July 27, 2026

  Blog

Microsoft’s Latest Security Play: Project Perception

My Atlas / Blog

539 wordsTime to read: 3 min
Mary Jo Foley by
Mary Jo Foley

Mary Jo Foley is the Editor in Chief at Directions on Microsoft. Before joining Directions, Mary Jo has worked as... more

A person touching a glass screen

Just three years after introducing its AI-centric security offering, Security Copilot, Microsoft is rolling out yet another new end-to-end security platform called “Project Perception.” Perception will go into preview worldwide on Aug. 3 for Microsoft business customers who already are testing its agent harness known as MDASH. 

Microsoft describes Perception as “an agentic system that brings a workforce of specialized AI agents to reason over your security data, tools, and workflows – delivering continuous, proactive defense with a human in control of every critical decision.” Perception will offer customers a choice of models, including a new, lower-cost Microsoft AI-developed Cyber-1-Flash model, along with its recently introduced multi-model agentic scanning harness (MDASH), which will orchestrate agents and models within this stack of AI-based security technologies. 

Microsoft officials said Perception will include all security agents” to form “AI that acts.” Security Copilot, on the other hand, is a “generative AI-assisted chat interface,” or “AI that assists.” While Microsoft didn’t talk about Security Copilot at its July 27 Perception launch event, officials said the two platforms will work together.

Like Security Copilot, Perception is surfacing agents through existing products, starting with Microsoft Defender, with more Microsoft security product endpoints to come. These endpoints will be the sensors and signal generators for Perception.  

As with Security Copilot, Perception will be priced using “Security Compute Units” (SCUs). Different agents will consumer SCUs at different rates, depending on the compute intensity of the task to be performed. 

Agents in Red, Blue, and Green

Perception will include three categories of specialized agents, which Microsoft is calling Red, Blue and Green team agents.  Note: These categories are not Microsoft’s own creation, but instead are based on common information security terminology that uses a range of primary colors to categorize the role of each team, such as defensive (blue), oppositional (red), responsive (green), etc.

Red Team agents will simulate attacks, blue will detect and triage, and green will fix and remediate, officials said. Agents will respond via “actuators,” officials said, without providing specifics on how this workflow mechanism will function, other than to say actuators will help agents to connect to actions to help defenders strengthen security “while remaining in control.”  

Project Perception is the first major security product developed under its new Security chief, Hayete Gallot, who rejoined Microsoft from Google in Feb. 2026. 

“Perception is our agentic security system that is designed for defenders to defend against AI with AI at the scaling speed that the attackers have,” Gallot told attendees of the Perception launch. 

She said Microsoft is redesigning its security stack to include agents, models, harnesses, sensors and a security graph to provide context in forming a layer of shared understanding for agents. 

Microsoft isn’t the only cloud and AI vendor to be working on agentic security solutions. AWS, Anthropic, OpenAI, and Google have all announced their own models and platforms in recent months. 

Mary Jo Foley is the Editor in Chief at Directions on Microsoft. Before joining Directions, Mary Jo has worked as a technology journalist for 40+ years and has focused on... more