Security

Microsoft Security Updates: Agent 365 and Defender

3 min read

Summary

Microsoft has announced new security capabilities across Agent 365, Defender for Cloud, GitHub Advanced Security, and Microsoft Purview. The updates focus on improving visibility into AI agent activity, strengthening code-to-runtime protection, and accelerating data security investigations for security and IT teams.

Need help with Security?Talk to an Expert

Microsoft Security updates focus on AI agents, apps, and data

Introduction

Microsoft has released a new round of security updates aimed at helping organizations secure AI-driven workflows, strengthen cloud and application protection, and improve data investigations. For IT and security administrators, these changes matter because they add more visibility, faster detection, and better coordination across security operations and development teams.

What’s new

Microsoft Defender capabilities for Agent 365 tooling gateway

Microsoft introduced new Microsoft Defender capabilities in preview for the Agent 365 tooling gateway. These features are designed to help security teams detect, block, and investigate threats targeting AI agents and agentic workflows.

Key highlights include:

  • Near real-time protection using webhooks to inspect agent actions.
  • Detection of anomalous or risky behavior before actions are executed.
  • Better visibility and control over how AI agents interact across systems.

This is especially important for organizations deploying autonomous AI agents that can access data and trigger actions across business environments.

Defender for Cloud and GitHub Advanced Security integration now GA

Microsoft also announced general availability of the Microsoft Defender for Cloud integration with GitHub Advanced Security.

This integration provides:

  • Unified visibility from code to production runtime.
  • Automatic mapping of code changes to production environments.
  • Alert prioritization based on real runtime context.
  • Coordinated remediation workflows for development and security teams.
  • AI-powered remediation tools to speed issue resolution.

For DevSecOps teams, this helps close the gap between developer findings and operational risk in production workloads.

New Microsoft Purview Data Security Investigations demo

Microsoft highlighted a new hands-on demo for Microsoft Purview Data Security Investigations. The demo shows how analysts can identify relevant data, use AI-powered deep content analysis, and investigate incidents such as breaches, leaks, fraud, or bribery.

Capabilities demonstrated include:

  • Proactive assessment of data security risks.
  • Reactive investigation of sensitive data involved in incidents.
  • Visualization of correlations between users, content, and activities through the data risk graph.

Impact on IT administrators

For security and IT teams, these updates support a more integrated security model across AI, applications, and data. Administrators can gain stronger oversight of AI agents, improve vulnerability management from source code to runtime, and streamline investigative workflows for sensitive data incidents.

Next steps

  • Evaluate the preview Defender capabilities for Agent 365 if your organization is adopting AI agents.
  • Review the Defender for Cloud and GitHub Advanced Security integration for DevSecOps workflows.
  • Explore the Purview Data Security Investigations demo to assess incident response and insider risk scenarios.
  • Monitor upcoming Microsoft Security announcements, especially ahead of Microsoft Build 2026.

These updates show Microsoft’s continued focus on Zero Trust for AI and more automated, context-aware security operations.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Microsoft SecurityMicrosoft DefenderAgent 365GitHub Advanced SecurityMicrosoft Purview

Related Posts

Security

ASSERT Framework Turns AI Specs Into Executable Evals

Microsoft has released ASSERT, an open-source framework that converts natural-language behavior requirements into executable evaluation pipelines for AI models, agents, and applications. The tool helps teams build behavior-specific tests faster, improve regression coverage, and better validate whether AI systems follow product policies and safety expectations.

Security

AI Activity Investigations: New Microsoft Playbook

Microsoft has published a new investigator playbook to help security teams reconstruct AI-related activity across Microsoft 365 Copilot and Azure AI services. The guidance brings together telemetry, KQL queries, schema references, and detection logic across Purview, Defender, and Sentinel so investigators can move from isolated signals to a clear incident timeline.

Security

AI Brand Phishing Campaigns Target Microsoft Users

Microsoft Threat Intelligence reports a rise in phishing, malvertising, and SEO-driven attacks that abuse popular AI brands like ChatGPT, Claude, Copilot, and DeepSeek as social engineering lures. The campaigns use familiar tactics such as urgent payment notices, fake policy violations, and malicious installers to steal credentials, payment data, and deploy malware, making user awareness and layered defenses critical.

Security

AI GitHub Actions Secret Exposure in Claude Code

Microsoft Threat Intelligence found that Anthropic’s Claude Code GitHub Action could expose CI/CD secrets when AI agents process untrusted GitHub content such as issues, pull requests, and comments. Anthropic fixed the issue in Claude Code 2.1.128, but the research highlights broader risks for any AI-enabled workflow with access to secrets, file reads, or outbound communication.

Security

Agentic AI Failure Modes Taxonomy Updated by Microsoft

Microsoft has updated its taxonomy of failure modes in agentic AI systems after a year of red teaming against real-world deployments. The v2.0 framework adds seven new risk categories and expanded mitigations, giving security teams a more practical model for assessing agentic AI threats such as MCP/plugin abuse, goal hijacking, and session context contamination.

Security

Red Hat npm Miasma Attack Hits CI/CD Supply Chains

Microsoft Threat Intelligence uncovered a large-scale npm supply chain attack involving trojanized packages under the @redhat-cloud-services scope. The campaign abused a compromised CI/CD publishing workflow to deliver credential-stealing malware targeting GitHub, npm, AWS, Azure, GCP, Kubernetes, and developer systems, making it especially relevant for security teams and DevOps administrators.