What’s new in Power Platform: September 2026 feature update

What’s new in Power Platform: September 2026 feature update

Summary
Welcome to the Power Platform monthly feature update! We will use this blog to share news in Power Platform from the last month, so you can find a summary of product, community, and learning updates from Power Platform in one easy place. Now, let’s dive into what’s new in Power Platform:

Get started with the latest updates today!

Jump into Power Apps, Power Automate, and Power Pages to try the latest updates, you can use an existing environment or get started for free using the Developer plan.

Join us at PPCC!

See these updates and more come to life at the Power Platform Community Conference 2026 – Join us October 27-29 at the MGM Grand in Las Vegas to discover how organizations are using agents, apps, and automations to drive business outcomes, build new solutions, and scale innovation. Connect with product experts, industry peers, and the community shaping what’s next.

Power Platform

Build hands-on Power Platform and AI expertise with Power Series

Power series lab catalog image

Developed by the Power CAT team, Power Series is now available with 20 hands-on labs that help customers, partners, and field teams build practical Power Platform and AI skills at their own pace. Drawing on the team’s experience delivering enterprise customer workshops, Power Series brings that expertise into a reusable, self-service learning experience.

Learners gain hands-on experience choosing the right capabilities, building working solutions, and making design decisions based on their business needs and solution complexity. The outcome: practical skills and greater confidence to apply Power Platform and AI to real projects, from modernizing applications and automating processes to governing solutions.

Power Apps

Build polished canvas apps faster with fluent screen templates

new templates sreenshot

Start new canvas app experiences faster with six additional ready-to-use screen templates based on fluent 2 patterns along with recently shipped 3 fluent templates. These templates give makers responsive layouts, editable controls, and practical starting points for common app scenarios. Add one from the new screen experience, connect your data, and customize the design instead of building every screen from scratch.

These templates are a replacement of previous out of box templates built on classic controls.

Additional improvements to modern controls and update from classic to modern controls

Update controls faster. Makers can now update eligible controls in bulk from the control-update surface instead of repeating the process one control at a time. Update all works on the current screen, can enable the required modern-control settings, and preserves the familiar Studio undo and redo experience. Review affected formulas after updating because property names, enum values, and behaviors may change.

More modern controls and quality improvements. The newly released progress bar supports determinate and indeterminate experiences, Power Fx-driven values, semantic colors, theme-aware styling, and accessible progress semantics. The modern avatar and spinner are also available, with improved interaction and upgrade behavior. Continued quality work makes date picker interactions and reset behavior more reliable and preserves formulas that reference checkbox, rating, and toggle.

Agentic apps

Generally available: refreshed model-driven apps UI, plus display density in public preview

Model apps UI modernization: Header and navigation refresh reaches general availability, with Display density arriving in preview

The next wave of UI modernization for model-driven apps arrives with version 2609.1. The header and navigation refresh feature reaches general availability, and the new display density feature enters preview. Together they deliver a cleaner, more efficient layout across the app shell, forms, and views, increasing your working area, reducing the time you spend navigating pages, and aligning the experience with modern Microsoft 365 design patterns.

Header and navigation refresh brings a modern app header with simplified layout and improved spacing, a streamlined sitemap that’s easier to scan, and noticeably more working space on forms. The command bar is now the only element fixed at the top of the page, with the summary area and form header scrolling alongside the rest of the form. Once the form header scrolls out of view, a condensed sticky header attached to the bottom of the command bar is shown. At GA, the experience remains opt-in so makers control adoption. Apps that already have the feature enabled get these enhancements automatically.

Display density (preview) answers a longstanding customer request to fit more content into model-driven app pages. Three levels are available — comfortable (the default), cozy, and compact — so users can tighten the interface to match how they work. An app setting lets customers set the default level for their users or turn the feature off entirely, and users can adjust their own density through personal settings. Display density requires the header and navigation refresh feature and is enabled by default once that feature is on.

AI powered development

Generally available: canvas authoring agent plugin for AI-assisted app building

The canvas authoring agent plugin is now generally available, giving makers and developers a new way to work with Power Apps canvas apps using agent-assisted development workflows. With the authoring agent plugin, makers can more easily create, inspect, and update canvas apps through agent-driven interactions with their favorite coding agent, helping accelerate common app-building tasks while keeping makers in control. Learn more about the agent here.

This update is part of our continued investment in making canvas app creation faster, easier, and more approachable. By bringing agentic authoring and MCP support to canvas apps, makers can use modern AI development patterns to move from idea to working app more quickly, iterate on app structure and controls, and streamline parts of the authoring process that previously required more manual effort.

