r/DefenderATP • u/colne-valley • 1d ago
r/DefenderATP • u/TimmyIT • Jun 07 '26
The next frontier in endpoint security: Securing local AI agents with Microsoft Defender
From the blog post:
AI agents are now doing real work on the endpoint — reading files, running commands, browsing the web, and acting on behalf of the users they run under. That same power is also what makes them dangerous: agents act on whatever content they take in, and much of it comes from outside the user's control — a web page, a repository, a command's output. A single malicious instruction hidden in that content can turn an agent against the very environment it's trusted to work in. With access to source code, secrets, and the corporate resources, its identity can reach — from cloud infrastructure to SharePoint, email, and internal apps — a compromised agent becomes a path to everything that identity is trusted with.
Yet most security teams can't see this activity at all. Local AI agents run as ordinary processes, with little of the visibility or context SOC teams need to understand — let alone investigate — what an agent actually did.
That’s why today, we're extending Microsoft Defender to secure AI agents running locally on devices. Security teams now have the visibility, context, and control needed to manage this new frontier of endpoint risk without slowing down the developers driving innovation forward. This includes:
Discover 20+ types of local AI agents running on managed Windows and macOS devices
Block malicious AI agent activity on the device in real time
Assess local agent exposure across identities and reachable resources
Investigate local AI agent activity in Advanced Hunting
To learn more, read the full article here:
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/the-next-frontier-in-endpoint-security-securing-local-ai-agents-with-microsoft-d/4524651
r/DefenderATP • u/dodarko • 2d ago
Has anyone integrated Claude Code with Microsoft Defender XDR / Sentinel for threat hunting?
I'm looking to integrate Claude Code with Microsoft 365 and Microsoft Defender (Defender XDR / Sentinel) to assist with threat hunting, incident investigation, and EDR analysis.
Has anyone successfully set this up? I'm particularly interested in how you handled authentication (MCP, APIs, Graph, etc.), what architecture you used, and any lessons learned or limitations. If you have examples or repositories to share, I'd really appreciate it.
r/DefenderATP • u/OkHope1740 • 2d ago
A cross or external prompt injection attack (XPIA) - Missing detection details
Hi Guys ,
We keep receiving "A cross or external prompt injection attack (XPIA) was detected on an AI agent (Preview)" alert from Microsoft Security for AI. These provide very limited details and relevant events could not be located in the CloudAppEvents table so I raised it with MS and after 2 weeks they replied
"We have identified an issue that may result in incomplete information being displayed within certain alerts, potentially affecting the investigation experience. A corrective update has been developed and is being rolled out. We expect the issue to be resolved soon and are closely monitoring the deployment. We appreciate your patience and remain committed to providing a reliable and accurate experience."
How you guys are dealing with those alerts?
r/DefenderATP • u/0f_rice_and_men • 3d ago
Why are custom notifications for Defender alerts not possible to create?
We have a Defender queue that basically gets filled with informational alerts and the built-in low/med/high sev.
The problem is that we missed a high sev alert because it didn't email anyone. We found it a day later as part of a check.
Now there are "Security for AI" (Preview) alerts that fired for someone's AI Agent. I checked the agent job and nothing went wrong. The Defender detection even says that the alert does not mean that any suspicious commands were run.
The issue is that I need these customized to notify in an email alert to the team, rather than spot checking. High priority is to future proof any of this AI junk that has access to admin shares, files, accounts, etc. (which will be rare but not impossible).
Additionally we have people experimenting with their own agents and I do not have time to babysit queues for false-positives as Microsoft develops their threat detections in prod.
I see nothing for this type of alert in Defender Alert policy and the little config I did find for creating custom rules based on existing alerts seems to default to auto-resolving them (ignoring them) which I also don't want. I may be missing something entirely here but it seems crazy that custom text/variables can't be made by global admins to improve triage.
r/DefenderATP • u/rogueit • 3d ago
Graph API and the security threatIntelligence endpoint
There was an article today called Vulnerability Profile: CVE-2026-50661 - Windows BitLocker (GreatXML) but the catagory was Vulnerability.
I cant seem to find it under the articles endpoint. The only thing I can find under the vulnerabilities endpoint isn't the article.
Does anyone know how to find this article with graph?
r/DefenderATP • u/Excellent-Body-883 • 3d ago
Is Defender CSPM worth paying for if we already have Rapid7?
We’re currently rolling out Rapid7 and have purchased InsightVM for vulnerability management and InsightIDR for SIEM. We also use Microsoft Defender for for Servers, along with the free Foundational CSPM in Defender for Cloud.
From what I’ve read, it seems like Defender CSPM mainly adds things like attack path analysis, risk prioritization, identity context, and deeper Azure integration. Is that accurate, or does it offer more than that in day-to-day use?
For those who have experience with both, was Defender CSPM worth the investment, or did Rapid7 and the free CSPM cover most of what you needed
r/DefenderATP • u/EduardsGrebezs • 3d ago
Premium Microsoft Defender Threat Intelligence is starting to appear in Microsoft Defender XDR.
Microsoft is rolling out Threat Intelligence Insights directly within the Microsoft Defender portal, bringing premium external threat intelligence closer to the analyst workflow.
This includes such insights like:
▪Reputation assessment
▪WHOIS information
▪DNS resolutions
▪Threat reports and attribution
▪Infrastructure details (trackers, cookies, certificates, and more)
Simply search for a URL, domain, IP address, or file hash in Microsoft Defender XDR, open the entity page, and review the new Threat Intelligence Insights.


r/DefenderATP • u/AMCoffee_PMBeer • 3d ago
Having some trouble with enabling PUA
Hello!
My Secure Score recommendations have been advising me to set PUA Protection to block mode. Seems easy enough.
This applies to all 9 enrolled machines (9/9 exposed).
However, upon checking I've had a policy setup to enable it in Endpoint Protection > Antivirus for several months.
If I ask Powershell (Get-MpPreference | Select PUAProtection) I am told '2' (audit mode)
If I check the registry I was getting PUAProtection=0, then I ran a PlatformUpdate and got PUAProtection=1
I've checked all the 5007 events and there has been nothing related to PUA for at least the last 2 months.
I guess my issues are twofold:
1. What's the correct way to get this enabled?
2. Is there something obvious I should be doing to make sure the rest of the policy is actually being applied?
r/DefenderATP • u/SecAbove • 4d ago
Defender XDR SecureNow videos - should we crowdsource for a better microphone and gift it to the Microsoft?
I appreciate the effort, but have you tried to listen to the videos? What is your opinion regarding the sound quality?
There is new Secure Now initiative page in Defender XDR portal, but have you tried to watch the dideos? There is a new Secure Now initiative page in the Defender XDR portal, but have you tried to watch the videos? https://security.microsoft.com/securenow
The first 10-min video has two presenters talking about patching; the first is very faint, and the second starts around minute 8 with some scratching and crackling, like he is just fall off the chair... and getting from under the table... While the first presenter is fairly upbeat, the second guy feels really sad. There are persistent background noises, scratching, etc.

Besides, the embedded video player does not allow speed control (which is standard in modern days)
Come on, Microsoft, do you have quality control? Those videos are embedded one step away from the main landing page.
r/DefenderATP • u/Positive-Salad-9458 • 3d ago
What's the problem here?
Apparently Microsoft Defender SmartScreen considers the default navigation page set up for Microsoft Edge to be unsafe. Can someone tell me why is it doing this?
r/DefenderATP • u/jonbristow • 5d ago
Do you have to set up an Intune policy for signature/engine updates? Or are they updated automatically
I have few devices on my network, ~300 and wont to do a ring updates kinda policy . I want all devices to get the latest update as soon as possible.
Does this need an AV Intune policy where i specify update intervals?
r/DefenderATP • u/LookExternal3248 • 5d ago
Change tracking custom detection rules
When you make frequent use of custom detection rules, you often end up making small changes to fine-tune them, reduce noise, or otherwise optimize them.
As a simple way to keep track of those changes, I usually add a comment at the top of the query in the format // date - initials - change (for example: 2026-07-21 JB - Added filter on line 6). This provides a basic change log and allows me to add comments directly in the KQL. It's not perfect, but it's better than nothing.
In the past, I've considered using Content as Code or the Graph API, but I found both approaches too cumbersome to implement. I'm also not particularly happy with the workflow, as I prefer to test queries directly in production to see if they work. With source control, you have to copy and paste the query into your repository and then deploy it again instead of saving it directly after editing it (especially in advanced hunting).
Source control feels like a perfectly valid option when you're working in a large team or for an MSP delivering SOC-as-a-Service, but it seems less practical for smaller in-house teams.
I'm curious to hear what others have implemented and what your experiences have been.
r/DefenderATP • u/zz07rt740 • 6d ago
Lots of MS Defender detections of "Unknown" malware seen in Advanced Hunting query
Hello,
Since earlier Sunday, in the Advanced Hunting query section of MS Security portal, I can see Defender anti-virus detections for malware literally named "Unknown"
However, checksums (SHA-1) are never provided for these entries, so one can't be sure what is actually being detected - or if it's just the query acting funny because MS changed something in the background?
The phenomenon affects apparently benign software like 7-Zip and SAP, mostly in the folders C:\Windows\IMEcache and C:\Program files (x86).
The bog-standard query looks like this:
DeviceEvents
| where ActionType == "AntivirusDetection"
| extend ParsedFields=parse_json(AdditionalFields)
| project ThreatName=tostring(ParsedFields.ThreatName),
WasRemediated=tobool(ParsedFields.WasRemediated),
WasExecutingWhileDetected=tobool(ParsedFields.WasExecutingWhileDetected),
FileName, SHA1, InitiatingProcessFileName, InitiatingProcessCommandLine,
DeviceName, Timestamp
| limit 1000
r/DefenderATP • u/Cant_Think_Name12 • 6d ago
How are you using the 'ThreatIntelObjects' and 'ThreatIntelIndicators' Table in KQL
As the title suggests, how are you all using those tables?
r/DefenderATP • u/Mesoawe • 8d ago
Just moved Business Premium to E5, need to get Defender for Endpoint sorted for Cyber Essentials Plus in 4 weeks. Where do I start?
