Securing AI Agents with Runtime Protection using Microsoft Defender and Intune

Key Takeaways

  • Securing AI Agents with Runtime Protection using Microsoft Defender and Intune
  • AI Agent Runtime Protection is disabled by default in Defender for Endpoint.
  • Use an Intune Endpoint Security Antivirus policy to deploy AI agent event inspection to enrolled Windows devices.
  • No runtime inspection or blocking of agent actions.
  • Detects and reports prompt injection but allows the agent action to continue.
  • Detects prompt injection and blocks supported agent actions before execution.
  • Devices must be onboarded to Microsoft Defender for Endpoint.

To use AI Agent Runtime Protection, onboard devices to Microsoft Defender for Endpoint, with Microsoft Defender Antivirus running in active mode and real-time protection enabled. During the public preview, test devices should also receive Microsoft Defender platform and engine updates through the Beta Channel.

Table of Content

Securing AI Agents with Runtime Protection using Microsoft Defender and Intune

Microsoft recommends starting with Audit mode and assigning the policy to a small group of test devices. Monitor the detections and review how the policy behaves. Once you are comfortable with the results, switch to Block mode to enforce protection. Finally, complete the policy configuration, assign it to the required device groups, and create the policy.

  • Open Microsoft Intune Admin Center and go to Endpoint security.
  • Select Antivirus under Manage.
  • Click Create Policy.
  • Select:
    • Platform: Windows
    • Profile: Microsoft Defender AI agent runtime protection
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.1
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.1

Basic Details of the AI Agents with Runtime Protection

In the Basics tab, you provide details such as the name of the policy as AI Agent Runtime Protection and the description of the policy stating that AI agent runtime protection in Defender for Endpoint is disabled by default.

Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.2
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.2

Configure AI Agent Protection Settings

Click Create and proceed to the Configuration settings page. Locate AI Agent Protection and select the appropriate protection level based on your organization’s requirements.

Patch My PC
  • Default: Protection is disabled.
  • Audit: Detects and reports prompt injection but does not block the agent.
  • Block: Detects prompt injection and blocks supported agent actions.
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.3
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.3

Microsoft recommends starting with Audit mode on a limited group of test devices. This allows administrators to monitor detections and understand the policy’s impact without blocking agent actions. After reviewing the results and confirming that the configuration works as expected, switch to Block mode to enforce AI agent runtime protection.

Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.4
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.4

Scope Tags Configuration

In the Scope tags tab, you can manage and assign tags to control access to the profile. By default, the Default scope tag is applied, and you can select additional tags (such as London) from the side panel to include them in the selected scope tags list.

Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.5
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.5

Assignments Configuration

In the Assignments tab, you configure which user or device groups are included or excluded under the policy settings. You can add groups like HTMD – Test Policy, view their status, member counts, filter options, and manage any group-specific exclusions as needed.

Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.6
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.6

inspect a complete summary of all your configured settings

In the Review + create tab, you can inspect a complete summary of all your configured settings before finalizing the profile. This includes verifying the name (AI Agent Runtime Protection), description (AI agent runtime protection in Defender for Endpoint is disabled by default), platform, and other configured parameters.

Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.7
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.7

Policy Creation Confirmation

Once the configuration is reviewed and finalized, a notification confirms that the policy “AI Agent Runtime Protection” has been created successfully. You are then redirected back to the Endpoint security | Antivirus dashboard where the new policy takes effect.

Securing AI Agents with Runtime Protection using Microsoft Defender and Intune - Fig.8
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Fig.8

Verify AI Agent Runtime Protection on the Enrolled Device

After the policy is deployed, verify that the setting has been successfully applied to the enrolled Windows device. Open the device in the Microsoft Defender portal, go to Configuration management > Effective settings, and check AI Agent Protection.

Steps
Open the Microsoft Defender portal and select the enrolled device
Go to Configuration management > Effective settings
Find AI Agent Protection
Check the Configuration source
Close existing agent/terminal windows
Open a new terminal window
Run the AI Agent Runtime Protection demonstration
Review the result
Securing AI Agents with Runtime Protection using Microsoft Defender and Intune – Table 1

Resources

Set up AI agent runtime protection with Microsoft Defender for Endpoint (Preview) – Microsoft Defender for Endpoint | Microsoft Learn

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair  is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. He is Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11 years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His focus is on Device Management technologies such as Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Leave a Comment