Generally available: vibe code entire model-driven apps with the app-builder skill

Vibe code entire model-driven apps with the new app-builder skill (preview)

Generative pages gave makers an AI-assisted way to build individual pages in model-driven apps. The new model app-builder skill extends that approach to the whole application, and it’s now generally available. Used with an AI code generation tool such as GitHub Copilot CLI or Claude Code, it builds and edits model-driven apps from natural-language requirements.

You start by describing the business process or app you need. The skill turns your requirements into an application plan that you review before it makes any changes. It starts with user personas and the jobs they need to accomplish, and then extends to cover a growing list of model-driven app artifacts including:

  • Tables, columns, relationships, and sample data
  • Forms, views, and charts
  • Generative pages for experiences that go beyond standard forms and views
  • A sitemap with custom icons for each table
  • JavaScript validation rules on forms
  • Security roles based on the planned personas and data access needs
  • Business process flows (recently added)
  • Business rules (recently added)

No app artifacts are created until you approve the build plan. The skill also works on editing your existing apps. Everything it produces is a standard Power Apps and Dataverse artifact, so you can keep iterating with the skill or switch to the Power Apps studio designers whenever you prefer.

Embed a generative page directly inside a model-driven app form

Embed a generative page directly inside a model-driven app form

Generative pages are no longer limited to standalone pages in your app’s navigation. You can now add a generative page to a model-driven app form so that it appears within a section or tab, letting an AI-generated experience sit right alongside the standard fields on a record.

Build the generative page to accept the recordId input parameter, and when a user opens a record, the form automatically passes the current record ID to the generative page for you. The page knows which record it’s on from the moment it loads. This unlocks the mixed layouts makers have been asking for, keeping the out-of-box form for structured data entry and dropping in a purpose-built generative page for the part of the record that needs a richer, more tailored view.

Public preview: generative pages can now use data from Power Platform connectors

Public preview: generative pages can now use data from Power Platform connectors

To date, generative pages have been built on Dataverse tables, but now they can reach further. Connector support (preview) lets a generative page use data outside of Dataverse through the Power Platform connector ecosystem. If the data your scenario needs already lives in SharePoint, SQL, or any other connected service, you can build a page against it directly.

Connector support works in both authoring experiences by targeting existing connection references in the environment. In the generative page designer, configured connectors are available through add data > connectors, where you select the connection reference and choose the data the page should use. With AI code generation tools, describe the data you want, and the agent walks you through selecting the right connector and adding the binding so it deploys with the page.

Power Automate

Quick start cards make it easier to begin automating from the Power Automate home page

Power Automate screenshot

New quick start cards on the Power Automate home page provide clear, actionable entry points for common automation scenarios. Users can move directly into creating a flow without first navigating menus or searching through the template gallery. By bringing relevant starting points to the home page, this experience helps new users discover what they can automate while giving experienced users a faster path from idea to flow.

Server-side search helps users find flows faster

Searching in My Flows is now faster and more reliable with server-side search. Instead of filtering only the flows already loaded in the browser, Power Automate sends the search request to the service and returns matching flows from the complete list of available flows in the current environment. This improvement is especially helpful for users who manage large numbers of flows. It provides more complete results while reducing the time and effort required to locate a specific flow.

Learning updates

Training paths and labs

Updated training

Power Apps maker

New

Updated

Power Apps user

New

Updated

Power Automate

New

Updated

Power Pages

New

Updated

Power Platform administration

New

Updated

Power Platform developer

New

Updated

AI Builder

Updated

Power Platform connectors

Updated

The post What’s new in Power Platform: September 2026 feature update appeared first on Microsoft Power Platform Blog.

Register now for PPCC 2026: Come for the learning, stay for the community

Register now for PPCC 2026: Come for the learning, stay for the community

The wait is over: the Power Platform Community Conference (PPCC) is back, and the fifth annual event is shaping up to be the biggest and best one yet.  

The Power Platform Community has always been defined by people who share what they know, help one another succeed, and turn creative ideas into meaningful solutions. From October 27-29, 2026 at the MGM Grand in Las Vegas, solution makers from all around the world will come together to learn, connect, and build what’s next with Microsoft 365 Copilot, agents, apps, automation, and data.  

More than 200 sessions. Dozens of hands-on workshops. Three days of keynotes. Onsite AI and agent certifications. And one global community building what’s next with AI. 

Whether you’re exploring AI in your business, building with low code, developing professional solutions, or leading enterprise-wide transformation, PPCC is your best opportunity to gain practical skills, meet the people shaping the platform, and return to work on Monday ready to make an impact.  

