M

Microsoft Project Perception

by Microsoft

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

An agentic security system of red, blue and green AI agents that expose, investigate and remediate risk inside Microsoft Defender

Usage-based · Contact for pricing·Added Aug 6, 2026·Updated Aug 6, 2026
Share:
THE DAILY BRIEF
Microsoft Project Perception

by Microsoft

Governance & SecurityAI Agents & OrchestrationEnterprise Platform

An agentic security system of red, blue and green AI agents that expose, investigate and remediate risk inside Microsoft Defender

Usage-based · Contact for pricing

Project Perception is Microsoft's agentic cybersecurity system, in public preview since August 3, 2026 inside Microsoft Defender. It runs three classes of specialized AI agents - red agents that map attack paths, blue agents that investigate and triage, and green agents that remediate - so security operations teams stop drowning in alerts they never get to close.

At a Glance

Category
Governance & Security
Pricing
Usage-based, Contact for pricing
Target Market
CISOs, CIOs, Security Operations Leaders, Enterprise Security Architects, IT Directors
Deployment
Cloud-only
Founded
1975
Headquarters
Redmond, Washington, United States
Team Size
500+

Key Features

  • Red, blue and green agent classes
  • The Harness orchestration framework
  • MAI-Cyber-1-Flash security model
  • Actuators that enforce decisions
  • Consumption billing in Security Compute Units
  • Native delivery inside Microsoft Defender
  • Gated autonomy with human approval

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Autonomous alert investigation
  • Continuous attack-path discovery
  • Vulnerability reachability and prioritization
  • Security baseline hardening
  • Containment of an active incident

Ideal For

Best For

  • Microsoft-standardized SOCs that want autonomous alert investigation without adding a separate agentic security vendor
  • Continuous internal red-teaming to surface attack paths across identity, endpoint and cloud before an attacker finds them
  • Configuration drift and security-baseline hardening driven by agents rather than quarterly manual reviews
  • Vulnerability triage at scale where MAI-Cyber-1-Flash reasoning can rank code-expressible flaws such as SQL injection and cross-site scripting
  • Teams already piloting Microsoft Security Copilot that want agents which act rather than only summarize

Not Ideal For

  • Heterogeneous or multicloud estates with substantial non-Microsoft security tooling - analysts flag coverage of non-Microsoft and unmanaged assets, not model quality, as where outcomes are actually decided
  • Organizations with inaccurate asset and identity inventory, because the agents reason over that graph and shadow IT, unmanaged identities and stale CMDB records become blind spots
  • Teams needing predictable, budgetable security spend - billing is token-metered in Security Compute Units with no published rate card, and analysts warn of sticker shock at SOC scale
  • Buyers expecting fully autonomous remediation today; autonomous action is gated to reversible moves such as isolating a machine, with patching still human-approved
  • Threat programs whose primary exposure is credential abuse and social engineering rather than application vulnerabilities

Market Analysis

Enterprise-gradeAgentic securityMicrosoft-native

Pros

  • Moves from surfacing information to taking action - Futurum estimates the system compresses roughly 146 hours of specialist time
  • Purpose-built MAI-Cyber-1-Flash scores 96 percent on CyberGym, ahead of Anthropic's Mythos at roughly half the cost per Futurum's read
  • No new agent vendor to procure or deploy for organizations already inside Defender, Entra and Windows
  • Consumption billing avoids per-analyst seat licensing, so cost tracks actual investigation volume
  • Governance hooks already exist through Microsoft Agent 365 and Entra Agent ID rather than needing a separate agent-identity layer

Cons

  • Autonomous remediation is deliberately gated - only reversible moves such as isolating a machine ship first and patching remains human-approved, so the headline automation value is deferred
  • Benchmark scores do not validate operational outcomes; TechRepublic notes public results do not show how the system performs against vulnerabilities in a customer's proprietary environment, and demos centre on code-expressible flaws like SQL injection and XSS rather than the credential theft and social engineering most real intrusions run on
  • Results depend entirely on the accuracy of the graph the agents reason over, and shadow IT, unmanaged identities and stale inventory are exactly where real intrusions start
  • Consumption pricing has no published rate card, creating budget unpredictability that Futurum's analyst calls a risk of sticker shock at scale
  • Support for mixed non-Microsoft security estates is unclear, and agent permissions can exceed controls designed for human users - TechRepublic also flags poisoned MCP tool descriptions as a way to steer agents toward unintended actions

