Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Microsoft Defender - Building the Agentic SOC with AI-Driven Security Operations - BRK241

Microsoft via YouTube

Overview

Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore Microsoft's vision for AI-driven security operations through this 44-minute conference talk from Microsoft Ignite 2025, featuring Rob Lefferts, Corina Feuerstein, and special guest Allie Mellen, Principal Analyst at Forrester. Discover how intelligent agents and automation are transforming Security Operations Centers (SOCs) by helping security teams prevent threats, respond faster, and stay ahead of attackers. Learn about Microsoft's mission for adaptive, autonomous defense that enables strategic work while addressing critical challenges like alert overload and false positives in SOC workflows. Examine real-world scenarios including how Defender XDR confirms account compromises when attackers federate compromised accounts into AWS environments, and witness automatic containment processes that revoke session tokens and disable compromised accounts. Gain insights into the importance of encoding runbooks, implementing guardrails, and ensuring explainability in agentic AI systems. Understand how the role of security analysts is evolving in the agentic era and why vendor transparency is crucial, including the importance of labeling generative AI capabilities and providing confidence levels. See demonstrations of new agentic capabilities transforming SOC operations and hear real-world stories of organizations strengthening their defenses through Microsoft Defender innovations.

Syllabus

0:00 - Microsoft's mission for adaptive, autonomous defense enabling strategic work
00:07:08 - Addressing alert overload and false positives in SOC workflows
00:13:29 - Attacker federates compromised account into AWS; Defender XDR confirms compromise
00:13:53 - Automatic containment revokes session tokens and disables compromised accounts
00:16:26 - Recap and transition to conversation on agentic AI and trust with analyst Ali Mellon
00:27:10 - Importance of Encoding Runbooks, Guardrails, and Explainability
00:29:19 - Evolving Role of Security Analysts in the Agentic Era
00:36:05 - Importance of Vendor Transparency: Labeling Generative AI and Confidence Levels
00:44:15 - Conversation Wrap-Up and Closing Remarks

Taught by

Microsoft Ignite

Reviews

Start your review of Microsoft Defender - Building the Agentic SOC with AI-Driven Security Operations - BRK241

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.