Learn. Build. Make it real.

Technology is moving quickly, but PPCC is about more than keeping up—it’s about getting ahead.  

Hear directly from Microsoft leaders, product teams, engineers, and community experts about the future of Copilot, Copilot Studio, Power Apps, Power Automate, Power BI, Power Pages, and Dataverse

At PPCC, you’ll learn how agents, apps, workflows, automation, and trusted data systems can work together as complete, governed business solutions. Learn how other organizations are moving from promising AI experiments to secure, production-ready solutions, and discover practical approaches you can apply immediately. 

At PPCC, every person  can find a path forward: 

  • Discover new product capabilities directly from the teams creating them, and see them live for the first time. 
  • Learn how to design, build, secure, govern, and scale AI-powered solutions. 
  • Connect with people solving similar challenges across roles, industries, and skill levels. 

We’ll do more than show what is possible. This is where product meets hands-on learning, and where your next big idea can become something real. 

Power Platform Community Conference 2026 promotional graphic inviting attendees to join the event in Las Vegas on October 27–29, 2026.

Go deeper with the people building the platform

The conference will open with Charles Lamanna, Executive Vice President at Microsoft, sharing a forward-looking view of Copilot, agents, the platform, and how these technologies are changing what every organization can build.  

Attendees will also hear from Microsoft product leaders, including Ryan Cunningham, Corporate Vice President of Copilot Studio & Power Platform, along with Microsoft engineers, product managers, enterprise practitioners, MVPs, and community experts. 

Across keynotes, product talks, innovation sessions, breakouts, and roundtables, speakers will share what they are building, what they are learning, and what your organization needs to know to turn innovation into business value.  

Come ready to ask questions, challenge your thinking, and learn directly from the people helping define the future of AI-powered solution development.

From promising ideas to production-ready AI solutions

The PPCC 2026 session catalog reflects how dramatically solution building is evolving.  

Attendees can explore Copilot-first app design, multi-agent systems, agent evaluation and governance, intelligent automation, enterprise architecture, adoption, and more. 

The common thread is moving from isolated experiments to complete solutions. PPCC will show how Copilot and agents can work with apps, workflows, automation, and trusted data to help organizations modernize processes, extend what teams can build, and operate AI responsibly at scale. 

The opportunity isn’t simply to add AI to an existing process. It’s to reimagine what the process, and the people responsible for it, can accomplish. 

Turn inspiration into hands-on experience

Great ideas become far more valuable when you know how to put them into practice. 

Full-day workshops on October 25, October 26, and October 30 create space to go deeper with guided, hands-on learning. Attendees can add one, two, or three workshops to their conference passes to build an experience around their goals.

PPCC will also offer onsite AI and agent certification opportunities designed to help attendees validate their skills and continue advancing their careers. 

Whether you’re creating your first solution or establishing architecture and governance for an enterprise program, you can leave Las Vegas with the knowledge, practical experience, and greater confidence in what you can build next.

Keep building with the community 

The PPCC maker community is incredibly unique and special, turning the conference into more than a set of sessions. It’s a place to meet people facing similar challenges, learn directly from practitioners, and find ideas you can carry back into your own work. 

At PPCC, those connections happen everywhere. Explore solutions and meet experts in the Expo Hall. Discover what fellow makers are creating in the Makers Market. Find experts and community leaders in the Community Lounge. Continue the conversation through meetups, networking activities, and the Night Market. 

These aren’t simply breaks between sessions. They are opportunities to find collaborators, learn from someone who solved the challenge you’re facing, and build relationships that continue long after the conference ends. 

And on Wednesday, October 28, 2026 we’re turning up the energy with an exclusive attendee celebration featuring a live performance by Pitbull. 

Don’t just watch the next era of AI-powered solution building take shape. Come help us shape it.

Plan your PPCC week

  • October 25–26, 2026: Pre-conference full-day workshops. 
  • October 27–29, 2026: Keynotes, sessions, roundtables, product talks, certifications, Expo Hall, Makers Market, Community Lounge, and community events. 
  • October 30, 2026: Post-conference full-day workshops. 

Join us in Las Vegas

Standard registration pricing is available through August 18, 2026 and teams can save up to 20% with group discounts. Choose a conference pass or add workshops to create the experience that best fits your goals. 

Explore the agenda, meet the speakers, and register for PPCC 2026.

Planning your stay? Book your hotel at the MGM Grand. 

We can’t wait to learn, connect, and build what’s next with you at #PPCC26 in Las Vegas!

