Body
Issue/Question
What is the USD Agentic AI SOC, what agents are in use, how do I interact with them
Environment
- M365
- Copilot Studio
- Agentic AI
- Generative AI
Cause
Common understanding of the USD Agentic AI SOC
Resolution
Overview
The University of South Dakota Security Team has designed and developed an Agentic AI Security Operations Center (Agentic AI SOC) to expand the reach and capacity of its cybersecurity team. The Agentic SOC combines:
- USD Security Team - developed agents built in Microsoft Copilot Studio and AI Foundry
- Microsoft Sentinel and the Sentinel Security Data Lake
- Microsoft XDR and Microsoft Security Copilot
- Cisco XDR and USD network-security platforms
- Red Canary Managed Detection and Response
- Security data from endpoints, identities, networks, Microsoft 365, cloud services, software vendors, vulnerabilities, and AI systems
The agents assist with security investigations, threat hunting, identity analysis, network reviews, vulnerability prioritization, software and vendor assessments, data-security incidents, compliance reporting, and recurring operational tasks.
USD’s approach is a hybrid, co-managed, and agent-augmented SOC model. The USD Security Team retains strategic control, institutional knowledge, incident leadership, and final decision-making. Red Canary provides external scale, continuous monitoring, and specialized threat expertise. AI agents automate or accelerate repeatable analysis, evidence collection, correlation, and reporting. This aligns with the hybrid SOC principle of retaining business-sensitive and strategic responsibilities internally while using service providers for scalable or highly specialized operational functions.

What Is an AI Agent?
An AI agent is a purpose-built system that can receive a goal or trigger, gather information from authorized sources, perform a defined sequence of tasks, evaluate the results, and produce findings or recommended actions.
Unlike a general chatbot, each USD security agent is assigned a specific specialty and is connected to relevant USD security information, documentation, tools, or other agents. The agents are intended to operate as digital members of the Security Operations Team rather than as independent decision-makers.
How the Agentic SOC Works
A typical Agentic SOC workflow follows this pattern:
- A security question, alert, task, scheduled process, or review is received.
- The Security Operations Orchestration Agent determines which tools and specialist agents are relevant.
- The appropriate context, evidence, documents, identities, assets, vendors, and timeframes are provided to those agents.
- Each agent performs its assigned portion of the analysis.
- Findings are correlated with evidence from Sentinel, Microsoft XDR, Cisco XDR, or other authoritative sources.
- The results are combined into a consolidated analysis, risk assessment, and recommended action plan.
- USD personnel review the results and make any consequential decisions.
Agents do not replace the responsibility of the Security Team, system owners, data stewards, IT administrators, compliance officers, or institutional leadership.
USD Security Team - Developed Security Agents
Security Operations Orchestration Agent — SOOA

The Security Operations Orchestration Agent (SOOA) functions as the coordinating lead for USD’s specialized security agents.
SOOA receives a question, incident, review, scheduled task, or operational problem and:
- Determines which agents and tools are needed
- Divides complex work into specialist assignments
- Provides each agent with the necessary context and documents
- Coordinates tasks that depend on findings from another agent
- Validates conclusions against available evidence
- Identifies conflicting or incomplete findings
- Combines the results into one consolidated response
- Identifies actions or decisions requiring human approval
SOOA is connected to the Sentinel MCP tool and the DGSA, NSA, ISA, VMA, and TPRMA.
SOOA should be viewed as the equivalent of a security AI Agent team leader. It coordinates specialists but does not replace the CISO, incident commander, or accountable system and data owners.
Identity Security Agent — ISA

The Identity Security Agent (ISA) investigates identities, accounts, authentication, and access activity.
Typical ISA functions include:
- Investigating compromised or suspicious accounts
- Reviewing Entra ID Protection risk
- Identifying anomalous sign-ins and impossible travel
- Evaluating MFA and authentication activity
- Reviewing token, application, and privileged-access concerns
- Determining whether activity is expected for a user or role
- Providing identity context to broader investigations
- Recommending account containment and remediation
ISA may be consulted by SOOA, NSA, DGSA, or other agents when an investigation involves a USD identity.
Sentinel Security Data Lake Agent — SSDLA

The Sentinel Security Data Lake Agent (SSDLA) provides natural-language investigation and analysis across security information maintained in the Sentinel environment.
Typical SSDLA functions include:
- Searching security data using natural-language questions
- Generating or assisting with KQL queries
- Reviewing historical security activity
- Correlating events across data sources
- Developing timelines and summaries
- Supporting threat hunting
- Enriching suspicious domains, IP addresses, URLs, and files with threat intelligence
- Preparing technical or executive investigation reports
Microsoft Security Copilot can use Sentinel data to summarize incidents and generate hunting queries, including natural-language-to-KQL capabilities where supported.
Data Governance and Security Agent — DGSA

