Products·4 min read·Microsoft Security

Microsoft’s Project Perception Ships Without Its Fix Button

Microsoft’s agentic security system enters public preview inside Defender today, with red and blue agents live — and the green agents that actually remediate held back behind human approval. The constraint, not the capability, is the story.

PROJECT PERCEPTION — PUBLIC PREVIEW RED maps attack paths ON BLUE investigates findings ON GREEN remediates — held back OFF BITSMINDS.COM
Share:

Microsoft's Project Perception enters public preview today, delivered inside Microsoft Defender. It is the company's bid to answer AI-driven attacks with AI-driven defence — a coordinated workforce of security agents rather than another assistant that writes summaries next to your alert queue.

The detail worth reading twice is what Microsoft didn't turn on. Perception's whole pitch is agents that act. In the preview, the agents that do the acting are throttled. Autonomous remediation is held back.

Three colours of agent, two of them switched on

Perception organises its work into three agent classes that hand findings to each other through an orchestrator and a shared message bus, so a discovery becomes a fix without a human retyping it into the next tool.

Agent classJobIn today's preview
RedMaps attack paths and vulnerabilities, works like an attackerYes
BlueInvestigates findings, decides what is meaningful riskYes
GreenRemediates and hardens systemsProposes only

Reversible actions — isolating a machine, for instance — are slated for later in 2026. The genuinely risky moves, like patching a production host, stay behind human sign-off with no announced end date. Microsoft's own framing for the split is blunt: strategy stays human, scale becomes autonomous. Approvals route through Agent 365 and Entra Agent ID, the control plane the company shipped for exactly this purpose.

That is the honest constraint of the whole category, and Microsoft is not alone in hitting it. Proposing a fix is a model problem. Being allowed to apply the fix unsupervised in someone else's production estate is a trust problem, and trust is not something you ship in a preview.

MAI-Cyber-1-Flash, and the 90/10 split

Underneath sits a purpose-built cyber model, MAI-Cyber-1-Flash, aimed at software vulnerability analysis. Microsoft claims 96% on the CyberGym benchmark, ahead of Anthropic's Mythos at roughly half the cost. The economics matter more than the leaderboard position: Microsoft says it routes about 90% of vulnerability workload to the small specialist model and escalates only the hardest tenth to frontier models.

Treat the benchmark number as a vendor claim until someone independent runs it. A score on vulnerability discovery is not the same thing as defensive efficacy inside a real enterprise, and Microsoft has been aggressive lately about positioning in-house MAI models against Anthropic and OpenAI on price and parity.

Metered by the intensity of the thought

Perception is sold on consumption, measured in Security Compute Units. Agents burn SCUs at different rates depending on how hard the task is, so a red agent grinding through an attack graph costs more than a blue agent triaging a single alert. It is a rational way to price non-deterministic work and an uncomfortable one to budget for — the bill scales with how interesting your month was.

What the demo doesn't cover

Perception's flagship walkthrough is application security: SQL injection, cross-site scripting, the sort of thing that lives in code and shows up cleanly in a graph. Real intrusions frequently do not start there. They start with harvested credentials and a convincing phone call to the help desk.

The system's usefulness is also downstream of graph quality. Agents reason over the picture the sensors give them, and an attack path that isn't in the graph isn't in the plan. Every organisation with a forgotten SaaS tenant or an unmanaged contractor laptop should assume the coverage gap is theirs, not Microsoft's, and that no agent will surface it.

Everyone is shipping this

Agentic defence has become table stakes: AWS, Google, Cisco, CrowdStrike, Palo Alto Networks and SentinelOne are all building toward the same shape, and 60+ vendors have already organised an alliance around agent security. Microsoft's edge isn't the agents. It's that it already owns the identity layer, the endpoints and the management plane most enterprises run on. Active Directory and Entra are the moat; Perception is what gets built on top of it.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles

Every desk gets an agent.
Products

Y Combinator Open-Sourced the Agent Harness It Runs Itself On — and the Best Part Is the Security File

ANTHROPIC · CLAUDE CODE Not Just Code Anymore build the release page a live page a running app Three things it couldn’t do before this week
Products

Claude Code Can Now Publish Live Pages, Test iOS Apps — and It Finally Runs on Linux

OPENAI · BUILD WEEK ChatGPT Work One agent that gathers context across your apps — and ships the finished work Documents Spreadsheets Presentations Dashboards GPT-5.6 · CODEX BUILT IN Works across web, phone & desktop · autonomous, runs in the background · Pro, Enterprise & Edu first
Products

OpenAI's ChatGPT Work Turns ChatGPT Into an Autonomous Agent That Does the Job Across Every App