CyberOne Blog | Cyber Security Trends, Microsoft Security Updates, Advice

What Is Microsoft Project Perception? The Red, Blue and Green Security Agents Explained

Written by Luke Elston | Sep 30, 2026, 8:15:01 AM

Security teams are familiar with AI support. The challenge now is learning how to supervise and direct AI agents through clear objectives, defined authority and robust controls.

Microsoft Project Perception marks a shift from AI that simply assists towards AI that can participate in security work. It introduces specialised agents intended to operate across connected workflows for discovering weaknesses, investigating threats, remediating issues and hardening defences.

This development could reshape how work moves through the Security Operations Centre. More importantly, it raises a critical question that goes beyond the intelligence of the AI itself:

What should an AI agent be permitted to do, and under whose authority?

For organisations considering agentic security, identity, access, evidence, approval and accountability are now central elements of the operating model.

What Is Microsoft Project Perception?

Microsoft Project Perception is an agentic security system currently in preview. It brings together red, blue and green AI agents that operate across security data, tools and workflows.

This is not a general-purpose chatbot, nor is it a new name for Microsoft Security Copilot. Microsoft describes Security Copilot as an AI-assisted interface that helps practitioners work with security information. Project Perception is the agentic system around it: a coordinated group of specialised agents designed to carry security work across connected workflows.

Put simply, Project Perception is designed to connect three activities that security teams usually manage across different tools, processes and specialists. Red agents expose weaknesses, blue agents investigate threats, and green agents remediate and harden. Rather than working as isolated assistants, these agents are intended to share intelligence and pass relevant context between one another, helping move a finding from discovery towards resolution.

That coordination is supported by more than the agents themselves. Microsoft says the system combines purpose-built security models, organisational context, signals from across endpoints, identities, clouds and applications, mechanisms that can translate decisions into action, and an orchestration framework that coordinates the overall workflow. At launch, this multi-agent approach is being introduced through Microsoft Defender.

The central idea is specialisation with orchestration. A conventional AI assistant responds to a request and returns an answer. Project Perception is designed to coordinate specialised agents around a defined security objective, carrying relevant information from one stage of the work to the next.

Is Microsoft Project Perception Replacing Microsoft Security Copilot?

No. Microsoft Project Perception is not a replacement or rebrand of Microsoft Security Copilot. The two are designed to play different but complementary roles.

Microsoft Security Copilot

  • A generative AI-assisted chat interface
  • Helps practitioners work with security information
  • Centred on AI assistance
  • Works alongside Project Perception

Microsoft Project Perception

  • An agentic security system
  • Coordinates specialised agents across security workflows
  • Centred on agent action and orchestration
  • Works alongside Security Copilot

The difference is assistance compared with participation. Security Copilot helps a practitioner interpret and work with security information. Project Perception introduces specialised agents that can contribute to connected security workflows within defined objectives and controls.

Microsoft describes this distinction as “AI that assists” and “AI that acts”, and says the two work together. 

This comparison does not imply equivalent licensing, consumption terms or availability. Organisations should refer to Microsoft’s current product and commercial documentation when evaluating either system.

 

Why Does Microsoft Use Three Types of Security Agent?

Security operations involve different types of work. Discovering a weakness, investigating suspicious activity and correcting the issue are connected activities, but each requires different information, permissions and decisions.

Project Perception divides this work between three specialised agent types:

  • Red agents find potential weaknesses. They examine the environment from an attacker’s perspective.
  • Blue agents investigate threats. They help establish what happened, what may be affected and whether the available evidence supports a response.
  • Green agents remediate and harden. They help turn validated findings into actions that reduce exposure and strengthen protection.

Microsoft says these agents are intended to share intelligence through orchestrated workflows. The aim is to connect discovery, investigation and remediation so that relevant context moves with the work rather than being reconstructed at every stage. [microsoft.com]

What Does a Red Agent Do?

A red agent examines the environment from an attacker’s perspective to expose potential weaknesses.

Its purpose is to show security teams where the organisation may be vulnerable. However, a finding is only the beginning of the risk assessment. Teams must still consider the affected asset, its business importance, the supporting evidence, existing controls and whether the agent operated within its authorised scope.

Scope is therefore critical. Organisations must define where the agent can operate, what it can test and which permissions it receives. Human practitioners remain responsible for validating the finding and deciding what should happen next.

Project Perception forms part of a wider shift towards specialised, multi-agent security. CyberOne explored a related example in How MDASH Signals the Next Evolution of Microsoft Security, which examines the use of coordinated agents for vulnerability discovery, validation and remediation support in software codebases.

MDASH and Project Perception are separate systems. MDASH illustrates Microsoft’s broader direction towards specialised security agents, but the available sources do not establish that it powers Project Perception’s red agents or represents its complete architecture.

What Does a Blue Agent Do?

A blue agent investigates suspicious activity to help security teams understand what happened, what may be affected and whether the evidence justifies a response.

This role most closely resembles traditional SOC investigation. Its value lies not simply in producing an explanation, but in assembling the context needed for a defensible decision.

A red agent may expose a potential weakness, while a blue agent can help investigate whether available security information indicates related threat activity. This illustrates how the roles may connect, rather than a fixed sequence prescribed by Microsoft.

Security teams must still test the agent’s conclusions. They need to determine whether evidence is missing, which users or systems may be affected, how confident they are in the assessment and whether the proposed response is proportionate.

Microsoft says decisions within Project Perception are intended to be scoped, traceable and replayable, with high-impact actions remaining under human sign-off. These are documented design principles for a private-preview system, rather than independently validated production outcomes.

The analyst’s role therefore goes beyond approving a recommendation. Practitioners must challenge the reasoning, identify missing context, interpret business risk and decide whether the evidence supports action.

Agentic security does not remove technical expertise from the SOC. It shifts more of that expertise towards evidence evaluation, exception handling and risk judgement.

What Does a Green Agent Do?

A green agent helps turn a validated finding into remediation or hardening that reduces exposure and strengthens protection.

Microsoft describes green agents as remediating and hardening within orchestrated workflows, while high-impact actions remain under human sign-off.

This is potentially the most operationally consequential role because remediation can change systems, configurations and controls. A technically valid action may still disrupt a business process, conflict with another control, require testing or fall outside the agent’s authority.

Security teams must therefore distinguish between different levels of agent involvement:

  • Recommend: The agent proposes a remediation.
  • Prepare: The agent creates or stages the proposed change for review.
  • Execute: The change is applied within the environment.

These are useful governance distinctions, not a workflow that Microsoft says Project Perception formally prescribes. The greater the potential business impact, the clearer the authority, evidence and human review should be.

The purpose of a green agent is not to fix every issue automatically. It is to reduce the distance between identifying a security problem and strengthening the organisation’s defences, within defined controls and approval boundaries.

How Does Microsoft Project Perception Relate to ISOC?

Project Perception provides the agentic system, including specialised agents, models and orchestration. ISOC in Microsoft Defender provides the integrated security-operations foundation through which people and agents can see, understand and act.

Microsoft describes ISOC as bringing security information and event management and threat protection together. It explains that foundation through three elements:

  • Signals and sensors provide awareness.
  • Context turns signals into understanding.
  • Actuators turn insights into protective action. 

Microsoft publicly describes ISOC in Defender as being in preview. Access to emerging capabilities such as Project Perception and ISOC is being managed through restricted preview programmes, with CyberOne participating in the private-preview process for Project Perception.

An agent’s value depends on the information it can access, the accuracy of the organisational context, its assigned permissions and the controls through which it can act.

Incomplete asset ownership, inconsistent identity data or poor system classification could limit the business relevance of an agent’s output. Readiness for agentic security therefore begins with strong security foundations, not simply enabling agents.

Agentic Security Is Evolving. CyberOne’s MXDR Is Ready to Evolve With It

CyberOne is not watching Microsoft’s shift towards agentic security from the sidelines. As a Microsoft Security Elite Partner, CyberOne gains earlier technical insight, priority access to private previews and direct engagement with Microsoft’s security engineering and product teams. This enables our specialists to evaluate emerging capabilities sooner, pressure-test their operational value and prepare customers for how the Microsoft security platform is evolving.

That advantage strengthens CyberOne’s MXDR as a Service, a Microsoft-native, AI-augmented service built to detect faster, investigate with greater context and respond decisively. Our 24×7 CREST-accredited Global SOC operates within the customer’s Microsoft environment, combining proactive hunting, continuous monitoring, expert-led response and NCSC-certified Cyber Incident Response while customers retain visibility and control of their data.

CyberOne’s Microsoft Verified Managed XDR Solution status provides further validation of this operating model. Using Microsoft Defender XDR and Microsoft Sentinel, supported by AI-assisted triage, our analysts hunt, contain and respond to threats while providing auditable evidence and board-ready reporting.

Our early exposure to emerging Microsoft capabilities means we can assess how agentic security could strengthen investigation, remediation and response before wider release. The value is not simply earlier access to new technology. It is the ability to turn Microsoft innovation into an operational advantage through informed design, careful integration, expert oversight and continuous optimisation.

For customers, that means an MXDR service equipped to evolve with Microsoft and convert new security capabilities into faster decisions, controlled action and measurable resilience.

Turn Agentic Security Into Measurable Resilience

Microsoft Project Perception points towards a security operation in which specialised AI agents connect weakness discovery, investigation and remediation. But machine speed alone will not deliver resilience. Organisations will still need trusted information, controlled permissions, meaningful human judgement and clear accountability for consequential decisions.

The future SOC will be defined by how effectively people and agents work together. Agents can extend speed and scale. Experienced practitioners must continue to provide business context, authority and oversight.

CyberOne’s MXDR as a Service provides a strong foundation for that change. Its Microsoft-native, AI-augmented operating model combines 24×7 security operations with expert response, customer approval processes, auditable evidence and board-ready reporting.

Build a security operation ready to evolve with Microsoft. Explore CyberOne’s MXDR as a Service and turn advanced security technology into controlled action and measurable resilience.

Frequently Asked Questions

 

Sources