Microsoft, Cybersecurity

Microsoft Project Perception, Explained: Why Multi-Model Security Changes Everything

Table of Contents

Why Multi-Model Security Changes Everything 

Six years building an agentic SOC analyst (ANSEL) teaches you something quickly: more data is critical but not the answer. Better understanding through context of what it means is.  

Microsoft Project Perception is built on exactly that insight. It’s not another security product. It’s a different way of thinking about how AI should reason, with context, consequence, and the kind of connected intelligence that a single model, processing one event at a time, simply cannot produce. 

Why Single-Model Security Is Already Failing 

The problem has always been context. In order to achieve better reasoning.  

A single AI model sees what it sees, one event, one signal, one moment. It misses how events connect, what the consequences of a decision are downstream, and whether what it’s seeing now is consistent with what happened last week. That gap is where threats now hide. 

The tasks that matter most, patching vulnerabilities before they’re exploited, spotting lateral movement earlier, keeping data from walking out of AI workflows and guardrails, need speed and precision a single model can’t deliver at scale.  

Rogue agents are now adding a new dimension to that problem. Multiple AI models, each playing to its strengths, working together: that’s what closes the gap. 

The diagram below shows how Project Perception maps security data to the right agents. 

Figure 1 – Microsoft Project Perception Agent alignment to context 

What Project Perception Actually Is 

Three things worth saying upfront. No single AI model is ever the right tool for every security situation. Models change constantly and need continuous validation.  

And Project Perception is not a Microsoft product in the traditional sense, it’s a new architectural approach to security delivery. 

In practice, it’s an AI-powered cyber security platform that: 

  • Runs across a structured six-layer security architecture 
  • Connects natively with Microsoft Defender, Entra ID, Azure, and Sentinel, catching vulnerabilities before they’re widely exploited 
  • Uses three types of AI agent: Red, Blue, and Green, each continuously learning, each with a distinct role 

Here’s the full Microsoft Project Perception six-layer model. 

Figure 2 – Microsoft’s new Cyber Stack 

Six Layers. Here’s What Each One Does. 

  1. Signals: Visibility across your entire digital environment: devices, apps, identities, cloud services, AI systems. Everything generates a signal. The question is whether you’re capturing it.
  2. Context: Raw data enriched with threat intelligence and historical behaviour. The system doesn’t just see what’s happening, it understands what it means. That distinction is everything.
  3. Models: The right model for the right situation. Microsoft’s own MAI-Cyber-1-Flash outperforms rival frontier models on cyber benchmarks. Critically, Project Perception isn’t locked to one provider — it runs across Microsoft, OpenAI, and Anthropic models. No single point of failure. No single point of learning.
  4. Harness: The orchestration layer. It decides which agents act, when, and how, balancing autonomous response with human oversight. This is where the biggest security gains are made or lost. More telemetry doesn’t win games. Better orchestration does.
  5. Agents: Three specialist teams, continuously working. Red Agents find weaknesses and map attack paths. Blue Agents investigate threats and decide what to prioritise. Green Agents apply the fixes and tighten the controls. Each knows its job.
  6. Actuators: Decisions turned into actions. An alert is not a defence. What you do with it is. Most organisations have a significant gap here, and it’s the one that costs the most when things go wrong. 

A Vulnerability That Proves the Point 

Earlier this year, OpenAI’s AI system found CVE-2026-33824, a critical Windows IKEEXT service vulnerability that every traditional security tool had missed.  

The weakness was spread across six separate files. No single scanner, looking at one file at a time, could see it. Only a multi-model, multi-agent system running continuously across the entire codebase could piece it together. 

That’s the capability. But it comes with a real cost. Hundreds of AI agents scanning your entire attack surface, continuously, is expensive. Microsoft’s pricing will be consumption-based, Security Compute Units (SCUs), meaning costs vary depending on how hard the agents are working. 

Across six layers and multiple models, managing that spend carefully isn’t optional. It’s a core operational responsibility. 

Why Perception Is the Control That Matters Most 

A rogue OpenAI agent recently found exposed credentials on public services and quietly went to work. It executed over 17,600 attacker actions, slow, deliberate, low-noise, before anyone noticed.  

It even got past OpenAI’s own sandbox guardrails. 

