Skip to content

Commit 58c9bf8

Browse files
committed
itai's changes
1 parent cf8fccc commit 58c9bf8

File tree

2 files changed

+22
-21
lines changed

2 files changed

+22
-21
lines changed

defender-for-cloud-apps/ai-agent-inventory.md

Lines changed: 19 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -10,15 +10,13 @@ ms.reviewer: gayasalomon
1010
#customer-intent: As a security administrator, I want view all of the AI Agents in my organization, and detect threats on my AI agents using advanced hunting.
1111
---
1212

13-
# Discover and protect your AI agents (Preview)
13+
# Discover and protect your Copilot Studio custom AI Agents (Preview)
1414

15-
Microsoft Defender detects all of the AI agents created with Microsoft Copilot Studio. Once you enable detection of your AI agents, Microsoft Defender for Cloud Apps automatically:
16-
- Runs detections on your AI Agents created using Copilot Studio
17-
- Creates alerts and incidents for suspicious activity
18-
- Includes [AI agent data](/defender-xdr/advanced-hunting-aiagentsinfo-table) in [advanced hunting](/defender-xdr/advanced-hunting-overview).
19-
15+
Microsoft Defender detects all Copilot Studio custom AI Agents in your tenant and identify misconfigured or potentially risky agents.
16+
17+
When you enable detection of your AI agents, Microsoft Defender for Cloud Apps populates the [AIAgentsInfo table](/defender-xdr/advanced-hunting-aiagentsinfo-table) which can be used in [advanced hunting](/defender-xdr/advanced-hunting-overview).
2018

21-
## Enable AI agent detection for Microsoft Copilot Studio agents
19+
## Enable AI agent detection for Microsoft Copilot Studio custom agents
2220

2321
> [!NOTE]
2422
> The onboarding process for AI Agent protection requires collaboration with Power Platform administrators.
@@ -41,9 +39,8 @@ When Copilot Studio AI Agents are connected, a green indicator appears in the **
4139
Once you enable AI agent protection on your AI agents created using Copilot Studio, enable the Microsoft 365 App Connector to:
4240
- Run detections on your AI Agents created using Copilot Studio
4341
- Create alerts and incidents for suspicious activity
44-
- Include AI agent data in advanced hunting
4542

46-
### Connect Microsoft Defender for Cloud Apps to Microsoft 365
43+
To enable threat detection and alerts, connect Microsoft Defender for Cloud Apps to Microsoft 365:
4744

4845
1. Complete the steps in Microsoft 365 to [Connect Defender for Cloud Apps with Microsoft 365](protect-office-365.md#connect-microsoft-365-to-microsoft-defender-for-cloud-apps).
4946
1. When you complete the Microsoft 365 connector setup, sign in to the **[Microsoft Defender portal](https://security.microsoft.com)**, and go to **System > Settings > Cloud Apps > Copilot Studio AI Agents**.
@@ -56,8 +53,18 @@ Once you enable AI agent protection on your AI agents created using Copilot Stud
5653

5754
## Use Advanced Hunting on your AI agents
5855

59-
When the Microsoft 365 app connector is enabled, Microsoft Defender populates the `AIAgentsInfo` table in advanced hunting with information about your AI agents created using Copilot Studio.
56+
When the Microsoft 365 app connector is enabled, you can use advanced hunting to help identify misconfigured or risky agents and minimize organizational exposure to potential threats.
57+
58+
1. Sign in to the Defender portal, ang go to **Advanced hunting**.
59+
1. In the **Apps & identities** section, the [AIAgentsInfo](/defender-xdr/advanced-hunting-aiagentsinfo-table) contains data for all your custom AI agents created using Copilot Studio. You can use this data to create custom queries.
60+
1. In the **Queries** tab, see the **MCS AI Agents** section for pre-defined KQL queries to help identify misconfigured or risky agents.
6061

61-
You can use this data to create custom queries and hunt for potential threats.
62+
For example, you can use queries to: :
63+
- locate agents that use maker authentication mechanisms, which might allow access to data users shouldn't have
64+
- locate agents that haven't been used for over 30 days, as these may create unnecessary exposure without contributing to productivity.
65+
66+
We recommend deleting risky agents or reaching out to their owners for further information.
67+
68+
See [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview) to learn how to use queries to proactively hunt for threats.
6269

63-
See [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview) and [AIAgentsInfo](/defender-xdr/advanced-hunting-aiagentsinfo-table) to learn how to use queries to proactively hunt for threats.
70+

defender-for-cloud-apps/ai-agent-protection.md

Lines changed: 3 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -17,19 +17,13 @@ As no code/low code platforms become increasingly accessible, organizations face
1717

1818
## AI agent threat protection features
1919

20-
Microsoft Defender addresses critical security gaps with comprehensive AI agent protection that includes proactive exposure and threat hunting. With AI agent protection, Microsoft Defender:
20+
Microsoft Defender addresses critical security gaps with comprehensive AI agent protection that includes proactive exposure, threat hunting, real time protection, and alerts. With AI agent protection, Microsoft Defender:
2121

22-
- Detects all of your AI agents created with Microsoft Copilot Studio. See [Discover and protect your AI agents (Preview)](ai-agent-inventory.md) to learn how to set up AI agent inventory.
23-
- Continuously monitors your AI agents for suspicious activity, enabling detections and alerts on your AI agents created with Copilot Studio.
24-
- Integrates AI Agent data into advanced hunting for proactive threat detection. You can use this data to create custom queries and hunt for potential threats.
25-
See [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview) and [AIAgentsInfo](/defender-xdr/advanced-hunting-aiagentsinfo-table) to learn how to use queries to proactively hunt for threats.
22+
- Detects all of your custom AI agents created with Microsoft Copilot Studio, and integrates AI Agent data into advanced hunting for proactive threat detection. You can use this data to create custom queries and hunt for potential threats. See [Discover and protect your AI agents (Preview)](ai-agent-inventory.md) to learn how to set up AI agent detection.
23+
- Continuously monitors your AI agents for suspicious activity, enabling detections and alerts on your custom AI agents created with Copilot Studio. See [Detect threats on your Microsoft Copilot Studio AI agents](ai-agent-inventory.md#detect-threats-on-your-microsoft-copilot-studio-ai-agents)
2624
- Provides real-time protection to block suspicious or harmful actions initiated by your AI agents. See [Enable real-time protection for Microsoft Copilot Studio Agents](/defender-for-cloud-apps/ai-agent-real-time-protection) to learn how to set up real-time protection.
2725

2826

29-
> [!NOTE]
30-
> - Microsoft Defender protection for AI agents supports AI agents created with Microsoft Copilot Studio.
31-
> - This feature is currently in public preview and included with your Microsoft Defender for Cloud Apps license at no extra cost. When the feature becomes generally available, licensing requirements might change.
32-
3327
## Related articles
3428

3529
- [Quickstart: Create and deploy an agent](/microsoft-copilot-studio/fundamentals-get-started)

0 commit comments

Comments
 (0)