The post Register now for PPCC 2026: Come for the learning, stay for the community appeared first on Microsoft Power Platform Blog.

Automate cybersecurity at scale with Microsoft Security Copilot agents

Automate cybersecurity at scale with Microsoft Security Copilot agents

This post was originally published on this site.

When we introduced Microsoft Security Copilot last year, we set out to transform the way defenders approach cybersecurity. As one of the industry’s first generative AI solutions for security and IT teams, Security Copilot is empowering teams to catch what others miss, respond faster, and strengthen team expertise in an evolving threat landscape.  

Customers like Eastman are already seeing the impact. “I’m finding that I can ask [Security Copilot] about attack factors that I’ve never seen before and get answers much faster”, said David Yates, Senior Cybersecurity Analyst at Eastman. “That helps me to make a better decision and respond faster to an attacker.” A recent study of Copilot users showed that using Security Copilot reduced mean time to resolution by 30%, helping accelerate response times and minimizing the impact of security incidents.  

But as defenders evolve, so have attackers. 

Adversaries are now leveraging AI to launch more sophisticated attacks with unprecedented speed and scale. Security and IT teams – already overwhelmed by a huge volume of alerts, data, and threats – are struggling to keep up. Traditional automation, while useful, lacks the flexibility and adaptability to keep up. 

Today, we’re taking the next leap forward in generative AI-powered cybersecurity. I am thrilled to introduce agents in Microsoft Security Copilot. 

AI-powered agents represent the natural evolution of Security Copilot, going beyond AI assistant capabilities. They autonomously manage high-volume security and IT tasks, seamlessly integrated with Microsoft Security solutions and partner solutions. Purpose-built for security, these agents learn from feedback, adapt to organizational workflows with your team fully in-control, and operate securely within Microsoft’s Zero-Trust framework. 

Delivering powerful automation across threat protection, identity management, data security, and IT operations, these agents empower teams to accelerate responses, prioritize risks, and drive efficiency at scale. By reducing manual workloads, they enhance operational effectiveness and strengthen overall security posture – allowing defenders to stay ahead. To bring this automation to life, we’re introducing six security agents from Microsoft and five security agents from partners which will be available for preview in April. 

Empowering security and IT teams with Security Copilot agents 

Our goal is to provide generative AI-powered security for everyone. Integrating Copilot with Microsoft Security products helps IT and security teams benefit from increased speed and accuracy. Now, you can use embedded Security Copilot agents with capabilities specific to use cases for your role in the products you know and love: 

Security Alert Triage Agent (previously named Phishing Triage Agent)

SOC analysts often face the challenge of managing hundreds of user-submitted phishing alerts each week, with each alert taking up to 30 minutes for manual triage. This process requires meticulous sifting through submissions to find the needle in the haystack – the genuine threat amidst all the noise.  Security Copilot solves this challenge with an AI-powered agent embedded in Microsoft Defender, that works in the background to autonomously triage user-submitted phishing incidents. Powered by advanced multi-modal AI tools, it determines whether an alert is a genuine phishing attempt or a false alarm with exceptional precision. The agent not only delivers natural language explanations for its decisions but also dynamically refines its detection capabilities based on analyst feedback. By alleviating the burden of reactive work, it empowers SOC analysts to focus on proactive security measures, ultimately strengthening the organization’s overall security posture. 

Note: The Phishing Triage Agent has since been expanded and is now called the Security Alert Triage Agent. Learn more at aka.ms/SATA

Alert Triage Agents for Data Loss Prevention and Insider Risk Management 

Data security admins regularly struggle to manage the volume of alerts they receive daily, addressing only about 60% of them due to time and resource constraints1. The Alert Triage Agents in Microsoft Purview Data Loss Prevention (DLP) and Insider Risk Management (IRM) identify the alerts that pose the greatest risk to your organization and should be prioritized first. These agents analyze the content and potential intent involved in an alert, based on the organization’s chosen parameters and selected policies, to categorize alerts based on the impact they have on sensitive data. Additionally, they provide a comprehensive explanation on the logic behind that categorization, allowing admins to analyze a risk in just a few minutes. These agents empower data security teams to focus on the most important alerts and concentrate on the critical threats, with a dynamic process that takes inputs from data security admins in natural language and fine-tunes the triage results to better match the organizations’ priorities. The agent learns from this feedback, using that rationale to calibrate the prioritization of future alerts in DLP and IRM. Learn more about the Alert Triage Agents for DLP and IRM here.

