Real-Time Threat Protection for Copilot Studio Agents with Microsoft Defender
Copilot Studio agents don't just answer questions. They take actions. They send emails, call APIs, and move data. That power is also a new security risk.
In this video, David Lorenzo, a Microsoft MVP, and I show how to protect Copilot Studio agents with Microsoft Defender. You will see how to inspect every tool call an agent makes, and how to block the risky ones before they run.
We cover why AI agents change the security picture, how prompt injection attacks work, and the built-in protection that ships by default. Then we connect Microsoft Defender as a second layer, step by step: registering the Entra app, creating the federated identity credential, configuring the Power Platform admin center, and building real-time protection rules. The video ends with a live demo where Defender blocks an agent from leaking sensitive data before the action runs.
To help you apply it in your own tenant, we published a companion GitHub repository with a full written guide, a PowerShell helper script, and sample hunting queries.
This is a preview feature, so always check the official Microsoft docs before using it in production.
GitHub guide: https://github.com/rafsan-huseynov/copilot-studio-defender-protection