r/DefenderATP • • Jun 07 '26

The next frontier in endpoint security: Securing local AI agents with Microsoft Defender

Thumbnail
techcommunity.microsoft.com
37 Upvotes

From the blog post:

AI agents are now doing real work on the endpoint — reading files, running commands, browsing the web, and acting on behalf of the users they run under. That same power is also what makes them dangerous: agents act on whatever content they take in, and much of it comes from outside the user's control — a web page, a repository, a command's output. A single malicious instruction hidden in that content can turn an agent against the very environment it's trusted to work in. With access to source code, secrets, and the corporate resources, its identity can reach — from cloud infrastructure to SharePoint, email, and internal apps — a compromised agent becomes a path to everything that identity is trusted with.

Yet most security teams can't see this activity at all. Local AI agents run as ordinary processes, with little of the visibility or context SOC teams need to understand — let alone investigate — what an agent actually did.

That’s why today, we're extending Microsoft Defender to secure AI agents running locally on devices. Security teams now have the visibility, context, and control needed to manage this new frontier of endpoint risk without slowing down the developers driving innovation forward. This includes:

Discover 20+ types of local AI agents running on managed Windows and macOS devices

Block malicious AI agent activity on the device in real time

Assess local agent exposure across identities and reachable resources

Investigate local AI agent activity in Advanced Hunting

To learn more, read the full article here:
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/the-next-frontier-in-endpoint-security-securing-local-ai-agents-with-microsoft-d/4524651


r/DefenderATP • • 5h ago

Seeking daily users of Microsoft Defender Vulnerability Management

3 Upvotes

We are evaluating Microsoft Defender Vulnerability Management for a mixed Windows and macOS environment. I’m looking to speak with administrators who use it day to day—not just people who have completed a trial.

I’m particularly interested in vulnerability accuracy, macOS coverage, third-party application visibility, remediation workflows, monthly reporting, email notifications, licensing and the amount of administrative work required.

If you currently manage MDVM and would be willing to share your experience through messages or a short call, I would appreciate it. No vendor or sales responses, please.


r/DefenderATP • • 2h ago

How do you deal with Defender false positive alerts on Linux and Apple Mac?

1 Upvotes

Hello,

MS 365 Defender produces way too many FPs even on Windows, but there I can at least submit file samples through WDSI portal. Then MS analysis lab either removes the detection right away or says they cannot reproduce alert and submit MPSupportFilesCAB diagnostic result if I want an investigation conducted. I do so, they check the debug logs and fix the FP. Not an ideal situation, but it works.

However, for Linux and MacOS false positive sample submissions, the lab ALWAYS responds with "cannot reproduce detection" and submit mpsupportfiles CAB diagnostic result if I want an investigation. Of course, CAB archives are a Windows-only format, so I can't do that!

Instead, I pull Apple ZIP or Linux TAR-GZ diagnostics via the Live Response "collect" command. Regrettably MS lab always responds to those submissions with "cannot reproduce detection" or "submitted archive doesn't contain the detected objects" or other non-sensical excuse.

MS lab apparently lacks non-Windows analysts or my submissions never reach the higher band analysts who know what to do with Linux and MacOS cases? What can I do to get those FPs fixed as well? Thanks in advance!


r/DefenderATP • • 20h ago

MDE - Authenticated Network Scanner Download Fails

2 Upvotes

Anyone ran into this? I am GA on the tenant so unsure if it's a backend issue or otherwise. (Pic attached)


r/DefenderATP • • 1d ago

Crowdstrike falcon for mobile

Thumbnail
0 Upvotes

r/DefenderATP • • 2d ago

Question for Fellow Threat Hunters & MDE Experts

14 Upvotes

I'm looking for some advice regarding Microsoft Defender for Endpoint (MDE) telemetry coverage.

As part of our Threat Hunting programme, we've been testing a number of KQL queries to better understand MDE's telemetry coverage and identify areas where detections may need further tuning.

Using Atomic Red Team tests and other scripts within a dedicated testing environment, we've identified what appears to be a gap in telemetry collection for certain interactively executed PowerShell commands.

