{"id":26014,"date":"2025-09-30T07:23:03","date_gmt":"2025-09-30T15:23:03","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2025\/09\/30\/news-19733\/"},"modified":"2025-09-30T07:23:03","modified_gmt":"2025-09-30T15:23:03","slug":"news-19733","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2025\/09\/30\/news-19733\/","title":{"rendered":"Empowering defenders in the era of agentic AI with Microsoft Sentinel"},"content":{"rendered":"<p><strong>Credit to Author: Vasu Jakkal| Date: Tue, 30 Sep 2025 13:00:00 +0000<\/strong><\/p>\n<h4 class=\"wp-block-heading\" id=\"microsoft-unveils-a-new-wave-of-security-innovation-delivering-an-agentic-platform-to-protect-organizations-at-scale\"><strong>Microsoft unveils a new wave of security innovation\u2014delivering an agentic platform to protect organizations at scale<\/strong><\/h4>\n<p class=\"wp-block-paragraph\">We are living through a turning point in how organizations work and defend themselves. Across industries, \u201c<a href=\"https:\/\/blogs.microsoft.com\/blog\/2025\/04\/23\/the-2025-annual-work-trend-index-the-frontier-firm-is-born\/\" target=\"_blank\" rel=\"noreferrer noopener\">Frontier Firms<\/a>\u201d are emerging; these are businesses where humans and AI agents collaborate in real time to solve problems, innovate, and build resilient organizations.<\/p>\n<p class=\"wp-block-paragraph\">For security teams, this shift brings new opportunities and challenges. The complexity and speed of modern cyberthreats demand solutions that go beyond traditional tools. To address these needs, Microsoft is introducing new agentic security capabilities to empower defenders to innovate boldly and safely in this new AI era.<\/p>\n<h2 class=\"wp-block-heading\" id=\"microsoft-sentinel-the-security-platform-for-the-agentic-era\">Microsoft Sentinel: The security platform for the agentic era<\/h2>\n<p class=\"wp-block-paragraph\">Defenders need to protect AI end-to-end and for that they need a platform that brings together data, context, automation, and intelligent agents, enabling them to defend and adapt at AI speed. That platform is <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-sentinel\">Microsoft Sentinel<\/a>.<\/p>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-sentinel\">Secure your multicloud, multiplatform environment with Microsoft Sentinel<\/a><\/div>\n<\/p><\/div>\n<p class=\"wp-block-paragraph\">Sentinel started as a cloud-native security information and event management (SIEM) and expanded to also include <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/07\/22\/microsoft-sentinel-data-lake-unify-signals-cut-costs-and-power-agentic-ai\/\" target=\"_blank\" rel=\"noreferrer noopener\">a unified security data lake in July<\/a>. Today, it is expanding into an agentic platform with the <a href=\"https:\/\/aka.ms\/sentinel\/datalake\/gablog\" target=\"_blank\" rel=\"noreferrer noopener\">general availability of Sentinel data lake<\/a>, and the public preview of <a href=\"https:\/\/aka.ms\/sentinel\/graph\/techblog\" target=\"_blank\" rel=\"noreferrer noopener\">Sentinel graph<\/a> and <a href=\"https:\/\/aka.ms\/sentinel\/mcp\/techblog\" target=\"_blank\" rel=\"noreferrer noopener\">Sentinel Model Context Protocol (MCP) server<\/a>. With graph-based context, semantic access, and agentic orchestration, Sentinel gives defenders a single platform to ingest signals, correlate across domains, and empower AI agents built in Security Copilot, VS Code using GitHub Copilot, or other developer platforms.<\/p>\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"ms-metrics-youtube-container\" data-video-id=\"oCl3Pplr__s\" id=\"ms-metrics-youtube-68dbe33dcff38\">\n<div class=\"ms-metrics-youtube-player\"><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<p class=\"wp-block-paragraph\">Sentinel ingests signals, either structured or semi-structured, and builds a rich, contextual understanding of your digital estate through vectorized security data and graph-based relationships. By integrating these insights with Microsoft Defender and Microsoft Purview, Sentinel brings graph-powered context to the tools security teams already use, helping defenders trace attack paths, understand impact, and prioritize response\u2014all within familiar workflows. <\/p>\n<blockquote class=\"wp-block-quote has-quote-default-font-size is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>With Microsoft Security and Sentinel data lake, we\u2019ve unified silos, scaled