Stream Agent Activity to Security Operations
Routes agent telemetry — invocations, tool calls, and interactions — from the agent platforms into the SOC's tooling, so that agent activity is monitored, hunted, and correlated alongside the rest of the estate.
Core capabilities
-
Stream agent telemetry from Agent 365, Azure AI Foundry, and Copilot into the Microsoft Sentinel data lake as the SOC's primary source for agent hunting and investigation
-
Emit the underlying OpenTelemetry activity — agent invocations and tool calls — that feeds the admin center, Defender, and Purview without manual instrumentation
-
Record agent and Copilot interactions in the unified audit log so analysts have a durable, compliance-grade activity trail
Supporting capabilities 4
-
Bring Power Platform and Copilot Studio activity into Sentinel to broaden coverage of low-code agents
-
Ingest agent identities as assets into the Sentinel data lake so the identity graph — owner, agent identity, blueprint, and service principal — is collected ahead of any investigation
-
Monitor agents across Foundry, Copilot Studio, and third-party frameworks in the unified Application Insights Agent details view, with opt-in high-fidelity Copilot Studio telemetry for deep KQL analysis when automatic observability isn't detailed enough
-
Scope Microsoft 365 Copilot activity through the CopilotActivity table for user-, host-, and model-level review