Microsoft has announced several new AI agents for its Security Copilot solution to assist with enterprise resilience.
These agents intend to support security and IT admins with critical areas such as phishing, data security, and identity management. Meanwhile, AI security remains a top priority, driving innovations in Microsoft Defender, Entra, and Purview to enhance protection and governance.
Vasu Jakkal, Corporate Vice President of Microsoft Security, wrote in an announcement blog post:
We are excited to announce the next evolution of Security Copilot with AI agents designed to autonomously assist with critical areas such as phishing, data security, and identity management. The relentless pace and complexity of cyberattacks have surpassed human capacity and establishing AI agents is a necessity for modern security."
Microsoft Copilot Security launched last April with the remit of helping security and IT admins "catch what others miss, move faster, and strengthen team expertise.” Copilot for Security functions ostensibly as a chatbot for security admins to use to read and analyse critical information such as threat summaries and security incidents.
Microsoft cites the ever-growing necessity for vigilance around cybersecurity as an inspiration for the agents' introduction. For example, Jakkal notes that phishing remains a major cyber threat, with Microsoft detecting over 30 billion attacks in 2024. Microsoft Security Copilot’s new phishing triage agent automates alerts, freeing defenders to tackle complex threats.
More Specifics on the New Security Agents' Feature Sets
Microsoft has introduced six specialised Security Copilot agents to help security and IT teams manage high-volume tasks autonomously. The tech giant stresses that these AI-driven agents integrate with Microsoft Security solutions, learning from feedback, adapting to workflows, and operating within its Zero Trust framework. The pitch is that with security teams in control, they accelerate responses, prioritise risks, and enhance efficiency to affirm cyber resilience.
Each agent is tailored for a specific function within Microsoft’s security ecosystem. The Phishing Triage Agent in Microsoft Defender precisely assesses phishing alerts, distinguishing real threats from false alarms while improving detection based on admin feedback. In Microsoft Purview, Alert Triage Agents prioritise critical data loss prevention and insider risk alerts, which Microsoft says constantly refines accuracy.
The Conditional Access Optimisation Agent in Microsoft Entra identifies gaps in security policies and recommends quick fixes for identity teams. In Microsoft Intune, the Vulnerability Remediation Agent monitors and prioritises vulnerabilities, streamlining app and policy configuration fixes and expediting Windows OS patches with admin approval.
Finally, the Threat Intelligence Briefing Agent in Security Copilot curates real-time threat intelligence based on an organisation’s unique risk profile, providing security teams with proactive insights.
Microsoft says these Security Copilot agents enable faster threat response, smarter risk management, and stronger overall protection by automating key security tasks.




