{"id":181474,"date":"2025-10-01T02:27:09","date_gmt":"2025-10-01T02:27:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/181474\/"},"modified":"2025-10-01T02:27:09","modified_gmt":"2025-10-01T02:27:09","slug":"microsoft-sentinel-the-security-platform-for-the-agentic-era","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/181474\/","title":{"rendered":"Microsoft Sentinel: The security platform for the agentic era"},"content":{"rendered":"<p>Microsoft unveils a new wave of security innovation\u2014delivering an agentic platform to protect organizations at scale<\/p>\n<p class=\"wp-block-paragraph\">We are living through a turning point in how organizations work and defend themselves. Across industries, \u201c<a href=\"https:\/\/blogs.microsoft.com\/blog\/2025\/04\/23\/the-2025-annual-work-trend-index-the-frontier-firm-is-born\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Frontier Firms<\/a>\u201d are emerging; these are businesses where humans and AI agents collaborate in real time to solve problems, innovate, and build resilient organizations.<\/p>\n<p class=\"wp-block-paragraph\">For security teams, this shift brings new opportunities and challenges. The complexity and speed of modern cyberthreats demand solutions that go beyond traditional tools. To address these needs, Microsoft is introducing new agentic security capabilities to empower defenders to innovate boldly and safely in this new AI era.<\/p>\n<p>Microsoft Sentinel: The security platform for the agentic era<\/p>\n<p class=\"wp-block-paragraph\">Defenders need to protect AI end-to-end and for that they need a platform that brings together data, context, automation, and intelligent agents, enabling them to defend and adapt at AI speed. That platform is <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-sentinel\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Sentinel<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Sentinel started as a cloud-native security information and event management (SIEM) and expanded to also include <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/22\/microsoft-sentinel-data-lake-unify-signals-cut-costs-and-power-agentic-ai\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">a unified security data lake in July<\/a>. Today, it is expanding into an agentic platform with the <a href=\"https:\/\/aka.ms\/sentinel\/datalake\/gablog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">general availability of Sentinel data lake<\/a>, and the public preview of <a href=\"https:\/\/aka.ms\/sentinel\/graph\/techblog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Sentinel graph<\/a> and <a href=\"https:\/\/aka.ms\/sentinel\/mcp\/techblog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Sentinel Model Context Protocol (MCP) server<\/a>. With graph-based context, semantic access, and agentic orchestration, Sentinel gives defenders a single platform to ingest signals, correlate across domains, and empower AI agents built in Security Copilot, VS Code using GitHub Copilot, or other developer platforms.<\/p>\n<p class=\"wp-block-paragraph\">Sentinel ingests signals, either structured or semi-structured, and builds a rich, contextual understanding of your digital estate through vectorized security data and graph-based relationships. By integrating these insights with Microsoft Defender and Microsoft Purview, Sentinel brings graph-powered context to the tools security teams already use, helping defenders trace attack paths, understand impact, and prioritize response\u2014all within familiar workflows. <\/p>\n<p class=\"wp-block-paragraph\">With Microsoft Security and Sentinel data lake, we\u2019ve unified silos, scaled operations, automated processes, and expanded coverage\u2014transforming how we detect patterns and prepare for the future with a unified, agile security posture. <\/p>\n<p>\u2014Bernard Knaapen, Chief Product Owner, Monitoring and Incident Response, ABN AMRO <\/p>\n<p class=\"wp-block-paragraph\">Sentinel also organizes and enriches your security data, making it ready for AI agents to detect issues faster, investigate with more clarity, and respond automatically when needed. And <a href=\"https:\/\/aka.ms\/sentinel\/graph\/techblog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Sentinel\u2019s graph-based approach<\/a> powers Security Copilot agents to reason over your environment with precision and speed, thanks to the built-in MCP server, which uses open standards for easy agent access and action. For advanced teams, Sentinel MCP server enables extensibility for predefined and custom agents, allowing AI-powered reasoning over unified data. This shifts security from reactive to predictive, helping teams anticipate threats and automate response at scale. <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/10\/Security-Diagram.webp.webp\" alt=\"\" class=\"wp-image-142761 webp-format\"  data-orig-src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/10\/Security-Diagram.webp.webp\"\/>\u00a0This diagram illustrates the architecture and integration of Microsoft\u2019s security ecosystem across multicloud and multiplatform environments.<\/p>\n<p class=\"wp-block-paragraph\">Sentinel is open and extensible, so partners can build their own agents and solutions. And with the <a href=\"https:\/\/aka.ms\/securitystore\/techblog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">new Microsoft Security Store<\/a>, finding and deploying these agents is simple. We\u2019re already collaborating with Accenture, ServiceNow, and Zscaler <a href=\"https:\/\/aka.ms\/sentinel\/isvblog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">to strengthen the security ecosystem together<\/a>. <\/p>\n<p class=\"wp-block-paragraph\">Sentinel is an industry-leading SIEM and the scalable backbone defenders need in the age of AI. Together, Sentinel and Security Copilot give security teams the visibility, automation, and scale they need to stay ahead of cyberthreats.<\/p>\n<p>Security Copilot: Build your own agents\u2014no code required<\/p>\n<p class=\"wp-block-paragraph\">Security Copilot was created to help security teams tackle the toughest challenges\u2014endless alerts, siloed tools, and constant pressure to do more with less. But no one understands your environment and unique needs like you do. Now you can build your own <a href=\"https:\/\/aka.ms\/SCP-Secure-2509\" rel=\"nofollow noopener\" target=\"_blank\">Security Copilot agents<\/a>. The Security Copilot portal features a no-code agent builder that lets you describe what you need in natural language and create, optimize, and publish agents tailored to your workflows in minutes.