Microsoft Announces Project Perception Agentic Cybersecurity System Entering Public Preview August 3
On July 27, 2026, Microsoft announced Project Perception, an agentic security system designed to defend against artificial intelligence-driven cyberattacks. Scheduled to enter public preview on August 3, 2026, the system coordinates specialized red, blue, and green agent teams to
On July 27, 2026, Microsoft announced Project Perception, an agentic security system designed to defend against artificial intelligence-driven cyberattacks. Scheduled to enter public preview on August 3, 2026, the system coordinates specialized red, blue, and green agent teams to automate threat defense. According to Microsoft, the system utilizes a multi-model architecture to lower cybersecurity operations costs while improving threat detection rates.
Autonomous Defense Through Red, Blue, and Green Agent Teams
The system operates on a specialized multi-agent architecture designed to automate detection and response. According to Microsoft Security Executive Vice President Hayete Gallot, Project Perception relies on three distinct categories of software agents to establish a closed-loop system of continuous defense. These agents share intelligence through orchestrated workflows, allowing findings to trigger fixes without manual intervention at every step.
These three agent groups divide responsibilities as follows:
- Red team agents: Proactively probe security environments to identify potential compromise paths and expose vulnerabilities before external attackers can exploit them.
- Blue team agents: Investigate detected anomalies, analyze the surrounding security context, and evaluate which activities represent genuine risks to the organization.
- Green team agents: Execute corrective remediation steps to resolve identified vulnerabilities and harden the overall security posture.
While earlier tools like Microsoft Security Copilot operate primarily as chat-assisted interfaces designed to assist human professionals, Project Perception is built as an agentic system designed to act autonomously. By coordinating these specialized teams, the platform evaluates risks and deploys protections at machine speed while keeping human security professionals in control of overall workflows.
Six Layers of the Modern Cyber Stack
To support these autonomous agents, Microsoft has introduced a new Cyber Stack framework. The architecture consists of six distinct layers designed to turn broad security telemetry into automated defensive actions:
- Signals and sensors: This foundational layer collects telemetry across the organization’s entire digital estate, including endpoints, identities, applications, data, clouds, and AI systems.
- Security context: This layer processes raw telemetry into a token-efficient understanding of the system’s assets, identities, relationships, and current activities, which agents can read in near real-time. Grounding operations here reduces the computing overhead required to operate the system.
- Models: This layer delivers the foundational intelligence and reasoning capabilities required to process the data, combining frontier and specialized cyber models.
- Harness: This component coordinates the various models and agents across active security workflows.
- Agents: These automated entities apply specialized reasoning to execute cybersecurity tasks, operating as red, blue, and green teams.
- Actuators: These mechanisms translate agent decisions into concrete security actions, integrating directly with existing Microsoft Security products to implement protections.
Multi-Model Architecture and MDASH Optimization
Rather than relying on a single large language model for all cybersecurity tasks, Project Perception uses a multi-model architecture. The system selects specific models for different security tasks by balancing quality, latency, reliability, and operating costs.
The first implementation of this multi-model approach is in software vulnerability management, utilizing Microsoft’s Multi-Model Agentic Scanning Harness (MDASH) software vulnerability agent team. For this workflow, Microsoft integrated its specialized MAI-Cyber-1-Flash model.
According to company testing, this configuration achieved the following results:
- A 96% score on CyberGym, an industry security benchmark, representing a 12-point improvement over the Mythos model.
- An estimated 50% cost reduction compared to the existing MDASH configuration.
Integration, Compliance, and Consumption-Based Pricing
Project Perception is scheduled to enter public preview on August 3, 2026, and will initially be available through Microsoft Defender. The preview targets Microsoft business customers who are already testing the MDASH harness.
Microsoft has disclosed that Project Perception will be priced using a consumption-based, pay-as-you-go model measured in Security Compute Units (SCUs), similar to Microsoft Security Copilot. Under this structure, different agents consume SCUs at different rates depending on the compute intensity of the specific task being performed.
The system is built in alignment with Microsoft’s Responsible AI principles. It inherits the standard security, compliance, governance, and operational controls of Microsoft’s existing enterprise platforms.
- #Opensource
Author
Krishnan
Contributor
Enterprise Technology Explorer is a business and operations professional with over 15 years of experience across multiple industries working with Fortune 500 companies. With a solid foundation in enterprise processes, digital adoption, and technology evaluation, he excels at bridging business needs with emerging technologies to build scalable enterprise-grade applications.