https://catalogartifact.azureedge.net/publicartifacts/microsoft_security.defenderphishingtriageagent-042682ae-af28-48f8-b6ff-b1923b1e1e4e/3f6ac36e-4599-41db-a65d-9b6225c93211_generatedimage.png

Phishing Triage Agent

firmy Microsoft Security

Automates phishing incident triage with advanced security workflows.

The Microsoft Defender Phishing Triage Agent triages user-submitted phishing incidents. Leveraging AI to autonomously classify and resolve alerts as either truly malicious or as false alarms, the agent provides a transparent rationale for its classification verdicts in natural language, and uses feedback provided by analysts to continuously improve its accuracy. Since user-submitted phishing incidents are often high volume and require significant time to triage, the Phishing Triage Agent frees up time for high-value work.


Agent tasks: Incident and alert triage, autonomous investigation, verdict analysis, contextual learning.
Agent workflow
Input: Alerts generated from user-submitted emails in Microsoft Defender.

Output: Classified alerts with detailed verdict explanation and visual graph insights to support incident triage and prioritization, including resolution of false alarms.

Learn more about setting up the Phishing Triage Agent.

W skrócie

https://catalogartifact.azureedge.net/publicartifacts/microsoft_security.defenderphishingtriageagent-042682ae-af28-48f8-b6ff-b1923b1e1e4e/a3e22636-3b0f-48f9-8f73-327d313e56d5_incidentqueuewithagentupload.png