Pricing

Public preview (consumption)

Contact for pricing

  • Metered in Security Compute Units (SCUs)
  • Agents consume SCUs at different rates by task intensity
  • Delivered inside Microsoft Defender
  • No published rate card or eligibility criteria

Consumption-based and metered in Security Compute Units, the same unit Microsoft uses for Security Copilot, with agents drawing SCUs at different rates depending on task intensity. Microsoft has published neither a per-SCU rate, preview eligibility requirements, nor a general-availability date, so total cost of ownership cannot be modelled from public information. Futurum's analysis flags consumption-pricing predictability as one of the five things buyers should watch, warning of sticker shock once agent volume scales across a full SOC.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Project Perception is Microsoft's agentic cybersecurity system, in public preview since August 3, 2026 inside Microsoft Defender. It runs three classes of specialized AI agents - red agents that map attack paths, blue agents that investigate and triage, and green agents that remediate - so security operations teams stop drowning in alerts they never get to close.

Project Perception is Microsoft's agentic security system, announced July 27, 2026 by Hayete Gallot, Executive Vice President of Microsoft Security, and released into public preview on August 3, 2026 delivered inside Microsoft Defender. Rather than adding another assistant that summarizes alerts, Perception coordinates a workforce of specialized agents in a continuous loop across identities, endpoints, applications, data, cloud environments and AI systems. Microsoft groups them into three classes: red agents identify potential paths to compromise before an attacker exploits them, blue agents investigate activity and reason over context to decide what represents meaningful risk, and green agents take corrective actions and harden configurations. Underneath sits a six-layer architecture Microsoft calls the new cyber stack - signals and sensors, enriched context, a multi-model layer, an orchestration framework named the Harness, the agents themselves, and actuators that convert decisions into enforced protections. The models are purpose-built: Microsoft simultaneously introduced MAI-Cyber-1-Flash, a cybersecurity-tuned model that handles roughly 90 percent of tasks in the MDASH vulnerability system and scores 96 percent on the CyberGym benchmark at close to 50 percent lower cost than the previous MDASH configuration, with GPT-5.4 reserved for the hardest work. Billing is consumption-based, metered in Security Compute Units, with agents drawing SCUs at different rates by task intensity. Microsoft has not published a rate card, eligibility detail, or a general-availability date.

Ideal Buyer

SOC leaders and CISOs at organizations already standardized on Microsoft Defender, Entra and Windows endpoints, who have more alerts than analyst hours and want investigation and hardening handled by agents rather than headcount.

Key Benefit

Alert triage, attack-path discovery and configuration hardening run continuously as agent work inside the Defender console instead of queuing for a human analyst.

At a Glance

Category
Governance & Security
Pricing
Usage-based, Contact for pricing
Target Market
CISOs, CIOs, Security Operations Leaders, Enterprise Security Architects, IT Directors
Deployment
Cloud-only
Founded
1975
Headquarters
Redmond, Washington, United States
Team Size
500+

Key Features

  • Red, blue and green agent classes

    Three specialized agent roles split offense, investigation and remediation so each has a bounded mandate and an auditable scope of action.

  • The Harness orchestration framework

    Coordinates which agent and which model handles a task, routing routine work to cheap models and hard reasoning to frontier ones.

  • MAI-Cyber-1-Flash security model

    Microsoft's cybersecurity-tuned in-house model covers roughly 90 percent of MDASH tasks at nearly half the previous configuration cost.

  • Actuators that enforce decisions

    Agent conclusions convert into real protection changes across the estate rather than stopping at a recommendation in a dashboard.

  • Consumption billing in Security Compute Units

    You pay per unit of agent work consumed rather than per analyst seat, so cost tracks investigation volume directly.

  • Native delivery inside Microsoft Defender

    Ships in the Defender console at preview with expansion planned across other Microsoft Security products, avoiding a separate deployment.

  • Gated autonomy with human approval

    Green agents begin with reversible actions like host isolation while consequential changes such as patching still require human sign-off.

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Autonomous alert investigation

    Blue agents pick up incoming Defender alerts, gather context across identity and endpoint signals, and produce a reasoned risk determination without analyst triage time.

  • Continuous attack-path discovery

    Red agents probe the environment the way an adversary would and surface compromise paths across identity, cloud and endpoint before they are exploited.