Conditional Access Optimization Agent 

As organizations grow, identity and IT admins must continuously ensure that access policies adapt to new employees, contractors, SaaS apps, and more – keeping security intact without adding complexity. But as their environments evolve, keeping Conditional Access (CA) policies up to date becomes increasingly difficult. New users and apps can slip through, and exclusions can go unaddressed, creating security risks. Even with routine reviews, manually auditing policies and adjusting coverage can take days or weeks –yet gaps can still go unnoticed.  The CA Optimization Agent in Microsoft Entra changes that for admins, automating the detection and resolution of policy drift. This agent continuously monitors for newly created users and applications, analyzing their alignment with existing CA policies, and proactively detects security gaps in real time. Unlike static automation, it recommends optimizations and provides one-click fixes, helping admins refine policy coverage effortlessly while ensuring a strong, adaptive security posture.  Learn more about the CA Optimization Agent here.

Vulnerability Remediation Agent 

Managing security vulnerabilities is a growing challenge for organizations, as the volume of CVEs and limited resources make it difficult to prioritize and implement critical fixes effectively.  Microsoft Intune is designed for organizations that need a modern, cloud-powered approach to endpoint management, one that not only simplifies IT operations but strengthens security in an evolving threat landscape. IT admins require more than just visibility into vulnerabilities; they need a proactive, risk-based security strategy that continuously assesses risk and automates remediation to minimize exposure. That’s why Intune is introducing the Vulnerability Remediation Agent—a solution built to help organizations stay ahead of emerging threats.  

By leveraging Microsoft Defender Vulnerability Management, the agent automatically identifies, evaluates, and prioritizes vulnerabilities. It continuously monitors newly published threats, assesses their risk levels, and offers clear, actionable recommendations for remediation. With continuous vulnerability detection, risk-based prioritization and guided remediation, the agent reduces exposure time while freeing up IT teams to focus on strategic initiatives. This is the first step toward designing vulnerability remediation at scale. A future, comprehensive approach will work across device platforms, address vulnerabilities in third-party applications, and remediate using configuration changes. Learn more about the Vulnerability Remediation Agent here.

Threat Intelligence Briefing Agent 

Cyber Threat Intelligence analysts often face data overload and resource constraints when sourcing the threat intelligence needed to help their organizations understand, prioritize, and respond to critical threats. Crafting a threat intelligence briefing for security teams and executives can take hours—or even days—due to the constant evolution of both the threat landscape and an organization’s attack surface. 

The Threat Intelligence Briefing Agent in Security Copilot dramatically expedites this process. It automatically curates up-to-date, context-specific intelligence tailored to your organization’s unique profile and attack surface. Operating autonomously in the background, it taps into Microsoft’s extensive threat intelligence resources (including Microsoft Defender Threat Intelligence and Microsoft Defender External Surface Management) to deliver prioritized reports in just 4-5 minutes. This tool not only cuts down on manual effort but also highlights the most pressing threats and provides actionable recommendations, ensuring your team stays well-informed and ready to respond. Learn more about the Threat Intelligence Briefing Agent here.

Extending agentic capabilities with partner solutions 

We are grateful to our partners who continue to play a vital role in empowering everyone to confidently adopt safe and responsible AIOur growing partner ecosystem seamlessly integrates Security Copilot with established tools across various applications. Today, I am pleased to share five new upcoming agents in partner solutions, with many more to come. 

  • Privacy Breach Response Agent by OneTrust analyzes a data breach based on type of data, geographic jurisdiction, and regulatory requirements to generate guidance for the privacy team on how to meet those requirements.  
  • Network Supervisor Agent by Aviatrix determines why a VPN, Gateway, or Site2Cloud connection is down and provides information about the failure.  
  • SecOps Tooling Agent by BlueVoyant assesses your security operations center (SOC) and state of controls to make recommendations to optimize security operations to improve controls, efficacy, and compliance. 
  • Alert Triage Agent by Tanium provides analysts with necessary context to quickly and confidently make a decision on each alert.  
  • Task Optimizer Agent by Fletch helps organizations forecast and prioritize the most critical threat alerts to reduce alert fatigue and improve security. 

Learn more about our partner integrations at aka.ms/partnerintegrations.

Get Started with Security Copilot Agents 

Microsoft Security Copilot agents will be available in preview starting April 2025. To get started with Security Copilot, check out the website for more information. Already using Security Copilot? Make sure you’re signed up for the Security Copilot Customer Connection Program (CCP) to receive the latest updates and features—join today at aka.ms/JoinCCP.  Learn more about the latest innovations at the Microsoft Secure digital event on April 9, 2025. Register now. 