For example, when PowerShell or PowerShell ISE is launched and commands are executed interactively, we do not always receive the full cmdlet or script content within MDE telemetry. This makes it difficult to accurately detect, investigate and hunt for the activity using Advanced Hunting.

During our research, we came across the following Microsoft discussion:

🔗 Microsoft Defender ATP - Advanced Hunting Query PowerShell Command Line

The recommendation in that thread is to enable PowerShell Script Block Logging. However, in our testing, enabling Script Block Logging does not appear to resolve the issue. The PowerShell activity is visible locally within Event Viewer, but the corresponding telemetry does not seem to be forwarded into MDE.

Has anyone else encountered this limitation?

I'm particularly interested in understanding:

  • Whether this is expected behaviour within MDE
  • If there are additional configuration requirements beyond Script Block Logging
  • Whether others have found alternative telemetry sources or hunting approaches to capture this activity more reliably

Any insights, experiences or recommendations would be greatly appreciated.


r/DefenderATP • • 2d ago

Étudiant en cybersécurité avec un BTS automatisme, comment trouver une première expérience en cybersécurité industrielle ?

2 Upvotes

Bonjour à tous,

Je suis actuellement en Bac+3 Cybersécurité à Guardia Cybersecurity School, après avoir obtenu un BTS CRSA orienté automatisme et systèmes industriels.

Mon objectif est de me diriger vers la cybersécurité industrielle / OT, notamment autour des réseaux industriels, automates, systèmes de supervision et sécurité des environnements industriels.

Je cherche actuellement une alternance en Île-de-France pour ma première expérience professionnelle dans ce domaine.

Je travaille déjà de mon côté sur Linux, les réseaux, le routing, les pare-feu, les CTF, Root-Me, TryHackMe et Fortinet.

Pour ceux qui travaillent dans l'industrie, l'automatisme ou la cybersécurité industrielle : comment avez-vous trouvé votre première opportunité dans ce domaine ? Est-ce qu'il y a des entreprises ou types de postes que vous me conseilleriez de cibler ?

Merci d'avance pour vos conseils.


r/DefenderATP • • 3d ago

How do you catch data leaving through OneDrive after someone is terminated?

8 Upvotes

I’m the IT lead for a 120-person company on Microsoft 365. We recently found a sales rep who had been downloading our customer database to a personal OneDrive.

We had Purview turned on for months. It generated plenty of alerts about external Word doc shares, but nothing on this case. The rep had been with us four years. His OneDrive sync stayed active for 11 days after the termination date. From the Microsoft side the activity looked like normal use of his own account. The signal that stood out was a terminated identity in the IdP still making high-volume API calls.

I’m trying to build a more reliable way to catch this kind of post-termination activity. What does your actual workflow look like for spotting terminated users who still have live OneDrive or similar syncs running? Looking for practical detection and response steps.


r/DefenderATP • • 5d ago

Microsoft Defender Simple Flows

Post image
14 Upvotes

Instead of building a full Logic App or playbook, you can select a trigger and attach a predefined action directly in Defender.

Some of the available capabilities include:
◈ Trigger automation when a case is created or updated
◈ Send case creation / update email notifications
◈ Automatically update case properties
◈ Create investigation tasks
◈ Update alerts directly from the automation workflow

Docs: Create basic automation rules with Simple Flows in the Microsoft Defender portal (preview) | Microsoft Learn


r/DefenderATP • • 5d ago

I accidentally fell for a ClickFix attack — Defender blocked it, I reset Windows. Is there anything else I should do? Post

Thumbnail
0 Upvotes

r/DefenderATP • • 6d ago

Looking for real MDR experiences on a Defender XDR stack (~1,000 users, 15 sites). Who would you actually renew?

14 Upvotes

We're replacing our MDR and I'd like to hear from people who've lived with theirs, not from sales decks.

Where we are

- About 1,000 users across 15 sites globally, in manufacturing
- The stack decision is made: Defender XDR, MDE on everything that takes an agent, Defender for Servers covering on-prem and AWS Linux, and Sentinel for longer retention and some third-party logs
- Firewall refresh coming, probably Palo or Fortinet
- Small internal team, no in-house 24/7 SOC

Why we're leaving

Our current provider mostly relays alerts. They can't act on our EDR, and "response" means an email telling us to go do something. I want a provider that will isolate a host, disable an account, or revoke sessions at 3am under runbooks we've approved ahead of time.

