Can you detect and respond when an agent becomes a risk?
- Thursday, December 10, 2026
- 2:00 PM Eastern (ET)
1:00 PM Central (CT)
12:00 PM Mountain (MT)
11:00 AM Pacific (PT) - Live on Microsoft Teams
A compromised agent can act as an insider threat.
An agent manipulated through prompt injection, with excessive permissions or with misconfigured tools can move data, change configurations or take actions on behalf of your organization. The question is no longer only how to prevent it, but how to detect and contain it in time.
In this session, our experts will walk through the full chain of exposure, detection, investigation and response using Microsoft Defender and Intune: prioritize assets by criticality, map the attack surface and blast radius, hunt across Agent 365 observability logs and apply runtime containment.
It closes the Agent 365 webinar series by connecting every session into a maturity model for the agentic enterprise.
Register now
What you’ll see in this session
EXPOSURE
Map the attack surface and blast radius of your agents, and prioritize assets by criticality and exposure to sensitive data.
DETECTION
Recognize the signs of an agent acting as an insider threat and investigate suspicious activity by hunting across unified logs.
RESPONSE
Apply runtime containment to agents and tool invocations to stop the risk before it escalates.
Your speakers


How the session will run
One hour with three live demos. Times shown in Eastern Time (ET). Open each block for details.
2:00 โ 2:05 PMWelcome and recap
A recap of the series: visibility, identity and data as the foundation for detecting risk.
2:05 โ 2:12 PMWhen the agent is the threat
A compromised or manipulated agent can act as an insider threat: misuse of tools and data leakage.
2:12 โ 2:20 PMMicrosoft Defender and Intune for agents
Where each agent runs, which MCP servers it has configured, which identities it is tied to and which cloud resources it reaches.
2:20 โ 2:30 PMDemo 1Exposure and blast radius
How to map the context of each asset and prioritize by resource criticality and exposure to sensitive data.
2:30 โ 2:40 PMDemo 2Detection and investigation
Alerts for suspicious activity and threat hunting across Agent 365 observability logs.
2:40 โ 2:50 PMDemo 3Containment and response
How to block, in real time, an agent trying to exfiltrate sensitive information and cut off its use of tools.
2:50 โ 2:57 PMQuestions and answers
Ask the speakers your questions and discuss the scenarios in your organization.
2:57 โ 3:00 PMSeries wrap-up
The key points of the series and a maturity model to move forward as an agentic enterprise.
Six sessions, one complete path
Six free online sessions to secure your identities and govern your AI agents. Register for each one separately.
Session 1 ยท Identity Protection Accelerator
Get ready for the SMS MFA retirement in Microsoft Entra
Wednesday, November 4 ยท 2:00 PM ET ยท Microsoft Teams
Session 2 ยท Beyond the Agent
How to observe, govern and protect your AI agents with Agent 365
Tuesday, November 10 ยท 2:00 PM ET ยท Microsoft Teams
Session 3 ยท Agent Visibility
Do you really know which agents exist in your organization?
Tuesday, December 1 ยท 2:00 PM ET ยท Microsoft Teams
Session 4 ยท Agent Identity
Who controls your AI agents?
Thursday, December 3 ยท 2:00 PM ET ยท Microsoft Teams
Session 5 ยท Agents & Data
What information can your agents access?
Tuesday, December 8 ยท 2:00 PM ET ยท Microsoft Teams
Session 6 ยท Protect the Agentic Enterprise
Can you detect and respond when an agent becomes a risk?
Thursday, December 10 ยท 2:00 PM ET ยท Microsoft Teams