Solutions  ·  2026-08-20

Microsoft Defender for Endpoint adds AI agent runtime protection (Preview)

SolutionsMedium impactGlobal
Microsoft published preview documentation (dated Aug 14, 2026) for AI agent runtime protection in Defender for Endpoint, offering agent-native event inspection and network inspection to detect prompt injection targeting local AI agents (e.g., agentic coding tools) and block or audit the resulting action in Audit/Block modes, deployable via Intune with phased rollout guidance.
Brings prompt-injection detection down to the endpoint/device level for locally-running AI agents (not just cloud/SaaS agents), closing a blind spot as coding agents and desktop AI tools proliferate with user-level privileges.
Enterprises running Defender for Endpoint Plan 2 / M365 E5/E7 with local AI coding agents in use should pilot audit mode now ahead of GA.
Microsoft Learn
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →