Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Some information in this article relates to a prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
The Sessions page displays all sessions visible to you based on your access permissions. Use this page to monitor active sessions, review completed work, and start new sessions.
Access the Sessions page
To view the Sessions list:
- Sign in to the Microsoft Defender portal.
- Select Perception in the navigation pane.
- Select Sessions.
Understand session visibility
The Sessions page shows only shared sessions. Private sessions are not displayed.
Important
- To view a session, you need at least the Security Reader role. If you don't have the required role, sessions aren't visible to you.
- To start a session using a playbook, you need the Security Reader or Security Admin role for all agents involved.
Switch between list view and Kanban board view
The Sessions page supports the following viewing modes:
- List view: Displays sessions in a table with detailed columns. Use list view when you need to see comprehensive information or sort by specific fields.
- Kanban board view: Displays sessions as cards organized by status. Use Kanban board view when you want a visual overview of session states.
To toggle between views:
- Select List view or Board view at the top of the Sessions page.
Start a new session
You can start a session from multiple entry points in Project Perception. Choose the approach that best fits your current workflow:
- Start a session from the Sessions page
- Start from a specific playbook
- Start from an incident or threat intelligence article
- Start from chat
Start a session from the Sessions page
Use the New session button, available from multiple locations in Project Perception:
- Sessions page: Select Perception > Sessions > New session.
- Agent detail page: Open an agent and select New session.
- Playbooks page: Open a playbook and select New session.
After selecting New session, choose a playbook from the list, provide the required inputs, and select Start session.
Start from a specific playbook
Open the playbook you want to run and select New session. For the complete procedure, see Start a session from a playbook.
Start from an incident or threat intelligence article
If you're already viewing an incident or a threat intelligence article, you can start a session directly from that page without navigating to Project Perception first. For more information, see Run playbooks from incidents and threat intelligence.
Start from chat
Use chat to describe your task in natural language. Project Perception identifies the most appropriate playbook, pre-populates the inputs it can infer, and runs the session for you. For more information, see Interact with Project Perception using chat.
The new session appears in the Sessions list with an In progress status.
View session details from the sessions list
Select a session to open its detail page. For a detailed walkthrough of the session detail page, including the conversation panel, overview sidebar, and how to respond to agent requests, see Work with a session.
Understand session statuses
Sessions progress through the following statuses:
| Status | Description | What happens next |
|---|---|---|
| In progress | One or more agents are actively working. | The session continues until agents complete their work or request input. |
| Waiting for input | One or more agent tasks are paused and need user input to continue. | Review the agent's request and provide approval, rejection, or alternative guidance. |
| Completed | All agent tasks finished successfully or were intentionally stopped by a user. | Review the session summary and artifacts. The session is archived. |
| Failed | All agent tasks ended, but at least one did not finish successfully. | Review the session details to understand what failed and why. The session is archived. |
Sessions do not automatically restart. To investigate a similar scenario, start a new session.
Note
Session status also controls the availability of agent chat. The dedicated chat for each agent is disabled while the agent is actively running and becomes available when the agent is waiting for input or has completed its current step. For more information, see Work with a session.