July was dominated by a single announcement, Project Perception, which is Microsoft going all in on agentic security. Around it there was a meaningful shift in how threat intelligence is delivered, plus a handful of smaller updates worth knowing about. Here is a rundown of what landed.
Project Perception, agentic defence lands in Defender
On July 27, Microsoft announced Project Perception, which is the biggest strategic move of the month. It is a coordinated system of security agents that reason over your data, tools, and workflows, built around three classes of agent working as a closed loop:
- Red agents probe the environment and look for paths an attacker could take.
- Blue agents investigate signals, add context, and decide which risks actually matter.
- Green agents take corrective action and harden what was found.
The idea is that a finding becomes a fix without a human hand-off at every step, with you setting the strategy and staying in control of anything consequential.
A few things worth knowing before you get too excited:
- It is built on MAI-Cyber-1, Microsoft’s first purpose-built cybersecurity model. Microsoft has published some strong benchmark numbers, but those are Microsoft’s own figures and have not been independently verified, so treat them as a starting point rather than gospel.
- At launch it brings this multi-agent defence directly into Microsoft Defender, which is exactly why it belongs in a Sentinel roundup. It is not a bolt-on product sitting off to the side.
- It is a public preview, opening August 3, so anything you read this month is early. There is a lot of demo polish to see through before you know how it behaves against your own noisy estate.
My honest take is that the direction is not surprising given where Sentinel has been heading, but the closed-loop framing where green agents can actually remediate is a meaningful step past the assistant model we have had with Security Copilot. Worth watching closely, worth being cautious about handing it the keys.
Threat intelligence converges, and MDTI standalone winds down
Microsoft is folding threat intelligence more tightly into the unified SecOps workflow, with Microsoft Defender Threat Intelligence convergence and an enhanced Threat Intelligence Agent bringing more out-of-the-box intel and automation into Defender.
The practical flag for anyone running MDTI: the standalone MDTI SKU reaches end of life on August 1, 2026. The capabilities are not disappearing, they are now available at no extra cost through the Defender portal to any customer with Defender or Sentinel, and there is no migration action needed. If you are a CSP partner, check the July partner announcement for the credit-memo detail, because you may need to pass credits through to end customers for any remaining subscription term.
Net effect for most SOCs is positive, the intel you were paying separately for is now just part of the platform. Just make sure your billing and licensing records reflect the change.
Prompt injection protection for the inbox
A timely one given how much AI is now sitting between email and action. Defender for Office 365 has new prompt injection protection in preview that identifies and isolates emails carrying malicious AI instructions before they are delivered.
The scenario it targets is an email crafted to hijack whatever AI assistant or agent might later read it, so the instructions never reach the inbox in the first place. As agents get more access to mailboxes and take more actions on our behalf, the inbox becomes an injection surface, and this is Microsoft starting to treat it like one. Worth enabling and testing if you are running Defender for Office 365.
Disable compromised identities straight from the SOC
There are new interconnected experiences between Defender and Microsoft Entra that let the SOC disable a compromised identity directly, using an RBAC mode that keeps least privilege intact.
The value here is time-to-contain. Instead of an analyst raising a request and waiting on the identity team to action it, the containment step happens in the same workflow as the investigation, without handing the SOC broad Entra permissions it should not have. If your incident response runbooks currently include a cross-team handoff just to disable an account, this is worth building into the process.
Defender Experts MDR reaches beyond the Microsoft estate
For teams that lean on managed detection and response, Defender Experts is expanding. Two parts to it:
- Defender Experts Threat Intelligence delivers human-led, curated insight into the threats most relevant to a given organisation.
- Defender Experts MDR now extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals, through Sentinel.
That second point is the interesting one for anyone whose environment is not a clean Microsoft-only shop. Using Sentinel as the reach into non-Microsoft signals is a sensible use of where Sentinel actually sits in most estates.
Quick hits
A few smaller items from the July drop that are worth noting without a full section:
- AgentsInfo table: the advanced hunting schema for AI agent inventory has moved to the unified
AgentsInfotable, covering Copilot Studio, Foundry, Microsoft 365 Copilot, third-party, and endpoint-discovered agents. The oldAIAgentsInfotable was accessible until July 1, so update any queries that still reference it. Details in the Defender monthly news. - Human identities card: the Identity Security dashboard added a new Human identities card in public preview, showing your human identities by source across Entra ID, SaaS, and on-premises in one view.
- Cloud agent protection: unified Defender posture and runtime protection for cloud agents arrived through Microsoft Agent 365, covering Foundry, Copilot Studio, and third party-managed agents.
- CSPM for serverless containers: Cloud Security Posture Management now extends to serverless containers running on Azure Container Apps, Azure Container Instances, and AWS ECS on Fargate.
Summary
July was more about direction than day-to-day tooling. The headline is Project Perception and the deeper threat intelligence convergence, both signalling where Microsoft wants security operations to head next.
The one item with a hard date on it is MDTI. Check your position before the standalone SKU reaches end of life on August 1, because there may be billing and licensing records to tidy up even though the capability itself carries on through the Defender portal.
Project Perception is the one that will fill up your feed, and it is genuinely a shift in direction. Just remember it is a preview, the benchmarks are Microsoft’s own, and closed-loop remediation is something you want to understand thoroughly before you let it run unattended in a client environment. The pattern from the last year holds, Sentinel keeps moving further away from being a place you read logs and further towards being the platform the agents reason over.