Microsoft is reshaping its cybersecurity strategy around autonomous systems. In an official announcement published on July 27, the company introduced Project Perception, an agentic security system intended to help organizations perceive risk, reason over security context and take action across their digital estates.
The announcement comes as attackers use AI to generate exploits, scale campaigns and operate at machine speed. Microsoft argues that security processes designed primarily around human analysts and manually reviewed alerts cannot keep pace with that change. Its proposed answer is a new “cyber stack” built around continuous visibility, multiple AI models and specialized agents.
From alert generation to continuous defense
Project Perception is described as a system that brings together signals, context, models, agents and operational controls. Rather than treating security as a sequence of isolated investigations, Microsoft wants the platform to maintain an evolving understanding of an organization’s identities, endpoints, applications, data, cloud resources and AI systems.
That context is central to the design. Microsoft says the system creates a continuously updated representation of assets, relationships, risks and activities, giving its agents a shared view of the environment. The stated goal is to reduce the time spent collecting and correlating raw telemetry before an analyst or automated workflow can make a decision.
The system is organized around three classes of specialized agents. Red team agents are intended to identify possible paths to compromise before an attacker can exploit them. Blue team agents investigate activity, evaluate context and determine which risks are meaningful. Green team agents take corrective actions and strengthen defenses. Microsoft presents these roles as a closed loop in which discovery, assessment and remediation continuously inform one another.
A multi-model approach to security work
Microsoft is also positioning Project Perception as a multi-model system rather than a product dependent on one general-purpose model. The company says each security task may require a different balance of quality, reliability, latency and cost, so the platform can select models suited to particular workflows.
The first announced scenario is software vulnerability management. Microsoft says Project Perception will bring MAI-Cyber-1-Flash into MDASH, its multi-model team of agents for software vulnerabilities. According to Microsoft, that configuration achieved 96% on CyberGym, which the company describes as an industry-leading benchmark, and scored 12 points above Mythos. Microsoft also claims almost 50% cost savings compared with the current MDASH configuration available in its market.
Those figures are company-reported results rather than an independent evaluation presented in the announcement. They therefore offer a useful indication of Microsoft’s internal positioning, but they do not establish how the system will perform across different organizations, codebases or operating conditions.
Public preview and the questions that remain
Microsoft said Project Perception would enter public preview on August 3. The announcement does not provide a pricing schedule, a complete list of supported environments or a detailed deployment procedure. It also does not describe the limits of automated remediation for every security workflow. Those details will matter to organizations deciding how much authority to give AI agents over production systems.
The company says the platform is built around human control and inherits Microsoft Security’s existing governance, compliance and operational controls. That is an important design claim, but it also highlights the practical challenge: agentic security must be evaluated not only on detection quality, but on permissions, auditability, rollback and failure handling.
For security teams, the most significant shift is conceptual. Project Perception treats cybersecurity as a continuous feedback system rather than a queue of alerts. The approach could help defenders prioritize exposure and reduce repetitive investigation work, especially when telemetry spans identities, applications, cloud infrastructure and AI services. It also introduces a larger governance surface, because every automated action needs a clearly defined owner, scope and approval boundary.
Microsoft’s announcement is therefore best understood as an early statement of direction, backed by a public-preview milestone and a specific vulnerability-management use case. The next test will be whether Project Perception can translate its closed-loop architecture into reliable, explainable and controllable outcomes in live security operations.
Source: Microsoft’s official announcement of Project Perception.
