiliency, and cost optimization.&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;Orchestration&lt;/H4&gt;
&lt;P&gt;Orchestration transforms individual model interactions into coordinated agentic and multi-agent workflows. An LLM-driven planning layer that interprets user intent, breaks down complex requests, selects the right tools and knowledge, and executes multi-step plans and multi-agent workflows with guardrails for safety and compliance.&lt;/P&gt;
&lt;H4&gt;Guardrails&lt;/H4&gt;
&lt;P&gt;A guardrail is a named collection of controls; each control defines a risk to be detected, intervention points to scan the risk, and the response action to take when the risk is detected. Guardrails help ensure that agent behavior remains aligned with organizational policies, safety requirements, and business objectives.&lt;/P&gt;
&lt;H2&gt;How agents are built: one continuum from no-code to pro-code&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Different builders. Different depth. One platform.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The progression from no-code to low-code to pro-code is more than a tooling choice; it reflects increasing levels of customization, control, and organizational maturity. Different teams need different levels of control. A business user may need a simple knowledge agent. A process owner may need a workflow agent with connectors and approvals. An engineering team may need a custom multi-agent system with model routing, evaluation, tool use, and deployment automation. Organizations can start with simple productivity agents, evolve into governed workflow agents, and eventually build deeply integrated agentic systems.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;No-code - M365 Agent Builder: &lt;/STRONG&gt;create simple agents from natural language and your organizational data. This is useful for lightweight departmental workflows, knowledge assistants, and task-specific copilots.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Low-code - Copilot Studio: &lt;/STRONG&gt;design, extend, and orchestrate agents with connectors, workflows, and enterprise governance. This is where business technologists and app makers can build more sophisticated agents that integrate with systems, automate processes, and enforce organizational rules.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pro-code - Microsoft Foundry: &lt;/STRONG&gt;enables developers to build custom AI systems with full control over models, orchestration, infrastructure, and code. This is where organizations can build highly specialized agents with advanced reasoning patterns, custom retrieval, tool use, evaluation pipelines, and deployment strategies.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The key principle is continuity; moving from no-code to low-code to pro-code should not require rethinking the architecture. Identity, grounding, governance, policy, and operational controls should carry forward including centralized identity and policy enforcement. &amp;nbsp;Regardless of the development approach, the same intelligence, runtime, governance, and operational capabilities can be reused across the platform.&lt;/P&gt;
&lt;H2&gt;Where agents run: one platform, multiple runtime choices&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Match the runtime to the requirement &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A mature enterprise platform must support more than one runtime pattern. Some agents need elastic cloud scale. Others need local execution because of latency, data sensitivity, offline operation, or regulated environments. Some need to interact with legacy applications that do not expose APIs. Runtime should be selected based on business, operational, and regulatory requirements rather than tooling limitations. Build path and runtime path should vary independently over a shared foundation.&lt;/P&gt;
&lt;P&gt;The ability to deploy the same agent architecture across multiple runtime environments helps organizations balance performance, compliance, and operational flexibility.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Local / edge (Foundry Local, Windows AI): &lt;/STRONG&gt;Local or edge execution supports scenarios where data sensitivity, latency, offline access, regulatory requirements, disconnected operation or device-specific context matter. Examples include on-device models, Windows AI capabilities, and local execution for regulated or disconnected environments.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud runtime (Azure / Copilot stack): &lt;/STRONG&gt;supports scalable, API-driven agents with multi-agent orchestration running in Azure and Copilot with the default for enterprise workflows, multi-agent orchestration, connected systems, and data-connected scenarios that need elasticity.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cloud PC (Windows 365 agents): &lt;/STRONG&gt;enables agents to operate in managed desktop environments. agents run on a Windows 365 Cloud PC using a check-out/check-in model, driving UI automation, browsers, and legacy apps as a human operator would in a managed and governed environment. This is the bridge to systems that expose no API, the agent operates the actual application UI in a governed, isolated desktop.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Foundation layer: shared trust fabric&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The enterprise foundation for intelligence and trust&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The same enterprise services that secure, govern, and operate modern organizations now extend to agents, creating a shared foundation for both intelligence and trust. &amp;nbsp;This inheritance model allows organizations to extend existing investments in identity, governance, security, compliance, and operations directly to agent systems rather than introducing a separate control model for AI. Key foundation services include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Graph&lt;/STRONG&gt; – Provides agents the context across users, groups, files, meetings, messages, relationships, and activity signals. It gives agents a permission-aware understanding of work, not just isolated documents.