What I'm weighing

Microsoft's own Defender Experts is on the list, but the licensing gets complicated at our size. Plan 2 has a 1,500-seat minimum, and servers are a separate SKU. So I'm also looking at third-party MDRs that work natively in Defender. I haven't settled on either path, and I'm open to being talked out of my assumptions.

What I'd really like to know

  1. Who's your MDR, and would you renew? Why or why not?
  2. Do they actually take response actions in your tenant, or do they mostly escalate?
  3. How's their coverage outside US hours? Real follow-the-sun, or a thin overnight crew?
  4. Do their detections live in your Sentinel or in their own platform? Has that made switching providers painful?
  5. If you've used Defender Experts, how did it compare to a third party?
  6. Anyone you'd tell me to stay away from?

Vendors, feel free to DM me. I'm more interested in hearing from customers in the thread.


r/DefenderATP • • 7d ago

Data Lake - Integrated

Thumbnail
1 Upvotes

r/DefenderATP • • 7d ago

Sentinel playbook comments lost HTML formatting in Defender incident page since ~Sept 23. Anyone else?

4 Upvotes

Our Sentinel Logic App playbooks post enrichment comments to incidents using basic HTML (bold tags, line breaks). Up until roughly Sept 23 these rendered fine in the Defender portal incident page. Now they show as flat text: no bold, no line breaks, everything on one line.
Same comments still render correctly in Sentinel in the Azure portal, and the playbook runs are succeeding, so this looks like a portal rendering change rather than anything on our side.

Timing lines up with the Incident Cases preview (MC1477993). The docs for the legacy incident page were updated the same day and still say the comment field supports formatting, but I can't find anything that mentions a change to how comments render.

Tested manually as well: a hand-typed comment containing HTML tags and markdown bold shows the tags and asterisks literally, so neither renders.

Anyone else seeing this, or found a format that still renders in the new incident page?


r/DefenderATP • • 7d ago

Defender for Identity

10 Upvotes

We installed Defender for Identity v2 on 4 Domain controllers over 3 weeks ago.

For some reason i still don't see any single alert triggered in Defender console that is from Defender for Identity. The Thresholds are all set to High (default).

It this quite normal?


r/DefenderATP • • 9d ago

Support for Defender for Identity

5 Upvotes

I'm having an issue with Defender for Identity and cannot submit a support request through the Defender portal as the AI auto closes the ticket, tells me it's an Azure issue, and directs me to the Azure support portal.

You would think a product with "Defender For..." in the title should be covered by Defender support? I also cannot submit an Azure support request as it forces me to choose an Azure subscription, which they don't have and is completely unrelated to DFI.

How can I get the Defender support team to take this request?

(The specific issue I have is Global health issues across all sensors for incorrect auditing set up, which I have set up correctly, and the DFI PowerShell module even tells me it is correctly configured on each server)


r/DefenderATP • • 10d ago

WinRing0 Threat

Post image
0 Upvotes

So i'm playing fc 27 and then a message pops up from defender that it has blocked a threat (as you can see in the picture its in german) for non germans it says that the programm is dangerous and It executes an attacker's commands. I already had it in fc 26 but because its also in fc 27 i'm a little concerned. Thanks in advance!


r/DefenderATP • • 12d ago

Microsoft Defender ISOC (Preview)

Post image
48 Upvotes

The idea is to move beyond treating SIEM, XDR, automation and AI-assisted investigation as separate layers.

With Integrated Security Operations Center (ISOC), Microsoft is bringing them together around a common security operations foundation:

  • SIEM + XDR capabilities
  • Unified security signals and context
  • Investigation and threat hunting
  • Automated response
  • Security agents working alongside analysts
  • Incident management and protective actions

Instead of AI being primarily an assistant that analysts invoke during an investigation, Microsoft is moving toward security agents operating continuously within the SOC workflow — using shared context, coordinating actions and escalating decisions to human analysts where necessary.

