Solutions  ·  2026-07-31

Microsoft Defender adds runtime threat detection (preview) and real-time protection (GA) for Microsoft Agent 365 agents

SolutionsHigh impactGlobal
Microsoft announced (July 27, 2026) two new Defender for AI capabilities: Threat detection for Microsoft Agent 365 agents (public preview), which surfaces alerts for indirect prompt injection, evasion, secret leakage, and malicious content propagation across Copilot Studio, Foundry, and M365 Copilot Agent Builder; and Real-time protection for Agent 365 tooling servers (WorkIQ/custom MCP servers), now generally available, which blocks malicious tool interactions inline during agent execution.
This is one of the first GA-level runtime enforcement capabilities purpose-built for agentic AI tool-calling (vs. just detection), extending Defender XDR into the agent execution lifecycle across Microsoft's entire agent ecosystem.
Enterprises running Microsoft Agent 365, Copilot Studio, or Foundry agents should enable Security for AI workload in Defender now; MCP/tooling-server operators should evaluate real-time protection immediately given GA status.
Microsoft Community Hub (Security for AI)Microsoft Security Blog - What's new July 2026
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →