Microsoft Defender XDR
General

Protect AI assets from emerging threats and vulnerabilities using Microsoft Defender

In brief

The documentation now states that real-time protection evaluates tool invocations and responses from Agent 365 agents using Work IQ MCP or customer MCP tools onboarded to Agent 365. The default rule audits activity, while custom rules can block matching actions. It also lists expanded threat-detection examples, including prompt injection, secret leakage, and suspicious IP access.

What Defender admins need to know

Administrators should review how MCP tools are onboarded and whether custom rules are needed to block risky activity; the default behavior audits activity.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Protect AI assets from emerging threats and vulnerabilities using Microsoft Defender

AI agents introduce unique security risks because of their ability to reason, invoke tools, access data, and take autonomous actions on connected systems. Securing agents at scale requires centralized visibility, security posture and risk management, runtime protection, and advanced investigation capabilities to detect the root cause of an attack.

Microsoft Agent 365 provides an enterprise control plane for managing and governing AI agents in your organization. When you enable youran Agent 365 license, Microsoft Defender integrates with Agent 365 to secure all managed agents -agents, including local AI agents on supported endpoints - with. The integration provides discovery, posture management, real-time protection, and investigation. Agents built withThreat detection uses observability data from Microsoft Copilot StudioStudio, Microsoft Foundry, Microsoft 365 Copilot Agent Builder, and agents integrated through the Microsoft Foundry also benefit from detection based on evaluation of model prompts and responses. Agent 365 SDK.

To get started, see Enable security for AI agents using Microsoft Defender.

|---|---|---| | AI agent discovery | Discover all agents onboarded to Agent 365, including local AI agents on supported endpoints and non-Microsoft agents built using the Microsoft Agent 365 SDK. View agent details using Kusto Query Language (KQL) queries in Advanced Hunting in Microsoft Defender, or the AI Assets page in the Defender portal. | Discover AI agents and assess security posture using Microsoft Defender | | Agent security posture management | Use Advanced Hunting in Microsoft Defender, which provides prebuilt queries to help you identify misconfigurations, risky agent settings, and excessive permissions. | Discover AI agents and assess security posture using Microsoft Defender | | Real-time protection | Real‑Real-time protection inspects user prompts,evaluates tool calls,invocations and tool responses throughout the agentic loop,against security policies when Agent 365 agents use Work IQ MCP and customer MCP tools onboarded to Agent 365. The default rule audits activity, while custom rules can block risky activitymatching actions before it executes. Blockedthey execute. Audited and auditedblocked activity is recorded as behaviors in the BehaviorInfo table for hunting and automation. These capabilities help protect against prompt‑based attacks, unsafe tool usage, credential exposure, data exfiltration, and anomalous execution patterns. | Protect AI agents in real time using Microsoft Defender | | Threat detection, investigation, and hunting | Near‑real‑Near-real-time detections surface alerts based onanalyze Agent 365 observability data.data for threats such as indirect prompt injection, evasion techniques, malicious content propagation, secret leakage, large language model (LLM) reconnaissance, and suspicious IP access. Microsoft Defender correlates signals from your Defender productsalerts into incidents, soand advanced hunting lets analysts see the full context of a potential attack, including the relationships between involved entities and the blast radius of AI agent threats. Use Advanced Hunting to query agent activity alongsidewith other security data for investigation and threat hunting.data. | Detect and investigate threats to AI agents using Microsoft Defender|

Protect AI infrastructure using Microsoft Defender