Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Some information in this article relates to a prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here. Project Perception is currently in Limited Public Preview. Limited Public Preview Program means Perception is available to a small, invitation-only set of customers for a defined preview window before broader public availability.
The Sessions page displays all sessions visible to you based on your access permissions. Use this page to monitor active sessions, review completed work, and start new sessions.
Access the Sessions page
To view the Sessions list:
- Sign in to the Microsoft Defender portal.
- Select Perception in the navigation pane.
- Select Sessions.
Understand session visibility
The Sessions page shows only shared sessions. Private sessions are not displayed.
Important
- To view a session, you need at least the Security Reader role. If you don't have the required role, sessions aren't visible to you.
- To start a session using a playbook, you need the Security Reader or Security Admin role.
Switch between list view and Kanban board view
The Sessions page supports the following viewing modes:
- List view: Displays sessions in a table with detailed columns. Use list view when you need to see comprehensive information or sort by specific fields.
- Kanban board view: Displays sessions as cards organized by status. Use Kanban board view when you want a visual overview of session states.
To toggle between views:
- Select List view or Board view at the top of the Sessions page.
Start a new session
You can start a session from multiple entry points in Project Perception. Choose the approach that best fits your current workflow:
- Start a session using the New session button
- Start from a specific playbook
- Start from an incident or threat intelligence article
- Start from chat
Start a session using the New session button
The New session button is available from the Sessions list and other locations in Project Perception.
- Select New session.
- Choose a playbook from the list.
- Provide the required inputs.
- Select Start session.
Start from a specific playbook
Open the playbook details by using one of the following paths:
- Go to Perception > Playbooks, and then select a playbook and run it.
- Go to Perception > Agents, open an agent, and then select one of its playbooks.
From the playbook details, select New session, provide the required inputs, and select Start session. For the complete procedure, see Start a session from a playbook.
Start from an incident or threat intelligence article
If you're already viewing an incident or a threat intelligence article, you can start a session directly from that page without navigating to Project Perception first. For more information, see Run playbooks from incidents and threat intelligence.
Start from chat
Use chat to describe your task in natural language. Project Perception identifies the most appropriate playbook, pre-populates the inputs it can infer, and runs the session for you. For more information, see Interact with Project Perception using chat.
The new session appears in the Sessions list with an In progress status.
View session details from the sessions list
Select a session to open its detail page. For a detailed walkthrough of the session detail page, including the conversation panel, overview sidebar, and how to respond to agent requests, see Work with a session.
Understand session statuses
Sessions progress through the following statuses:
| Status | Description | What happens next |
|---|---|---|
| In progress | One or more agents are actively working. | The session continues until agents complete their work or request input. |
| Waiting for input | One or more agent tasks are paused and need user input to continue. | Review the agent's request and provide approval, rejection, or alternative guidance. |
| Completed | All agent tasks finished successfully. | Review the session summary and artifacts. The session is archived. |
| Stopped | A user manually forced the session to terminate by selecting Stop. | Any unfinished agent activities are also marked Stopped. The session can't be resumed and is archived. |
Sessions do not automatically restart. To investigate a similar scenario, start a new session.
Note
Session status also controls the availability of agent chat. The dedicated chat for each agent is disabled while the agent is actively running and becomes available when the agent is waiting for input or has completed its current step. For more information, see Work with a session.