Why security must change scale
Autonomous systems can now analyze, adapt and act continuously. This evolution also accelerates offensive operations. Attackers can industrialize vulnerability research, multiply campaigns and reduce the time between discovery and exploitation.
Security architectures designed around sequential human actions are reaching their limits when faced with machine-driven attacks. Microsoft proposes a new approach with Project Perception, an agentic system designed to transform security signals into operational protections.

Availability
Project Perception enters public preview on August 3, 2026. A preview feature must be evaluated within a controlled scope before any generalization to production.
Project Perception: A closed-loop defense
Project Perception brings together signals, security context, multiple artificial intelligence models and specialized agents. Its objective is not to produce more alerts. It is to continuously understand risk, prioritize it and trigger an appropriate response.
The architecture is based on three families of agents:
- Red Team agents search for potential compromise paths before they are exploited.
- Blue Team agents analyze events, cross-reference available context and assess actual risk.
- Green Team agents apply corrective measures and strengthen security controls.
These roles form a continuous loop: discovery, investigation, decision and remediation. The model is particularly suited to environments where identities, workstations, applications, data, clouds and artificial intelligence systems evolve simultaneously.

Control Point
Automation does not eliminate human governance. Teams must define authorized actions, approval levels and scenarios requiring validation before remediation.
The six layers of the new Cyber Stack
Project Perception is not limited to adding agents to existing tools. Microsoft describes a Cyber Stack composed of six complementary layers. Operational value comes from their coordination, not from an isolated layer.
| Layer | Operational role | Question to verify |
|---|---|---|
| Signals and sensors | Collection of visibility on identities, endpoints, data, clouds, applications and AI systems | Are critical sources covered? |
| Context | Enrichment of signals with assets, relationships, activities and risks | Do agents have actionable context? |
| Models | Reasoning about threats with multiple specialized or generalist models | Does the chosen model match the task? |
| Harness | Orchestration of models and agents in security workflows | Are decisions traceable? |
| Agents | Investigation, simulation and correction by Red, Blue and Green teams | Are responsibilities clearly separated? |
| Actuators | Translation of decisions into protection actions | Are actions reversible and controlled? |
This breakdown provides a useful framework for evaluating an agentic security project. An organization that has high-performing models but low visibility will not be able to obtain a reliable result. Conversely, abundant telemetry without coherent context increases the volume of analysis demanded from teams.
Security context reduces analytical noise
Raw signals are not enough for an agent. It must know the affected assets, the identities involved, the relationships between resources, attack paths and event history.
Project Perception relies on security context updated from Microsoft visibility, threat intelligence and operational expertise. This context notably represents:
- assets and their dependencies;
- identities and their relationships;
- alerts, exposures and activities;
- attack graphs and lateral movement;
- process trees and anomaly scenarios;
- Red Team operations and email-related threats.

This mechanism prevents agents from reconstructing context from each event. It reduces the amount of information to process and speeds up prioritization. For operational deployment, the quality of this context must be verified on the most sensitive assets: privileged accounts, resources exposed on the Internet, administration chains and critical data.
A multi-model architecture to control costs
No model is optimal for all cybersecurity tasks. The selection must take into account the quality of the response, reliability, latency and execution cost.
Project Perception therefore adopts a multi-model architecture. State-of-the-art models and specialized models can be combined according to the workflow. This approach avoids systematically mobilizing the most expensive model for an operation that does not justify it.
The first announced scenario concerns software vulnerability management. MAI-Cyber-1-Flash is integrated with MDASH, presented as a multi-model team of agents dedicated to this field. This configuration achieves 96% on CyberGym, which is 12 points higher than Mythos, with an announced reduction of nearly 50% in costs compared to the MDASH configuration then available on the market.
These results must be interpreted in their context. CyberGym is a benchmark and does not replace evaluation on code, change processes and production constraints specific to each organization. Before adoption, the accuracy of detections, false positives, processing time and the ability to justify each recommendation must be measured.
Evaluation Method
Start with a known set of vulnerabilities. Compare the agent's recommendations with those of analysts, then separately verify the quality of triage and corrective actions.
From information to action with actuators
A security platform that detects without correcting leaves risk in place. Actuators therefore constitute a determining layer of the Cyber Stack. They connect an agent's decision to the protection mechanisms available in Microsoft Security products.
Actions can target exposure reduction, configuration hardening or threat response. Their scope depends, however, on available integrations, granted permissions and controls applied by the organization.
Teams must document at minimum:
- actions that can be executed automatically;
- actions subject to approval;
- accounts or identities used to act;
- logs retained for audit;
- the rollback procedure when an action produces an undesirable effect.
The preview is precisely an appropriate framework for testing these safeguards. Irreversible or high-impact scenarios must remain behind human validation as long as behavior is not sufficiently characterized.
Security, compliance and accountability
Project Perception is presented as aligned with Microsoft's responsible AI principles. The system also inherits the security, compliance, governance and operational controls used in the Microsoft ecosystem.
This promise does not dispense with internal analysis. Security leaders must verify data flows, necessary roles, log retention and limits on access to context information. Requirements vary by industry, data sensitivity and responsibility separation rules.
Human supervision remains necessary for high-impact decisions. An agent can accelerate an investigation or propose remediation. It should not become an implicit authority when a decision affects a privileged account, business application or production resource.
What teams must prepare
Availability in public preview on August 3, 2026 allows for a first evaluation. A useful pilot must remain measurable and limited.
Define the scope
Select a specific scenario, such as software vulnerability management. Exclude production actions until validation criteria are established.
Verify visibility
Inventory available sources for identities, endpoints, applications, data, clouds and AI systems. Identify blind spots that could skew agent reasoning.
Establish safeguards
Define permissions, approvals, logging and rollback procedures. Maintain a clear separation between simulation, investigation and remediation.
Measure results
Compare accuracy, latency, cost, false positive rate and resolution time with the existing process. Use a set of cases representative of the real environment.
Key takeaways
The Project Perception approach relies on three capabilities: perceive the environment, reason with rich context and act at the speed of automated threats. Its Cyber Stack combines signals, context, models, orchestration, agents and actuators.
Success will depend less on the number of agents than on the quality of visibility, the relevance of models and the control of actions. Teams can follow information available on the Microsoft Security website, the Security blog and the page dedicated to Project Perception.



