Multi-agent defense
- Red agents probe like an attacker, blue agents investigate like your best responder, and green agents remediate and harden – sharing intelligence through orchestrated workflows so a finding becomes a fix, proactively, without a hand-off at every step.
- Agents start with the full context of your organization — past incidents, policy decisions, identity relationships, and real-time signals across endpoints, identities, clouds, and apps — so the work starts at insight, not data collection. Evidence-grade reasoning, not pattern matching.
- Agents carry the work; humans carry the judgment. Defenders set the objectives and guardrails, and every high-impact action stays under human sign-off. Enterprise-grade governance and responsible AI keep every decision scoped, traceable, and replayable.
Inside Project Perception
Meet your workforce: red, blue, & green agents
Agentic system in action
Frequently asked questions
Frequently asked questions
-
Project Perception is an agentic system that brings a workforce of specialized AI agents to reason over your security data, tools, and workflows – delivering continuous, proactive defense with a human in control of every critical decision.
-
Project Perception includes red, blue, and green agents; purpose-built models including MAI-Cyber-1; organizational context; full-estate signals and sensors; actuators to help agents act on a decision; and an orchestration harness.
-
Project Perception is our agentic system that includes all security agents: AI that acts. Microsoft Security Copilot is our generative AI-assisted chat interface: AI that assists. They work together.
-
At launch, Project Perception brings multi-agent coordinated defense directly into Microsoft Defender. Over time, Perception will extend across Microsoft Security products to deliver agentic defense end-to-end.
-
Project Perception uses consumption-based, pay-as-you-go pricing. You pay only for what you use, measured in Security Compute Units (SCUs). Different agents consume SCUs at different rates depending on the intensity of the task they perform.
-
A Security Compute Unit (SCU) is the unit used to measure Project Perception usage. As agents run scenarios in the portal, they consume SCUs. More intensive tasks consume more SCUs, so your cost reflects the actual work performed.
Follow Microsoft Security