A workforce of security agents that act
ManagementProject Perception is Microsoft's agentic security system inside Defender. Specialised AI agents investigate threats, map attack paths and prioritise fixes on their own, while people stay in control of the decisions that matter.
TechnicalMicrosoft-published agents run in sessions under their own Entra agent identity and role assignment. They chain into read-only playbooks, are started from chat, and pause for human approval before significant actions such as disabling a user or isolating a device.
AI that acts, not only AI that assists
Perception is the top of Microsoft's agentic cyber stack: purpose-built cyber models, a harness that orchestrates them, and specialised agents. It runs on the ISOC foundation in Defender, which supplies the signals, context and controls the agents work with.
Security Copilot
- You ask, it answers or summarises
- An analyst drives every step
- Helps a person do the work faster
Project Perception
- Agents reason, use tools and take action
- Work flows from agent to agent without manual handoffs
- People set direction and approve significant actions
Red, blue and green agents
Red agents probe like an attacker, blue agents investigate and respond, green agents remediate and harden. The output of one agent becomes the input of the next.
From a threat article to what to fix first
Each agent's output feeds the next agent: no manual handoffs.
Chat, agents or playbooks
Three entry points into the same agents. Pick one to see what it looks like (illustrative).
Watch a session, you make the call
A session records everything an agent does: activity, decisions, inputs, outputs and every human intervention. When an agent wants to take a significant action, the session waits for you. Illustrative scenario with fictional data.
Session status
Board view, as in the Sessions list.
Your three options at an approval
- Approve: the agent carries out the action.
- Reject: it skips the action and carries on with other tasks.
- Suggest an alternative: it weighs your idea and may ask again with a new plan.
Every agent needs an identity
Before an agent can work, a Security Admin gives it an identity and permissions. That choice decides what the agent can reach, and how easy it is to govern. Click an option.
Create a new agent identity
Perception creates a Microsoft Entra Agent ID for the agent.
- +Access scoped to the permissions you assign for that agent
- +Actions are traceable to the agent, not to a person
- +Can be governed like other agent identities in Entra
- +Lifecycle independent of employees joining or leaving
Connect an existing user account
The agent uses that user's access and permissions.
- −Inherits everything that user can reach, often far more than the task needs
- −Agent and human activity are harder to tell apart in logs
- −Breaks or lingers when the person changes role or leaves
- −A compromised account now also steers an agent
Security Admin
At least one is required in your organisation.
- Installs and configures agents
- Assigns agent identities and permissions
- Edits and removes agents
Security Reader
Can use every configured agent.
- Starts sessions
- Views and interacts with sessions
- Views session details
Prerequisite: Defender unified role-based access control (URBAC) must be enabled across all Defender workloads. Removing an agent disables it immediately, stops its sessions in progress and marks playbooks that depend on it as needing setup.
Set up your first agent
Microsoft recommends starting with the Threat Intelligence Agent and the Triage Agent: limited permissions, immediate value. Steps advance automatically; click one to pause.
Open Perception
Defender portal (security.microsoft.com) › Perception.
Pick an agent
Agents tab › “Ready for setup” › Set up.
Assign identity
Create a new agent identity (Entra Agent ID).
Grant permissions
Assign the permissions listed on the agent's detail page.
Finish & run
Finish setup, then New session › provide input › Start.
Pros, cons and watch-outs
Promising, and clearly still a preview. Govern the agents like any other privileged identity.
Five-question quiz
Go deeper
Microsoft's documentation, plus the companion ISOC explainer for the foundation underneath.
Project Perception: agentic security system
Microsoft's overview of the models, harness and red, blue and green agents.
Open → Microsoft LearnGet started with Project Perception
Prerequisites, roles, agent setup and your first session.
Read the docs → Microsoft LearnKey concepts: sessions, agents, playbooks
What each agent does and how playbooks chain them.
Read the docs → Microsoft LearnApprove or reject agentic work
How approvals, rejections and alternatives work.
Read the docs → Microsoft LearnWhat are agent identities?
Entra Agent ID, the identity model Perception agents use.
Read the docs → Companion explainerISOC in Microsoft Defender Explained
The signals, context and controls foundation Perception runs on.
Open the ISOC explainer →