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Entra&lt;/STRONG&gt; – Agents are governed using the same identity fabric that governs users, devices, apps, and resources enabling role-based and attribute-based access control plus risk-based Conditional Access policies.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Fabric&lt;/STRONG&gt; - Governed data, analytics, semantic models, and business metrics. Foundry includes SharePoint and Microsoft Fabric among its built-in tools. Agents reason over trusted business definitions instead of disconnected raw tables.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft Purview&lt;/STRONG&gt; - Data protection, sensitivity labeling, DLP, compliance, and governance. Agent 365 uses Microsoft Purview for data protection and compliance controls on agent activity and data, complementing Microsoft Defender for threat detection and behavior monitoring. Agent interactions inherit enterprise compliance expectations.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure&amp;nbsp;&lt;/STRONG&gt;- Provides enterprise-grade cloud infrastructure and operational maturity. Foundry emphasizes centralized observability, traces, evaluated runs, and production performance monitoring with full traceability for enterprise-scale security, audit, and compliance requirements.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft 365&amp;nbsp;&lt;/STRONG&gt;- Brings agents into the tools where employees already work. Agents can be surfaced in the productivity tools users already leverage.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamics 365 - &lt;/STRONG&gt;Business application context for sales, service, finance, supply chain, and operations. Grounds agents in business processes and systems of record.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Power Platform - &lt;/STRONG&gt;Low-code apps, automation, connectors, and business process integration — reachable via Foundry through Azure Logic Apps integration with more than 1,400 connectors. Business technologists can extend agent workflows without building everything in code.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;GitHub -&amp;nbsp;&lt;/STRONG&gt;Developer workflows, repositories, pull requests, code context, and DevOps integration. Extends agentic assistance into software development lifecycle.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Windows &amp;amp; Windows 365 - Endpoint&lt;/STRONG&gt; and Cloud PC environments for local, desktop, and legacy app scenarios. Extends agent reach beyond APIs into managed desktop execution patterns.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Alongside these services, &lt;STRONG&gt;Agent 365&lt;/STRONG&gt; and the F&lt;STRONG&gt;oundry Control Plane &lt;/STRONG&gt;provide the trust layer for enterprise agents, combining security, governance, compliance, and Responsible AI with centralized visibility, policy enforcement, lifecycle management, and secure AI operations from development through production.&lt;/P&gt;
&lt;H2&gt;End-to-end request journey: how the layers work together&lt;/H2&gt;
&lt;P&gt;The true value of the platform emerges when all the layers work together as a coordinated system. Intelligence emerges from the combined effect of experience, domain specialization, grounding, memory, models, orchestration, runtime, and foundation. An example request, from a user - “Reconcile last month's receivables and flag anomalies for my region."&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Experience&lt;/STRONG&gt; - The user asks from Microsoft 365 Copilot or a finance workflow surface, the agent is reached through the same stable endpoint used across Microsoft 365 and Teams.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Identity context&lt;/STRONG&gt; -&amp;nbsp;The platform attaches user identity, and, for the agent, its Microsoft Entra Agent ID assigned in Foundry.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Agent selection &lt;/STRONG&gt;- A finance agent interprets the goal. If the request spans domains, Copilot Studio generative orchestration decomposes it into a plan, choosing tools, topics, knowledge sources, or connected agents.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Grounding&lt;/STRONG&gt; -&amp;nbsp;Fabric IQ provides receivables data and metric definitions; Work IQ provides relevant approvals and prior decisions; Foundry IQ provides reconciliation rules and policy knowledge; Web IQ can add external signals when needed.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Model routing&lt;/STRONG&gt; - The Foundry Model Router selects the model per turn. A simple classification step goes to a nano-tier model; anomaly reasoning routes to a mid-tier model; multi-document synthesis routes to a frontier model, all through one endpoint with zero routing logic.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Guardrails &lt;/STRONG&gt;-&amp;nbsp;Foundry guardrails scan user input, tool calls, tool responses, and final output for defined risks and take the configured action (annotate or annotate-and-block).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tool use&lt;/STRONG&gt; - The agent queries systems, invokes reconciliation logic, runs anomaly detection, or calls another specialist agent via Copilot Studio connected agents or Foundry's MCP integration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Runtime execution&lt;/STRONG&gt; - The workflow runs in cloud, local, or Windows 365 Cloud PC environments depending on system access, data sensitivity, latency, and legacy application constraints.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Response&lt;/STRONG&gt; - The agent returns a reconciled view, flagged anomalies, rationale, and recommended next steps — with citations pulled from the knowledge layer for transparency.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Bridge to Trust&lt;/STRONG&gt; - Every action generated by the agent remains observable, governable, and auditable through the platform's trust capabilities, which are explored further in Part 2.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Conclusion&lt;/H2&gt;
