Chronicle/Defense & research

Microsoft announces Security Copilot agents for phishing triage, alert triage and remediation

DefenseTool releaseSignificance assistant-drafted

Microsoft announced Microsoft-built Security Copilot agents, including a Phishing Triage Agent in Defender, alert triage agents in Purview, a Conditional Access Optimization Agent, a Vulnerability Remediation Agent in Intune and a Threat Intelligence Briefing Agent, plus five partner agents. Preview was planned from April 2025; the announcement contains no evaluation of agent accuracy.

Why it matters

It marked a major vendor's shift from assistant-style copilots to semi-autonomous triage and remediation agents inside SOC tooling.

Key facts

As stated in the sources, with where to find them.

  • Named Microsoft agents include Phishing Triage (Defender), Alert Triage (Purview DLP and insider risk), Conditional Access Optimization (Entra), Vulnerability Remediation (Intune) and Threat Intelligence Briefing.Section listing Microsoft Security Copilot agents
  • Partner agents announced: OneTrust, Aviatrix, BlueVoyant, Tanium and Fletch.Partner agents section
  • Microsoft states it detected more than 30 billion phishing emails between January and December 2024.Opening context

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records