Microsoft Defender: Enhancements in AI Security Controls

This post maps Microsoft Defender’s AI security capabilities — primarily Defender for Cloud Apps AI agent protection, plus relevant Defender for Cloud (CSPM) and Defender XDR integrations The objective is to identify which controls are materially improved by Defender for AI Apps, where the contribution is partial, where it does not apply for declarative-agent scope, and which Defender capabilities are currently in Preview and therefore subject to the organization’s no-preview-features-in-production policy.

Defender for AI Apps — Capability Inventory

The capabilities below are organized by control plane and release status. Preview rows are shaded orange; GA rows are shaded green.

Defender CapabilityControl Plane / PortalRelease StatusScope Relevance for Declarative
AI Agent Inventory (auto-discovery of Copilot Studio agents)Defender XDR / Defender for Cloud AppsPreviewHigh
Real-time runtime protection (blocks suspicious tool invocations)Defender for Cloud Apps (Work IQ MCP integration)PreviewHigh — blocks prompt-injection-triggered actions
Audit log collection from Copilot Studio agentsDefender for Cloud AppsPreviewMedium — complements Purview Audit and Application Insights
Advanced Hunting integration (Copilot Studio telemetry in KQL)Defender XDRGAHigh — enables proactive threat hunting on agent activity
Advanced Hunting Community Hunting Queries (10 misconfigurations)Defender XDRGA (Feb 2026)High
XDR alerts: persistent jailbreak attempts, suspicious agent execution, suspicious user activity tied to jailbreakDefender XDRPreviewHigh
Exposure Management: misconfiguration detection and attack-path analysis for AI agentsDefender for Cloud Apps / Defender XDRPreviewHigh
Cloud App Catalog (1000+ GenAI apps, risk scoring, sanction/unsanction)Defender for Cloud AppsGAMedium-High
AI BOM discovery for Copilot Studio (via CSPM with Defender for Cloud Apps license)Defender for Cloud Apps + Defender CSPMPreviewMedium — relevant if CSPM plan is enabled
AI model security / scanning (registered ML models)Defender for CloudGANot applicable — Foundry/AzureML scope only
AI threat protection for Azure OpenAI / Foundry workloadsDefender for CloudGANot applicable — Foundry/Azure OpenAI direct scope
DSPM for AI (Purview-side — sensitive data interactions in AI prompts)Microsoft PurviewGAHigh — but Purview, not Defender; included for completeness

Control-by-Control Mapping

Mappings are organized in three tiers by strength of Defender contribution. Each row records the  status, the strength of the Defender contribution, the production-readiness implication, and the residual organization-side action required to achieve full conformance.

Strong Alignment — Defender materially closes the gap

Control Title StatusDefender StrengthDefender ContributionProduction ReadinessResidual Organization Action
Agent and MCP DiscoveryPartialStrongAI Agent Inventory auto-discovers Copilot Studio agents in the tenant Centralized asset view in Defender portal (Assets > AI Agents) Populates agent attribute set: creator, environment, status, tool list (partial)Preview• MCP server inventory — not provided • Agent-to-agent topology — not provided • R/W classification per connector — not provided • Treat as AG-01 input, not full solution
Detection and ResponsePartialStrongXDR alerts for persistent jailbreak attempts, suspicious user activity tied to jailbreak, suspicious agent execution Real-time runtime protection blocks risky tool invocations before execution Native integration with XDR Incidents and AlertsPreview• SOAR playbooks for agent isolation, access restriction • Per-agent behavioral baselines (tool sequence, timing) • Hallucination-based security alerts • Cross-agent context manipulation rules
Configurations AnalysisPartialStrongExposure Management provides misconfiguration detection and attack-path analysis for AI agents Advanced Hunting Community Hunting Queries (Feb 2026, GA) cover 10 common Copilot Studio misconfigurations including elevated privileges and exposed agents Posture recommendations through Defender portalMixed (Hunting Queries GA; Exposure Mgmt for AI agents in Preview)• MCP server configuration scanning (Checkov / Trivy / GitGuardian) • Human review for AI-generated code with elevated privileges
Oversight of AI Safety FilterPartialStrongPrompt Shield triggers (UPIA/XPIA) surfaced as XDR alerts Content Safety filter triggers correlated into XDR incident timeline Centralized oversight view rather than scattered Application Insights queriesPreview (for the Copilot Studio extended set; baseline alerting in core XDR is GA)• Reporting cadence and ownership of safety-filter alerts • Threshold tuning per agent and per audience (employee vs customer-facing)
Incident Management PracticesPartialStrongNative integration with Defender XDR Incidents and Alerts framework AI agent alerts correlate into the same incident structure as the rest of SOC operations Dedicated Agent entity in XDR for incident pivotingPreview• Incident response runbook updates to cover AI-specific scenarios • Alignment with Technology Incident Management Standard • Tabletop exercises validating Defender alert routing

Partial Alignment — Defender contributes but does not close

Control ID & Title StatusDefender StrengthDefender ContributionProduction ReadinessResidual Organization Action
Policy Enforcement and GuardrailsPartialPartialReal-time blocking of malicious tool invocations (preview) Adds detective layer on top of Prompt ShieldsPreview• Custom Purview SITs for organization-specific PII
• Multi-turn jailbreak detection
• Cross-agent context manipulation rules • Per-agent expected data-flow profile
Logging and RepudiationPartialPartialAudit log collection from Copilot Studio agents into Defender Advanced Hunting KQL queries against agent telemetryPreview• Two-pillar architecture (Purview Audit + App Insights) remains primary
• Defender XDR is third consumption layer, not replacement
• Knowledge source change lineage still not exposed
• Permission-elevation aggregation still requires Sentinel correlation
Identity AccessPartialPartialXDR can detect anomalous identity behaviour patterns Suspicious OBO token use surfaces as alertsPreview• MCP-protocol-level controls (token nonce, session-IP binding) remain custom-MCP-server responsibility
• Entra Agent ID configuration unchanged
• PIM and Conditional Access remain primary identity controls
Input and Output SanitizationPartialPartialRuntime protection blocks injection-style inputs before tool execution Complements Prompt Shields for input sanitizationPreview• Application-layer sanitization for downstream-system integrity
• Output validation for documents and structured data
Excessive Agency / Blast Radius LimitationPartialPartialReal-time tool invocation blocking limits blast radius at runtime Inspection of agent-initiated tool calls before executionPreview• Per-agent blast-radius design documentation
• Connector permission scoping at design time
• HITL configuration for high-impact actions
Multi-Agent Orchestration SecurityPartialPartialXDR can correlate agent execution telemetry across parent-child agents Suspicious chained execution patterns surfaced as alertsPreview• Agent-to-agent topology visualization remains custom build
• Cross-agent prompt injection detection rules
• Connected-agent invocation as a ‘powerful action’ control plane
Prompt Shields (User Prompt Attacks / Indirect Attacks)YesPartialAdds detection, alerting and hunting layer on top of Prompt Shields XPIA / UPIA events surfaced into Defender XDR incidents Persistent jailbreak attempts detected as distinct alertsPreview• Prompt Shields themselves remain GA and Microsoft-managed
• Defender enrichment is additive — not required for baseline conformance