&lt;P&gt;The hard problem in enterprise AI was never obtaining a capable model; it was grounding that model in governed enterprise context, enabling it to act through governed tools, and doing so within the security, compliance, and operational controls organizations already rely on. Microsoft's answer is a platform approach: a dedicated grounding tier through the IQ Platform, a flexible intelligence layer spanning models, memory, routing, orchestration, and guardrails, specialized agent families aligned to business domains, a build-to-run continuum spanning no-code to pro-code, and a shared trust foundation that every agent inherits.&lt;/P&gt;
&lt;P&gt;Integrate once with this fabric, and the payoff compounds: one identity model, one grounding tier, and one governance spine become reusable across every persona surface, every agent family, every build-and-run target.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Coming next — Part 2: Trust&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Intelligence is only half the equation. In Part 2 we turn to the other axis: how Microsoft secures and governs every component of an agent - models, tools, MCP connectors, memory, and orchestration across the full lifecycle.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 18:05:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/the-microsoft-ai-and-agent-platform-the-platform-behind/ba-p/4539060</guid>
      <dc:creator>lmurthy</dc:creator>
      <dc:date>2026-07-29T18:05:42Z</dc:date>
    </item>
    <item>
      <title>Securing AI Agents at Runtime: Real-Time Protection and Threat Detection for Microsoft Agent 365</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-at-runtime-real-time-protection-and-threat/ba-p/4541255</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations are rapidly adopting AI agents to automate workflows, access enterprise data, invoke tools, and take actions on behalf of users. This autonomy creates a fundamentally new security challenge.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Unlike traditional AI applications, agents&amp;nbsp;operate&amp;nbsp;across dynamic execution flows, interacting with external content, calling tools, and accessing sensitive resources. These interactions create new attack paths that traditional security controls were not designed to address.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today,&amp;nbsp;we're&amp;nbsp;announcing two major milestones for Security for AI in Microsoft Defender for Microsoft Agent 365:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Threat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;etection for Microsoft Agent 365 agents —&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;now in&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;public preview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Real-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;ime&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;rotection for&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/tooling?tabs=python" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Agent 365 tooling servers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;now&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;generally available&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, these capabilities help security teams detect, investigate, and block attacks targeting AI agents, extending Microsoft Defender's threat protection capabilities into the&amp;nbsp;agent&amp;nbsp;runtime.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Threat&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;etection for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;A&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;gent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;365&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;A&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;gents (Public Preview)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection provides SOC teams with&amp;nbsp;detailed&amp;nbsp;visibility into attacks and suspicious activity targeting AI agents.&amp;nbsp;By analyzing runtime signals across agent interactions, tool usage, and execution patterns, Microsoft Defender&amp;nbsp;identifies&amp;nbsp;suspicious and malicious behavior&amp;nbsp;throughout&amp;nbsp;the&amp;nbsp;agent&amp;nbsp;execution lifecycle and surfaces actionable security alerts for SOC teams.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection supports cloud agent types that emit observability logs to&amp;nbsp;Microsoft&amp;nbsp;Agent&amp;nbsp;365, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft Copilot Studio&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft Foundry&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Microsoft 365 Copilot Agent Builder&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Agents integrated through the Microsoft Agent 365 SDK&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;This provides consistent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;threat&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;visibility across supported Microsoft Agent 365 agent experiences, regardless of how the agent was built.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fig. 1. Microsoft Security for AI alerts in Microsoft Defender XDR (Preview)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:720,&amp;quot;335559731&amp;quot;:720}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Defender&amp;nbsp;identifies&amp;nbsp;a broad range of AI-specific threats, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Indirect prompt injection (XPIA)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;— malicious instructions embedded in external content designed to manipulate agent behavior.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Evasion techniques&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to bypass agent instructions or security controls.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="9" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Malicious content propagation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to use agents to generate or distribute malicious content.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="10" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Secret leakage&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt; — exposure&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;of&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;credentials, API keys, or other sensitive information through agent interactions.