
Microsoft's Project Perception uses coordinated red, blue and green agents to autonomously find and fix security gaps. The system requires Defender and the Microsoft stack, with a private preview next week. Analysts say real-world performance is unproven.
Alpha Score of 73 reflects strong overall profile with strong momentum, strong value, strong quality, moderate sentiment.
Microsoft announced Project Perception, a system of coordinated red, blue and green team agents designed to autonomously find and fix security gaps in cloud environments. The agents run on Microsoft Defender and will be available in private preview next week, with consumption-based pricing.
Red team agents probe for attack paths. Blue team agents prioritize the findings and build new detections. Green team agents implement fixes, including opening pull requests on GitHub, according to a Forrester analyst blog post outlining the announcement.
Microsoft's approach differs from earlier vulnerability tools like MDASH, which focused on scanning without remediation. Project Perception aims to close the full security lifecycle, from identification through implementation, the analyst said.
Initial demos focus on hardening web applications. The blue team can pull in threat intelligence, pass it to the red team for reconnaissance, and build net new detections. The green team can propose fixes and connect to GitHub to open a pull request, according to the blog. The system also includes an MCP server for CLI execution.
Forrester's analyst noted that the coordination between agents is the key differentiator. Other vendors, including Wiz, have released separate red, blue and green team agents, but Microsoft's architecture ties them together in an orchestrated loop. The company's graph database is cited as a differentiator for gathering context, the analyst said.
Getting value from the agents requires the Microsoft security stack. Pricing is separate and consumption-based, the blog said.
Microsoft also released its first custom cybersecurity model, Microsoft AI-Cyber-1-Flash, focused on vulnerability analysis. The company has previously released models for image, transcription, reasoning, coding and speech. The shift to a security-specific model shows Microsoft's desire to control the entire security stack, the analyst said.
Project Perception does not rely solely on its own model. It includes an orchestration layer that chooses the best model for quality, reliability, latency and cost–a practice Forrester recommends for any AI system, the blog said.
The analyst cautioned that real-world performance remains unproven. AI agents are non-deterministic and can take different execution paths. In an agentic architecture, cascading failures are possible, the analyst said. Microsoft has received positive feedback on its simpler Phishing Triage Agent, but Project Perception is far more complex.
Forrester said the announcement underscores the intersection of cyber platform consolidation and AI agent deployment. The more comprehensive the visibility from a security platform, the better the agent outcomes, the analyst wrote.
The private preview opens next week, Microsoft said.
Microsoft's Enterprise AI Will Be Defined By Trust approach will be tested as these agents move from demos to production. The MSFT stock page shows the stock up 1.91% today at $389.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.