Itequia

Microsoft Introduces New AI Agents in Security Copilot

Laptop on a wooden desk displaying code, with a hand typing and digital code overlays, representing Microsoft’s new AI agents in Security Copilot.

Microsoft has announced the expansion of its Security Copilot tool with the addition of new artificial intelligence agents. These agents are designed to enhance security in critical areas such as phishing, data security, and identity management.

The autonomous agents enable security teams to quickly identify and respond to cyber threats. This allows them to focus on more complex threats and proactive security measures.

Circular diagram showing Microsoft’s end-to-end security approach with AI, clouds, apps, data, devices, and identities at the center, surrounded by products like Defender, Sentinel, Intune, Entra, and Purview.

Expansion of Microsoft Security Copilot with AI Agent Capabilities

Microsoft has integrated new AI agents into Security Copilot, allowing companies to increase efficiency in responding to cyberattacks.

These agents operate autonomously, performing tasks that previously required human intervention, such as threat detection and incident management. This improves the ability of security teams to react to faster and more complex attacks.

New AI Agent Solutions from Microsoft Security

Microsoft has launched new AI-based solutions that expand the capabilities of Security Copilot to cover a wider range of threats. These new tools include:

  • Microsoft Defender Identity Assessment Agent (phishing): Responsible for accurately classifying phishing alerts. It helps identify real cyber threats and filters out false alarms.
  • Priority Classification Agent in Microsoft Purview: Focuses on managing alerts related to data loss prevention and internal risks. Its function is to prioritize critical incidents, allowing security teams to focus their efforts on the most urgent issues.
  • Conditional Access Optimization Agent in Microsoft Entra: Monitors new users or applications not covered by existing conditional access policies. It identifies potential security gaps and provides recommendations to address them, simplifying the process for security teams.
  • Vulnerability Remediation Agent in Microsoft Intune: Helps monitor and prioritize security vulnerabilities within applications and configuration policies.
  • Threat Intelligence Agent in Security Copilot: Automatically selects the most relevant intelligence information for each organization. This agent filters threat intelligence based on the unique attributes of the company and its exposure to cyber threats.
Flowchart illustrating how Security and IT teams interact with Microsoft Security Copilot and its autonomous agents, covering threat protection, data security, identity, devices, threat intelligence, and partner-developed agents.

Five New AI Agent Solutions from Microsoft Partners

In addition to Microsoft’s own solutions, the company has collaborated with strategic partners to integrate five new solutions. These include:

  • Privacy Breach Response Agent from OneTrust: Analyzes data breaches and provides guidance to comply with privacy regulatory requirements.
  • Network Supervisor Agent from Aviatrix: Conducts root cause analysis and summarizes connectivity issues related to VPN, gateways, or Site2Cloud.
  • SecOps Tooling Agent from BlueVoyant: Assesses the state of a security operations center (SOC) and recommends improvements in controls, effectiveness, and compliance.
  • Alert Triage Agent from Tanium: Provides context to analysts to make quick and secure decisions about each security alert.
  • Task Optimizer Agent from Fletch: Helps forecast and prioritize critical cyber threat alerts, reducing alert fatigue and improving security.

New AI-Driven Data Security Research and Analysis

Microsoft is launching new data security investigations in Microsoft Purview, using AI to quickly identify and mitigate sensitive data exposure risks. These investigations enable teams to collaborate more efficiently and simplify complex tasks, improving incident response. They will be available in preview in April 2025 and will integrate with Defender incidents and Purview internal risk cases.

New Advances in Generative AI Security and Control

As organizations rapidly adopt generative AI, there is an urgent need to ensure its security. A Microsoft report reveals that 57% of organizations have experienced more security incidents related to AI use. And while many recognize the need for controls, 60% have yet to take action.

Microsoft is implementing new security solutions to protect AI investments, addressing key concerns such as data leakage, new threats, and regulatory compliance.

AI Security Posture Management for Multimodel and Multicloud Environments

Microsoft Defender will extend AI security posture management beyond Azure and Amazon Web Services to include Google VertexAI and the Azure AI Foundry model catalog.

This new multicloud interoperability will provide greater visibility into AI security across platforms like Azure, AWS, and Google Cloud, enabling organizations to better protect their multimodel and multicloud environments. It will be available in preview in May 2025.

New Detection and Protection for Emerging AI Threats

With AI come new risks and vulnerabilities. Starting in May 2025, Microsoft Defender will offer new risk detections identified by OWASP, such as injection attacks and exposure of sensitive data. These enhanced detections will help protect custom AI applications and models from Azure OpenAI Service.

New Controls to Prevent Risky Access and Data Leaks in Shadow AI Applications

To combat unauthorized use of AI applications, Microsoft is introducing the AI web category filter in Microsoft Entra, which controls access to unapproved AI applications.

Additionally, data loss prevention (DLP) controls will be launched in Microsoft Edge for businesses, allowing security policies to be applied to protect sensitive data from being leaked to generative AI applications.

New Phishing Protection in Microsoft Teams for Safer Collaboration

Microsoft Defender for Office 365 will be available in April 2025, offering protection against phishing and other advanced threats within Microsoft Teams. This includes protection against malicious URLs and real-time detonation of attachments, providing SOC teams with full visibility into security attempts and incidents related to Teams.

Conclusion

Microsoft continues to demonstrate its commitment to innovation in cybersecurity. These innovations not only enhance the protection of organizations today but also prepare companies for future security challenges, building a more secure and resilient digital environment.

At Itequia, we specialize in implementing these technologies to improve content management and team collaboration. We help organizations optimize their operational efficiency and tackle cyber threats. Do not hesitate to contact us for more information or to discover how we can help protect your organization.

Itequia Team