Microsoft's new AI agents aim to help security pros combat the latest threats

Microsoft is rolling out a new set of AI agents as part of its Security Copilot initiative, aimed at simplifying the job of security professionals in safeguarding their organizations from modern threats. The announcement came on Monday, with Microsoft developing six of these agents, while five others are crafted by third-party collaborators. Starting in April, all these agents will be available for a preview.
These AI agents, integrated with Microsoft's security software, are designed to assist security teams in managing high-volume security and IT tasks more efficiently. Drawing from Microsoft's Zero Trust framework, these agents are capable of learning from user interactions and adapting to the specific workflows within an organization.
Also: Navigating AI-powered cyber threats in 2025: 4 expert security tips for businesses
Here's a closer look at the six Microsoft-developed agents:
- Phishing Triage Agent in Microsoft Defender: This agent sorts through Microsoft Defender's phishing alerts, distinguishing genuine threats from false alarms. It provides clear explanations for its decisions and can enhance its detection abilities based on your feedback.
- Alert Triage Agent in Microsoft Purview: This agent focuses on prioritizing alerts from Microsoft Purview related to data loss and insider risks. It also refines its operations with your feedback.
- Conditional Access Optimization Agent in Microsoft Entra: This agent scans for new users and applications in Microsoft Entra not covered by current policies. It recommends policy updates to close security gaps and offers quick solutions for identity and authentication issues.
- Vulnerability Remediation Agent in Microsoft Intune: Tailored for Microsoft Intune, this agent prioritizes security vulnerabilities, identifies issues with app and policy configurations, and suggests appropriate Windows patches.
- Threat Intelligence Briefing Agent in Security Copilot: This agent collaborates with Security Copilot to deliver timely and relevant threat intelligence tailored to your organization's specific risks and environment.
Moving on to the five third-party agents, all integrated into Security Copilot:
- Privacy Breach Response Agent by OneTrust: This agent assesses data breaches and provides guidance on meeting regulatory requirements.
- Network Supervisor Agent by Aviatrix: It monitors and analyzes security risks associated with VPN, gateway, and Site2Cloud connection issues.
- SecOps Tooling Agent by BlueVoyant: This agent evaluates your security operations center and offers recommendations for enhancements.
- Alert Triage Agent by Tanium: It contextualizes security alerts to help you decide on the best course of action.
- Task Optimizer Agent by Fletch: This agent prioritizes the most urgent security alerts, aiding in efficient task management.
Microsoft Security Copilot, which was officially launched about a year ago, leverages AI to monitor and analyze potential security threats facing your organization. The aim is to automate routine tasks, thereby freeing up IT and security staff to focus on more pressing issues. Additionally, the AI provides strategic guidance to help teams respond to threats more swiftly and effectively.
Also: AI bots scraping your data? This free tool gives those pesky crawlers the run-around
Security Copilot operates on a flexible pay-as-you-go model, allowing organizations to scale their usage as needed. The cost is calculated monthly based on a Security Compute Unit (SCU) at $4 per hour. If an organization uses one SCU continuously for 24 hours a day throughout a month, the estimated cost would be approximately $2,920.
Kris Bondi, CEO and co-founder of security firm Mimoto, shared with ZDNET, "Security professionals are constantly bombarded with alerts and issues, often lacking sufficient context. While AI agents may not detect threats themselves, they can assist in managing responses to detected threats. An AI agent can be programmed to automatically initiate a multi-step response when triggered by specific cues, alleviating some of the burden from security professionals."
However, AI technology is not infallible. Tools like Security Copilot may miss genuine threats or generate false positives, highlighting the necessity for human oversight. As a relatively new product, many organizations are still navigating the best ways to integrate it into their security strategies.
Also: How AI agents help hackers steal your confidential data - and what to do about it
J. Stephen Kowski, Field CTO at SlashNext Email Security+, told ZDNET, "AI agents hold the promise of enhancing threat response capabilities, but the performance of baseline models has been underwhelming. Many users report that even top-tier solutions miss a significant number of threats. Microsoft's Security Copilot has potential, but its adoption rate is slower than anticipated due to concerns about data management, necessary services, and licensing fees."
Want more stories about AI? Sign up for Innovation, our weekly newsletter.
Related article
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
Google Tests Remy AI Agent for Gemini as Focus Shifts to User Control
According to Business Insider, Google is testing Remy, a new AI personal agent for Gemini. This tool aims to execute tasks on behalf of users, streamlining both professional workflows and daily routines.Currently, Remy is undergoing testing in an int
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust
Related Special Topic Recommendations
Comments (29)
0/500
セキュリティ担当者の仕事がAIで楽になるのは夢のよう!Microsoftの新しいエージェント、特に「脅威検出」の部分がすごく気になる。でも、こういうツールが普及したら、将来的にセキュリティエンジニアの仕事は減っちゃうのかな?少し不安に思う反面、どう進化するのかとても興味津々です😊
Really curious how these AI agents will perform in real-world scenarios. Microsoft's push into security automation could be a game-changer, but I hope they've addressed the 'black box' problem—security pros need to understand the reasoning behind alerts, not just receive them. Also, integration with existing non-Microsoft tools will be key for adoption.
보안 전문가들이 AI 에이전트를 믿고 의존할 수 있을지 걱정이네요. 기술이 발전하긴 했지만, 보안은 아직도 인간의 판단이 중요한 분야인 것 같아요. 마이크로소프트의 이번 시도가 성공할지 지켜봐야겠어요! 🔍

