Securing AI Agents at Runtime: Real-Time Protection and Threat Detection for Microsoft Agent 365
Businesses are increasingly turning to AI agents to streamline workflows, retrieve company data, access various tools, and act on users’ behalf. However, this independence presents a new set of security challenges.
Unlike conventional AI systems, these agents interact in dynamic workflows, engaging with external content, calling different tools, and accessing sensitive data. This behaviour creates attack routes that traditional security measures aren’t equipped to handle.
Today, we’re thrilled to share two significant advancements regarding AI Security in Microsoft Defender for Microsoft Agent 365:
- Public preview of threat detection for Microsoft Agent 365 agents—now available!
These new features provide security teams with tools to detect, investigate, and counter threats aimed at AI agents, expanding Microsoft Defender’s protection capabilities into the agent’s runtime environment.
Threat detection equips Security Operations Centre (SOC) teams with in-depth visibility into potential attacks and suspicious activities targeting AI agents. By examining runtime signals from agent interactions, tool operations, and execution patterns, Microsoft Defender highlights unusual or harmful behaviours throughout the agent’s execution lifecycle, delivering actionable security alerts.
This threat detection functionality is compatible with cloud agent types that send observability logs to Microsoft Agent 365, including:
- Microsoft Copilot Studio
- Microsoft 365 Copilot Agent Builder
- Agents integrated via the Microsoft Agent 365 SDK
This ensures consistent visibility of threats across all supported Microsoft Agent 365 experiences, no matter the method of agent construction.
Fig. 1. Alerts from Microsoft Security for AI in Microsoft Defender XDR (Preview)
Microsoft Defender is adept at spotting a wide array of AI-specific threats, such as:
- Indirect prompt injection (XPIA) — malicious instructions hidden in external content to manipulate agent behaviour.
- Evasion techniques — attempts to bypass agent instructions or security protocols.
- Propagation of malicious content — attempts to use agents for generating or spreading harmful content.
- Secret leakage — risks of exposing credentials, API keys, or other sensitive information via agent interactions.
- LLM reconnaissance — attempts to explore the capabilities, instructions, or security thresholds of agents.
- Suspicious IP access — agent access from anonymized or suspicious IP addresses.
Alerts are directly visible in Microsoft Defender, allowing SOC analysts to investigate and respond with familiar tools, Advanced Hunting queries, and the Defender XDR experience.
Real-time protection goes beyond mere detection by blocking threats as they appear when AI agents communicate with WorkIQ and custom MCP servers (see Microsoft Agent 365 server tools).
Whenever an agent calls a registered tool or receives a tool response, Defender checks the interaction against designed security policies to decide whether to permit or block it on-the-fly within the agent’s execution framework.
This proactive approach prevents harmful actions and data breaches in real time, eliminating the need for agent developers to create custom security measures.
Fig. 2. Real-Time Protection policy for AI in Microsoft Defender
Real-time protection currently safeguards against major threats, including:
- Evasion techniques — attempts to circumvent agent protections or security protocols.
- Propagation of malicious content — stopping agents from disseminating harmful content through tool actions.
- Secret leakage — ensuring agents don’t accidentally reveal credentials or sensitive information during tool interactions.
- Unauthorized communication with untrusted domains — stopping agents from sending emails or data to risky or untrustworthy domains.
The two features of threat detection and real-time protection address different aspects of the agent security lifecycle.
Real-time protection offers immediate actions to block harmful interactions during execution, while threat detection provides SOC teams with the insights and investigation context necessary to recognise attack trends, evaluate impacts, and respond to any suspicious activities.
Together, they offer a robust defence strategy that merges runtime enforcement with SOC-driven detection and investigation, specifically designed for AI agents.
Both features can be accessed via Microsoft Defender, featuring a dedicated Security for AI workload to consolidate AI threat detection, investigations, and runtime protection policies.
If you’d like to learn more:
As AI agents gain more independence and access to company data and tools, ensuring their runtime security is crucial. With its Threat Detection and Real-Time Protection features, Microsoft Defender supports organisations in adopting AI agents, incorporating security protocols tailored to how these agents operate—detecting threats, assisting SOC investigations, and blocking harmful interactions as they occur.
Share this content:
Discover more from Qureshi
Subscribe to get the latest posts sent to your email.