That’s the defining problem with agentic security. Rogue AI doesn’t announce itself. It looks normal. It mimics legitimate behaviour. And in a world where agents talk to agents, one compromised system corrupts every decision downstream. 

You can only respond to what you can see.  

Perception, accurately seeing, verifying, and understanding what every agent is doing and why, is the most important control in modern security operations.  

Human oversight still matters. But it only works when AI behaviour is visible, explainable, and consistently checked. Project Perception is built on that principle. It’s also why we built Ansel the same way. 

If you would like to understand more about Microsoft’s Project Perception or agentic agent governance monitoring, feel free to reach out to CloudGuard as ever [email protected]  

Author: Matt Lovell
Share:
Author: Matt Lovell
Share:

Related Resources

A glowing vendor evaluation checklist on a dark purple background
Why Your Vendor Evaluation Process Is Failing You (do this BEFORE YOU SIGN)
Most vendor evaluation processes are built to survive procurement, not to protect you eighteen months after go-live. Here’s the gap almost nobody catches before signing. Outlining The Problem The majority of security technologies need 90 days just to establish an accurate behavioural baseline and fair comparison. Please remember your existing...
Understanding Microsoft Purview licensing: The breakdown SMBs actually NEED
Room filled with people at conference and two people presenting on a screen
CloudGuard Sponsors Inaugural Microsoft Executive Partner Connect for SMB Security
What a couple of days in Cascais! Last week, Microsoft hosted its first-ever EMEA Executive Partner Connect dedicated entirely to security for SMBs, and CloudGuard was proud to be one of just three sponsors who helped bring it to life. Being selected as a sponsor for an event of this...
two men talking on a podcast posted on linkedin with a red arrow pointing towards a deepfake
Why Social Engineering Always Works: How Hackers Use Phishing & Deepfakes
We’ve all done the training, so why are attackers still getting through? Attackers no longer rely on bad spelling or suspicious links, they use AI-generated deepfakes and psychological profiling to manipulate people with astonishing precision. By exploiting the brain’s emergency response system, they trigger fear, urgency, or authority to override...
Dark purple background with claude logo and words pro, team and enterprise.
Claude Business Security: Choosing the Right Account for SMBs
When I shared my last article, a few people got in touch asking for a more practical follow-up, specifically around how small teams can use Claude Pro without putting business data at risk. This piece goes step by step through exactly that. Understand what you’re actually adopting Claude Pro is...
Two analysts looking surprised. Purple cyber background with phishing hook.
What Happens After a Phishing Attack? A Real Microsoft 365 Incident Walkthrough
If your organisation thinks a password reset or MFA alone are enough, think again. In this phishing attack breakdown by CloudGuard’s SOC team, Conor and Jon reveal the reality behind an actual breach involving a UK law firm, exposing how hackers use four methods to regain access long after initial...
purple background with computer that says threat from the field in cartoon like design
Cyber Threat Trends Q1 2026: Data Theft, AI Attacks and Emerging Risks
Executive Summary Every 90 days, we review the latest cyber threat trends to identify what IT leaders should learn, where resilience gaps are widening, and what practical actions organisations should take next.  The first quarter of 2026 has been intense. The UK threat picture is not defined by one single...
Microsoft Defender for Cloud
Microsoft Defender for Cloud Cloud environments change fast. New workloads, new services and new risks appear daily, often without full visibility or clear ownership. Microsoft Defender for Cloud provides continuous assessment across Azure, hybrid and multi-cloud environments to help organisations understand and reduce cloud security risk. CloudGuard ensures your cloud...
Woman looking at tablet with cyber imagery across the top.
The Limitations of External Penetration Testing (And What to Do About Them)
Core argument  Traditional internal penetration tests gives executives false confidence because it’s typically scope-limited, scheduled, doesn’t reflect real attacker behaviour and ignores the AI threats with user access. Would you feel comfortable boarding a plane if the pilot had practised emergency landings but had never actually simulated an engine failure?  So, why do businesses specifically exclude their...
Get In Touch

Our Cybersecurity Services Can Instantly Improve Your Business’ Security Posture

Complete the form to find out more about any of our one-off or managed cybersecurity services. Not seeing what you’re looking for? Our cybersecurity consultants and MXDR experts are always on-hand to provide the guidance and support you need.