|
| 1 | +--- |
| 2 | +title: Discover and detect threats using the AI agents inventory (Preview) |
| 3 | +ms.author: abbyweisberg |
| 4 | +author: AbbyMSFT |
| 5 | +description: Learn how to view all of the AI Agents in your organization using Microsoft Defender. |
| 6 | +ms.date: 11/02/2025 |
| 7 | +ms.topic: how-to |
| 8 | +ms.service: defender-for-cloud-apps |
| 9 | +ms.reviewer: gayasalomon |
| 10 | +#customer-intent: As a security administrator, I want view all of the AI Agents in my organization, and detect threats on my AI agents using advanced hunting. |
| 11 | +--- |
| 12 | + |
| 13 | +# Discover and protect your AI Agents (Preview) |
| 14 | + |
| 15 | +Microsoft Defender detects all Copilot Studio custom AI agents in your tenant and provides tools to identify misconfigured or potentially risky agents, and collects data from Copilot Studio for use in [advanced hunting](/defender-xdr/advanced-hunting-overview). |
| 16 | + |
| 17 | +## Prerequisites |
| 18 | +To enable AI agent inventory and detection you must opt in to the [Microsoft Defender preview features](https://security.microsoft.com/securitysettings/defender/preview_features) of: |
| 19 | +- Microsoft Defender for Cloud Apps |
| 20 | +- Microsoft Defender for Cloud |
| 21 | +- Microsoft Defender XDR |
| 22 | + |
| 23 | +## Enable the Copilot Studio AI agent inventory |
| 24 | + |
| 25 | +> [!NOTE] |
| 26 | +> The onboarding process for the AI agent inventory requires collaboration with Power Platform administrators. |
| 27 | +
|
| 28 | +To enable the Copilot Studio AI agent inventory, follow these steps: |
| 29 | + |
| 30 | +1. **Sign in to the [Microsoft Defender portal](https://security.microsoft.com)** as the System Administrator. |
| 31 | +1. Go to **System > Settings > Cloud Apps > Copilot Studio AI Agents**. |
| 32 | +1. Turn on **Copilot Studio AI Agents**. Enabling Copilot Studio AI Agents confirms that you read the disclaimer and agree to use the Microsoft Defender AI agent protection features. |
| 33 | + |
| 34 | + :::image type="content" source="media/protect-ai-agents/copilot-studio-ai-agents-button.png" alt-text="Screenshot of the Copilot Studio AI Agent configuration toggle."::: |
| 35 | + |
| 36 | +1. Work together with the Power Platform administrator to complete these steps in the [Power Platform Portal](https://admin.preview.powerplatform.microsoft.com/security/threatdetection): |
| 37 | + 1. Go to **Security** -> **Threat Protection**. |
| 38 | + 1. Select **Microsoft Defender - Copilot Studio AI Agents**. |
| 39 | + 1. Turn on **Enable Microsoft Defender - Copilot Studio AI Agents**. |
| 40 | + |
| 41 | +When Copilot Studio AI Agents are connected, a green indicator appears in the **AI Agents Inventory** section in the Microsoft Defender system settings. It can take up to 30 minutes for the initial connection status to update. Depending on the size and complexity of your environment, it might take longer to see the full deployment of the AI agent inventory. |
| 42 | + |
| 43 | + |
| 44 | +## Identify misconfigured or risky AI agents using advanced hunting |
| 45 | + |
| 46 | +After you give Microsoft Defender access to your custom agents, you can use advanced hunting to help identify misconfigured or risky agents and minimize organizational exposure to potential threats. |
| 47 | +We recommend that you reach out to the owners of the risky agents for more information, and that you consider quarantining or deleting risky agents. |
| 48 | + |
| 49 | +1. Sign in to the Defender portal, and go **Investigation & response** -> **Hunting** -> **Advanced hunting**. |
| 50 | +1. In the **Apps & identities** section, the [AIAgentsInfo table](/defender-xdr/advanced-hunting-aiagentsinfo-table) contains data for all your custom AI agents created using Copilot Studio. You can use this data to create custom queries. |
| 51 | + |
| 52 | +### Sample queries |
| 53 | + |
| 54 | +Run this query to get a list of all the agents in your tenant: |
| 55 | + |
| 56 | +```kusto |
| 57 | + AIAgentsInfo |
| 58 | + | summarize arg_max(Timestamp, *) by AIAgentId |
| 59 | +``` |
| 60 | + |
| 61 | +Run this query to identify all published agents that are configured with an incorrect authentication mechanism: |
| 62 | + |
| 63 | +```kusto |
| 64 | + AIAgentsInfo |
| 65 | + | summarize arg_max(Timestamp, *) by AIAgentId |
| 66 | + | where AgentStatus != "Deleted" |
| 67 | + | where AgentStatus == "Published" |
| 68 | + | where UserAuthenticationType == "None" or AuthenticationTrigger == "As Needed" |
| 69 | + | project-reorder AgentCreationTime ,AIAgentId, AIAgentName, AgentStatus, CreatorAccountUpn, OwnerAccountUpns |
| 70 | +``` |
| 71 | + |
| 72 | + |
| 73 | +See [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview) to learn how to use queries to proactively hunt for threats. |
| 74 | + |
| 75 | + ## Related articles |
| 76 | + |
| 77 | + - [Protect your Copilot Studio custom AI Agents (Preview)](ai-agent-protection.md) |
| 78 | + - [Enable real-time protection for Microsoft Copilot Studio Agents](real-time-agent-protection-during-runtime.md) |
0 commit comments