Detect Threats to AI Agents
Turns agent activity into detections — surfacing prompt injection, jailbreak, credential theft, and abnormal execution against agents and the AI infrastructure they depend on, with alerts centralized for the SOC.
Core capabilities
-
Detect threats targeting agents — abnormal execution, risky tool use, and suspicious activity — and raise alerts in the Microsoft Defender portal
-
Detect runtime attacks on the underlying Azure OpenAI and Azure AI model inference workloads — prompt injection, jailbreak, data leakage, and wallet abuse — and centralize alerts in Defender XDR
-
Confirm that Copilot Studio agents are covered by runtime protection so detections aren't blind to low-code agents
Supporting capabilities 2
-
Flag sensitive data flowing into agent prompts so detections can be prioritized by data-exposure risk
-
Reduce the attack surface ahead of detection by identifying misconfigurations and posture gaps across agents