This is the fifth is a series of blog posts about Intune Agents. Intune Agents (also known as Security Copilot agents) are AI-powered assistants, available in the Intune Admin Center, that enhance enterprise security. They automate tasks for endpoint protection, identity management, threat intelligence, and device configuration, and they help IT teams quickly address vulnerabilities, policy gaps, and emerging threats.
The first post in the series introduced Security Copilot and SCUs, and then took a closer look at the Change Review Agent. The second post concentrated on the Device Offboarding Agent. The third post looked at the Policy Configuration Agent, which helps IT admins to translate complex requirements and industry standard documents into actionable Intune settings. In the fourth post we looked at the Vulnerability Remediation Agent, which uses data from Microsoft Defender Vulnerability Management to identify Common Vulnerabilities and Exposures (CVEs) on your managed devices.
In this post we will deviate a bit from Intune agents and examine how to deploy additional agents from the Microsoft Security Store. The Microsoft Security Store is a dedicated virtual marketplace for discovering, buying, and deploying agents that integrate with Microsoft Security products.
All the agents we previously looked at were deployed and configured using the Intune admin center.
Selecting Agents displayed these agents.
Even though the agents are exposed in Intune, they actually live in Microsoft Security Copilot https://securitycopilot.microsoft.com/. Here you can see the agents that we deployed in previous posts. Click Browse more agents to see what is available.
This links us to the Security Store. You can see that a lot of agents have been published by many organizations. The Security Store provides a centralized storefront where you can easily find, buy, and deploy security SaaS solutions, AI agents and services that work with Microsoft Security products like Microsoft Sentinel, Microsoft Entra, and Microsoft Defender. You can explore vetted solutions aligned to cybersecurity and purchase them using existing Microsoft billing options.
Getting the agent
I've chosen this agent as an example, not because I'm endorsing it, it just looks interesting.
I selected Get agent.
We're redirected to the security store to "purchase" the agent. In this case it is free but you still need to provide some details. In Account details, choose your Billing subscription and Resource group and enter a new Resource name.
Scroll down for Solution details. Select Choose plan.
There is only one choice. Choose Select plan.
The plan has been selected. Choose your Billing term - I've chosen 1 month. You can also configure Auto-renewal.
Scroll down to the Tags section. This is optional. Click Next to continue.
On the Deployment configuration page, click Next.
Review the Order details.
Scroll down to review the Deployment details. Click Place order.
The order is complete in the security store. Click Use in Security Copilot so that we can get started.
Setting up the agent
We're directed back to Security Copilot where the agent requires further action. Click Start approval.
Review the permissions the agent needs and click Approve.
Now we can see that the agents is ready to be set up. Click Set up.
More information about the agent is displayed. Click Set up again.
Sign in with an account that is able to assign the relevant permissions.
Click Next to start setting up the agent.
You are invited to customize the agent by adding an Analysis type and Target name. This is optional and not required at this time. You can add these details when you choose the run the agent.
Click Finish.
The agent is ready. You can select Go to agent.
Alternatively, you could select Go to agent from the agent list in Security Copilot.
Now we can run the agent.
Using the agent
Click the ellipses (three dots) beside Run and select One time.
Now you can enter the details you want. I want to know more about how the Intune Company Portal is deployed in my test tenant. Click Submit.
The job is In progress.
After a short while, the job has completed. Click on the job to see the details. The results are interesting.
First we get an executive summary and target overview.
We get an assignment analysis of direct assignments and exclusions. We can see that the Company Portal is assigned to All users.
We get an impact assessment of devices and users affected. The assessment tells me that app is targeted at 0 users. I'm not so sure about that.
We get a logic visualization of the assignments.
We get optimization recommendations.
We get a targeting explanation.
Finally we have a section on potential issues. A warning tells us that the member count of All users is 0. That's not quite right. However some of the other information in the results looks quite useful.
I hope this helps you to explore the available agents in the security store. Until next time........