You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-for-cloud-apps/ai-agent-inventory.md
+19-12Lines changed: 19 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,15 +10,13 @@ ms.reviewer: gayasalomon
10
10
#customer-intent: As a security administrator, I want view all of the AI Agents in my organization, and detect threats on my AI agents using advanced hunting.
11
11
---
12
12
13
-
# Discover and protect your AI agents (Preview)
13
+
# Discover and protect your Copilot Studio custom AI Agents (Preview)
14
14
15
-
Microsoft Defender detects all of the AI agents created with Microsoft Copilot Studio. Once you enable detection of your AI agents, Microsoft Defender for Cloud Apps automatically:
16
-
- Runs detections on your AI Agents created using Copilot Studio
17
-
- Creates alerts and incidents for suspicious activity
18
-
- Includes [AI agent data](/defender-xdr/advanced-hunting-aiagentsinfo-table) in [advanced hunting](/defender-xdr/advanced-hunting-overview).
19
-
15
+
Microsoft Defender detects all Copilot Studio custom AI Agents in your tenant and identify misconfigured or potentially risky agents.
16
+
17
+
When you enable detection of your AI agents, Microsoft Defender for Cloud Apps populates the [AIAgentsInfo table](/defender-xdr/advanced-hunting-aiagentsinfo-table) which can be used in [advanced hunting](/defender-xdr/advanced-hunting-overview).
20
18
21
-
## Enable AI agent detection for Microsoft Copilot Studio agents
19
+
## Enable AI agent detection for Microsoft Copilot Studio custom agents
22
20
23
21
> [!NOTE]
24
22
> The onboarding process for AI Agent protection requires collaboration with Power Platform administrators.
@@ -41,9 +39,8 @@ When Copilot Studio AI Agents are connected, a green indicator appears in the **
41
39
Once you enable AI agent protection on your AI agents created using Copilot Studio, enable the Microsoft 365 App Connector to:
42
40
- Run detections on your AI Agents created using Copilot Studio
43
41
- Create alerts and incidents for suspicious activity
44
-
- Include AI agent data in advanced hunting
45
42
46
-
### Connect Microsoft Defender for Cloud Apps to Microsoft 365
43
+
To enable threat detection and alerts, connect Microsoft Defender for Cloud Apps to Microsoft 365:
47
44
48
45
1. Complete the steps in Microsoft 365 to [Connect Defender for Cloud Apps with Microsoft 365](protect-office-365.md#connect-microsoft-365-to-microsoft-defender-for-cloud-apps).
49
46
1. When you complete the Microsoft 365 connector setup, sign in to the **[Microsoft Defender portal](https://security.microsoft.com)**, and go to **System > Settings > Cloud Apps > Copilot Studio AI Agents**.
@@ -56,8 +53,18 @@ Once you enable AI agent protection on your AI agents created using Copilot Stud
56
53
57
54
## Use Advanced Hunting on your AI agents
58
55
59
-
When the Microsoft 365 app connector is enabled, Microsoft Defender populates the `AIAgentsInfo` table in advanced hunting with information about your AI agents created using Copilot Studio.
56
+
When the Microsoft 365 app connector is enabled, you can use advanced hunting to help identify misconfigured or risky agents and minimize organizational exposure to potential threats.
57
+
58
+
1. Sign in to the Defender portal, ang go to **Advanced hunting**.
59
+
1. In the **Apps & identities** section, the [AIAgentsInfo](/defender-xdr/advanced-hunting-aiagentsinfo-table) contains data for all your custom AI agents created using Copilot Studio. You can use this data to create custom queries.
60
+
1. In the **Queries** tab, see the **MCS AI Agents** section for pre-defined KQL queries to help identify misconfigured or risky agents.
60
61
61
-
You can use this data to create custom queries and hunt for potential threats.
62
+
For example, you can use queries to: :
63
+
- locate agents that use maker authentication mechanisms, which might allow access to data users shouldn't have
64
+
- locate agents that haven't been used for over 30 days, as these may create unnecessary exposure without contributing to productivity.
65
+
66
+
We recommend deleting risky agents or reaching out to their owners for further information.
67
+
68
+
See [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview) to learn how to use queries to proactively hunt for threats.
62
69
63
-
See [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview) and [AIAgentsInfo](/defender-xdr/advanced-hunting-aiagentsinfo-table) to learn how to use queries to proactively hunt for threats.
Copy file name to clipboardExpand all lines: defender-for-cloud-apps/ai-agent-protection.md
+3-9Lines changed: 3 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,19 +17,13 @@ As no code/low code platforms become increasingly accessible, organizations face
17
17
18
18
## AI agent threat protection features
19
19
20
-
Microsoft Defender addresses critical security gaps with comprehensive AI agent protection that includes proactive exposure and threat hunting. With AI agent protection, Microsoft Defender:
20
+
Microsoft Defender addresses critical security gaps with comprehensive AI agent protection that includes proactive exposure, threat hunting, real time protection, and alerts. With AI agent protection, Microsoft Defender:
21
21
22
-
- Detects all of your AI agents created with Microsoft Copilot Studio. See [Discover and protect your AI agents (Preview)](ai-agent-inventory.md) to learn how to set up AI agent inventory.
23
-
- Continuously monitors your AI agents for suspicious activity, enabling detections and alerts on your AI agents created with Copilot Studio.
24
-
- Integrates AI Agent data into advanced hunting for proactive threat detection. You can use this data to create custom queries and hunt for potential threats.
25
-
See [Proactively hunt for threats with advanced hunting in Microsoft Defender](/defender-xdr/advanced-hunting-overview) and [AIAgentsInfo](/defender-xdr/advanced-hunting-aiagentsinfo-table) to learn how to use queries to proactively hunt for threats.
22
+
- Detects all of your custom AI agents created with Microsoft Copilot Studio, and integrates AI Agent data into advanced hunting for proactive threat detection. You can use this data to create custom queries and hunt for potential threats. See [Discover and protect your AI agents (Preview)](ai-agent-inventory.md) to learn how to set up AI agent detection.
23
+
- Continuously monitors your AI agents for suspicious activity, enabling detections and alerts on your custom AI agents created with Copilot Studio. See [Detect threats on your Microsoft Copilot Studio AI agents](ai-agent-inventory.md#detect-threats-on-your-microsoft-copilot-studio-ai-agents)
26
24
- Provides real-time protection to block suspicious or harmful actions initiated by your AI agents. See [Enable real-time protection for Microsoft Copilot Studio Agents](/defender-for-cloud-apps/ai-agent-real-time-protection) to learn how to set up real-time protection.
27
25
28
26
29
-
> [!NOTE]
30
-
> - Microsoft Defender protection for AI agents supports AI agents created with Microsoft Copilot Studio.
31
-
> - This feature is currently in public preview and included with your Microsoft Defender for Cloud Apps license at no extra cost. When the feature becomes generally available, licensing requirements might change.
32
-
33
27
## Related articles
34
28
35
29
-[Quickstart: Create and deploy an agent](/microsoft-copilot-studio/fundamentals-get-started)
0 commit comments