Microsoft's new AI agents aim to help security pros combat the latest threats

Microsoft is rolling out a new set of AI agents as part of its Security Copilot initiative, aimed at simplifying the job of security professionals in safeguarding their organizations from modern threats. The announcement came on Monday, with Microsoft developing six of these agents, while five others are crafted by third-party collaborators. Starting in April, all these agents will be available for a preview.
These AI agents, integrated with Microsoft's security software, are designed to assist security teams in managing high-volume security and IT tasks more efficiently. Drawing from Microsoft's Zero Trust framework, these agents are capable of learning from user interactions and adapting to the specific workflows within an organization.
Also: Navigating AI-powered cyber threats in 2025: 4 expert security tips for businesses
Here's a closer look at the six Microsoft-developed agents:
- Phishing Triage Agent in Microsoft Defender: This agent sorts through Microsoft Defender's phishing alerts, distinguishing genuine threats from false alarms. It provides clear explanations for its decisions and can enhance its detection abilities based on your feedback.
- Alert Triage Agent in Microsoft Purview: This agent focuses on prioritizing alerts from Microsoft Purview related to data loss and insider risks. It also refines its operations with your feedback.
- Conditional Access Optimization Agent in Microsoft Entra: This agent scans for new users and applications in Microsoft Entra not covered by current policies. It recommends policy updates to close security gaps and offers quick solutions for identity and authentication issues.
- Vulnerability Remediation Agent in Microsoft Intune: Tailored for Microsoft Intune, this agent prioritizes security vulnerabilities, identifies issues with app and policy configurations, and suggests appropriate Windows patches.
- Threat Intelligence Briefing Agent in Security Copilot: This agent collaborates with Security Copilot to deliver timely and relevant threat intelligence tailored to your organization's specific risks and environment.
Moving on to the five third-party agents, all integrated into Security Copilot:
- Privacy Breach Response Agent by OneTrust: This agent assesses data breaches and provides guidance on meeting regulatory requirements.
- Network Supervisor Agent by Aviatrix: It monitors and analyzes security risks associated with VPN, gateway, and Site2Cloud connection issues.
- SecOps Tooling Agent by BlueVoyant: This agent evaluates your security operations center and offers recommendations for enhancements.
- Alert Triage Agent by Tanium: It contextualizes security alerts to help you decide on the best course of action.
- Task Optimizer Agent by Fletch: This agent prioritizes the most urgent security alerts, aiding in efficient task management.
Microsoft Security Copilot, which was officially launched about a year ago, leverages AI to monitor and analyze potential security threats facing your organization. The aim is to automate routine tasks, thereby freeing up IT and security staff to focus on more pressing issues. Additionally, the AI provides strategic guidance to help teams respond to threats more swiftly and effectively.
Also: AI bots scraping your data? This free tool gives those pesky crawlers the run-around
Security Copilot operates on a flexible pay-as-you-go model, allowing organizations to scale their usage as needed. The cost is calculated monthly based on a Security Compute Unit (SCU) at $4 per hour. If an organization uses one SCU continuously for 24 hours a day throughout a month, the estimated cost would be approximately $2,920.
Kris Bondi, CEO and co-founder of security firm Mimoto, shared with ZDNET, "Security professionals are constantly bombarded with alerts and issues, often lacking sufficient context. While AI agents may not detect threats themselves, they can assist in managing responses to detected threats. An AI agent can be programmed to automatically initiate a multi-step response when triggered by specific cues, alleviating some of the burden from security professionals."
However, AI technology is not infallible. Tools like Security Copilot may miss genuine threats or generate false positives, highlighting the necessity for human oversight. As a relatively new product, many organizations are still navigating the best ways to integrate it into their security strategies.
Also: How AI agents help hackers steal your confidential data - and what to do about it
J. Stephen Kowski, Field CTO at SlashNext Email Security+, told ZDNET, "AI agents hold the promise of enhancing threat response capabilities, but the performance of baseline models has been underwhelming. Many users report that even top-tier solutions miss a significant number of threats. Microsoft's Security Copilot has potential, but its adoption rate is slower than anticipated due to concerns about data management, necessary services, and licensing fees."
Want more stories about AI? Sign up for Innovation, our weekly newsletter.
Related article
AI Voice Translator G5 Pro: Seamless Global Communication
In a world where global connectivity is essential, bridging language gaps is more important than ever. The AI Voice Translator G5 Pro offers a practical solution with its real-time translation feature
Elevate Your Images with HitPaw AI Photo Enhancer: A Comprehensive Guide
Want to transform your photo editing experience? Thanks to cutting-edge artificial intelligence, improving your images is now effortless. This detailed guide explores the HitPaw AI Photo Enhancer, an
AI-Powered Music Creation: Craft Songs and Videos Effortlessly
Music creation can be complex, demanding time, resources, and expertise. Artificial intelligence has transformed this process, making it simple and accessible. This guide highlights how AI enables any
Comments (25)
0/200
JerryGonzález
April 18, 2025 at 5:00:31 AM EDT
マイクロソフトの新しいAIエージェントはセキュリティプロにとって救世主です!脅威に対処するのがとても簡単になりました。唯一の欠点は学習曲線ですが、一度慣れればスムーズに使えます。強くお勧めします!🚀
0
DouglasHarris
April 16, 2025 at 10:47:50 PM EDT
