AI Agent - Aug 2, 2026

Microsoft Project Perception Public Preview: Access and Evaluation Guide

Quick Answer

Microsoft announced that Project Perception would enter public preview on August 3, 2026. The current product page says the initial access surface is Microsoft Defender and describes consumption-based, pay-as-you-go pricing measured in Security Compute Units (SCUs).

Treat August 3 as an announced preview date, not proof that every tenant, region, agent, or scenario will be enabled at the same moment. Verify the live Defender portal, preview terms, supported scenarios, roles, data boundary, and SCU rate before enabling it.

What Is Project Perception?

Project Perception is Microsoft’s agentic security system. It coordinates red, blue, and green agents over shared security context, purpose-built and frontier models, an orchestration harness, and actuators that can turn decisions into defensive actions.

Microsoft distinguishes it from Security Copilot this way: Project Perception is the system containing security agents that act, while Security Copilot is the generative AI-assisted chat interface. They are designed to work together, but access to one should not be treated as proof of every capability in the other.

Preview Facts to Verify

QuestionCurrent Microsoft statementTenant check
When?Public preview announced for August 3, 2026Confirm the portal and documentation show the preview live
Where?Initial coordinated defense in Microsoft DefenderRecord exact product, region, and portal entry point
What agents?Red, blue, and green rolesConfirm which scenarios are actually enabled
Who approves?High-impact actions remain under human signoffTest the exact approval and rollback path
How billed?Pay as you go in SCUs; intensive tasks consume moreCapture current rate, budget, caps, and usage reporting

The product page’s “now in preview” copy may be updated ahead of or during rollout. Use the signed-in product and dated documentation for the operational decision.

A Safe Evaluation Plan

  1. Choose one non-production security scenario with known evidence and an established manual workflow.
  2. Document the Defender tenant, region, licenses, roles, connectors, and data sources in scope.
  3. Start in observe or recommend mode where available; do not begin with autonomous remediation.
  4. Compare the agent’s finding with analyst-reviewed ground truth.
  5. Inspect evidence, handoffs, approvals, actuator actions, logs, and rollback behavior.
  6. Record SCUs consumed per accepted investigation or fix, not only per run.
  7. Expand only after false positives, missed issues, permission failures, and recovery paths are understood.

Preview status does not establish production readiness, regulatory suitability, or a measured security improvement in a particular environment.

What to Measure

Use outcome and guardrail metrics together:

  • validated exposures or threats found;
  • false-positive and missed-case rate;
  • time from finding to reviewed decision;
  • correct red-to-blue-to-green handoffs;
  • human overrides and rejected actions;
  • unauthorized or out-of-scope attempts;
  • rollback success;
  • SCUs and analyst time per accepted outcome.

The red, blue, and green agents guide explains the handoff contract. The architecture guide covers context, models, harness, and actuators.

Official Sources

Source check: August 2, 2026. Verify the live preview, tenant eligibility, SCU pricing, data controls, and terms before use.