The Data Governance and Security Agent (DGSA) provides institutional data-governance, data-security, privacy, and compliance expertise.
Typical DGSA functions include:
- Determining data classification and sensitivity
- Identifying data owners, stewards, and custodians
- Applying USD and SDBOR data-governance requirements
- Reviewing Defender XDR and Microsoft Purview data-security incidents
- Evaluating oversharing, inappropriate access, retention, and exfiltration concerns
- Determining whether FERPA, HIPAA, GLBA, PCI DSS, or privacy requirements apply
- Identifying institutional stakeholders who should participate in a response
- Providing data and compliance context to software reviews and incidents
DGSA helps answer not only what happened, but also what data was involved, who is responsible for it, and what obligations apply.
Third-Party Risk Management Agent — TPRMA

The Third-Party Risk Management Agent (TPRMA) supports software security reviews and the continuing monitoring of USD technology vendors.
Typical TPRMA functions include:
- Reviewing software and SaaS providers
- Assessing HECVAT documentation
- Reviewing SOC 2 Type 2 reports and vendor questionnaires
- Evaluating subprocessors and parent companies
- Monitoring vendor breaches and security incidents
- Identifying ownership, financial, legal, or operational changes
- Evaluating supply-chain risk
- Identifying products that store or interact with sensitive USD data
- Producing recurring third-party risk reports
- Escalating material vendor posture changes
TPRMA is intended to automate much of the routine research associated with software security reviews while escalating material findings to the Security Team.
Vulnerability Management Agent — VMA

The Vulnerability Management Agent (VMA) correlates and prioritizes vulnerabilities using technical findings and USD-specific risk context.
VMA may use information from:
- Microsoft Defender Vulnerability Management
- Internal Nessus scans
- CISA external scans
- Cisco Vulnerability Management and Kenna
- The National Vulnerability Database
- CISA’s Known Exploited Vulnerabilities Catalog
- EPSS exploitation probability
- Public exploit evidence
- Asset exposure and business importance
- Sensitive-data and compliance scope
VMA helps distinguish high-count vulnerability findings from the vulnerabilities that present the greatest practical risk to USD. It produces remediation priorities, trends, overdue-finding reports, and evidence for risk and exception decisions.
Network Security Agent — NSA

Within the Agentic SOC, NSA means Network Security Agent, not the federal National Security Agency.
The NSA provides expertise related to:
- Cisco Firepower and firewall policy
- Cisco routing and switching
- VPN and secure remote access
- Segmentation and security zones
- Network architecture
- Network traffic and log analysis
- Firewall-rule and network-risk reviews
- Network indicators of compromise
- Vulnerability impact on network devices
- Network containment recommendations
- Compliance and architecture validation
NSA is grounded in USD’s multi-site network environment, institutional standards, documented architecture, known risks, and approved exceptions. This reduces the likelihood that previously documented conditions will repeatedly be reported as new findings.
Red Canary AI Agents