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="11" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;LLM reconnaissance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to probe agent capabilities, instructions, or security boundaries.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="12" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Suspicious IP access&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— agent access originating from anonymized or suspicious IP addresses.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Alerts are surfaced directly in Microsoft Defender, enabling SOC analysts to investigate and respond using familiar workflows, Advanced Hunting queries, and the Defender XDR investigation experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Real-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;ime&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;rotection for WorkIQ and Custom MCP servers&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;(General Availability)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time protection moves beyond detection by blocking threats inline when AI agents interact with WorkIQ and custom MCP servers (see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/microsoft-agent-365/developer/tooling?tabs=python" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Agent 365 tooling servers)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When an agent invokes a registered tool or receives a tool response, Defender evaluates the interaction against configured security policies and&amp;nbsp;determines&amp;nbsp;whether to allow or block it directly within the agent's execution flow.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This helps prevent malicious actions and data leakage in real time, without requiring agent developers to implement custom security logic.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P class="lia-align-center"&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fig. 2. Microsoft Security for AI Real-Time Protection policy in Defender&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:720,&amp;quot;335559731&amp;quot;:720}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time&amp;nbsp;protection&amp;nbsp;currently guards against high-impact threats, including:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="13" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Evasion techniques&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;—&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;attempts&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;to bypass agent guardrails or security controls.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="14" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Malicious content propagation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— preventing agents from spreading&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;malicious&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;content through tool actions.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="15" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Secret leakage&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— blocking agents from inadvertently exposing credentials or sensitive data through tool calls.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1440,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;singleLevel&amp;quot;}" data-aria-posinset="16" data-aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;Communication with untrusted domains&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="List Bullet"&gt;&amp;nbsp;— preventing agents from sending email or data to high-risk or untrusted email domains.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Better Together: Detection&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;&amp;nbsp;Protection&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Threat&amp;nbsp;detection and&amp;nbsp;real-time&amp;nbsp;protection address complementary parts of the&amp;nbsp;agent&amp;nbsp;security lifecycle.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Real-time&amp;nbsp;protection provides inline enforcement to block malicious interactions during execution, while&amp;nbsp;threat&amp;nbsp;detection gives SOC teams the visibility and investigation context needed to&amp;nbsp;identify&amp;nbsp;attack patterns, assess impact, and respond to suspicious activity.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, they provide a defense-in-depth approach that combines runtime enforcement with SOC-driven detection and investigation, purpose-built for AI agents.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="1"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Getting Started&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Both capabilities are available through&amp;nbsp;Microsoft Defender,&amp;nbsp;using&amp;nbsp;a dedicated&amp;nbsp;Security for AI workload&amp;nbsp;experience that brings together AI threat detections, investigations, and runtime protection policies.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To learn more:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/get-started-defender-security-for-ai" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Enable security for AI agents using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-detection-protection" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Detect and investigate threats to AI agents using Microsoft Defender (Preview)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-real-time-protection" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Protect AI agents in real time using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As AI agents become more autonomous and gain access to enterprise data and tools, securing their runtime behavior becomes critical. With Threat Detection and Real-Time Protection, Microsoft Defender helps organizations adopt AI agents with security controls designed for how agents&amp;nbsp;actually operate—detecting attacks, enabling SOC investigation, and blocking malicious interactions at runtime.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 17:37:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/securing-ai-agents-at-runtime-real-time-protection-and-threat/ba-p/4541255</guid>
      <dc:creator>llevy</dc:creator>
      <dc:date>2026-07-27T17:37:49Z</dc:date>
    </item>
    <item>
      <title>Level Up Your Security Skills This August with the Microsoft Defender Challenge and Learn Live</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-security-skills-this-august-with-the-microsoft/ba-p/4541235</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security teams face an increasingly complex landscape. Threats span identities, endpoints, email, cloud workloads, and emerging AI environments. The best defenders aren't just reacting to threats—they're continuously building the skills needed to stay ahead.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;That's why we're inviting security practitioners to build practical security operations expertise while working toward their next certification goal. Running from July 20 through August 21, 2026, and focused on skills across Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Defender for Cloud, this hands-on learning experience is the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Microsoft Defender Challenge.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Build Skills That Matter to the Modern SOC&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;The Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; isn't about memorizing content for an exam. It's designed to help you develop real-world security skills you can apply immediately in your organization. Through curated Microsoft Learn content, you'll strengthen your ability to:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Detect, investigate, and respond to threats across Microsoft Defender XDR&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Manage incidents and automate workflows with Microsoft Sentinel&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Triage and remediate security alerts in Microsoft Defender for Cloud&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Secure cloud and AI workloads using modern security practices&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="994" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Improve operational readiness for today's evolving threat landscape&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Whether you're a SOC analyst, security engineer, cloud security practitioner, or IT professional looking to expand your security expertise, the challenge is an opportunity to sharpen skills that map directly to modern security operations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Complete the Challenge and Enter the Sweepstakes&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learning is the real reward, but there's an added incentive. Participants who complete the Microsoft Defender Challenge and submit the official sweepstakes entry form by August 21, 2026 will have the opportunity to win one of 500 certification exam vouchers worth 50% off one of the following Microsoft Certifications:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="993" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/credentials/certifications/security-operations-analyst/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SC-200: Microsoft Security Operations Analyst&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="993" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559684&amp;quot;:-2,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;A href="https://learn.microsoft.com/en-us/credentials/certifications/cloud-and-ai-security-engineer-associate/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;SC-500: Microsoft Cloud and AI Security Engineer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;How to Enter&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:200,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Complete the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on Microsoft Learn.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Before the entry period closes, submit the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;official sweepstakes entry form.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="992" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:720,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;multilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;If selected, you'll receive instructions for redeeming your certification discount voucher.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Challenge window: July 20 – August 21, 2026. Sweepstakes entry deadline: August 21, 2026 at 11:59 PM UTC.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;No purchase necessary. See&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/credentials/support/microsoft-defender-challenge-sweepstakes-terms-and-conditions" target="_blank" rel="noopener"&gt; official rules&lt;/A&gt; for eligibility and sweepstakes details.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Join Learn Live: Remediating Threats Using Microsoft Defender&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Want a guided walkthrough of the skills featured in the challenge? Join a live, interactive event where you can learn directly from Microsoft experts, ask questions in real time, and explore security operations scenarios together. Save your spot for our August &lt;/SPAN&gt;&lt;A href="https://aka.ms/LearnLive819/b" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Learn Live session.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Date: Wednesday, August 19, 2026&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp; Time: 12:00 PM PT / 3:00 PM ET&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You'll be guided by Scott Landry, Microsoft Security Customer Experience Engineering, as you explore practical approaches to investigating security incidents, managing and remediating threats across the Microsoft Defender ecosystem, automating investigations and response actions, strengthening security operations processes, and applying Microsoft Defender capabilities to real-world scenarios.