Work with agents in Project Perception

Important

Some information in this article relates to a prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

The Agents page displays all agents available to your organization, grouped into Agents ready for setup and Agents in use. Use this page to set up new agents, view agent details, and manage agent settings.

Access the Agents page

To view the Agents list:

  1. Sign in to the Microsoft Defender portal.
  2. Select Perception in the navigation pane.
  3. Select Agents.

View agents ready for setup

The Ready for setup section appears at the top of the Agents page when agents need configuration. This section displays detail cards for agents that are available but not yet enabled.

Note

If you're not an administrator, the Set up button is unavailable. Contact your administrator to enable agents.

Set up an agent

For the complete setup procedure, including identity and permission configuration, see Set up an agent.

Some agents have additional configuration requirements. Review the documentation for the agent you want to set up before starting the setup wizard.

Filter and sort the agents list

Use filters and sorting to find specific agents:

  • Keyword search: Enter text in the search box to filter by agent name or description.
  • Publisher filter: Select a publisher from the dropdown to view only agents from that publisher (Microsoft, partner names, or third parties).
  • Status filter: Select a status from the dropdown to view agents by their current state (Enabled, Setup required, or Disabled).

Select column headers to sort the list by Name, Publisher, Status, or Playbooks.

Permissions

Permissions in Project Perception work at the agent level, not the playbook level.

Permission level What you can do
Security Admin Install and configure agents: set up agent identities and permissions, and remove agents. At least one user in your organization must have this role.
Security Reader Use agents: view and interact with agent sessions, start sessions, and view session details.

Tip

To delegate agent setup to others, assign the Security Admin role. Contact your Microsoft Entra administrator if you need role assignments.

Important

  • To view a session, you need at least the Security Reader role. If you don't have the required role, sessions aren't visible to you.
  • To start a session using a playbook, you need the Security Reader or Security Admin role for all agents involved.

View agent details

Select an agent name from the agents list to open its detail page. The page header shows the agent name, its status (Active or inactive), the publisher, and an Edit agent button. The page has the following tabs:

  • Overview: agent configuration and recent sessions
  • Sessions: full session history for this agent

Overview tab

The Overview tab has a left panel and a right panel.

Left panel:

Section Description
About this agent A description of what the agent does and the tasks it performs.
Playbooks Playbooks that use this agent, with agent count. Select the link icon to open a playbook's detail page.
Permissions Permissions the agent needs to access data and take actions. Select Permission details for the full reference.
Identity The Microsoft Entra agent ID the agent runs under. Select it to view.
Plugins Plugins enabled for this agent. Shows None if none are configured.
Role-based access Describes who can view and manage this agent's output.

Right panel - Recent Sessions:

Shows the most recent sessions involving this agent. Columns: Session name, Session status, Activity status, Last activity. Select View all to open the full session history.

Sessions tab

The Sessions tab shows all sessions in which this agent has participated. Each row shows the Session name, Session status, Activity status, and Last activity timestamp. Use this tab to review historical activity and find specific sessions by status or time.

Select a session name to open its detail page. For information about the page layout, agent chat, inputs, outputs, and approval requests, see Work with a session.

Administrative actions for agents

If you're an administrator you can perform additional actions on enabled agents.

Edit agent configuration

To modify an agent's settings:

  1. Go to Perception > Agents.
  2. Select the agent name to open the agent detail page.
  3. Select Edit (available only to administrators).
  4. Modify any of the following:
    • Agent identity
    • Agent role
    • User roles that can execute or steer sessions
    • User roles that can view sessions
    • Custom agent settings (if applicable)
  5. Select Save changes.

Remove an agent

To disable an agent:

  1. Go to Perception > Agents.
  2. Select the agent name to open the agent detail page.
  3. Select Remove Agent (available only to administrators).
  4. Review the warning message. Removing an agent:
    • Disables the agent immediately
    • Stops any in-progress sessions using the agent
    • Prevents the agent from being used in new sessions
    • Marks playbooks that require the agent as needing setup
  5. Select Remove to confirm.

Warning

Removing an agent stops all active sessions that include the agent. Ensure no critical sessions are running before you remove an agent.

Next steps