Perception Explained
Microsoft Defender · Project Perception · preview

A workforce of security agents that act

ManagementProject Perception is Microsoft's agentic security system inside Defender. Specialised AI agents investigate threats, map attack paths and prioritise fixes on their own, while people stay in control of the decisions that matter.

TechnicalMicrosoft-published agents run in sessions under their own Entra agent identity and role assignment. They chain into read-only playbooks, are started from chat, and pause for human approval before significant actions such as disabling a user or isolating a device.

0specialised agents published by Microsoft
0teams: red, blue and green
0ways to work: chat, agents, playbooks
Humanapproval for significant actions
The agent team · click an agent
The harness in the middle coordinates agents, models, tools and controls. Click an agent to see what it does.
01 · What it is

AI that acts, not only AI that assists

Perception is the top of Microsoft's agentic cyber stack: purpose-built cyber models, a harness that orchestrates them, and specialised agents. It runs on the ISOC foundation in Defender, which supplies the signals, context and controls the agents work with.

Security Copilot

AI that assists
  • You ask, it answers or summarises
  • An analyst drives every step
  • Helps a person do the work faster
vs

Project Perception

AI that acts
  • Agents reason, use tools and take action
  • Work flows from agent to agent without manual handoffs
  • People set direction and approve significant actions
02 · The agent team

Red, blue and green agents

Red agents probe like an attacker, blue agents investigate and respond, green agents remediate and harden. The output of one agent becomes the input of the next.

Example playbook · illustrative

From a threat article to what to fix first

Each agent's output feeds the next agent: no manual handoffs.

03 · Ways to work

Chat, agents or playbooks

Three entry points into the same agents. Pick one to see what it looks like (illustrative).

04 · Sessions and approvals

Watch a session, you make the call

A session records everything an agent does: activity, decisions, inputs, outputs and every human intervention. When an agent wants to take a significant action, the session waits for you. Illustrative scenario with fictional data.

Session · Attack Investigation Agent
Input: incident “Suspicious sign-in followed by mailbox rule”
Start the session to see the agent work.

Session status

Board view, as in the Sessions list.

Your three options at an approval

  • Approve: the agent carries out the action.
  • Reject: it skips the action and carries on with other tasks.
  • Suggest an alternative: it weighs your idea and may ask again with a new plan.
05 · Identity and access

Every agent needs an identity

Before an agent can work, a Security Admin gives it an identity and permissions. That choice decides what the agent can reach, and how easy it is to govern. Click an option.

Recommended by Microsoft

Create a new agent identity

Perception creates a Microsoft Entra Agent ID for the agent.

  • +Access scoped to the permissions you assign for that agent
  • +Actions are traceable to the agent, not to a person
  • +Can be governed like other agent identities in Entra
  • +Lifecycle independent of employees joining or leaving
Use with care

Connect an existing user account

The agent uses that user's access and permissions.

  • −Inherits everything that user can reach, often far more than the task needs
  • −Agent and human activity are harder to tell apart in logs
  • −Breaks or lingers when the person changes role or leaves
  • −A compromised account now also steers an agent

Security Admin

At least one is required in your organisation.

  • Installs and configures agents
  • Assigns agent identities and permissions
  • Edits and removes agents

Security Reader

Can use every configured agent.

  • Starts sessions
  • Views and interacts with sessions
  • Views session details

Prerequisite: Defender unified role-based access control (URBAC) must be enabled across all Defender workloads. Removing an agent disables it immediately, stops its sessions in progress and marks playbooks that depend on it as needing setup.

06 · Getting started

Set up your first agent

Microsoft recommends starting with the Threat Intelligence Agent and the Triage Agent: limited permissions, immediate value. Steps advance automatically; click one to pause.

1

Open Perception

Defender portal (security.microsoft.com) › Perception.

2

Pick an agent

Agents tab › “Ready for setup” › Set up.

3

Assign identity

Create a new agent identity (Entra Agent ID).

4

Grant permissions

Assign the permissions listed on the agent's detail page.

5

Finish & run

Finish setup, then New session › provide input › Start.

07 · Trade-offs

Pros, cons and watch-outs

Promising, and clearly still a preview. Govern the agents like any other privileged identity.

08 · Check your understanding

Five-question quiz

0/5Answer all five questions.
09 · Resources

Go deeper

Microsoft's documentation, plus the companion ISOC explainer for the foundation underneath.