Microsoft Defender XDR
A unified extended detection and response platform that correlates threat signals across endpoints, identities, email, apps, and cloud workloads to deliver coordinated detection, investigation, and automated response.
Capabilities
- Agent Security Posture ManagementSecureObserve Agents
Assesses each agent's posture risk from risk indicators — weak instructions, indirect prompt injection exposure, privileged business-system access, and active threats — assigns an overall risk level, and provides security recommendations to reduce exposure in the Microsoft Defender portal. Posture is derived from the Agent 365 inventory on the AI agents page and the AgentsInfo advanced hunting table.
- Agent Threat DetectionSecureObserve Agents
Detects suspicious and malicious agent behavior — jailbreak and prompt injection attempts, credential leaks, evasion techniques, and malicious content propagation — and surfaces near-real-time alerts in the Defender portal for investigation through incidents and Advanced Hunting over Agent 365 observability data.
- Agent Threat Hunting & InvestigationObserveSecure Agents
Correlates AI agent alerts into incidents and gives analysts an incident graph to scope the blast radius, then queries Agent 365 observability data with Kusto Query Language in Advanced Hunting — across the AgentsInfo, CloudAppEvents, and BehaviorInfo tables — to investigate threats and proactively hunt for risk. Turns near-real-time agent detections into full investigation and threat-hunting workflows in the Microsoft Defender portal.
- AI Agent InventoryObserve Agents
Discovers all Agent 365-managed agents in the Microsoft Defender portal — cloud agents from Copilot Studio, Foundry, Microsoft 365, and supported non-Microsoft platforms plus local agents on endpoints — through the AI agents page and the AgentsInfo advanced hunting table, and surfaces their security-relevant configuration for posture assessment.
- Real-time Agent ProtectionSecure Agents
Inspects agent activity throughout the agentic loop and blocks risky actions before they execute, using a default audit rule and custom blocking rules scoped to specific agents from Security for AI policies in the Microsoft Defender portal. Covers Agent 365 tool invocations and Copilot Studio agents, and records audit and block events as behaviors in the BehaviorInfo table for hunting and custom detections.
- Security Dashboard for AIObserveGovern Agents Users Data Infrastructure
Aggregates AI security posture and real-time risk signals from Microsoft Defender, Microsoft Entra, and Microsoft Purview into one scorecard and inventory spanning Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry apps and agents, and third-party or shadow AI. Gives security leaders a single cross-product view of AI assets and their risk; currently in preview.