Microsoft is rolling out a new set of AI agents as part of its Security Copilot initiative, aimed at simplifying the job of security professionals in safeguarding their organizations from modern threats. The announcement came on Monday, with Microsoft developing six of these agents, while five others are crafted by third-party collaborators. Starting in April, all these agents will be available for a preview.
These AI agents, integrated with Microsoft's security software, are designed to assist security teams in managing high-volume security and IT tasks more efficiently. Drawing from Microsoft's Zero Trust framework, these agents are capable of learning from user interactions and adapting to the specific workflows within an organization.
Also: Navigating AI-powered cyber threats in 2025: 4 expert security tips for businesses
Here's a closer look at the six Microsoft-developed agents:
- Phishing Triage Agent in Microsoft Defender: This agent sorts through Microsoft Defender's phishing alerts, distinguishing genuine threats from false alarms. It provides clear explanations for its decisions and can enhance its detection abilities based on your feedback.
- Alert Triage Agent in Microsoft Purview: This agent focuses on prioritizing alerts from Microsoft Purview related to data loss and insider risks. It also refines its operations with your feedback.
- Conditional Access Optimization Agent in Microsoft Entra: This agent scans for new users and applications in Microsoft Entra not covered by current policies. It recommends policy updates to close security gaps and offers quick solutions for identity and authentication issues.
- Vulnerability Remediation Agent in Microsoft Intune: Tailored for Microsoft Intune, this agent prioritizes security vulnerabilities, identifies issues with app and policy configurations, and suggests appropriate Windows patches.
- Threat Intelligence Briefing Agent in Security Copilot: This agent collaborates with Security Copilot to deliver timely and relevant threat intelligence tailored to your organization's specific risks and environment.
Moving on to the five third-party agents, all integrated into Security Copilot:
- Privacy Breach Response Agent by OneTrust: This agent assesses data breaches and provides guidance on meeting regulatory requirements.
- Network Supervisor Agent by Aviatrix: It monitors and analyzes security risks associated with VPN, gateway, and Site2Cloud connection issues.
- SecOps Tooling Agent by BlueVoyant: This agent evaluates your security operations center and offers recommendations for enhancements.
- Alert Triage Agent by Tanium: It contextualizes security alerts to help you decide on the best course of action.
- Task Optimizer Agent by Fletch: This agent prioritizes the most urgent security alerts, aiding in efficient task management.
Microsoft Security Copilot, which was officially launched about a year ago, leverages AI to monitor and analyze potential security threats facing your organization. The aim is to automate routine tasks, thereby freeing up IT and security staff to focus on more pressing issues. Additionally, the AI provides strategic guidance to help teams respond to threats more swiftly and effectively.
Also: AI bots scraping your data? This free tool gives those pesky crawlers the run-around
Security Copilot operates on a flexible pay-as-you-go model, allowing organizations to scale their usage as needed. The cost is calculated monthly based on a Security Compute Unit (SCU) at $4 per hour. If an organization uses one SCU continuously for 24 hours a day throughout a month, the estimated cost would be approximately $2,920.
Kris Bondi, CEO and co-founder of security firm Mimoto, shared with ZDNET, "Security professionals are constantly bombarded with alerts and issues, often lacking sufficient context. While AI agents may not detect threats themselves, they can assist in managing responses to detected threats. An AI agent can be programmed to automatically initiate a multi-step response when triggered by specific cues, alleviating some of the burden from security professionals."
However, AI technology is not infallible. Tools like Security Copilot may miss genuine threats or generate false positives, highlighting the necessity for human oversight. As a relatively new product, many organizations are still navigating the best ways to integrate it into their security strategies.
Also: How AI agents help hackers steal your confidential data - and what to do about it
J. Stephen Kowski, Field CTO at SlashNext Email Security+, told ZDNET, "AI agents hold the promise of enhancing threat response capabilities, but the performance of baseline models has been underwhelming. Many users report that even top-tier solutions miss a significant number of threats. Microsoft's Security Copilot has potential, but its adoption rate is slower than anticipated due to concerns about data management, necessary services, and licensing fees."
Want more stories about AI? Sign up for Innovation, our weekly newsletter.
Swedish AI Startup Lovable Eyes $13.2 Billion Valuation After Major Funding Round
As AI-driven coding tools gain traction, Swedish startup Lovable has secured a major funding round. The company aims to raise $3 billion, potentially boosting its valuation to $13.2 billion—double the $6.6 billion recorded last December. Menlo Ventur
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust
セキュリティ担当者の仕事がAIで楽になるのは夢のよう!Microsoftの新しいエージェント、特に「脅威検出」の部分がすごく気になる。でも、こういうツールが普及したら、将来的にセキュリティエンジニアの仕事は減っちゃうのかな?少し不安に思う反面、どう進化するのかとても興味津々です😊
Really curious how these AI agents will perform in real-world scenarios. Microsoft's push into security automation could be a game-changer, but I hope they've addressed the 'black box' problem—security pros need to understand the reasoning behind alerts, not just receive them. Also, integration with existing non-Microsoft tools will be key for adoption.
보안 전문가들이 AI 에이전트를 믿고 의존할 수 있을지 걱정이네요. 기술이 발전하긴 했지만, 보안은 아직도 인간의 판단이 중요한 분야인 것 같아요. 마이크로소프트의 이번 시도가 성공할지 지켜봐야겠어요! 🔍





Home






