Microsoft’s Project Perception Ships Without Its Fix Button
Microsoft’s agentic security system enters public preview inside Defender today, with red and blue agents live — and the green agents that actually remediate held back behind human approval. The constraint, not the capability, is the story.
Microsoft's Project Perception enters public preview today, delivered inside Microsoft Defender. It is the company's bid to answer AI-driven attacks with AI-driven defence — a coordinated workforce of security agents rather than another assistant that writes summaries next to your alert queue.
The detail worth reading twice is what Microsoft didn't turn on. Perception's whole pitch is agents that act. In the preview, the agents that do the acting are throttled. Autonomous remediation is held back.
Three colours of agent, two of them switched on
Perception organises its work into three agent classes that hand findings to each other through an orchestrator and a shared message bus, so a discovery becomes a fix without a human retyping it into the next tool.
| Agent class | Job | In today's preview |
|---|---|---|
| Red | Maps attack paths and vulnerabilities, works like an attacker | Yes |
| Blue | Investigates findings, decides what is meaningful risk | Yes |
| Green | Remediates and hardens systems | Proposes only |
Reversible actions — isolating a machine, for instance — are slated for later in 2026. The genuinely risky moves, like patching a production host, stay behind human sign-off with no announced end date. Microsoft's own framing for the split is blunt: strategy stays human, scale becomes autonomous. Approvals route through Agent 365 and Entra Agent ID, the control plane the company shipped for exactly this purpose.
That is the honest constraint of the whole category, and Microsoft is not alone in hitting it. Proposing a fix is a model problem. Being allowed to apply the fix unsupervised in someone else's production estate is a trust problem, and trust is not something you ship in a preview.
MAI-Cyber-1-Flash, and the 90/10 split
Underneath sits a purpose-built cyber model, MAI-Cyber-1-Flash, aimed at software vulnerability analysis. Microsoft claims 96% on the CyberGym benchmark, ahead of Anthropic's Mythos at roughly half the cost. The economics matter more than the leaderboard position: Microsoft says it routes about 90% of vulnerability workload to the small specialist model and escalates only the hardest tenth to frontier models.
Treat the benchmark number as a vendor claim until someone independent runs it. A score on vulnerability discovery is not the same thing as defensive efficacy inside a real enterprise, and Microsoft has been aggressive lately about positioning in-house MAI models against Anthropic and OpenAI on price and parity.
Metered by the intensity of the thought
Perception is sold on consumption, measured in Security Compute Units. Agents burn SCUs at different rates depending on how hard the task is, so a red agent grinding through an attack graph costs more than a blue agent triaging a single alert. It is a rational way to price non-deterministic work and an uncomfortable one to budget for — the bill scales with how interesting your month was.
What the demo doesn't cover
Perception's flagship walkthrough is application security: SQL injection, cross-site scripting, the sort of thing that lives in code and shows up cleanly in a graph. Real intrusions frequently do not start there. They start with harvested credentials and a convincing phone call to the help desk.
The system's usefulness is also downstream of graph quality. Agents reason over the picture the sensors give them, and an attack path that isn't in the graph isn't in the plan. Every organisation with a forgotten SaaS tenant or an unmanaged contractor laptop should assume the coverage gap is theirs, not Microsoft's, and that no agent will surface it.
Everyone is shipping this
Agentic defence has become table stakes: AWS, Google, Cisco, CrowdStrike, Palo Alto Networks and SentinelOne are all building toward the same shape, and 60+ vendors have already organised an alliance around agent security. Microsoft's edge isn't the agents. It's that it already owns the identity layer, the endpoints and the management plane most enterprises run on. Active Directory and Entra are the moat; Perception is what gets built on top of it.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.