Every Microsoft security product mapped to the AI security stack. Updated with RSAC 2026 announcements. GA/Preview status reflects what was confirmed on March 20, 2026.
โ Click on a product name to navigate to the Microsoft documentation page.
โ Click on a product name to navigate to the Microsoft documentation page.
โ Click on a product name to navigate to the Microsoft documentation page.
CopilotActivity table in Sentinel. Enables analytic rules, workbooks, hunting queries, and automation specifically targeting AI/agent interactions. Record types include: CopilotInteraction, plugin lifecycle (create/update/delete), CopilotPromptBook operations, CopilotForSecurityTrigger, CopilotAgentManagement. Also supports Sentinel data lake for low-cost long-term retention and MCP server integration. Note: data ingestion costs apply. Prompt content ingested becomes a sensitive artifact โ apply field-level masking and access controls on CopilotActivity table.AIAgentsInfo Advanced Hunting table. Detects no-auth agents, ownerless agents, and risky configurations. Setup requires collaboration between Defender admin AND Power Platform admin โ two separate portals. Takes up to 30 minutes for initial connection and longer for full data population. Three Defender preview features must be enabled separately.โ Click on a product name to navigate to the Microsoft documentation page.
โ Click on a product name to navigate to the Microsoft documentation page.