operations, automated processes, and expanded coverage\u2014transforming how we detect patterns and prepare for the future with a unified, agile security posture<\/em>. <\/p>\n<p> <cite>\u2014<em>Bernard Knaapen, Chief Product Owner, Monitoring and Incident Response, ABN AMRO<\/em> <\/cite><\/p><\/blockquote>\n<p class=\"wp-block-paragraph\">Sentinel also organizes and enriches your security data, making it ready for AI agents to detect issues faster, investigate with more clarity, and respond automatically when needed. And <a href=\"https:\/\/aka.ms\/sentinel\/graph\/techblog\" target=\"_blank\" rel=\"noreferrer noopener\">Sentinel\u2019s graph-based approach<\/a> powers Security Copilot agents to reason over your environment with precision and speed, thanks to the built-in MCP server, which uses open standards for easy agent access and action. For advanced teams, Sentinel MCP server enables extensibility for predefined and custom agents, allowing AI-powered reasoning over unified data. This shifts security from reactive to predictive, helping teams anticipate threats and automate response at scale. <\/p>\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/MS-Secure_Storyboard_Sept-30-FY26_FOR-BP-FINAL-1024x576.webp\" alt=\"Blue flow chart with app icons and white and light blue font\" class=\"wp-image-142728 webp-format\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/MS-Secure_Storyboard_Sept-30-FY26_FOR-BP-FINAL-1024x576.webp 1024w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/MS-Secure_Storyboard_Sept-30-FY26_FOR-BP-FINAL-300x169.webp 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/MS-Secure_Storyboard_Sept-30-FY26_FOR-BP-FINAL-768x432.webp 768w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/MS-Secure_Storyboard_Sept-30-FY26_FOR-BP-FINAL-809x455.webp 809w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/MS-Secure_Storyboard_Sept-30-FY26_FOR-BP-FINAL.webp 1280w\" data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/MS-Secure_Storyboard_Sept-30-FY26_FOR-BP-FINAL-1024x576.webp\"><figcaption class=\"wp-element-caption\">&nbsp;<em>This diagram illustrates the architecture and integration of Microsoft&#8217;s security ecosystem across multicloud and<\/em> <em>multiplatform environments.<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Sentinel is open and extensible, so partners can build their own agents and solutions. And with the <a href=\"https:\/\/aka.ms\/securitystore\/techblog\" target=\"_blank\" rel=\"noreferrer noopener\">new Microsoft Security Store<\/a>, finding and deploying these agents is simple. We\u2019re already collaborating with Accenture, ServiceNow, and Zscaler <a href=\"https:\/\/aka.ms\/sentinel\/isvblog\" target=\"_blank\" rel=\"noreferrer noopener\">to strengthen the security ecosystem together<\/a>. <\/p>\n<p class=\"wp-block-paragraph\">Sentinel is an industry-leading SIEM and the scalable backbone defenders need in the age of AI. Together, Sentinel and Security Copilot give security teams the visibility, automation, and scale they need to stay ahead of cyberthreats.<\/p>\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"ms-metrics-youtube-container\" data-video-id=\"QuDg_b147Q8\" id=\"ms-metrics-youtube-68dbe33dd13aa\">\n<div class=\"ms-metrics-youtube-player\"><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-2 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/aka.ms\/sentineldatalakedocs\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more about Microsoft Sentinel platform and take the next steps<\/a><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\" id=\"security-copilot-build-your-own-agents-no-code-required\">Security Copilot: Build your own agents<strong>\u2014<\/strong>no code required<\/h2>\n<p class=\"wp-block-paragraph\">Security Copilot was created to help security teams tackle the toughest challenges<strong>\u2014<\/strong>endless alerts, siloed tools, and constant pressure to do more with less. But no one understands your environment and unique needs like you do. Now you can build your own <a href=\"https:\/\/aka.ms\/SCP-Secure-2509\">Security Copilot agents<\/a>. The Security Copilot portal features a no-code agent builder that lets you describe what you need in natural language and create, optimize, and publish agents tailored to your workflows in minutes.