What happened
Microsoft published preview documentation (dated Aug 14, 2026) for AI agent runtime protection in Defender for Endpoint, offering agent-native event inspection and network inspection to detect prompt injection targeting local AI agents (e.g., agentic coding tools) and block or audit the resulting action in Audit/Block modes, deployable via Intune with phased rollout guidance.
Why it matters
Brings prompt-injection detection down to the endpoint/device level for locally-running AI agents (not just cloud/SaaS agents), closing a blind spot as coding agents and desktop AI tools proliferate with user-level privileges.
Applicability
Enterprises running Defender for Endpoint Plan 2 / M365 E5/E7 with local AI coding agents in use should pilot audit mode now ahead of GA.