Three Agent Classes, Not Just More Alerts
Project Perception divides security work among three types of specialized agent. Red-team agents look for potential paths to compromise before attackers exploit them. Blue-team agents investigate, reason over context and decide which risks matter. Green-team agents take corrective action and strengthen defenses. They share security context spanning identities, endpoints, applications, data and cloud environments, creating a loop that continuously discovers, evaluates and remediates risk. Microsoft says humans remain in control rather than handing every response decision to agents.
Software Vulnerability Management Comes First
The first scenario brings Microsoft's MAI-Cyber-1-Flash model into MDASH, its multi-model team of vulnerability-management agents. Microsoft reports that this configuration scores 96% on CyberGym, 12 points above Mythos, while cutting costs by nearly 50% compared with the current commercial MDASH configuration. These are vendor-run benchmarks and estimates, with no independent reproduction published yet, so they are better read as product claims than externally confirmed capability.
The Shift Is From Assessment to Action
Security tools have traditionally stopped at detecting problems and producing alerts. Project Perception's more consequential change is connecting model judgment to remediation actions. Its multi-model architecture selects models according to quality, reliability, latency and cost, and Microsoft plans to begin public preview on August 3. Whether enterprises will grant agents production remediation privileges will still depend on audit trails, permission boundaries and human approval controls; Microsoft has not yet disclosed full pricing or rollout details.
via: Official Microsoft Blog (2026-07-27; verified 2026-07-28)