Microsoft announced Microsoft-built Security Copilot agents, including a Phishing Triage Agent in Defender, alert triage agents in Purview, a Conditional Access Optimization Agent, a Vulnerability Remediation Agent in Intune and a Threat Intelligence Briefing Agent, plus five partner agents. Preview was planned from April 2025; the announcement contains no evaluation of agent accuracy.
Why it matters
It marked a major vendor's shift from assistant-style copilots to semi-autonomous triage and remediation agents inside SOC tooling.
Key facts
As stated in the sources, with where to find them.
- Named Microsoft agents include Phishing Triage (Defender), Alert Triage (Purview DLP and insider risk), Conditional Access Optimization (Entra), Vulnerability Remediation (Intune) and Threat Intelligence Briefing.Section listing Microsoft Security Copilot agents
- Partner agents announced: OneTrust, Aviatrix, BlueVoyant, Tanium and Fletch.Partner agents section
- Microsoft states it detected more than 30 billion phishing emails between January and December 2024.Opening context
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
Nov 17, 2025
Aug 5, 2025
Dec 5, 2023
Nov 22, 2024
Jul 14, 2025
Mar 13, 2026