Agent365 Security Posture and Defender¶
Atlanta, USA
Last updated: 2026-08-04
References
Security objective¶
Continuously reduce identity abuse, unsafe behavior, and malicious activity across agent execution paths while preserving productivity.

Source: Microsoft Agent 365 documentation.
Threat model dimensions¶
| Dimension | Questions to answer |
|---|---|
| Identity abuse | Can agent identities be misused for unauthorized actions? |
| Data misuse | Can prompts or outputs leak sensitive content? |
| Tool exploitation | Can tool calls execute harmful or out-of-policy actions? |
| Supply-chain risk | Are dependencies and connectors trusted and monitored? |
| Runtime manipulation | Can prompt injection or chaining bypass safeguards? |
Defender-aligned controls¶
- Baseline discovery of all active agents and associated risk signals.
- Continuous monitoring for suspicious behavior and anomalous tool activity.
- Alert triage playbooks that map to accountable owners.
- Automated containment paths for high-confidence detections.
- Post-incident hardening feedback into governance policy.
Security scorecard¶
| Control area | Example indicator |
|---|---|
| Identity hardening | Privileged identity exposure trend |
| Runtime safety | Policy-block success rate |
| Threat detection | Mean time to detect and triage |
| Containment | Mean time to contain high-severity event |
| Hardening | Recurrence rate after remediation |
Business example¶
A runtime detection identifies an unusual sequence of tool requests by a normally low-impact agent. Security operations isolate the agent, revoke tool tokens, review prompts and telemetry, and update policy templates to block the pattern before restoring service.