<\/p>\n<p class=\"wp-block-paragraph\">You can also build agents in a Sentinel MCP server-enabled coding platform, such as VS Code using GitHub Copilot. Once built, you can refine and deploy agents to your Security Copilot workspace while keeping the process within the familiar development platform. <\/p>\n<p class=\"wp-block-paragraph\">Security Copilot agents are designed to integrate into daily tools and workflows\u2014whether embedded in the Microsoft Security products you already use, partner-built, or custom-built for your environment. Since <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/SecurityCopilotBlog\/automate-cybersecurity-at-scale-with-microsoft-security-copilot-agents\/4394675\/\" rel=\"nofollow noopener\" target=\"_blank\">launching Security Copilot agents in March 2025<\/a>, we\u2019ve delivered <a href=\"https:\/\/aka.ms\/mechanics-scp-agents\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">more than a dozen agents<\/a> for scenarios such as phish triage and conditional access optimization. We continue to add embedded agents such as the <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/the-microsoft-entra-agent-for-smarter-access-governance-access-review-agent\/4279689\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Access Review Agent in Microsoft Entra<\/a>. Microsoft and partner-created Security Copilot agents are available to discover, buy, and deploy in the Security Store today.<\/p>\n<p class=\"wp-block-paragraph\">Building on Sentinel\u2019s graph-based context, Security Copilot agents can now reason more effectively across your environment\u2014correlating alerts, enriching context with relationships, prioritizing by impact, and automating common actions. This enables fewer false positives, faster triage, and lower mean time to resolution (MTTR). Work shifts from manual triage to agent-led workflows: agents orchestrate and automate routine tasks, while analysts review and approve outcomes\u2014focusing their time on strategic decisions and proactive threat hunts. <\/p>\n<p>Secure and govern your AI comprehensively<\/p>\n<p class=\"wp-block-paragraph\">As organizations embrace AI, Microsoft continues to invest in tools that help security teams secure and govern their AI platforms, apps, and agents across the enterprise.<\/p>\n<p class=\"wp-block-paragraph\">Over the past few months, we\u2019ve expanded our Security for AI capabilities, including <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/announcing-microsoft-entra-agent-id-secure-and-manage-your-ai-agents\/3827392\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Entra Agent ID<\/a> to help discover and manage your agent estate, controls to prevent data oversharing in <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/enterprise-grade-controls-for-ai-apps-and-agents-built-with-azure-ai-foundry-and\/4414757\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">custom-built AI apps and agents<\/a>, risk discovery tools for AI model providers and <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftthreatprotectionblog\/discover-risks-in-ai-model-providers-and-mcp-servers-with-microsoft-defender\/4440050\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">MCP servers<\/a>, and advanced detection for prompt injection attacks. <\/p>\n<p class=\"wp-block-paragraph\">At Microsoft Build 2025, we announced new enhancements to Azure AI Foundry that provide more protection for AI agents across their lifecycle. These will be available soon and include:<\/p>\n<p>Agent task adherence control to help keep agents aligned with tasks in real time<\/p>\n<p>Personally identifiable information (PII) guardrail <\/p>\n<p>Spotlighting capability in prompt shields to enhance protection against cross-prompt injection attacks<\/p>\n<p class=\"wp-block-paragraph\">Together, these innovations help you secure and govern your AI apps and agents in Microsoft 365 Copilot, Copilot Studio, and Azure AI Foundry\u2014helping you build on the trusted tools your teams already use and offering you more natively built protections for your Microsoft AI platforms.<\/p>\n<p>Security is a team sport<\/p>\n<p class=\"wp-block-paragraph\">We are entering a new era: security is adaptive, intelligent, and acts at the speed of thought. The advances announced today are the building blocks for a new generation of defense.<\/p>\n<p class=\"wp-block-paragraph\">I firmly believe that security is a team sport. That team includes all of us\u2014 innovating together, learning together, and defending together. <\/p>\n<p class=\"wp-block-paragraph\">Together, we\u2019re not just imagining the future. We\u2019re securing it. <\/p>\n<p>Learn more with Microsoft Security<\/p>\n<p class=\"wp-block-paragraph\">To learn more about Microsoft Security solutions, visit our\u202f<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">website<\/a>. Bookmark the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Security blog<\/a> to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">@MSFTSecurity<\/a>)\u202ffor the latest news and updates on cybersecurity.<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft unveils a new wave of security innovation\u2014delivering an agentic platform to protect organizations at scale We are&hellip;\n","protected":false},"author":2,"featured_media":181475,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,105],"class_list":{"0":"post-181474","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-artificialintelligence","11":"tag-au","12":"tag-australia","13":"tag-technology"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/181474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=181474"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/181474\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/181475"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=181474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=181474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=181474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}