Investigate and Respond to Agent Incidents
Gives responders what they need to work an agent incident end to end — the agent inventory, the identity graph behind it, the conversation evidence, and the legal-hold path — so an alert can be scoped, understood, and acted on.
Core capabilities
-
Pivot from an alert to the affected agent and its configuration through the AI agent inventory and advanced hunting in the Defender portal
-
Trace the identity graph behind the agent — owner, agent identity, blueprint, and service principal — to understand blast radius and lateral reach
-
Retrieve the conversation transcripts and metadata that show what the agent actually did and said during the incident window
-
Place agent interactions on legal hold and collect them through eDiscovery when an incident requires a defensible investigation
Supporting capabilities 4
-
Correlate Power Platform and Copilot Studio activity in Sentinel to reconstruct the sequence of events
-
Draw on the unified audit trail to establish who did what, and when, across agents and Copilot
-
Scope Microsoft 365 Copilot activity through the CopilotActivity table when the incident touches Copilot interactions
-
Summarise the incident, correlate signals across Defender and Sentinel, and follow guided responses in natural language to accelerate triage and containment