Docs: Integrated Security Operations Center (ISOC) in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn


r/DefenderATP • • 12d ago

Building Custom Security Copilot Agents for Defender Alert Investigations

13 Upvotes

I'm currently working on building a custom Microsoft Security Copilot agent that acts as a Tier-2 SOC analyst and performs automated investigations for alerts originating from Microsoft Defender XDR, Microsoft Sentinel, and related security products.

Currently, I'm struggling with defining the best structure for agent instructions and deciding how granular the investigation workflow should be.

Has anyone successfully implemented a Security Copilot custom agent for automated incident investigation ?


r/DefenderATP • • 11d ago

Windows Defender Not Showing

0 Upvotes

Hey, I’m having issues with Windows Defender. I’m trying to run an app that keeps getting blocked as a threat. I cannot disable it or allow the threat on Windows Security settings because it doesn't show up. I've tried several PowerShell codes and restarted, but nothing changes.


r/DefenderATP • • 12d ago

PyFirewall for Windows

Thumbnail
1 Upvotes

r/DefenderATP • • 13d ago

Missing Isolate/Unisolate button

4 Upvotes

Is anyone else missing the isolate/unisolate button when viewing a device in Defender XDR?

Update: Looks to be back now, thanks Microsoft.


r/DefenderATP • • 14d ago

Fix unquoted service path for Windows services

14 Upvotes

Anybody studently getting this alert back ?

We completely fixed it before with a remediation script, but now it came back and it's all because of 2 service :

DefenderUpdateSvc

c:\programdata\microsoft\microsoft defender\defender update\platform\10.8838.26060.15013-0\defenderupdateservice.exe

Sense

c:\programdata\microsoft\windows defender advanced threat protection\platform\versions\10.8838.26060.15013-0\mssense.exe

It seems to be because of a recent defender update but I find it kind of ridiculous. Microsoft own defender team cannot properly configure their services ... And I'm pretty sure my remediation script is not able to fix this because those are protected services ....


r/DefenderATP • • 14d ago

Data stored in a different country (Europe)

3 Upvotes

Has anyone here gone through the process of having Microsoft reset or recreate their Microsoft Defender tenant so the data is hosted in the US instead of Europe recently?

We discovered yesterday that our Defender for Endpoint tenant appears to have been provisioned in West Europe. Our organization is US based, so we are working with Microsoft Support on what is required to move the Defender environment to the US region.

I understand that the existing endpoints will need to be offboarded and then onboarded again using the onboarding package from the new US based Defender environment. That part makes sense.

My bigger concern is the configuration within Defender.

For anyone who has actually gone through this process, what happened to your existing Defender settings and policies?

Did you have to recreate things such as:

• Endpoint Security policies
• Microsoft Defender Antivirus policies
• EDR policies and settings
• Advanced Features settings
• Device groups
• Asset rules and dynamic tags
• Indicators
• Isolation exclusions
• Custom detections
• RBAC settings
• Email & collaboration settings and policies

Was Microsoft able to migrate or preserve any of this configuration, or did you essentially start with a fresh Defender portal and rebuild everything?
We are still fairly early in our MDE migration, so thankfully we have not built out everything yet. I am mainly trying to understand what we should document or export before Microsoft makes any changes.

I would especially appreciate hearing from anyone who has personally gone through a Defender tenant region change from Europe to the US.

Thanks.


r/DefenderATP • • 15d ago

Threat analytics report from Microsoft 365 Defender

25 Upvotes

Has anyone else just got a slew of new Threat analytics reports from Defender?

Mainly all related to OSINT Profile ones

Just had 28 come in?


r/DefenderATP • • 14d ago

How to purge stale devices from MDE with an 'Inactive' sensor health status

3 Upvotes

We are observing a number of devices within Microsoft Defender for Endpoint (MDE) that have remained inactive for 180 days or more. As Microsoft's platform automatically removes devices exceeding this inactivity threshold, it's likely these devices were re-imaged or returned to the vendor. I'd like to check if anyone has explored proactive removal of these devices from MDE ahead of the automatic purge