SecOps for AI
Connect agent activity to security operations — stream telemetry to the SOC, detect AI-specific threats, and investigate and respond to agent incidents across Microsoft Sentinel, Defender, and Purview.
Once agents are discovered, governed, and running, the security operations centre has to treat them like any other part of the estate: watched, detected on, and answerable when something goes wrong. SecOps for AI is that motion. First, stream agent telemetry — invocations, tool calls, and interactions — into the SOC's tooling so agent activity can be hunted and correlated alongside everything else. Then turn that activity into detections for the attacks that target agents and the AI infrastructure beneath them: prompt injection, jailbreak, credential theft, and abnormal execution. Finally, give responders what an agent incident demands — the agent inventory, the identity graph behind it, the conversation evidence, and a defensible eDiscovery path — so an alert can be scoped, understood, and acted on.
How to address SecOps for AI
-
Stream Agent Activity to Security Operations
Routes agent telemetry — invocations, tool calls, and interactions — from the agent platforms into the SOC's tooling, so that agent activity is monitored, hunted, and correlated alongside the rest of the estate. -
Detect Threats to AI Agents
Turns agent activity into detections — surfacing prompt injection, jailbreak, credential theft, and abnormal execution against agents and the AI infrastructure they depend on, with alerts centralized for the SOC.Detect Threats to AI Agents Microsoft Defender XDRMicrosoft Defender for CloudMicrosoft Copilot StudioMicrosoft Purview Data Security Posture ManagementAgent Threat Detection Agents Agent Security Posture Management Agents AI Threat Protection Infrastructure Agent Runtime Protection Status Agents Purview DSPM AI Interaction Discovery Users -
Investigate and Respond to Agent Incidents
Gives responders what they need to work an agent incident end to end — the agent inventory, the identity graph behind it, the conversation evidence, and the legal-hold path — so an alert can be scoped, understood, and acted on.Investigate and Respond to Agent Incidents Microsoft Defender XDRMicrosoft SentinelMicrosoft DataverseMicrosoft PurviewMicrosoft Security CopilotAI Agent Inventory Agents Agent Identities Asset Connector Agents Power Platform Activity Monitoring Agents Copilot Activity Investigation Agents Users Data Conversation Transcript Retention Agents Data eDiscovery for Agent Interactions Agents Data AI and Agent Activity Audit Agents Users Data AI-Assisted Incident Investigation & Response Agents
Control coverage
Monitoring12
Continuous observability of AI workload behaviour, usage, and anomalies through logging, metrics, and alerting — enabling detection of drift, misuse, and security events.
Threat Detection6
Capabilities that identify, alert on, and help respond to threats targeting AI models, inference endpoints, training pipelines, and supporting infrastructure.
Discovery5
Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.
Incident Response5
Capabilities that support detection, investigation, containment, and recovery for security incidents involving AI workloads — including automated response playbooks, forensic telemetry, and remediation guidance.
Compliance3
Controls that help organisations meet regulatory and policy obligations for AI systems, including audit trails, data residency, and policy enforcement.
Agent Security1
Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.
Governance1
Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.
Identity & Access1
Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.