With agents, Security Copilot continues to lead the way in AI-powered cybersecurity, helping organizations defend against threats faster, smarter, and with greater confidence. 

Power Platform Monitor Alerts Are Now Generally Available

Power Platform Monitor Alerts Are Now Generally Available

We are excited to announce that Power Platform Monitor alerts are now generally available! Since entering public preview in August 2025, many organizations have created alert rules to stay on top of app, agent and flow health. Reliability is critical when alerts are used to detect and respond to issues in production. Today, Monitor alerts meet the reliability and maturity standards required for general availability, following sustained investments to improve quality and simplify onboarding.

This image shows the new Monitor overview page, which has become more alerts-centric. It has visuals describing the state of your triggered custom alerts in addition to triggered predefined alerts that are authored by Microsoft.

What are Monitor Alerts?

Monitor alerts allow tenant and environment administrators to proactively monitor the operational health of their Power Platform resources and receive notifications when health metrics fall below thresholds they define. Instead of learning about problems from end users, admins can identify and address issues before they cause disruption. This reduces downtime and improves reliability across the organization.

What’s New with GA

Predefined alerts — protection with zero configuration

The biggest addition we’ve added is predefined alerts: a set of configured, Microsoft-authored alerts that are enabled by default for every tenant. These alerts automatically surface high-use canvas apps, model-driven apps, agents, desktop flows and cloud flows whose health has dropped below recommended baseline thresholds — with no setup required.

For example, predefined alerts will flag when:

  • The availability of high-use canvas apps drops below 90%
  • The availability of high-use model-driven apps drops below 90%
  • High-use cloud flows are experiencing success rate degradation

Predefined alerts give admins an immediate signal on what matters most in their tenant, even before they’ve configured a single custom alert rule. Items can trigger these alerts regardless if they’re in a managed environment, and predefined alerts will encourage users to create their own alert rules to monitor these items against their own custom thresholds.

This image shows the triggered alert experience for a predefined alert. In this image, it specifically shows the cloud flow predefined alert, with two cloud flows that triggered it. These cloud flows aren't in a Managed Environment.

Redesigned Monitor overview page

We redesigned the Monitor overview page to be alerts-centric. When you land in Monitor, you now get an at-a-glance view of active alert conditions and resource health across your environments — making it faster to identify what needs attention and act on it.

Code app alerts

Custom alert rules now support alerting on your code apps in addition to canvas and model-driven apps. This gives admins deeper visibility into code app performance and the ability to catch performance degradation before it affects users’ day-to-day experience.

Work queue alerts (public preview)

Admins can now configure alerts for Power Automate work queues in Monitor, enabling proactive monitoring of work queue health alongside apps, flows and agents. This capability is launching in public preview alongside alerts GA.

How Monitor Alerts Work

Admins define threshold-based rules on Monitor metrics. For example, this can look like receiving an alert when a cloud flow’s success rate drops below a custom threshold, or when a canvas app’s availability falls below an acceptable level.

Monitor alerts evaluate alert rules daily after aggregating new metric data for your environments. When a metric breaches a threshold, admins receive an email notification with a direct link to the details that triggered the alert.

You can scope alert rules to an environment or individual item, configure multiple recipients per rule (including security groups), and manage all active rules and review triggered alert history from the Alert Rules view in Monitor.

This image shows the alert configuration panel in Monitor, where admins can create their own custom alert rule to proactively monitor the resources they care about against health thresholds they define.
This image shows the alert rule list in Monitor, where admins can manage their rules, like turning them on/off or editing or deleting them.

What’s Supported

Product Resource
Power Apps Code apps
Power Apps Canvas apps
Power Apps Model-driven apps
Power Automate Cloud flows
Power Automate Desktop flows
Power Automate Work queues (public preview)
Copilot Studio Agents

We’re excited for you to improve the operational health of your apps, agents and automations in Power Platform. Learn more about Monitor and how to create alerts here.

The post Power Platform Monitor Alerts Are Now Generally Available appeared first on Microsoft Power Platform Blog.

Automate cybersecurity at scale with Microsoft Security Copilot agents

From alert overload to decisive action: How Security Copilot agents are transforming security and IT

This post was originally published on this site.

Security and IT teams operate in a constant stream of alerts, incidents, and investigations. As environments expand across identities, endpoints, cloud, and data, the challenge becomes clear: identifying real risk quickly enough to act.

Security Copilot agents bring AI directly into the flow of work, helping teams understand risk with greater context, investigate threats more efficiently, and take action sooner. Security Copilot is now included with Microsoft 365 E5 and E7 licenses at no additional cost, so teams can start using agents right away.

