Microsoft · soc-agent

Security Alert Triage Agent

LLM-based alert classification and resolution for supported Defender workloads.

First observed 2025-03-24 · Last verified 2026-08-27 ·FRESH · ASI-1.0 · ASI-TAXONOMY-1.1

Deterministic executive summary

EARLYUNKNOWNUNKNOWN

Security Alert Triage Agent has 1 confirmed capability assertion(s) and 1 confirmed control assertion(s). Evidence maturity is EARLY; autonomy is UNKNOWN; action authority is UNKNOWN. No qualifying independent validation is recorded.

What actually differs?

The documented boundary is UNKNOWN with UNKNOWN operation. This describes authority and initiation, not effectiveness. No qualifying independent validation is recorded.

buyer

Treat missing independent validation as NONE_FOUND, not proof of ineffectiveness.

competitive

Compare documented action authority, trigger model, lifecycle, and evidence breadth; do not compare vendor outcome claims as equivalent measurements.

confidence

EARLY under ASI-1.0; No qualifying independent validation is recorded.

governance

Control evidence covers 1 scoped control assertion(s); verify local policy configuration before enabling write actions.

operational

Plan operating procedures around UNKNOWN initiation and UNKNOWN action authority.

technical

Current evidence establishes 1 scoped capability assertion(s); undocumented capabilities remain UNKNOWN.

Derived under ASI-1.0; last verified 2026-08-27.

Lifecycle

GA · 2026-07-02

Evidence EV-MS-TRIAGE-CAPABILITY

email and collaboration scope; cloud and identity remain preview

Agents

UNKNOWN — no named agent is established by current evidence.

Autonomy and control

Derived autonomy UNKNOWN

Trigger
UNKNOWN · LOW · UNKNOWN
Persistence
UNKNOWN · LOW · UNKNOWN
Permission scope
UNKNOWN · LOW · UNKNOWN
Human gate
UNKNOWN · LOW · UNKNOWN

Each facet is separately evidence-backed; the A-label is derived.

Administrators can review feedback and pause or remove the triage agent.

AFFIRMED

Architecture

UNKNOWN — no architecture assertion is established.

Capabilities

Alert triage

The Security Alert Triage Agent classifies supported alerts using contextual LLM analysis.

AFFIRMED

Capability evidence

Vendor documentation
HIGH
Public demonstration
NONE_FOUND
Independent validation
NONE_FOUND
Production effectiveness
UNKNOWN

ASI-1.0: Rows represent evidence categories; assertion support confidence is intentionally not rendered beside the capability name.

Assertion support

HIGH under ASI-1.0:Recomputed at publication semantic_as_of with current freshness and unresolved-contradiction state.

Evidence and provenance

VENDOR DOCUMENTATION EV-MS-TRIAGE-CAPABILITY · E1

The Phishing Triage Agent uses large language model based analysis to assess reported emails, determine intent, and classify each submission as a real threat or a false positive.
Canonical source →

Evidence conflicts

No human-confirmed conflict is published for this system.

Recent changes

NO_MATERIAL_CHANGE is recorded for this profile.

Unknowns

Any evidence-panel row marked UNKNOWN is not a negative capability claim. Any NONE_FOUND row means the current governed corpus contains no qualifying evidence.

Sources

Compare claims with evidence categories