Limited Applicability — Defender is not the right control plane

Control ID & Title StatusDefender StrengthDefender ContributionProduction ReadinessResidual Organization Action
Model Version Lifecycle and DeprecationPartialLimitedDefender model scanning applies to Foundry / AzureML registered models, not declarative-scope modelsNot applicable for declarative scope• Microsoft Roadmap monitoring
• Internal model deprecation process
• Pin model versions where possible
Embedding and Vector Store SecurityPartialLimitedDeclarative agents inherit M365 search and Microsoft-managed embedding infrastructure Defender does not expose embedding store controlsNot applicable for declarative scope• Purview sensitivity labels on indexed content
• Restricted Content Discovery for source-level access control
Cost-Based Denial of Service / Wallet Attack ProtectionYesLimitedDefender can alert on anomalous activity volumes Does not enforce cost ceilingsCapability gap• Power Platform admin centre capacity controls
• Microsoft 365 Admin Centre Copilot Credit pool management
• Quota / rate-limit configuration per agent
AI Security Testing & Red Team Exercise CadenceNoLimitedDefender is detective (runtime), not pre-deployment testingCapability gap• Promptfoo / Microsoft PyRIT / Garak for pre-deployment testing
• Red team exercise cadence definition
• Test plan with documented scenarios
Bias and Fairness TestingPartialLimitedNot in scope for DefenderCapability gap• Fairlearn or comparable bias-testing framework
• Documented test plan separate from security testing
Model Card and Transparency DocumentationPartialLimitedNot in scope for DefenderCapability gap• Internal model card template
• Publication process aligned with EU AI Act Article 13
AI-Specific Vendor Risk AssessmentYesLimitedNot in scope for DefenderCapability gap• Third-party risk management process
• AI-specific vendor questionnaire
AI Solution Sunset TriggersNoLimitedNot in scope for DefenderCapability gap• Measurable sunset triggers (drift, regulatory change, vendor support)
• Sunset playbook
Content Generation / EU AI Act Article 50PartialLimitedNot in scope for DefenderCapability gap• Watermarking / provenance metadata for synthetic content • User disclosure mechanism for AI-generated outputs
Citation and Source Attribution IntegrityPartialLimitedNot in scope for DefenderCapability gap• Citation verification against trusted sources • Hallucination scoring at output time (Foundry Groundedness Detection)
AI Solution Decommissioning and Data DeletionPartialLimitedNot in scope for DefenderCapability gap• Documented decommissioning procedure • Data deletion verification against approved retention schedules
Data Protection / Data Pipeline / Dataset ApprovalPartial / YesLimitedPurview / DSPM for AI is the right control plane, not DefenderCapability gap (Defender) — use Purview• Purview sensitivity labels • DSPM for AI policies for sensitive data in prompts • Dataset approval workflow

Production-Readiness Decisions

Given that the strongest Defender contributions are currently in Preview, a per-capability production-readiness decision is required before any of these mappings can be reflected as ‘Yes’ status in the . The table below records the proposed decisions and the rationale for each.

Defender CapabilityRelease StatusRationale / Notes
Cloud App Catalog (shadow AI discovery)GAGA today; aligns with no-preview policy. Onboarding cost is low if Defender for Cloud Apps already licensed via Microsoft 365 E5. Strong fit for AI BOM (AG-01) input feed.
Advanced Hunting Community Hunting QueriesGA (Feb 2026)GA today; already cited in  (AMCP-03, AMCP-09). Onboarding requires Defender XDR access and KQL skill in SOC team.
Advanced Hunting integration (Copilot Studio telemetry in KQL)GAGA today; complements existing two-pillar logging architecture (Purview Audit + App Insights). Provides third consumption layer for SOC.
AI Agent Inventory (Copilot Studio agents)PreviewHighest-value. Decision contingent on the AI BOM workstream timeline and the organization’s appetite for Preview features in security tooling.
Real-time runtime protection (tool invocation blocking)PreviewHighest-value runtime protection. Failure-mode analysis required: what happens when Defender misclassifies a legitimate tool call as suspicious? Customer impact and rollback plan needed before Preview acceptance.
XDR alerts for AI agents (jailbreak, suspicious execution)PreviewDetective control with no business impact on legitimate use. Lower risk Preview adoption candidate.
Exposure Management for AI agentsPreviewPosture-only — recommendations and findings, not enforcement. Lower risk Preview adoption candidate.
AI BOM discovery for Copilot Studio in Defender CSPMPreviewRequires Defender for CSPM plan in addition to Defender for Cloud Apps. Evaluate licensing cost against  alternatives (Power Platform CoE Starter Kit).

Leave a Reply

Discover more from Microsoft AI Product Notes

Subscribe now to keep reading and get access to the full archive.

Continue reading