Over the past year, organizations have used Security Copilot to triage alerts, surface real threats earlier, and move faster from investigation to action. At this RSA 2026 conference, we are announcing new capabilities that reflect a continuous wave of innovation, evolving from built-in AI assistance and automated summaries to new agents that can analyze signals, investigate incidents, and execute security workflows.

Real-world impact: measurable results

Security Copilot agents help security and IT teams identify and respond to risk more effectively. Customers are seeing that impact in their day-to-day operations.

At St. Luke’s University Health Network, the Phishing Triage Agent in Microsoft Defender saves security analysts more than 200 hours every month, automatically triaging phishing alerts and surfacing those that actually matter.

Independent randomized controlled studies reinforce the results. Security professionals using the Phishing Triage Agent triaged alerts up to 78% faster, delivered 77% more accurate verdicts, and identified 6.5 times more malicious emails.

That same impact extends beyond the SOC into other critical areas of security and IT.

A data security team at a large telecommunications organization used the Data Security Triage Agent in Microsoft Purview to triage more than 40,000 Data Loss Prevention (DLP) alerts in 90 days, surfacing the 10% most critical alerts that required investigation.

Identity teams are also seeing huge improvements with the Conditional Access Optimization Agent in Microsoft Entra, which continuously analyzes access policies against Zero Trust baselines and recommends actions. In controlled productivity studies, identity admins completed policy-related tasks 43% faster and 48% more accurately when identifying configuration weaknesses.

IT teams are also seeing impact using the Vulnerability Remediation Agent in Microsoft Intune, which continuously detects new vulnerabilities as threats emerge.  As one CTO at a renewable energy and technology company shared, the agent is “dramatically changing the way we approach working with vulnerabilities in our environment. A two‑week process is now a two‑minute process, really huge number for us.”

Across these scenarios, teams begin investigations with clearer context and a better understanding of what actually matters. Instead of piecing together signals across dozens of tools, they can focus on the highest-risk issues and move from investigation to action with confidence.

As environments continue expanding across identities, endpoints, applications, and data, quickly connecting signals and understanding risk becomes essential.

New Security Copilot agents and capabilities announced at RSA Conference

Our innovation continues. Microsoft is introducing new Security Copilot agents and expanded capabilities designed to help organizations analyze complex security data, triage alerts more effectively, and strengthen security posture across identity, endpoint, cloud, and data environments.

New and updated Security Copilot agents built by Microsoft
  • Security Analyst Agent in Microsoft Defender

Security teams are often sitting on enormous volumes of security data, but turning that data into answers takes time. The Security Analyst Agent helps teams move from raw telemetry to real understanding much faster. By performing deep, multi-step investigations across Microsoft Defender and Sentinel telemetry, the agent can analyze up to ~100MB of security data to uncover anomalies, hidden risks, and high-impact threats that might otherwise stay buried. Analysts can chat directly with the agent to ask questions, explore hypotheses, and dig deeper into findings. The results include transparent reasoning and supporting evidence, helping teams quickly understand what matters and move forward with confidence.

  • Security Alert Triage Agent in Microsoft Defender

One of the biggest challenges for SOC teams is deciding which alerts actually deserve attention. The Security Alert Triage Agent helps cut through that noise so analysts can focus on the threats that truly matter. Building on its existing phishing triage capabilities, the agent now extends autonomous triage to identity and cloud alerts. Each verdict includes clear, transparent reasoning so analysts can quickly understand the outcome and prioritize the alerts that matter most.

  • New capabilities for Conditional Access Optimization Agent in Microsoft Entra

Identity environments are constantly evolving as organizations add new apps, users, and authentication methods. New capabilities in the Conditional Access Optimization Agent help identity teams identify and close critical policy gaps faster, with recommendations tailored to their organization’s needs. The agent now delivers business-context-aware recommendations, supports phased rollout of new policies, enables automated least-privilege enforcement for supported third-party agent identities, and helps drive passkey adoption. Together, these capabilities help organizations continuously strengthen identity security while maintaining productivity.

  • New capabilities for Data Security Posture Agent in Microsoft Purview

Sensitive data often moves through documents, emails, chats, and collaboration tools, which makes it easy for credentials or secrets to end up where they shouldn’t be. A new credential scanning capability in the Data Security Posture Agent helps data security teams proactively identify exposed credentials within their data environment. By analyzing data signals and access patterns, the agent surfaces potential credential exposure risks and helps teams quickly investigate and remediate them. This gives organizations better visibility into hidden data risks and strengthens overall protection of critical systems.