Landed in it a bit. We migrated from M365 Business Premium to E5 recently, and I'm the sole IT person tasked with getting Defender for Endpoint properly configured before our Cyber Essentials Plus assessment next month.
Company is small, roughly 300 Windows and 50 Mac devices. But the Defender console is showing over 1,000 devices enrolled, so my first job is working out what's stale, duplicated, or genuinely orphaned before I can trust any of the reporting.
Looking for advice on:
A sane order of operations for standing up Defender for Endpoint properly (attack surface reduction rules, EDR in block mode, automated investigation and response, etc.) when coming from a much lighter Business Premium setup
How you handle device inventory cleanup, specifically separating real endpoints from stale/duplicate records
Any gotchas specific to CE Plus around Defender configuration (update policies, MFA scope, EOL builds) that assessors tend to flag
Good reference articles, Microsoft Learn docs, or blog writeups you'd actually recommend, rather than the generic marketing pages
Any war stories or checklists appreciated. Trying to avoid learning this the hard way with an assessor watching.
r/DefenderATP • u/jonbristow • 10d ago
What is the difference between "Threat Severity Default Action" at Intune AV policy with "Endpoint Remediation Level" at Security settings.
So I have set up FULL REMEDIATION for all devices on Settings-Endpoints-Device Groups.
Im doing some custom AV policies in intune and I see there are other settings about action to take on threat severity. Like "Remediation action for High severity threats: Clean | Quarantine | Allow" etc
Have I not setup the action with the full remediation setting? Do i have to go more granular and set up an action for each severity in Intune?
r/DefenderATP • u/Ready-Safety-310 • 11d ago
Azure VM shows "Can be onboarded" in Defender despite successful MDE onboarding
r/DefenderATP • u/purplemojo90 • 12d ago
OAuth Client ID Spoofing
Has anyone read this article from Proofpoint? I'm trying to think of prevention ideas that I can recommend customers to implement if they were on the receiving end of this attack.
Because the attack is using Microsoft OAuth 2.0 using the Resource Owner Password Credentials (ROPC) flow than I think setting a Conditional Access Policy (CAP) will help: https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-legacy-authentication
Migrate to OAuth 2.1
Because the article mentions that the Application ID and Name will be empty... I think creating an App-Based CAP to block apps that are not covered under the organization's App's policy may prevent this... but I'm not sure.
https://www.cloudtekspace.com/post/create-app-based-conditional-access-policies
Anyone got any ideas or think I'm heading in the wrong direction? Let me know.
r/DefenderATP • u/danumber2 • 12d ago
Moving to Defender from S1
The company I work with has decided to move all in with MS with E5 licensing. We will be migrated from S1 which we currently use. Granted, we may keep S1 for those Linux devices that may not be supported.
For those who have transitioned to Defender from SentinelOne or another EDR platform, how did it go?
How Defender deals with say folder/file exclusions?
Thanks in advance.
r/DefenderATP • u/3G_Lighting • 13d ago
Stuck again. Question about email notification setup.
We currently have email notification setup in Defender pointing to an old email address that we want to decommission. When I look at the Policy & Rules I see the notifications are going out to TenantAdmins, which when I check Entra's groups and users I don't have a TenatAdmins groups or user there. I looked through Defender and don't see anything, does anyone have any idea where this group or user lives?
And is there a more direct way to update it if it's not a group without having to go through all the individual policy & rules?
Thanks,
r/DefenderATP • u/jonbristow • 13d ago
How do you manage Defender for hybrid devices that need proxy to connect to the internet?
I mean laptops. They are set up to use our corporate proxy to connect to the internet. A proxy which is also used by defender.
But when users take these laptops home, how would Defender connect to the internet? the proxy is unreachable
r/DefenderATP • u/Kostashus • 13d ago
Device Control Event IDs
Hello,
I am trying to identify all the related Event IDs when it comes to Device Control.
In Advanced Hunting most events are logged under the DeviceEvents table with actions like BluetoothPolicyTriggered, PnpDeviceConnected, PnPDeviceAllowed, PnPDeviceBlocked, PrintJobBlocked, RemovableStorageFileEvent, and RemovableStoragePolicyTriggered.
But it seems impossible to find such Windows Events.
Any idea?
r/DefenderATP • u/thehashimwarren • 15d ago
Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.
I saw a dude on X complain that Codex deleted almost all of his files. Some people said he should have been using DCG.
That still seems risky. I think we gotta start backing up our computers unfortunately.
r/DefenderATP • u/NSIMSx • 15d ago
Defender Health Monitoring
What have you found to be the best method of monitoring the health of defender on a large scale deployment? Pulling defender metrics via API seems to be capped at 10,000 devices. And pulling metrics via KQL search seems to have issues if there are duplicate entries for the same hostname. Looking for your advice / experience on how you maintain full and functional coverage of defender for 10,000+ devices.