<\/p>\n<p class=\"wp-block-paragraph\">You can also build agents in a Sentinel MCP server-enabled coding platform, such as VS Code using GitHub Copilot. Once built, you can refine and deploy agents to your Security Copilot workspace while keeping the process within the familiar development platform. <\/p>\n<p class=\"wp-block-paragraph\">Security Copilot agents are designed to integrate into daily tools and workflows<strong>\u2014<\/strong>whether embedded in the Microsoft Security products you already use, partner-built, or custom-built for your environment. Since <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/SecurityCopilotBlog\/automate-cybersecurity-at-scale-with-microsoft-security-copilot-agents\/4394675\/\">launching Security Copilot agents in March 2025<\/a>, we\u2019ve delivered <a href=\"https:\/\/aka.ms\/mechanics-scp-agents\" target=\"_blank\" rel=\"noreferrer noopener\">more than a dozen agents<\/a> for scenarios such as phish triage and conditional access optimization. We continue to add embedded agents such as the <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/the-microsoft-entra-agent-for-smarter-access-governance-access-review-agent\/4279689\" target=\"_blank\" rel=\"noreferrer noopener\">Access Review Agent in Microsoft Entra<\/a>. Microsoft and partner-created Security Copilot agents are available to discover, buy, and deploy in the Security Store today.<\/p>\n<p class=\"wp-block-paragraph\">Building on Sentinel\u2019s graph-based context, Security Copilot agents can now reason more effectively across your environment\u2014correlating alerts, enriching context with relationships, prioritizing by impact, and automating common actions. This enables fewer false positives, faster triage, and lower mean time to resolution (MTTR). Work shifts from manual triage to agent-led workflows: agents orchestrate and automate routine tasks, while analysts review and approve outcomes\u2014focusing their time on strategic decisions and proactive threat hunts. <\/p>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-3 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/aka.ms\/SCP-Secure-2509\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more about Security Copilot agents and explore what\u2019s possible<\/a><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\" id=\"secure-and-govern-your-ai-comprehensively\"><strong>Secure and govern your AI comprehensively<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">As organizations embrace AI, Microsoft continues to invest in tools that help security teams secure and govern their AI platforms, apps, and agents across the enterprise.<\/p>\n<p class=\"wp-block-paragraph\">Over the past few months, we\u2019ve expanded our Security for AI capabilities, including <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-entra-blog\/announcing-microsoft-entra-agent-id-secure-and-manage-your-ai-agents\/3827392\" target=\"_blank\" rel=\"noreferrer noopener\">Entra Agent ID<\/a> to help discover and manage your agent estate, controls to prevent data oversharing in <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoft-security-blog\/enterprise-grade-controls-for-ai-apps-and-agents-built-with-azure-ai-foundry-and\/4414757\" target=\"_blank\" rel=\"noreferrer noopener\">custom-built AI apps and agents<\/a>, risk discovery tools for AI model providers and <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftthreatprotectionblog\/discover-risks-in-ai-model-providers-and-mcp-servers-with-microsoft-defender\/4440050\" target=\"_blank\" rel=\"noreferrer noopener\">MCP servers<\/a>, and advanced detection for prompt injection attacks. <\/p>\n<p class=\"wp-block-paragraph\">At Microsoft Build 2025, we announced new enhancements to Azure AI Foundry that provide more protection for AI agents across their lifecycle. These will be available soon and include:<\/p>\n<ol start=\"1\" class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Agent task adherence control to help keep agents aligned with tasks in real time<\/li>\n<li class=\"wp-block-list-item\">Personally identifiable information (PII) guardrail <\/li>\n<li class=\"wp-block-list-item\">Spotlighting capability in prompt shields to enhance protection against cross-prompt injection attacks<\/li>\n<\/ol>\n<p class=\"wp-block-paragraph\">Together, these innovations help you secure and govern your AI apps and agents in Microsoft 365 Copilot, Copilot Studio, and Azure AI Foundry\u2014helping you build on the trusted tools your teams already use and offering you more natively built protections for your Microsoft AI platforms.