SecOps for AI

Updated

Connect agent activity to security operations — stream telemetry to the SOC, detect AI-specific threats, and investigate and respond to agent incidents across Microsoft Sentinel, Defender, and Purview.

Once agents are discovered, governed, and running, the security operations centre has to treat them like any other part of the estate: watched, detected on, and answerable when something goes wrong. SecOps for AI is that motion. First, stream agent telemetry — invocations, tool calls, and interactions — into the SOC's tooling so agent activity can be hunted and correlated alongside everything else. Then turn that activity into detections for the attacks that target agents and the AI infrastructure beneath them: prompt injection, jailbreak, credential theft, and abnormal execution. Finally, give responders what an agent incident demands — the agent inventory, the identity graph behind it, the conversation evidence, and a defensible eDiscovery path — so an alert can be scoped, understood, and acted on.

How to address SecOps for AI

  1. Stream Agent Activity to Security Operations

    Routes agent telemetry — invocations, tool calls, and interactions — from the agent platforms into the SOC's tooling, so that agent activity is monitored, hunted, and correlated alongside the rest of the estate.
  2. Detect Threats to AI Agents

    Turns agent activity into detections — surfacing prompt injection, jailbreak, credential theft, and abnormal execution against agents and the AI infrastructure they depend on, with alerts centralized for the SOC.
  3. Investigate and Respond to Agent Incidents

    Gives responders what they need to work an agent incident end to end — the agent inventory, the identity graph behind it, the conversation evidence, and the legal-hold path — so an alert can be scoped, understood, and acted on.

Control coverage

Control coverage for SecOps for AI — where its 16 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
Monitoring
12
Threat Detection
6
Discovery
5

Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.

Incident Response
5

Capabilities that support detection, investigation, containment, and recovery for security incidents involving AI workloads — including automated response playbooks, forensic telemetry, and remediation guidance.

Compliance
3

Controls that help organisations meet regulatory and policy obligations for AI systems, including audit trails, data residency, and policy enforcement.

Agent Security
1

Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.

Governance
1

Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.

Identity & Access
1

Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.