Last week, I was invited to attend Microsoft’s latest security launch, and it reinforced a central tension in enterprise cybersecurity: Agentic AI systems become more effective when they have deep access to telemetry, context, and enforcement controls. Yet the same integration that improves their effectiveness can also pull customers more tightly into one vendor’s platform.
Microsoft showcased four technologies at the launch event. Microsoft Perception is designed to coordinate security context, models, specialized agents, and enforcement mechanisms across Microsoft’s security estate. Red agents test environments, blue agents investigate threats, and green agents recommend or execute remediation. MDASH extends the architecture into source-code vulnerability discovery and developer workflows. MAI-Cyber-1-Flash provides a specialized model for part of that work, while Microsoft Security FORGE Labs will pursue more autonomous vulnerability discovery and remediation.
Microsoft’s potential advantage is the number of enterprise control planes it can connect. Defender supplies endpoint and security-operations context. Entra provides identity information. Azure contributes cloud context and enforcement. GitHub and Azure DevOps connect the system to source code and development workflows. A deeply integrated environment could allow an agent to move from a threat-intelligence question to an investigation, determine which identities and assets are exposed, apply a temporary control, and propose a permanent code fix. Context can be assembled before a model begins reasoning, potentially reducing ambiguity, latency, and processing costs. Native permissions and APIs may also make actions more reliable than loosely connected third-party integrations.
The role of temporary controls connects this development directly to Dell’Oro Group’s Network Security research. Firewalls, web application firewalls, workload controls, and other enforcement points could increasingly provide machine-generated shielding while application teams develop and validate permanent fixes. Microsoft demonstrated this type of workflow through custom detections, posture changes, application protections, and proposed code remediation.
Microsoft is not alone in pursuing this strategy. Palo Alto Networks is connecting security operations, cloud security, application security, agent orchestration, and network enforcement. CrowdStrike is building agentic workflows around its security operations platform and third-party ecosystem. Google can combine security operations, threat intelligence, cloud security, vulnerability research, and developer tools. Each vendor wants its platform to become the place where agents obtain context, make decisions, and coordinate action.
Agentic security could therefore accelerate security platform consolidation. Customers may prefer agents that arrive with preassembled context, tested tools, and established permission models rather than having to build cross-vendor workflows themselves. Vendors with broad telemetry and enforcement portfolios may also be able to improve their agents through operational feedback across more customers and use cases.
However, most large enterprises will remain multivendor. They may use Microsoft identity and productivity tools, Palo Alto firewalls, CrowdStrike’s endpoint platform, Google Wiz for cloud, and specialized products for application or data security. An agent that reasons accurately only inside its own vendor’s environment will provide an incomplete view of risk.
This challenge is particularly relevant to Dell’Oro Group’s AI & Cloud-native Security research, where risk context and enforcement are already distributed across cloud configurations, identities, workloads, application pipelines, and third-party security platforms. Agentic systems may improve how those signals are correlated and acted upon, but they do not eliminate the need to normalize data and coordinate controls across heterogeneous environments.
Microsoft acknowledged that third-party data quality, normalization, permissions, and enforcement remain difficult. Security data is inconsistent, customers frequently limit centralized ingestion because of cost, and external products expose different control mechanisms. Microsoft is exploring approaches such as data federation, but Perception’s practical openness will need to be demonstrated in customer environments.
The same test applies to competing platforms. Supporting connectors or open agent protocols does not by itself create reliable interoperability. Vendors must demonstrate that agents can interpret external evidence correctly, preserve source attribution, respect permissions, and execute actions without losing the safeguards available inside native products.
Openness also applies to models. Microsoft is pursuing a multi-model architecture but expects to certify supported configurations rather than permit unrestricted model substitution. That approach can improve quality and accountability, although customers may require different models because of sovereignty, cost, availability, or organizational policy. Platforms will need to balance customer choice against the risks created by untested combinations.
The market is approaching a practical contest between integrated performance and ecosystem reach. Broad platforms should have an advantage when their native products already dominate the customer environment. Openness will matter more as agents depend on external data sources and attempt to act across competing control planes.
Perception makes Microsoft’s platform opportunity visible, but it also sharpens the requirement for neutrality. Agentic security cannot become an enterprise operating layer unless it works across the enterprise that actually exists. The strongest platforms will not merely offer the largest collection of native agents. They will combine deep integration with credible operation across competing products.