View and manage sessions in Project Perception

Important

Some information in this article relates to a prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

The Sessions page displays all sessions visible to you based on your access permissions. Use this page to monitor active sessions, review completed work, and start new sessions.

Access the Sessions page

To view the Sessions list:

  1. Sign in to the Microsoft Defender portal.
  2. Select Perception in the navigation pane.
  3. Select Sessions.

Understand session visibility

The Sessions page shows only shared sessions. Private sessions are not displayed.

Important

  • To view a session, you need at least the Security Reader role. If you don't have the required role, sessions aren't visible to you.
  • To start a session using a playbook, you need the Security Reader or Security Admin role for all agents involved.

Switch between list view and Kanban board view

The Sessions page supports the following viewing modes:

  • List view: Displays sessions in a table with detailed columns. Use list view when you need to see comprehensive information or sort by specific fields.
  • Kanban board view: Displays sessions as cards organized by status. Use Kanban board view when you want a visual overview of session states.

To toggle between views:

  1. Select List view or Board view at the top of the Sessions page.

Start a new session

You can start a session from multiple entry points in Project Perception. Choose the approach that best fits your current workflow:

Start a session from the Sessions page

Use the New session button, available from multiple locations in Project Perception:

  • Sessions page: Select Perception > Sessions > New session.
  • Agent detail page: Open an agent and select New session.
  • Playbooks page: Open a playbook and select New session.

After selecting New session, choose a playbook from the list, provide the required inputs, and select Start session.

Start from a specific playbook

Open the playbook you want to run and select New session. For the complete procedure, see Start a session from a playbook.

Start from an incident or threat intelligence article

If you're already viewing an incident or a threat intelligence article, you can start a session directly from that page without navigating to Project Perception first. For more information, see Run playbooks from incidents and threat intelligence.

Start from chat

Use chat to describe your task in natural language. Project Perception identifies the most appropriate playbook, pre-populates the inputs it can infer, and runs the session for you. For more information, see Interact with Project Perception using chat.

The new session appears in the Sessions list with an In progress status.

View session details from the sessions list

Select a session to open its detail page. For a detailed walkthrough of the session detail page, including the conversation panel, overview sidebar, and how to respond to agent requests, see Work with a session.

Understand session statuses

Sessions progress through the following statuses:

Status Description What happens next
In progress One or more agents are actively working. The session continues until agents complete their work or request input.
Waiting for input One or more agent tasks are paused and need user input to continue. Review the agent's request and provide approval, rejection, or alternative guidance.
Completed All agent tasks finished successfully or were intentionally stopped by a user. Review the session summary and artifacts. The session is archived.
Failed All agent tasks ended, but at least one did not finish successfully. Review the session details to understand what failed and why. The session is archived.

Sessions do not automatically restart. To investigate a similar scenario, start a new session.

Note

Session status also controls the availability of agent chat. The dedicated chat for each agent is disabled while the agent is actively running and becomes available when the agent is waiting for input or has completed its current step. For more information, see Work with a session.

Next steps