What happened
Microsoft announced (July 27, 2026) two new Defender for AI capabilities: Threat detection for Microsoft Agent 365 agents (public preview), which surfaces alerts for indirect prompt injection, evasion, secret leakage, and malicious content propagation across Copilot Studio, Foundry, and M365 Copilot Agent Builder; and Real-time protection for Agent 365 tooling servers (WorkIQ/custom MCP servers), now generally available, which blocks malicious tool interactions inline during agent execution.
Why it matters
This is one of the first GA-level runtime enforcement capabilities purpose-built for agentic AI tool-calling (vs. just detection), extending Defender XDR into the agent execution lifecycle across Microsoft's entire agent ecosystem.
Applicability
Enterprises running Microsoft Agent 365, Copilot Studio, or Foundry agents should enable Security for AI workload in Defender now; MCP/tooling-server operators should evaluate real-time protection immediately given GA status.