Microsoft Defender XDR
General

Ai Agent Real Time Protection

In brief

The documentation now labels Copilot Studio agent protection as Preview and describes protection for Foundry agents, covering user requests, agent responses, tool invocations, and tool responses.

What Defender admins need to know

Administrators can account for these agent types when assessing Microsoft Defender protection coverage. No action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Real-time protection inspects AI agent activity throughout the agentic loop and blocks risky actions before they execute. Coverage depends on the agent type:

  • Agent 365 tool invocations: Defender integrates with Work IQ MCP to evaluate tool invocations before they run, including invocations of customer MCP tools onboarded to Agent 365. Agents that rely on unsupported tools or don't integrate with Work IQ MCP aren't covered.

  • Copilot Studio agents (Preview): Covered by evaluatingProtection evaluates tool invocations, which doesn't depend on Work IQ MCP. To enable it, make sure that Copilot Studio is connected. For more information, see Enable security for AI agents using Microsoft Defender.

  • Foundry agents (Preview): Protection evaluates user requests, agent responses, tool invocations, and tool responses.

  • Local AI agents: Covered through endpoint runtime protection in Microsoft Defender for Endpoint.

For cloud agents, there are two types of real-time protection rules: