You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-for-cloud-apps/ai-agent-inventory.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,23 +12,23 @@ ms.reviewer: gayasalomon
12
12
13
13
# Discover and protect your Copilot Studio custom AI Agents (Preview)
14
14
15
-
Microsoft Defender detects all Copilot Studio custom AI Agents in your tenant and provides tools to identify misconfigured or potentially risky agents.
16
-
17
-
When you give Microsoft Defender access to your custom agents, Microsoft Defender for Cloud Apps collects data from your Copilot Studio custom AI Agents for use in [advanced hunting](/defender-xdr/advanced-hunting-overview).
15
+
Microsoft Defender identifies all Copilot Studio custom AI agents in your tenant and provides tools to identify misconfigured or potentially risky agents, and collects
16
+
data from Copilot Studio for use in [advanced hunting](/defender-xdr/advanced-hunting-overview).
18
17
19
18
## Prerequisites
20
-
To enable AI agent inventory and detection you must opt in to public preview features of:
19
+
To enable AI agent threat protection inventory and detection you must opt in to public preview features of:
21
20
- Microsoft Defender for Cloud Apps
22
21
- Microsoft Defender for Cloud
23
22
- Microsoft Defender XDR
24
23
25
24
For more information, see [Microsoft Defender preview features](https://security.microsoft.com/securitysettings/defender/preview_features).
26
25
27
-
## Enable AI agent detection for Microsoft Copilot Studio custom agents
26
+
## Enable Copilot Studio AI agent threat protection inventory
28
27
29
28
> [!NOTE]
30
-
> The onboarding process for AI Agent protection requires collaboration with Power Platform administrators.
31
-
To enable AI agent detection for your Microsoft Copilot Studio agents, follow these steps:
29
+
> The onboarding process for AI Agent threat protection inventory requires collaboration with Power Platform administrators.
30
+
31
+
To enable Copilot Studio AI agent threat protection inventory, follow these steps:
32
32
33
33
1.**Sign in to the [Microsoft Defender portal](https://security.microsoft.com)** as the System Administrator.
34
34
1. Go to **System > Settings > Cloud Apps > Copilot Studio AI Agents**.
@@ -40,10 +40,10 @@ To enable AI agent detection for your Microsoft Copilot Studio agents, follow th
40
40
1. Select **Microsoft Defender - Copilot Studio AI Agents**.
41
41
1. Turn on **Enable Microsoft Defender - Copilot Studio AI Agents**.
42
42
43
-
When Copilot Studio AI Agents are connected, a green indicator appears in the **AI Agents Inventory** section. It can take up to 30 minutes for the initial connection status to update. Depending on the size and complexity of your environment, it might take longer to see the full deployment of the AI agent inventory.
43
+
When Copilot Studio AI Agents are connected, a green indicator appears in the **AI Agents Inventory** section in the Microsoft Defender portal. It can take up to 30 minutes for the initial connection status to update. Depending on the size and complexity of your environment, it might take longer to see the full deployment of the AI agent inventory.
44
44
45
45
46
-
## Use Advanced Hunting on your AI agents
46
+
## Identify misconfigured or risky AI agents
47
47
48
48
After you give Microsoft Defender access to your custom agents, you can use advanced hunting to help identify misconfigured or risky agents and minimize organizational exposure to potential threats.
Copy file name to clipboardExpand all lines: defender-for-cloud-apps/ai-agent-protection.md
+6-4Lines changed: 6 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,7 +10,7 @@ ms.reviewer: gayasalomon
10
10
11
11
# Protect your Microsoft Copilot Studio AI agents (Preview)
12
12
13
-
As no code/low code platforms become increasingly accessible, organizations face new types of security risks. These platforms empower people to build and deploy custom agents without centralized security review or controls in place. Attackers can attempt to manipulate these agents by:
13
+
As no code/low code platforms become increasingly accessible, organizations face new types of security risks. These platforms empower non-technical users to build and deploy custom agents without centralized security review or controls in place. Attackers can attempt to manipulate these agents by:
14
14
- injecting malicious prompts
15
15
- triggering unintended tool executions
16
16
- exploiting data sources to escalate privileges or exfiltrate data.
@@ -19,9 +19,11 @@ As no code/low code platforms become increasingly accessible, organizations face
19
19
20
20
Microsoft Defender addresses critical security gaps with comprehensive AI agent protection that includes proactive exposure, threat hunting, real time protection, and alerts. With AI agent protection, Microsoft Defender:
21
21
22
-
- Detects all of your custom AI agents created with Microsoft Copilot Studio, and integrates AI Agent data into advanced hunting for proactive threat detection. You can use this data to create custom queries and hunt for potential threats. See [Discover and protect your AI agents (Preview)](ai-agent-inventory.md) to learn how to set up and make use of the AI agent inventory.
23
-
- After you give Microsoft Defender access to your custom agents and [enable the Microsoft 365 app connector](protect-office-365.md#connect-microsoft-365-to-microsoft-defender-for-cloud-apps), Microsoft Defender continuously monitors and collects audit logs for your AI agents for suspicious activity, enabling detections and alerts on your custom AI agents created with Copilot Studio.
24
-
- Provides real-time protection to block suspicious or harmful actions initiated by your AI agents. See [Enable real-time protection for Microsoft Copilot Studio Agents](/real-time-agent-protection-during-runtime.md) to learn how to set up real-time protection.
22
+
- Detects all of your custom AI agents created with Microsoft Copilot Studio, and integrates their data into advanced hunting for proactive threat detection. You can use this data to create custom queries and hunt for potential threats. See [Discover and protect your AI agents (Preview)](ai-agent-inventory.md) to learn how to set up and make use of the AI agent inventory.
23
+
- Collects audit logs for your custom AI agents created with Copilot Studio, continuously monitors the agents for suspicious acitivity, and enables detections and alerts. To enable this monitoring, make sure that you:
24
+
- Give Microsoft Defender access to your custom agents by [Enabling AI agent detection for Microsoft Copilot Studio custom agents](ai-agent-inventory.md#enable-ai-agent-detection-for-microsoft-copilot-studio-custom-agents).
25
+
-[Enable the Microsoft 365 app connector](protect-office-365.md#connect-microsoft-365-to-microsoft-defender-for-cloud-apps)
26
+
- Provides real-time protection to block suspicious or harmful actions initiated by your AI agents, and triggers an informative alert integrated into the XDR incidents and alerts environment. See [Enable real-time protection for Microsoft Copilot Studio Agents](/real-time-agent-protection-during-runtime.md) to learn how to set up real-time protection.
Copy file name to clipboardExpand all lines: defender-for-cloud-apps/real-time-agent-protection-during-runtime.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,7 +33,7 @@ If Microsoft Defender determines that a prompt is suspicious:
33
33
- Under **Microsoft 365 connector**, select **Connect** or **Edit**.
34
34
- Select **Microsoft Entra ID Management events** and **Microsoft 365 activities**.
35
35
- Select **Connect Microsoft 365**.
36
-
1.Enter the App ID provided by your Power Platform administrator and select **Save**.
36
+
1.Work together with a Power Platform administrator to and enter the App ID provided by your Power Platform administrator and select **Save**.
37
37
38
38
:::image type="content" source="media/protect-ai-agents/turn-on-real-time-agent-protection.png" alt-text="Screenshot that shows how to turn on Real time agent protection during runtime in the Defender portal." lightbox="media/protect-ai-agents/turn-on-real-time-agent-protection.png":::
0 commit comments