Microsoft launches Project Perception agentic security system
Microsoft puts Project Perception into preview: an agentic system with red, blue and green agents running on its own MAI-Cyber-1-Flash security model, priced per SCU.
Microsoft Security has unveiled Project Perception, an agentic system now in preview. Unlike Security Copilot — which Microsoft describes as "AI that assists" through a chat interface — Project Perception is positioned as "AI that acts": a workforce of specialized agents that reason across an organization's security data, tools and workflows to expose gaps, investigate threats and remediate continuously.
The system splits into three roles: red agents probe like an attacker, blue agents investigate like a responder, and green agents remediate and harden. The three share intelligence through orchestrated workflows so a finding becomes a fix without a hand-off at every step.
Key points
- A purpose-built security model: Perception uses a multi-model approach that includes the new MAI-Cyber-1-Flash model, which Microsoft says brings deep, security-specific expertise to reasoning over threats.
- Six building blocks: agents (red/blue/green), purpose-built models, organizational context (past incidents, policy decisions, identity relationships), signals and sensors across endpoints/identities/clouds/apps, actuators that let agents act on decisions, and an orchestration harness.
- Humans keep the judgment: defenders set objectives and guardrails, and every high-impact action stays under human sign-off. Microsoft says each decision is scoped, traceable and replayable.
- Microsoft Defender is the entry point: at launch Perception brings multi-agent coordinated defense directly into Microsoft Defender, and will extend across Microsoft Security products over time.
- Consumption pricing: pay-as-you-go, measured in Security Compute Units (SCUs), with more intensive agent tasks consuming more SCUs.