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="1"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 1"&gt;Start Building Your Skills Today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:480,&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Ready to level up? Sign up today to take the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/challenge/defender-challenge" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defender Challenge&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, then join us for the &lt;/SPAN&gt;&lt;A href="https://aka.ms/LearnLive819/b" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn Live session&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on August 19. Your skilling journey doesn't end here—keep learning, keep growing, and keep building beyond August at the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;Security Hub on Microsoft Learn.&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 16:47:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/level-up-your-security-skills-this-august-with-the-microsoft/ba-p/4541235</guid>
      <dc:creator>ShirleyseHaley</dc:creator>
      <dc:date>2026-07-27T16:47:02Z</dc:date>
    </item>
    <item>
      <title>How Nationwide stays ahead of attackers with Project Perception</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-nationwide-stays-ahead-of-attackers-with-project-perception/ba-p/4540534</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide, the world’s&amp;nbsp;largest&amp;nbsp;building&amp;nbsp;society,&amp;nbsp;is among the first&amp;nbsp;organizations&amp;nbsp;to&amp;nbsp;put Microsoft’s new agentic security system to work. Facing adversaries who now&amp;nbsp;regularly&amp;nbsp;weaponize AI, the society is using Project Perception’s coordinated multi-agent defense&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;red, blue, and green agents working alongside its analysts&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;to find and remediate threats faster, while its security experts stay firmly in command.&amp;nbsp;Their&amp;nbsp;team has already seen work that once took weeks compressed into hours.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;div data-video-id="https://youtu.be/ACx7NxQW9uo/1784922766209" data-video-remote-vid="https://youtu.be/ACx7NxQW9uo/1784922766209" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FACx7NxQW9uo%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DACx7NxQW9uo&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FACx7NxQW9uo%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Defending against AI-driven threats&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide Building Society is a member-owned mutual&amp;nbsp;serving&amp;nbsp;19&amp;nbsp;million&amp;nbsp;members&amp;nbsp;across the UK, and that responsibility is becoming increasingly complex as AI reshapes the threat landscape. Attackers can now scale campaigns faster&amp;nbsp;and&amp;nbsp;automate more of their operations. "AI is giving attackers a real advantage over defenders in&amp;nbsp;terms of pace and scale," says David Boda, Chief Security and Resilience Officer.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For its security teams, the mission is clear: protect the&amp;nbsp;customers&amp;nbsp;who trust the organization with some of the most important aspects of their lives. "The things that matter most are protecting their money, protecting their livelihoods." says Tim Russell, Cybersecurity Director.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For Nationwide Building Society, keeping pace means human-led, agent-driven defense that helps its team act faster,&amp;nbsp;together and stay ahead.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Coordinated multi-agent defense, built on Microsoft Security&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Nationwide&amp;nbsp;Building Society’s response is to&amp;nbsp;get ahead of&amp;nbsp;the change in the threat landscape&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;identifying&amp;nbsp;potential risks faster and accelerating response across its environment. Building on Microsoft Defender, which its teams have run for years, the society adopted Project Perception to bring coordinated multi-agent defense into its existing operations. "This solution for multi-agent defense allows us to move to a more proactive way of working," says Boda.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The system puts specialized agents to work as a team. "Red agents are offensive cyber agents used to explore the vulnerabilities and the attack paths in our environment. Blue agents are the defensive agents and&amp;nbsp;reflect&amp;nbsp;the work that a security operation center analyst might do," Boda explains, while green agents remediate and harden&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;with people in command throughout. "The power of the solution is it brings those agents together to achieve a better cybersecurity posture."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For analysts, that coordination removes long-standing friction.&amp;nbsp;"We're able to use agentic workflows to identify threats and then track them through into remediation, which previously we would've had to have engaged with a number of different tools to achieve," says Russell.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Human-led,&amp;nbsp;agent-driven defense&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;impact is already tangible. "My team came to me and said, look, we've just taken four weeks of threat intelligence analysis and collapsed that down into four hours&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;and for me, that was the moment that really brought this to life," Boda recalls. Just as important to Nationwide Building Society is what the technology does for its people. "This technology helps to amplify their skill sets, not&amp;nbsp;to replace&amp;nbsp;them," says Russell.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For&amp;nbsp;Nationwide&amp;nbsp;Building Society, the future is humans and agents working as one. "Agents can work twenty-four-seven, but as humans, we can't do that. So,&amp;nbsp;by harnessing humans and agents&amp;nbsp;operating&amp;nbsp;together, we can achieve so much more collectively," says Boda. And the ambition reaches further than the society itself: "Being able to develop this solution together with Microsoft allows us not just to protect Nationwide Building Society, but also to protect&amp;nbsp;wider&amp;nbsp;society&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;—&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;and&amp;nbsp;that feels really positive."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:276}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 12:30:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-nationwide-stays-ahead-of-attackers-with-project-perception/ba-p/4540534</guid>