<\/p>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-4 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/learn.microsoft.com\/en-us\/security\/security-for-ai\/\" target=\"_blank\" rel=\"noreferrer noopener\">Learn more about end-to-end protection for your AI agents<\/a><\/div>\n<\/p><\/div>\n<div class=\"is-style-vertical wp-block-bloginabox-theme-promotional\">\n<div class=\"promotional promotional--has-media promotional--media-right\">\n<div class=\"promotional__wrapper\">\n<div class=\"promotional__content-wrapper\">\n<div class=\"promotional__content\">\n<h2 class=\"wp-block-heading\" id=\"upcoming-security-events\"><strong>Upcoming security events<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Deep dive into these innovations at <a data-bi-an=\"Global CTA\" data-bi-ct=\"cta link\" data-bi-id=\"cta-block\" href=\"https:\/\/register.secure.microsoft.com\/?ocid=cmme8nzzcuz\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Secure<\/a> on Sep 30, Oct 1, or on demand. Then, join us at <a href=\"https:\/\/ignite.microsoft.com\/en-US\/home?wt.mc_ID=Ignite2025_marx_corp_bl_oo_bl_Security_2_1\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Ignite<\/a>, Nov, 17\u201321 in San Francisco, CA or online\u2014for more innovations, hands-on labs, and expert connections.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"promotional__media-wrapper\">\n<div class=\"promotional__media\"> \t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"718\" height=\"530\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2025\/09\/Security_Blog_Events_06-e1759177113312.png\" class=\"attachment-full size-full\" alt=\"Microsoft Security banners at event\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\" id=\"looking-ahead-securing-the-future-is-a-team-sport\"><strong>Security is a team sport<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">We are entering a new era: security is adaptive, intelligent, and acts at the speed of thought. The advances announced today are the building blocks for a new generation of defense.<\/p>\n<p class=\"wp-block-paragraph\">I firmly believe that security is a team sport. That team includes all of us\u2014 innovating together, learning together, and defending together. <\/p>\n<p class=\"wp-block-paragraph\">Together, we\u2019re not just imagining the future. We\u2019re securing it. <ins><\/ins><\/p>\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-5 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button has-custom-width wp-block-button__width-75\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/siem-and-xdr\/microsoft-sentinel\">Secure more with Microsoft Sentinel<\/a><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\" id=\"learn-more-with-microsoft-security\">Learn more with Microsoft Security<\/h2>\n<p class=\"wp-block-paragraph\">To learn more about Microsoft Security solutions, visit our\u202f<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener\">website<\/a>. Bookmark the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security blog<\/a> to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>)\u202ffor the latest news and updates on cybersecurity.<\/p>\n<p class=\"wp-block-paragraph\">\n<p>The post <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/09\/30\/empowering-defenders-in-the-era-of-agentic-ai-with-microsoft-sentinel\/\">Empowering defenders in the era of agentic AI with Microsoft Sentinel<\/a> appeared first on <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/09\/30\/empowering-defenders-in-the-era-of-agentic-ai-with-microsoft-sentinel\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Vasu Jakkal| Date: Tue, 30 Sep 2025 13:00:00 +0000<\/strong><\/p>\n<p>Microsoft Sentinel is expanding into an agentic platform with general availability of the Sentinel data lake, and the public preview of Sentinel graph\u00a0and\u00a0Sentinel\u00a0Model Context Protocol (MCP)\u00a0server.\u00a0<\/p>\n<p>The post <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/09\/30\/empowering-defenders-in-the-era-of-agentic-ai-with-microsoft-sentinel\/\">Empowering defenders in the era of agentic AI with Microsoft Sentinel<\/a> appeared first on <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[],"class_list":["post-26014","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26014"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26014\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26014"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}