Real-time Agent Protection
Inspects agent activity throughout the agentic loop and blocks risky actions before they execute, using a default audit rule and custom blocking rules scoped to specific agents from Security for AI policies in the Microsoft Defender portal. Covers Agent 365 tool invocations and Copilot Studio agents, and records audit and block events as behaviors in the BehaviorInfo table for hunting and custom detections.