  • Vulnerability reachability and prioritization

    MDASH with MAI-Cyber-1-Flash reasons over disclosed software vulnerabilities, scoring 96 percent on the CyberGym benchmark in Microsoft's own testing.

  • Security baseline hardening

    Green agents improve configurations and apply updates continuously, raising the organization's security baseline instead of waiting for a quarterly review cycle.

  • Containment of an active incident

    Reversible containment actions such as isolating a compromised machine execute at machine speed while irreversible remediation stays behind a human approval gate.

Ideal For

Best For

  • Microsoft-standardized SOCs that want autonomous alert investigation without adding a separate agentic security vendor
  • Continuous internal red-teaming to surface attack paths across identity, endpoint and cloud before an attacker finds them
  • Configuration drift and security-baseline hardening driven by agents rather than quarterly manual reviews
  • Vulnerability triage at scale where MAI-Cyber-1-Flash reasoning can rank code-expressible flaws such as SQL injection and cross-site scripting
  • Teams already piloting Microsoft Security Copilot that want agents which act rather than only summarize

Not Ideal For

  • Heterogeneous or multicloud estates with substantial non-Microsoft security tooling - analysts flag coverage of non-Microsoft and unmanaged assets, not model quality, as where outcomes are actually decided
  • Organizations with inaccurate asset and identity inventory, because the agents reason over that graph and shadow IT, unmanaged identities and stale CMDB records become blind spots
  • Teams needing predictable, budgetable security spend - billing is token-metered in Security Compute Units with no published rate card, and analysts warn of sticker shock at SOC scale
  • Buyers expecting fully autonomous remediation today; autonomous action is gated to reversible moves such as isolating a machine, with patching still human-approved
  • Threat programs whose primary exposure is credential abuse and social engineering rather than application vulnerabilities

Deployment

On-Premise

Market Analysis

Enterprise-gradeAgentic securityMicrosoft-native

Pros

  • Moves from surfacing information to taking action - Futurum estimates the system compresses roughly 146 hours of specialist time
  • Purpose-built MAI-Cyber-1-Flash scores 96 percent on CyberGym, ahead of Anthropic's Mythos at roughly half the cost per Futurum's read
  • No new agent vendor to procure or deploy for organizations already inside Defender, Entra and Windows
  • Consumption billing avoids per-analyst seat licensing, so cost tracks actual investigation volume
  • Governance hooks already exist through Microsoft Agent 365 and Entra Agent ID rather than needing a separate agent-identity layer

Cons

  • Autonomous remediation is deliberately gated - only reversible moves such as isolating a machine ship first and patching remains human-approved, so the headline automation value is deferred
  • Benchmark scores do not validate operational outcomes; TechRepublic notes public results do not show how the system performs against vulnerabilities in a customer's proprietary environment, and demos centre on code-expressible flaws like SQL injection and XSS rather than the credential theft and social engineering most real intrusions run on
  • Results depend entirely on the accuracy of the graph the agents reason over, and shadow IT, unmanaged identities and stale inventory are exactly where real intrusions start
  • Consumption pricing has no published rate card, creating budget unpredictability that Futurum's analyst calls a risk of sticker shock at scale
  • Support for mixed non-Microsoft security estates is unclear, and agent permissions can exceed controls designed for human users - TechRepublic also flags poisoned MCP tool descriptions as a way to steer agents toward unintended actions

Pricing

Public preview (consumption)

Contact for pricing

  • Metered in Security Compute Units (SCUs)
  • Agents consume SCUs at different rates by task intensity
  • Delivered inside Microsoft Defender
  • No published rate card or eligibility criteria

Consumption-based and metered in Security Compute Units, the same unit Microsoft uses for Security Copilot, with agents drawing SCUs at different rates depending on task intensity. Microsoft has published neither a per-SCU rate, preview eligibility requirements, nor a general-availability date, so total cost of ownership cannot be modelled from public information. Futurum's analysis flags consumption-pricing predictability as one of the five things buyers should watch, warning of sticker shock once agent volume scales across a full SOC.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Connect

Sources

This page was written from 4 sources, 3 on domains other than microsoft.com.

  1. 1.microsoft.comproject perception agentic systemvendor
  2. 2.blogs.microsoft.comrethinking security for the age of ai
  3. 3.techrepublic.comnews microsoft project perception preview
  4. 4.futurumgroup.commicrosofts project perception bets on agents that act not ju
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe