News

Microsoft Puts AI Agents to Work in Security Operations with Project Perception

Microsoft has begun testing Project Perception, a multi-agent cybersecurity system designed to investigate threats and take corrective action inside the company’s security products.

The system entered a limited public preview on August 3 following its July 27 announcement. Despite the name, the preview is available only to a small group of invited customers, and Microsoft cautions that the product could change substantially before its commercial release, according to Microsoft Learn.

Project Perception marks a shift beyond the chat-based assistance associated with Microsoft Security Copilot. Rather than waiting for a user to ask a question, Perception coordinates specialized agents that can execute security workflows, share findings, and request approval before taking sensitive actions.

Microsoft describes the distinction simply: Security Copilot is AI that assists, while Project Perception is AI that acts. The two systems are designed to work together, according to the company’s Project Perception product page.

The approach reflects a broader change in enterprise AI. Software vendors are moving from copilots that summarize information or recommend next steps toward systems that can perform work across multiple applications. In cybersecurity, that transition carries unusually high stakes because an agent may need access to sensitive data, administrative tools, and production systems.

Red, Blue, and Green Agents
Project Perception organizes its agents into roles modeled on established cybersecurity practices.

Red agents search for weaknesses and potential paths an attacker could use to compromise an environment. Blue agents investigate activity and determine whether it represents a meaningful threat. Green agents remediate problems and strengthen defenses after risks have been identified.

The agents operate through playbooks that assign objectives and coordinate work across a security workflow. Each agent performs a defined function, but they share findings and organizational context with the other agents involved in the session, according to Microsoft’s technical overview.

A company might use a red agent to identify an exposed cloud resource, for example. A blue agent could then evaluate whether the exposure presents an immediate risk, while a green agent proposes or applies a corrective action.

Microsoft says defenders retain control over critical decisions. Security administrators configure each agent’s identity and permissions, and users can approve, reject, or modify a proposed action. Agent activity and outputs are available for review through the Microsoft Defender portal.

The company’s setup documentation states that Project Perception uses Microsoft Entra Agent IDs to scope access. Organizations must also have unified role-based access control enabled across their Defender workloads.

Those controls will be central to the system’s enterprise value. An agent cannot remediate a problem without permission to change the affected system. Giving it that permission, however, increases the consequences of faulty reasoning, compromised instructions, or an incorrectly configured workflow.

From Alerts to Actions
Security tools traditionally generate alerts that analysts must investigate and resolve. Microsoft is betting that coordinated agents can handle more of that work while allowing human defenders to concentrate on decisions requiring judgment.

“The defining characteristic of the next generation of security systems will not be their ability to generate more alerts,” Microsoft said in its announcement. “It will be their ability to continuously perceive, reason and act.”

Project Perception draws on signals from Microsoft’s security products and combines them with information about the customer’s environment. That context can include previous incidents, policy decisions, identity relationships, and current activity.

The agents use a multi-model architecture rather than relying on a single AI model for every task. Microsoft said the system can select models based on the demands and cost of a particular job.

Its first specialized model is MAI-Cyber-1-Flash, a Microsoft-developed cybersecurity model used inside MDASH, the company’s multi-agent system for identifying and remediating software vulnerabilities.

Microsoft said MDASH with MAI-Cyber-1-Flash scored about 96% on the CyberGym benchmark, 12 percentage points higher than Anthropic’s Mythos model. The company also said the configuration reduced costs by nearly half compared with the version of MDASH then in use.

Those are Microsoft’s own benchmark and cost claims. The company has not published independent customer testing demonstrating the same performance in production environments. Benchmark results also cover a specific vulnerability-management task, not the full range of work Project Perception is expected to perform.

Microsoft said it plans to use MAI-Cyber-1-Flash in additional security workflows. The model has 5 billion active parameters and was trained for vulnerability identification and remediation, according to its model card.

Human Control Remains the Test
Microsoft says every high-impact action will remain subject to human approval. Its documentation nevertheless allows administrators to configure agents to run manually or trigger automatically, making governance choices an important part of deployment.

Administrators will need to decide which systems agents can access and which actions require approval. They will also need procedures for examining agent activity when an automated workflow produces an unexpected result.

Project Perception includes a central view of agent sessions and generated artifacts. Users can stop active work and respond to approval requests. Microsoft also provides a record of the agents involved in each session, according to its session documentation.

Some limitations are built into the preview. Playbooks are managed by Microsoft, and customers cannot create, edit, or delete them. Organizations can configure individual agents, but they do not yet have full control over the workflows coordinating those agents.

The product initially operates through Microsoft Defender. Microsoft said it plans to extend Project Perception across the rest of its security portfolio, but it has not provided a timetable.

A Consumption-Based Model
Project Perception will use pay-as-you-go pricing based on Security Compute Units. Agents consume units at different rates depending on the intensity of the work they perform, Microsoft said.

The consumption model could align cost with actual use, but it may also make spending harder to predict. An investigation involving several agents and a long-running playbook could consume more capacity than a narrowly defined task.

Microsoft has not disclosed general pricing for Project Perception or provided enough public information to estimate the cost of operating the system at enterprise scale.

That question matters because security operations run continuously. If autonomous investigation and remediation become standard, organizations will need to evaluate not only whether the agents work, but whether their benefits justify an ongoing and potentially variable compute bill.

Why It Matters
Project Perception is significant because it moves agentic AI closer to operational control of enterprise security systems. The product is designed to do more than summarize incidents or suggest responses. It can coordinate work and turn decisions into actions.

That could help security teams process more threats without expanding staff at the same rate. It could also introduce new risks if permissions are too broad, agent behavior is difficult to audit, or organizations automate workflows before understanding their failure modes.

For now, Project Perception remains a preview rather than a proven replacement for established security operations. Microsoft still needs to demonstrate how reliably the agents perform across varied environments and how customers can control costs at scale.

The larger direction is clear. Microsoft is betting that the next phase of cybersecurity will depend less on giving analysts more alerts and more on allowing AI systems to carry out carefully governed work. Project Perception is an early test of whether enterprises are ready to make that trade.

About the Author

John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS.  He can be reached at [email protected].

Featured