माइक्रोसॉफ्ट के नए AI एजेंट सुरक्षा पेशेवरों के लिए एक जीवन रक्षक हैं! वे खतरों से निपटना बहुत आसान बनाते हैं। एकमात्र नकारात्मक पक्ष सीखने की अवस्था है, लेकिन एक बार जब आप इसके आदी हो जाते हैं, तो यह आसान हो जाता है। मजबूती से सुझाव दिया! 🚀
0
AlbertWalker
April 16, 2025 at 6:32:37 PM EDT
Os novos agentes de IA da Microsoft são um salva-vidas para profissionais de segurança! Eles tornam o lidar com ameaças muito mais fácil. O único ponto negativo é a curva de aprendizado, mas uma vez que você se acostuma, é navegação tranquila. Recomendo muito! 🚀
0
PeterJohnson
April 16, 2025 at 9:10:24 AM EDT
Microsoft's new AI agents are a lifesaver for security pros! They make dealing with threats so much easier. Only downside is the learning curve, but once you get the hang of it, it's smooth sailing. Highly recommend! 🚀
0
JackMartin
April 16, 2025 at 3:52:23 AM EDT
マイクロソフトの新しいAIエージェント、セキュリティのプロにとって有望そう!🤓 最新の脅威に対抗して、私たちの生活を楽にするらしい。実際に使うのが楽しみだけど、どれだけ効果があるかは少し懐疑的。期待してるよ!🙏
0
SamuelRoberts
April 15, 2025 at 4:55:40 AM EDT
Os novos agentes de IA da Microsoft para profissionais de segurança parecem promissores! 🤓 Eles devem facilitar nossas vidas ao enfrentar as últimas ameaças. Mal posso esperar para vê-los em ação, mas estou um pouco cético sobre quão eficazes serão. Dedos cruzados! 🙏
0
Microsoft is rolling out a new set of AI agents as part of its Security Copilot initiative, aimed at simplifying the job of security professionals in safeguarding their organizations from modern threats. The announcement came on Monday, with Microsoft developing six of these agents, while five others are crafted by third-party collaborators. Starting in April, all these agents will be available for a preview.
These AI agents, integrated with Microsoft's security software, are designed to assist security teams in managing high-volume security and IT tasks more efficiently. Drawing from Microsoft's Zero Trust framework, these agents are capable of learning from user interactions and adapting to the specific workflows within an organization.
Also: Navigating AI-powered cyber threats in 2025: 4 expert security tips for businesses
Here's a closer look at the six Microsoft-developed agents:
- Phishing Triage Agent in Microsoft Defender: This agent sorts through Microsoft Defender's phishing alerts, distinguishing genuine threats from false alarms. It provides clear explanations for its decisions and can enhance its detection abilities based on your feedback.
- Alert Triage Agent in Microsoft Purview: This agent focuses on prioritizing alerts from Microsoft Purview related to data loss and insider risks. It also refines its operations with your feedback.
- Conditional Access Optimization Agent in Microsoft Entra: This agent scans for new users and applications in Microsoft Entra not covered by current policies. It recommends policy updates to close security gaps and offers quick solutions for identity and authentication issues.
- Vulnerability Remediation Agent in Microsoft Intune: Tailored for Microsoft Intune, this agent prioritizes security vulnerabilities, identifies issues with app and policy configurations, and suggests appropriate Windows patches.
- Threat Intelligence Briefing Agent in Security Copilot: This agent collaborates with Security Copilot to deliver timely and relevant threat intelligence tailored to your organization's specific risks and environment.
Moving on to the five third-party agents, all integrated into Security Copilot:
- Privacy Breach Response Agent by OneTrust: This agent assesses data breaches and provides guidance on meeting regulatory requirements.
- Network Supervisor Agent by Aviatrix: It monitors and analyzes security risks associated with VPN, gateway, and Site2Cloud connection issues.
- SecOps Tooling Agent by BlueVoyant: This agent evaluates your security operations center and offers recommendations for enhancements.
- Alert Triage Agent by Tanium: It contextualizes security alerts to help you decide on the best course of action.
- Task Optimizer Agent by Fletch: This agent prioritizes the most urgent security alerts, aiding in efficient task management.
Microsoft Security Copilot, which was officially launched about a year ago, leverages AI to monitor and analyze potential security threats facing your organization. The aim is to automate routine tasks, thereby freeing up IT and security staff to focus on more pressing issues. Additionally, the AI provides strategic guidance to help teams respond to threats more swiftly and effectively.
Also: AI bots scraping your data? This free tool gives those pesky crawlers the run-around
Security Copilot operates on a flexible pay-as-you-go model, allowing organizations to scale their usage as needed. The cost is calculated monthly based on a Security Compute Unit (SCU) at $4 per hour. If an organization uses one SCU continuously for 24 hours a day throughout a month, the estimated cost would be approximately $2,920.
Kris Bondi, CEO and co-founder of security firm Mimoto, shared with ZDNET, "Security professionals are constantly bombarded with alerts and issues, often lacking sufficient context. While AI agents may not detect threats themselves, they can assist in managing responses to detected threats. An AI agent can be programmed to automatically initiate a multi-step response when triggered by specific cues, alleviating some of the burden from security professionals."
However, AI technology is not infallible. Tools like Security Copilot may miss genuine threats or generate false positives, highlighting the necessity for human oversight. As a relatively new product, many organizations are still navigating the best ways to integrate it into their security strategies.
Also: How AI agents help hackers steal your confidential data - and what to do about it
J. Stephen Kowski, Field CTO at SlashNext Email Security+, told ZDNET, "AI agents hold the promise of enhancing threat response capabilities, but the performance of baseline models has been underwhelming. Many users report that even top-tier solutions miss a significant number of threats. Microsoft's Security Copilot has potential, but its adoption rate is slower than anticipated due to concerns about data management, necessary services, and licensing fees."
Want more stories about AI? Sign up for Innovation, our weekly newsletter.




マイクロソフトの新しいAIエージェントはセキュリティプロにとって救世主です!脅威に対処するのがとても簡単になりました。唯一の欠点は学習曲線ですが、一度慣れればスムーズに使えます。強くお勧めします!🚀




माइक्रोसॉफ्ट के नए AI एजेंट सुरक्षा पेशेवरों के लिए एक जीवन रक्षक हैं! वे खतरों से निपटना बहुत आसान बनाते हैं। एकमात्र नकारात्मक पक्ष सीखने की अवस्था है, लेकिन एक बार जब आप इसके आदी हो जाते हैं, तो यह आसान हो जाता है। मजबूती से सुझाव दिया! 🚀




Os novos agentes de IA da Microsoft são um salva-vidas para profissionais de segurança! Eles tornam o lidar com ameaças muito mais fácil. O único ponto negativo é a curva de aprendizado, mas uma vez que você se acostuma, é navegação tranquila. Recomendo muito! 🚀




Microsoft's new AI agents are a lifesaver for security pros! They make dealing with threats so much easier. Only downside is the learning curve, but once you get the hang of it, it's smooth sailing. Highly recommend! 🚀




マイクロソフトの新しいAIエージェント、セキュリティのプロにとって有望そう!🤓 最新の脅威に対抗して、私たちの生活を楽にするらしい。実際に使うのが楽しみだけど、どれだけ効果があるかは少し懐疑的。期待してるよ!🙏




Os novos agentes de IA da Microsoft para profissionais de segurança parecem promissores! 🤓 Eles devem facilitar nossas vidas ao enfrentar as últimas ameaças. Mal posso esperar para vê-los em ação, mas estou um pouco cético sobre quão eficazes serão. Dedos cruzados! 🙏