Red Canary is USD’s Managed Detection and Response provider. Red Canary provides continuous external monitoring, investigation, threat hunting, escalation, and response recommendations.
Red Canary states that its AI agents perform specialized, narrowly scoped security tasks and operate alongside human security experts. Red Canary MDR customers have these agents working on their behalf, and customers can review agent activity and provide feedback.
The agents visible in or supporting USD’s Red Canary service may include the following.
Investigation and Triage
| Agent or function |
Purpose |
| Alert Summary Agent |
Produces structured summaries and recommendations for security alerts. |
| Cloud Security Investigation Agent — AWS GuardDuty |
Investigates and triages AWS GuardDuty alerts. |
| Endpoint Investigation Agent — Microsoft Defender for Endpoint |
Investigates endpoint alerts and associated activity. |
| Investigation Agent — Red Canary EDR |
Investigates endpoint activity observed through Red Canary detection capabilities. |
| SIEM Investigation Agent — Microsoft Sentinel |
Investigates and triages Sentinel alerts and incidents. |
| Identity Investigation Agent — Cisco Duo |
Investigates Duo Trust Monitor and identity-related alerts. |
| Identity Investigation Agent — Microsoft Entra Identity Protection |
Investigates risky users and Entra identity alerts. |
| Identity Investigation Agent — Red Canary Identity Engine |
Investigates identity events detected by Red Canary. |
| Identity Investigation Agent — User Baselining and Analysis |
Compares current identity behavior with historical login patterns. |
| Email Analyzer Agent |
Reviews email content, metadata, links, and attachments. |
| Phishing Triage Agent |
Assesses whether a reported email is likely malicious. |
Red Canary’s public descriptions also identify specialized alert-enrichment, authentication-research, reputation-analysis, device-compliance, user-activity, and user-baseline functions that contribute to investigations.
Analysis and Detection Tuning
| Agent or function |
Purpose |
| Customization Review Agent |
Reviews proposed alert-tuning or customization instructions. |
| Event Hide Comment Agent |
Explains why an event was hidden or considered nonmalicious. |
| Threat Review Agent |
Reviews threat evidence and institutional context. |
| Threat Escalation Potential Agent |
Assesses how urgently a potential threat should be escalated. |
| Threat Recommendations Agent |
Produces prioritized recommended actions. |
| Agentic Tuning |
Uses organizational preferences and context to recommend whether alerts should be suppressed. |
Threat Documentation and Response
Red Canary uses several specialized agents to create or improve threat documentation. These may appear as separate entries in a Red Canary timeline or threat record:
- Threat Annotation Description Agent
- Threat Annotation Summary Agent
- Threat Annotation Timeline Activity Agent
- Threat Annotation Timeline Indicator Agent
- Threat Annotation Hunting Agent
- Threat Annotation Hardening Agent
- Threat Annotation Response Remediation Agent
- Threat Response Recommendation Agent
- Threat Resource Recommendations Agent
- Threat Report Agent
Collectively, these agents help summarize events, explain indicators, develop timelines, recommend threat hunts, identify hardening opportunities, and prepare containment, eradication, and remediation guidance.
Red Canary states that customer data used by its agents remains within Red Canary-controlled infrastructure and is not made available to other customers or used to train external AI models.
Agent names and functions may change as Red Canary updates its service.
Microsoft-Provided AI Agents

Microsoft Security Copilot provides assistive and agentic security capabilities across Microsoft Defender, Sentinel, Entra, Intune, and Purview. Microsoft agents can run manually, on schedules, or in response to supported events. Administrators configure the agent identity, permissions, triggers, plugins, and available actions.
The following sections describe Microsoft-provided agents that may be relevant to USD. Listing an agent does not mean that it is currently enabled at USD. Some agents remain in preview, require specific licenses or permissions, or may change before general availability.
Microsoft Defender and Sentinel Agents
Microsoft currently documents these agents within the Defender security-operations ecosystem:
- Security Alert Triage Agent: Classifies supported alerts, identifies likely attacks or false positives, and provides a natural-language rationale. It expands upon the earlier Phishing Triage Agent and supports additional workloads in preview.
- Threat Intelligence Briefing Agent: Produces recurring or on-demand threat-intelligence briefings using Microsoft threat intelligence and available organizational exposure information.
- Threat Hunting Agent: Supports complete threat-hunting sessions using natural language, including KQL generation, result interpretation, and identification of relevant findings.
- Security Analyst Agent: Performs custom or predefined analysis across Defender XDR, Sentinel Log Analytics, or the Sentinel Data Lake and can assist with anomaly detection, clustering, risk scoring, and forecasting.
- Dynamic Threat Detection Agent: Continuously correlates events, alerts, anomalies, and threat intelligence to identify potential detection gaps or previously unidentified activity.
- Data Security Triage Agent: Triages supported DLP alerts and produces classifications and natural-language explanations.
Security Copilot also provides incident summarization, guided response, report generation, script analysis, and natural-language KQL assistance across Defender and Sentinel.
Microsoft Entra Agents
Microsoft currently documents:
- Conditional Access Optimization Agent: Reviews Conditional Access policies for gaps, overlap, and misconfigurations and recommends improvements based on Microsoft and Zero Trust guidance.
- Identity Risk Management Agent: Investigates identity risk and helps administrators understand potential impacts and recommended protective actions. This capability is documented as preview.
These Microsoft agents may complement USD’s ISA. Microsoft agents provide native product analysis and automation, while ISA adds broader USD context and can correlate identity information with Sentinel, network, vulnerability, and governance findings.
Microsoft Intune Agents
Microsoft currently documents:
- Change Review Agent: Evaluates the potential effect of proposed Intune changes and provides recommendations.
- Device Offboarding Agent: Identifies stale or misaligned devices and presents recommendations before administrative offboarding.
- Policy Configuration Agent: Converts plain-language requirements or imported documents into recommended Intune settings and policy configurations.
- Vulnerability Remediation Agent: Uses Defender information to prioritize endpoint vulnerability remediation.
These agents complement USD’s VMA and endpoint-management processes but do not replace administrative testing, change control, or approval.
Microsoft Purview Agents
Microsoft currently documents these preview agents:
- Triage Agent in Insider Risk Management: Evaluates alerts using user, file, and activity risk.
- Alert Triage Agent in Data Loss Prevention: Evaluates alerts using data sensitivity, potential exfiltration, and policy risk.
These agents complement DGSA by providing native Purview alert triage. DGSA adds USD data classifications, governance roles, institutional policy, compliance context, and escalation requirements.
How the Agent Layers Work Together
The three agent layers serve different purposes:
| Layer |
Primary value |
| USD Security Team - developed agents |
Apply USD-specific architecture, data, governance, standards, risk context, software inventory, and operational knowledge. |
| Microsoft agents |
Provide native analysis and automation within Microsoft Defender, Sentinel, Entra, Intune, and Purview. |
| Red Canary agents and analysts |
Provide continuous MDR monitoring, external threat expertise, investigation at scale, escalation, and response recommendations. |
SOOA coordinates the USD-developed layer and may incorporate evidence or findings produced by Microsoft and Red Canary capabilities.
What IT Staff May See
As the Agentic SOC becomes part of routine security operations, IT staff may see agent-generated material in:
- TeamDynamix tickets
- Security incident records
- Incident timelines
- Endpoint or identity investigations
- Vulnerability reports
- Firewall and network reviews
- Software and SaaS security reviews
- HECVAT and vendor assessments
- Data-security and compliance reviews
- Third-party risk reports
- Executive or audit reports
- Remediation plans and assigned tasks
Agent-generated content may include:
- Investigation summaries
- Log extracts or event timelines
- User, device, application, or vendor context
- Indicators of compromise
- Vulnerability and exploit information
- Risk ratings
- Compliance considerations
- Recommended containment or remediation
- Questions requiring system-owner input
- Supporting evidence and identified limitations
Agent-generated findings should be treated as Security Team work product when included in an official ticket, incident, review, or report. They are still subject to validation and human review.
IT staff should notify Information Security when an agent response appears inaccurate, lacks context, conflicts with known system behavior, or recommends an action that could create operational impact.
Human Oversight and Authority
Agents may analyze information and recommend actions, but they do not independently:
- Accept institutional risk
- Approve or reject software
- Authorize a compliance exception
- Determine legal notification obligations
- Make public statements
- Disable critical accounts without authorization
- Make significant network or firewall changes
- Take disruptive containment actions unless specifically preauthorized
- Replace system-owner, data-steward, compliance, legal, or executive authority
Microsoft’s agent model similarly relies on configured identities, permissions, triggers, and action rights, allowing administrators to determine what an agent can access and what actions it may perform.
Responsible Use and Safeguards
USD’s Agentic SOC follows these operating principles:
- Use the minimum necessary sensitive information.
- Grant agents only the permissions required for their assigned purpose.
- Prefer direct security evidence over unsupported conclusions.
- Clearly distinguish confirmed facts, probable findings, assumptions, and missing evidence.
- Preserve forensic evidence during incident response.
- Keep consequential actions under human oversight.
- Document which agents, tools, and evidence contributed to material findings.
- Retain agent output within approved USD systems.
- Review agent permissions, instructions, integrations, and performance regularly.
- Do not place passwords, private keys, authentication tokens, or other secrets into agent prompts.
Frequently Asked Questions
Are the agents replacing USD IT or Security personnel?
No. They reduce repetitive work, expand investigative capacity, and provide specialist analysis. USD personnel remain accountable for decisions and actions.
Why does USD use several agents instead of one general security agent?
Each agent has a defined specialty, data scope, and purpose. Specialized agents generally produce more reliable results and reduce unnecessary access to systems or information.
Are agent findings always correct?
No. Agent outputs are decision-support material. Material conclusions should be supported by logs, configurations, scan data, authoritative documentation, or human validation.
Can an agent make changes to a USD system?
Only when the connected tool, permissions, and approved process permit it. Significant changes and disruptive actions remain subject to human approval.
Why might multiple agents contribute to one ticket?
A single event may involve several domains. For example, a compromised account could require ISA identity analysis, NSA network review, VMA vulnerability context, DGSA data-impact analysis, SMCP log evidence, and TPRMA vendor review.
How should staff request assistance from the Agentic SOC?
Use established USD Information Security and TeamDynamix processes. Provide relevant systems, users, dates, error messages, logs, screenshots, and other context so the Security Team and agents can perform an effective review.
