This post maps Microsoft Defender’s AI security capabilities — primarily Defender for Cloud Apps AI agent protection, plus relevant Defender for Cloud (CSPM) and Defender XDR integrations The objective is to identify which controls are materially improved by Defender for AI Apps, where the contribution is partial, where it does not apply for declarative-agent scope, and which Defender capabilities are currently in Preview and therefore subject to the organization’s no-preview-features-in-production policy.
Defender for AI Apps — Capability Inventory
The capabilities below are organized by control plane and release status. Preview rows are shaded orange; GA rows are shaded green.
| Defender Capability | Control Plane / Portal | Release Status | Scope Relevance for Declarative |
| AI Agent Inventory (auto-discovery of Copilot Studio agents) | Defender XDR / Defender for Cloud Apps | Preview | High |
| Real-time runtime protection (blocks suspicious tool invocations) | Defender for Cloud Apps (Work IQ MCP integration) | Preview | High — blocks prompt-injection-triggered actions |
| Audit log collection from Copilot Studio agents | Defender for Cloud Apps | Preview | Medium — complements Purview Audit and Application Insights |
| Advanced Hunting integration (Copilot Studio telemetry in KQL) | Defender XDR | GA | High — enables proactive threat hunting on agent activity |
| Advanced Hunting Community Hunting Queries (10 misconfigurations) | Defender XDR | GA (Feb 2026) | High |
| XDR alerts: persistent jailbreak attempts, suspicious agent execution, suspicious user activity tied to jailbreak | Defender XDR | Preview | High |
| Exposure Management: misconfiguration detection and attack-path analysis for AI agents | Defender for Cloud Apps / Defender XDR | Preview | High |
| Cloud App Catalog (1000+ GenAI apps, risk scoring, sanction/unsanction) | Defender for Cloud Apps | GA | Medium-High |
| AI BOM discovery for Copilot Studio (via CSPM with Defender for Cloud Apps license) | Defender for Cloud Apps + Defender CSPM | Preview | Medium — relevant if CSPM plan is enabled |
| AI model security / scanning (registered ML models) | Defender for Cloud | GA | Not applicable — Foundry/AzureML scope only |
| AI threat protection for Azure OpenAI / Foundry workloads | Defender for Cloud | GA | Not applicable — Foundry/Azure OpenAI direct scope |
| DSPM for AI (Purview-side — sensitive data interactions in AI prompts) | Microsoft Purview | GA | High — but Purview, not Defender; included for completeness |
Control-by-Control Mapping
Mappings are organized in three tiers by strength of Defender contribution. Each row records the status, the strength of the Defender contribution, the production-readiness implication, and the residual organization-side action required to achieve full conformance.
Strong Alignment — Defender materially closes the gap
| Control Title | Status | Defender Strength | Defender Contribution | Production Readiness | Residual Organization Action |
| Agent and MCP Discovery | Partial | Strong | AI Agent Inventory auto-discovers Copilot Studio agents in the tenant Centralized asset view in Defender portal (Assets > AI Agents) Populates agent attribute set: creator, environment, status, tool list (partial) | Preview | • MCP server inventory — not provided • Agent-to-agent topology — not provided • R/W classification per connector — not provided • Treat as AG-01 input, not full solution |
| Detection and Response | Partial | Strong | XDR alerts for persistent jailbreak attempts, suspicious user activity tied to jailbreak, suspicious agent execution Real-time runtime protection blocks risky tool invocations before execution Native integration with XDR Incidents and Alerts | Preview | • SOAR playbooks for agent isolation, access restriction • Per-agent behavioral baselines (tool sequence, timing) • Hallucination-based security alerts • Cross-agent context manipulation rules |
| Configurations Analysis | Partial | Strong | Exposure Management provides misconfiguration detection and attack-path analysis for AI agents Advanced Hunting Community Hunting Queries (Feb 2026, GA) cover 10 common Copilot Studio misconfigurations including elevated privileges and exposed agents Posture recommendations through Defender portal | Mixed (Hunting Queries GA; Exposure Mgmt for AI agents in Preview) | • MCP server configuration scanning (Checkov / Trivy / GitGuardian) • Human review for AI-generated code with elevated privileges |
| Oversight of AI Safety Filter | Partial | Strong | Prompt Shield triggers (UPIA/XPIA) surfaced as XDR alerts Content Safety filter triggers correlated into XDR incident timeline Centralized oversight view rather than scattered Application Insights queries | Preview (for the Copilot Studio extended set; baseline alerting in core XDR is GA) | • Reporting cadence and ownership of safety-filter alerts • Threshold tuning per agent and per audience (employee vs customer-facing) |
| Incident Management Practices | Partial | Strong | Native integration with Defender XDR Incidents and Alerts framework AI agent alerts correlate into the same incident structure as the rest of SOC operations Dedicated Agent entity in XDR for incident pivoting | Preview | • Incident response runbook updates to cover AI-specific scenarios • Alignment with Technology Incident Management Standard • Tabletop exercises validating Defender alert routing |
Partial Alignment — Defender contributes but does not close
| Control ID & Title | Status | Defender Strength | Defender Contribution | Production Readiness | Residual Organization Action |
| Policy Enforcement and Guardrails | Partial | Partial | Real-time blocking of malicious tool invocations (preview) Adds detective layer on top of Prompt Shields | Preview | • Custom Purview SITs for organization-specific PII • Multi-turn jailbreak detection • Cross-agent context manipulation rules • Per-agent expected data-flow profile |
| Logging and Repudiation | Partial | Partial | Audit log collection from Copilot Studio agents into Defender Advanced Hunting KQL queries against agent telemetry | Preview | • Two-pillar architecture (Purview Audit + App Insights) remains primary • Defender XDR is third consumption layer, not replacement • Knowledge source change lineage still not exposed • Permission-elevation aggregation still requires Sentinel correlation |
| Identity Access | Partial | Partial | XDR can detect anomalous identity behaviour patterns Suspicious OBO token use surfaces as alerts | Preview | • MCP-protocol-level controls (token nonce, session-IP binding) remain custom-MCP-server responsibility • Entra Agent ID configuration unchanged • PIM and Conditional Access remain primary identity controls |
| Input and Output Sanitization | Partial | Partial | Runtime protection blocks injection-style inputs before tool execution Complements Prompt Shields for input sanitization | Preview | • Application-layer sanitization for downstream-system integrity • Output validation for documents and structured data |
| Excessive Agency / Blast Radius Limitation | Partial | Partial | Real-time tool invocation blocking limits blast radius at runtime Inspection of agent-initiated tool calls before execution | Preview | • Per-agent blast-radius design documentation • Connector permission scoping at design time • HITL configuration for high-impact actions |
| Multi-Agent Orchestration Security | Partial | Partial | XDR can correlate agent execution telemetry across parent-child agents Suspicious chained execution patterns surfaced as alerts | Preview | • Agent-to-agent topology visualization remains custom build • Cross-agent prompt injection detection rules • Connected-agent invocation as a ‘powerful action’ control plane |
| Prompt Shields (User Prompt Attacks / Indirect Attacks) | Yes | Partial | Adds detection, alerting and hunting layer on top of Prompt Shields XPIA / UPIA events surfaced into Defender XDR incidents Persistent jailbreak attempts detected as distinct alerts | Preview | • Prompt Shields themselves remain GA and Microsoft-managed • Defender enrichment is additive — not required for baseline conformance |
Limited Applicability — Defender is not the right control plane
| Control ID & Title | Status | Defender Strength | Defender Contribution | Production Readiness | Residual Organization Action |
| Model Version Lifecycle and Deprecation | Partial | Limited | Defender model scanning applies to Foundry / AzureML registered models, not declarative-scope models | Not applicable for declarative scope | • Microsoft Roadmap monitoring • Internal model deprecation process • Pin model versions where possible |
| Embedding and Vector Store Security | Partial | Limited | Declarative agents inherit M365 search and Microsoft-managed embedding infrastructure Defender does not expose embedding store controls | Not applicable for declarative scope | • Purview sensitivity labels on indexed content • Restricted Content Discovery for source-level access control |
| Cost-Based Denial of Service / Wallet Attack Protection | Yes | Limited | Defender can alert on anomalous activity volumes Does not enforce cost ceilings | Capability gap | • Power Platform admin centre capacity controls • Microsoft 365 Admin Centre Copilot Credit pool management • Quota / rate-limit configuration per agent |
| AI Security Testing & Red Team Exercise Cadence | No | Limited | Defender is detective (runtime), not pre-deployment testing | Capability gap | • Promptfoo / Microsoft PyRIT / Garak for pre-deployment testing • Red team exercise cadence definition • Test plan with documented scenarios |
| Bias and Fairness Testing | Partial | Limited | Not in scope for Defender | Capability gap | • Fairlearn or comparable bias-testing framework • Documented test plan separate from security testing |
| Model Card and Transparency Documentation | Partial | Limited | Not in scope for Defender | Capability gap | • Internal model card template • Publication process aligned with EU AI Act Article 13 |
| AI-Specific Vendor Risk Assessment | Yes | Limited | Not in scope for Defender | Capability gap | • Third-party risk management process • AI-specific vendor questionnaire |
| AI Solution Sunset Triggers | No | Limited | Not in scope for Defender | Capability gap | • Measurable sunset triggers (drift, regulatory change, vendor support) • Sunset playbook |
| Content Generation / EU AI Act Article 50 | Partial | Limited | Not in scope for Defender | Capability gap | • Watermarking / provenance metadata for synthetic content • User disclosure mechanism for AI-generated outputs |
| Citation and Source Attribution Integrity | Partial | Limited | Not in scope for Defender | Capability gap | • Citation verification against trusted sources • Hallucination scoring at output time (Foundry Groundedness Detection) |
| AI Solution Decommissioning and Data Deletion | Partial | Limited | Not in scope for Defender | Capability gap | • Documented decommissioning procedure • Data deletion verification against approved retention schedules |
| Data Protection / Data Pipeline / Dataset Approval | Partial / Yes | Limited | Purview / DSPM for AI is the right control plane, not Defender | Capability gap (Defender) — use Purview | • Purview sensitivity labels • DSPM for AI policies for sensitive data in prompts • Dataset approval workflow |
Production-Readiness Decisions
Given that the strongest Defender contributions are currently in Preview, a per-capability production-readiness decision is required before any of these mappings can be reflected as ‘Yes’ status in the . The table below records the proposed decisions and the rationale for each.
| Defender Capability | Release Status | Rationale / Notes |
| Cloud App Catalog (shadow AI discovery) | GA | GA today; aligns with no-preview policy. Onboarding cost is low if Defender for Cloud Apps already licensed via Microsoft 365 E5. Strong fit for AI BOM (AG-01) input feed. |
| Advanced Hunting Community Hunting Queries | GA (Feb 2026) | GA today; already cited in (AMCP-03, AMCP-09). Onboarding requires Defender XDR access and KQL skill in SOC team. |
| Advanced Hunting integration (Copilot Studio telemetry in KQL) | GA | GA today; complements existing two-pillar logging architecture (Purview Audit + App Insights). Provides third consumption layer for SOC. |
| AI Agent Inventory (Copilot Studio agents) | Preview | Highest-value. Decision contingent on the AI BOM workstream timeline and the organization’s appetite for Preview features in security tooling. |
| Real-time runtime protection (tool invocation blocking) | Preview | Highest-value runtime protection. Failure-mode analysis required: what happens when Defender misclassifies a legitimate tool call as suspicious? Customer impact and rollback plan needed before Preview acceptance. |
| XDR alerts for AI agents (jailbreak, suspicious execution) | Preview | Detective control with no business impact on legitimate use. Lower risk Preview adoption candidate. |
| Exposure Management for AI agents | Preview | Posture-only — recommendations and findings, not enforcement. Lower risk Preview adoption candidate. |
| AI BOM discovery for Copilot Studio in Defender CSPM | Preview | Requires Defender for CSPM plan in addition to Defender for Cloud Apps. Evaluate licensing cost against alternatives (Power Platform CoE Starter Kit). |
Leave a Reply