Microsoft Project Perception Enters Public Preview: What Security Teams Should Know

Microsoft is giving security agents more than alerts to summarize. Project Perception entered public preview on Aug. 3 with specialized AI agents designed to investigate threats, assess risk, and connect findings with defensive actions.

Microsoft Project Perception Enters Public Preview: What Security Teams Should Know

Microsoft Project Perception Enters Public Preview: What Security Teams Should Know

Microsoft is giving security agents more than alerts to summarize. Project Perception entered public preview on Aug. 3 with specialized AI agents designed to investigate threats, assess risk, and connect findings with defensive actions.

The system extends Microsoft’s push from AI-assisted analysis toward coordinated security operations. Its agents can work across security data and tools, but wider authority raises immediate questions about permissions, accuracy, oversight, and auditability.

Microsoft puts specialized agents on defense

According to Microsoft’s agentic security announcement, Project Perception combines security signals, organizational context, multiple AI models, and specialized agents in what the company calls a new Cyber Stack. Microsoft says it can assess risk across identities, endpoints, applications, data, cloud environments, and AI systems.

Three classes of agents divide the work. Red-team agents identify possible paths to compromise. Blue-team agents investigate activity and determine which findings represent meaningful risk. Green-team agents take corrective actions intended to strengthen defenses.

Project Perception selects models according to quality, reliability, latency, and cost. Microsoft says human operators retain control, though customers will need to establish which actions require approval and how narrowly each agent can be permissioned.

That concern extends beyond one Microsoft product. Recent disclosures show how AI agent permissions can exceed existing controls when identity and monitoring systems were designed primarily for human users.

Project Perception is related to, but separate from, MDASH and MAI-Cyber-1-Flash. MDASH is Microsoft’s multi-agent system for identifying and remediating software vulnerabilities. MAI-Cyber-1-Flash is a specialized cybersecurity model deployed within MDASH.

Microsoft reported that MDASH, using MAI-Cyber-1-Flash for most work and GPT-5.4 for its hardest tasks, scored 95.95% on the CyberGym vulnerability benchmark. The company’s model performance report says the smaller model can handle up to 90% of MDASH tasks.

Microsoft says the configuration costs nearly 50% less than its previous MDASH setup. The benchmark and cost figures apply to MDASH, not Project Perception pricing or customers’ total security spending.


Advertisement

The rollout follows Google’s limited CodeMender cybersecurity preview, another effort to apply specialized models to vulnerability discovery and remediation. Public benchmark results do not yet show how either system will perform against vulnerabilities in a customer’s proprietary environment.

The preview will test Microsoft’s controls

Organizations should begin with narrowly scoped permissions and retain human approval for actions that could alter protections or affect production systems.

Security teams should also examine the tools and data each agent consumes. Microsoft has warned that poisoned MCP tool descriptions can steer an authorized agent toward disclosing data or taking unintended actions through apparently legitimate tool calls.

Useful pilot metrics include investigation accuracy, false-positive rates, analyst review time, and the percentage of recommendations requiring correction. Teams should also verify that agent inputs, decisions, approvals, and outcomes create a complete audit record.

Project Perception may offer the most context to organizations already using Microsoft products across identity, endpoint, cloud, data, and threat protection. Companies with mixed security environments should confirm which telemetry and actions are supported outside Microsoft’s ecosystem.

Microsoft has not disclosed simple public pricing, detailed eligibility requirements, or a general-availability date. Until those details emerge, the preview is best treated as a controlled evaluation rather than the basis for a production rollout.

Read more: Similar safeguards apply when workplace agents reach beyond chat, including three security checks for connected AI tools with access to files, applications, and business systems.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.