Microsoft Defender XDR
Incidents and response

Security Alert Triage Agent

In brief

The article now labels supported alert types more clearly, separates prerequisite guidance by alert category, updates RBAC terminology and links, and renames feedback guidance links. It also clarifies that existing Phishing Triage Agent users can enable additional alert types through configuration.

What Defender admins need to know

Use the revised prerequisites and alert-type guidance when setting up or expanding triage. No required administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

The Microsoft Security Copilot Security Alert Triage Agent is an autonomous agent embedded in Microsoft Defender that helps security teams triage alerts at scale. It applies AI-driven, dynamic reasoning across evidence to deliver clear verdicts for supported security workloads. By identifying which alerts represent real attacks and which are false positives, the agent enables analysts to focus on investigating real threats, with transparent, step-by-step reasoning to support every decision.

This article provides an overview of the Security Alert Triage Agent, how it works, and its alert triage capabilities. Before you set up the agent, make sure you meet the Security Alert Triage Agent prerequisites, including Security Copilot provisioning, unified RBAC activation, and workload-specific licensing. Watch this video to see a quick demo:

[!VIDEO https://learn-video.azurefd.net/vod/player?id=868ecb6a-6545-4703-b58e-d3130e0c2eaa]

  • Transparent rationale: Records classification verdicts and provides supporting reasoning in natural language and visual graphs, including the evidence used to reach each conclusion.
  • Learning based on feedback: For supported alert types, the agent can incorporate analyst feedback when explicitly provided and approved to tune its verdict analysis. This capability is currently available for email and collaboration alerts only.

Supported alertsalert types for the Security Alert Triage Agent

The Security Alert Triage Agent currently supports the following subset of alert types in Microsoft Defender. The set of supported alerts is expected to grow over time.

Email and collaboration alerts

The following prerequisites apply when you want the agent to triage email and collaboration alerts.

Product and license requirements

The following product and license are required for email and collaboration alerts:

Cloud alerts

The following prerequisites apply when you enable cloud alert triage.

Product and license requirements

Cloud alert triage requires the following products and licenses:

Identity alerts

The following prerequisites apply when you enable identity alert triage.

Product and license requirements

Identity alert triage requires the following products and licenses:

Unified RBAC requirements

Activate Microsoft Defender for Identity and Microsoft Defender for Cloud Apps in Microsoft Defender XDR unified RBAC settings. For more information, see Activate workloads in Microsoft Defender settings.

:::image type="content" source="media/security-alert-triage-agent/rbac-settings-defender-identity.png" alt-text="Screenshot of Microsoft Defender XDR Permissions and roles page showing unified RBAC activation with Identity and Cloud Apps settings." lightbox="media/security-alert-triage-agent/rbac-settings-defender-identity.png":::

| View feedback page | Security Copilot (read), Security data basics (read), and Email & collaboration metadata (read) under the Security operations permissions group in the Defender portal.

OR

Security Administrator in Microsoft Entra ID. | | Reject feedback | Security Administrator in Microsoft Entra ID. |

For more information about unified RBAC in the Defender portal, see Microsoft Defender Unified role-based access control (RBAC).

Set up the Security Alert Triage Agent

Make sure you have the required user permissions and that all agent prerequisites are met before setting up the agent.

Begin setup

:::image type="content" source="media/security-alert-triage-agent/manage-alert-why.png" alt-text="Screenshot highlighting the classification and feedback fields in the Manage alert pane" lightbox="media/security-alert-triage-agent/manage-alert-why.png":::

  1. To apply your feedback, select Use this feedback to teach the agent. You can use the best practices for writing agent feedback to help you craft effective input, and then choose Evaluate feedback to allow you to preview how the agent translates your feedback into a lesson and assess whether the outcome aligns with your intent. Additionally, the feedback evaluation performs basic safety checks to ensure that the applied feedback is relevant for the agent to use and doesn't conflict with previous feedback.
  1. Ensure feedback is relevant and contextual. Feedback should pertain only to the email currently under review. It must also align with the updated classification you've assigned.
  2. Be descriptive and specific. Clearly explain the characteristics of the email. Provide relevant details like the email subject, message body, sender, or recipients to help the agent understand the context. Specific feedback with multiple details enhances effectiveness.
  3. Ensure clarity and decisiveness. Avoid vague or universal statements. Give feedback that's clear and actionable. Use decisive and clear identification terms.
  4. Be consistent with previous feedback. Ensure that new feedback aligns with what was previously provided to avoid contradictions that could confuse the agent or reduce the accuracy of its decisions. You can review all previously submitted input on the agent feedback management management page.
  5. Review the agent's interpretation of your feedback. When you submit feedback, always verify that the feedback is accurately translated into a lesson. Confirm that the lesson reflects your intent and maintains consistency with your original input. Checking the validity of AI-generated responses to ensure they're applicable to the scenario.

Here are examples of how you can write your feedback to the agent.

Frequently asked questions

Following are responses toThis section answers commonly asked questions about the Security Alert Triage Agent. For information about the agent's capabilities and requirements, see How the Security Alert Triage Agent works and Prerequisites.

What is the Security Alert Triage Agent, how does it differ from the Phishing Triage Agent, and how do I onboard if I’m already using the agent to triage phishing alerts?

The Security Alert Triage Agent is the same agent as the Phishing Triage Agent, extended to triage additional alert types beyond email and collaboration. The Security Alert Triage Agent is modular - you choose which alert types you want the agent to triage. The agent now extends to identity and cloud alerts, starting with containers, which are currently in preview. Email and collaboration alert triage capabilities are already generally available (GA). The set of supported alerts is expected to grow over time.

If you’re already using the Phishing Triage Agent, you don’t need to install a new agent. Your existing agent will continue to operate, and you can enable the additional alert types through configuration. To onboard to the expanded capabilities, review the Security Alert Triage Agent prerequisites for the additional alert types and edit the Security Alert Triage Agent settings to select the alert types you want to enable.

Your existing phishing triage configuration and feedback carry over automatically. For more information, see How the Security Alert Triage Agent works and Set up the Security Alert Triage Agent.