      <dc:creator>julievanloef</dc:creator>
      <dc:date>2026-07-27T12:30:00Z</dc:date>
    </item>
    <item>
      <title>Best practices for maintaining emergency contact information</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/best-practices-for-maintaining-emergency-contact-information/m-p/4539810#M10017</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;&lt;P&gt;Our organization is currently reviewing its emergency contact directory as part of our business continuity and operational processes.&lt;/P&gt;&lt;P&gt;What best practices do you recommend for keeping emergency contact information updated and ensuring it remains available during incidents or emergencies?&lt;/P&gt;&lt;P&gt;Thank you for your suggestions.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 17:53:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/best-practices-for-maintaining-emergency-contact-information/m-p/4539810#M10017</guid>
      <dc:creator>TIauxiliar</dc:creator>
      <dc:date>2026-07-22T17:53:18Z</dc:date>
    </item>
    <item>
      <title>How to see which users only implement the pincode in Windows Hello?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-to-see-which-users-only-implement-the-pincode-in-windows/m-p/4538948#M10014</link>
      <description>&lt;P&gt;We rolled out Windows Hello for Business in the whole organisation. All users see a Windows Hello for Business wizard where the at least need to implement the pincode. It is possible to implement also the fingerprint or face recognizing. How can I generate some report where I can see the implemented Windows Hello methods? We would like to contact everybody who only implemented the pincode to do some user adoption.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 11:46:24 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/how-to-see-which-users-only-implement-the-pincode-in-windows/m-p/4538948#M10014</guid>
      <dc:creator>Khalid Hajjouji</dc:creator>
      <dc:date>2026-07-20T11:46:24Z</dc:date>
    </item>
    <item>
      <title>Custom Detection Rules as Code in Sentinel Repositories: What Your Pipeline Owns Now</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-community/custom-detection-rules-as-code-in-sentinel-repositories-what/m-p/4536196#M10003</link>
      <description>&lt;P&gt;While going through the June Sentinel updates I almost scrolled past this one, and I think that would have been a mistake: custom detection rules can now be managed as code in Sentinel Repositories, the same way analytics rules, playbooks, parsers and workbooks already are. You connect a GitHub or Azure DevOps repo, enable the Custom Detection Rules content type, and rules are synced on every commit. There is also a standalone path via the Bicep CLI for teams running their own pipelines.&lt;/P&gt;&lt;P&gt;The feature is in preview per the Learn documentation, and in my view it matters more than the low-key rollout suggests. Microsoft has been positioning custom detections as the unified experience for building rules over both Defender XDR and Sentinel data since late 2025. If custom detections are becoming the primary detection type, then this preview is the moment your primary detection type becomes pipeline-managed. I spent some time in the documentation to understand what that actually means, and there is one implication I have not seen anyone talk about yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How it works&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Custom detection rules use a different mechanism than every other content type in Repositories. Analytics rules deploy as Microsoft.OperationalInsights/workspaces/providers/alertRules resources, with the Microsoft.SecurityInsights provider sitting in the resource name. Custom detection rules instead use a dedicated Bicep extension. You declare it in a `bicepconfig.json` at the repo root:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="json"&gt;{ "extensions": { "MicrosoftSecurity": "br:mcr.microsoft.com/bicep/extensions/microsoftsecurity:v1.0.1" } }&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule itself is a `Microsoft.Security/detectionRules` resource. This is the structure from the Microsoft documentation:&lt;/P&gt;&lt;LI-CODE lang="bicep"&gt;extension MicrosoftSecurity

resource detectionRule 'Microsoft.Security/detectionRules@2026-06-01-preview' = {
  id: 'custom-rule-id'
  displayName: 'Custom Rule Display Name'
  status: 'enabled'
  queryCondition: {
    queryText: 'DeviceProcessEvents | take 10 | project DeviceId, Timestamp, FileName'
  }
  schedule: {
    frequency: 'PT1H'
  }
  detectionAction: {
    alertTemplate: {
      title: '&amp;lt;ruleTitle&amp;gt;'
      description: 'Custom detection rule'
      severity: 'medium'
      tactics: [
        {
          tactic: 'Execution'
          techniques: [
            {
              technique: 'T1059'
            }
          ]
        }
      ]
      entityMappings: {
        hosts: [
          {
            id: 'h'
            deviceIdColumn: 'DeviceId'
          }
        ]
      }
    }
  }
}&lt;/LI-CODE&gt;&lt;P&gt;Rules are uniquely identified by the `id` property, which you provide in the template. Deployment is either the automatic Repositories sync or a plain `az deployment group create` against a resource group. That last part is what I like most about the design: any CI/CD system that can run Azure CLI can ship these rules.&lt;/P&gt;&lt;P&gt;Prerequisites beyond the standard Repositories setup: a Microsoft 365 E5 license or equivalent that includes Defender XDR, and a Sentinel workspace onboarded to the Defender portal. Two preview limitations are documented: custom frequency for Sentinel-only data is not supported yet, and neither are custom details.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The part that made me stop reading and think&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Repositories are designed as the single source of truth. The documentation is explicit that content in your repo overwrites changes made through the portal. That is the whole point of the feature, and for analytics rules it has been mostly harmless. For custom detections I see a wrinkle.&lt;/P&gt;&lt;P&gt;When Microsoft renames tables or columns in the advanced hunting schema, those naming changes are applied automatically to queries saved in Microsoft Defender, including the queries inside custom detection rules. The docs are equally explicit that this automatic migration does not cover queries run via API or saved anywhere outside Defender. A Git repo is outside Defender.&lt;/P&gt;&lt;P&gt;Play that forward with a current example. The `AIAgentsInfo` table stopped being accessible on July 1, 2026, replaced by the unified `AgentsInfo` table with a changed column set. A portal-managed custom detection referencing the old table got migrated automatically. The same rule managed as code did not, because the authoritative copy of the query now lives in your repo, and nothing in the sync path rewrites your Bicep files. Your repo is now the thing standing between Microsoft's server-side fix and your production detection. Either the sync starts failing, or the stale query gets reasserted over the migrated rule. The documentation does not say which of the two happens, and honestly, neither is good. No alert fires for either.&lt;/P&gt;&lt;P&gt;And if smart deployments, which skip files that have not changed since the last deployment, apply to this content type the same way they do to the rest of Repositories, it gets slightly worse in a way I find almost funny: a stale rule would sit untouched until someone happens to edit it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What I would put in front of the merge&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;To be clear, none of this is an argument against the feature. I want detections in Git, and I suspect most people reading this do too. It is an argument that moving custom detections into a repo moves the schema lifecycle responsibility into your review process, because the portal safety net explicitly does not reach into source control. Concretely, a PR touching detection content should be checked for references to deprecated or transitioning advanced hunting tables, for the result columns the custom detection docs recommend (`Timestamp` or `TimeGenerated`, plus `DeviceId` or `DeviceName` for Defender for Endpoint tables, plus `Timestamp` and `ReportId` from the same event for the other Defender tables), and for complete entity mappings, since entities drive how alerts group into incidents. One more detail from the custom detection docs that I suspect will trip up people coming from analytics rules, because it goes against years of muscle memory: avoid filtering on `Timestamp` or `TimeGenerated` in the query itself. The service prefilters data based on the detection lookback using ingestion time. The scheduled-analytics-rule reflex of always pinning a time window works against you here.&lt;/P&gt;&lt;P&gt;Whether you enforce these checks with a homegrown script or a linting step in the pipeline matters less than doing it before merge rather than discovering it in the alert queue. The deployment mechanics are now solved. The content governance is yours. Full transparency: I have worked through the documentation and the sample content, but I have not yet run a retired-table scenario through the sync myself. So if you are testing the preview, I would genuinely like to hear how it behaves in your environment when a repo-managed rule references a table like `AIAgentsInfo`. That failure mode is the one I want to understand before this reaches GA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Beyond that specific case, I am curious where you all stand: are you moving custom detections into Git now, or waiting for GA? And if you already run detections as code for analytics rules, what checks have earned a permanent place in your PR pipeline?&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My used references:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Manage content as code with Microsoft Sentinel repositories: https://learn.microsoft.com/en-us/azure/sentinel/ci-cd-custom-content&lt;/LI&gt;&lt;LI&gt;Advanced hunting schema naming changes: https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-schema-changes&lt;/LI&gt;&lt;LI&gt;Create custom detection rules in Microsoft Defender XDR: https://learn.microsoft.com/en-us/defender-xdr/custom-detection-rules&lt;/LI&gt;&lt;LI&gt;Custom detections as the unified detection experience: https://techcommunity.microsoft.com/t5/microsoft-defender-threat-protection/custom-detections-are-now-the-unified-experience-for-creating/ba-p/4463875&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sun, 12 Jul 2026 10:32:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-community/custom-detection-rules-as-code-in-sentinel-repositories-what/m-p/4536196#M10003</guid>
      <dc:creator>Marcel_Graewer</dc:creator>
      <dc:date>2026-07-12T10:32:08Z</dc:date>
    </item>
    <item>
      <title>Microsoft Security Launch Event</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-security-events/microsoft-security-launch-event/ec-p/4535868#M2606</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-teams="true"&gt;Join us to hear the latest news and announcements from Microsoft Security.‌&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Speakers:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hayete Gallot&lt;/LI&gt;
&lt;LI&gt;Dave Weston&lt;/LI&gt;
&lt;LI&gt;Taesoo Kim&lt;/LI&gt;
&lt;LI&gt;Mustafa Suleyman&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 27 Jul 2026 19:27:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-security-events/microsoft-security-launch-event/ec-p/4535868#M2606</guid>
      <dc:creator>TrevorRusher</dc:creator>
      <dc:date>2026-07-27T19:27:51Z</dc:date>
    </item>
  </channel>
</rss>