  • New capabilities for Data Security Triage Agent in Microsoft Purview Insider Risk Management

Investigating insider risk alerts often requires piecing together signals from many different sources to understand what is really happening. The Data Security Triage Agent now introduces an advanced AI reasoning layer that helps security teams evaluate those signals more holistically. By performing deeper, multi-step analysis across behavioral signals from users, devices, and data activity, the agent can surface the incidents that truly require investigation while filtering out noise. The result is faster, more accurate investigations and better confidence when responding to potential insider risks.

  • New capabilities for Data Security Triage Agent in Microsoft Purview Data Loss Prevention                                

Custom Sensitive Information Types (SITs) are often difficult for analysts to interpret quickly because the underlying definitions and patterns lack clear context at triage time. This latest enhancement makes custom Sensitive Information Types (SITs) easier for both the agent and analysts to understand in Data Loss Prevention alerts. Purview interprets custom SIT definitions, generates semantic descriptions of the data, and surfaces that context directly within the agent. This allows the agent to classify and prioritize alerts involving custom data more accurately, helping analysts quickly recognize real risk and respond appropriately.

New Security Copilot agents built by partners

To meet customers where they are across their existing security stack, the Security Copilot ecosystem continues to grow with more than 70 partner-built agents available today in the Security Store, bringing additional signals and investigation capabilities into the platform. Some of these agents include the following:  

Together, these partner agents extend Security Copilot’s ability to connect signals across Microsoft and third-party security platforms, giving organizations broader visibility and stronger investigation capabilities across their security environment. To explore all new Security Copilot agents, visit the Microsoft Security Store.

New Security Copilot innovations that turn insight into action

Security Copilot continues to integrate more deeply into the tools security and IT teams already use every day. These capabilities bring AI directly into the environments where investigations happen, helping teams explore threats, understand context, and take action without switching between tools.

  • Security Copilot interactive chat experience in Microsoft Defender

Analysts can ask questions, explore investigative hypotheses, and follow threat activity across incidents, alerts, identities, devices, and IPs without leaving their investigation. Copilot understands the context of the page analysts are working on and grounds responses in the relevant signals already available in Defender. As analysts ask questions, Copilot can run investigative steps, gather additional evidence, and surface new insights. This allows teams to iterate quickly, validate assumptions, and dig deeper into threats while staying in the same workflow.

  • Secret finder skill in Security Copilot is now generally available

Available in the Security Copilot standalone portal, the Secret Finder skill can be invoked to analyze unstructured content such as emails, chats, documents, and investigation notes to identify exposed credentials hidden in real-world workflows. Using agentic capabilities such as multi-step reasoning rather than simple pattern matching, it detects real, usable secrets and the systems they unlock, helping security teams quickly understand potential exposure and respond with confidence. Additional integrations and use cases are planned to expand how this capability can be used across security workflows.

  • Security Copilot trigger in Logic Apps

Building on how many organizations already use Logic Apps to automate security workflows, a new connector action for Security Copilot in Logic Apps flows allows teams to easily invoke partner-built agents and custom agents they create as part of repeatable workflows. This brings deeper AI-driven investigation, context, and decision support into tasks such as incident triage, threat intelligence analysis, and policy validation.

See Security Copilot in action at RSA Conference

Join us at RSA Conference to see the latest Security Copilot agents and capabilities in action. Stop by the Microsoft booth to connect with the team, explore new innovations, and experience how agents are helping security and IT teams investigate threats, understand risk, and strengthen security posture.

Hear from Microsoft Security product leaders in these booth sessions

  • March 23 | 5:15 PM
    Empowering the SOC with assistive and autonomous AI, Yuval Derman
  • March 24 | 3:00 PM
    Security Copilot agents: Insight. Action. Impact., Lizzie Heinze and Donna Lee
  • March 25 | 10:30 AM
    Turning Data Risk into Action with Security Copilot Agents, Paige Johnson and Tanay Baldua
  • March 26 | 12:00 PM
    Defend identity autonomously with agentic AI in Microsoft Entra, Mitch Muro, Rahul Prakash, Nikhil Reddy

Join our deep dive session

Stop by the Microsoft booth for a hands-on experience

  • Test out the latest Security Copilot agents at the demo station and connect with our experts.
  • Agentic AI Arena: Try a fun, gamified experience that shows how Security Copilot agents investigate threats, surface risk, and help security teams respond faster.
Start using Security Copilot in your daily workflows

If you have received access to Security Copilot as part of your Microsoft 365 E5 plan, we recommend following steps to get started quickly: