Wednesday, 22 July 2026

My first look at agents (part5) - security store

This is the fifth is a series of blog posts about Intune Agents. Intune Agents (also known as Security Copilot agents) are AI-powered assistants, available in the Intune Admin Center, that enhance enterprise security. They automate tasks for endpoint protection, identity management, threat intelligence, and device configuration, and they help IT teams quickly address vulnerabilities, policy gaps, and emerging threats.

The first post in the series introduced Security Copilot and SCUs, and then took a closer look at the Change Review Agent. The second post concentrated on the Device Offboarding Agent. The third post looked at the Policy Configuration Agent, which helps IT admins to translate complex requirements and industry standard documents into actionable Intune settings. In the fourth post we looked at the Vulnerability Remediation Agent, which uses data from Microsoft Defender Vulnerability Management to identify Common Vulnerabilities and Exposures (CVEs) on your managed devices.

In this post we will deviate a bit from Intune agents and examine how to deploy additional agents from the Microsoft Security Store. The Microsoft Security Store is a dedicated virtual marketplace for discovering, buying, and deploying agents that integrate with Microsoft Security products.

All the agents we previously looked at were deployed and configured using the Intune admin center.


Selecting Agents displayed these agents.


Even though the agents are exposed in Intune, they actually live in Microsoft Security Copilot https://securitycopilot.microsoft.com/. Here you can see the agents that we deployed in previous posts. Click Browse more agents to see what is available.


This links us to the Security Store. You can see that a lot of agents have been published by many organizations. The Security Store provides a centralized storefront where you can easily find, buy, and deploy security SaaS solutions, AI agents and services that work with Microsoft Security products like Microsoft Sentinel, Microsoft Entra, and Microsoft Defender. You can explore vetted solutions aligned to cybersecurity and purchase them using existing Microsoft billing options.

Getting the agent


I've chosen this agent as an example, not because I'm endorsing it, it just looks interesting. 


I selected Get agent.


We're redirected to the security store to "purchase" the agent. In this case it is free but you still need to provide some details. In Account details, choose your Billing subscription and Resource group and enter a new Resource name


Scroll down for Solution details. Select Choose plan.


There is only one choice. Choose Select plan.


The plan has been selected. Choose your Billing term - I've chosen 1 month. You can also configure Auto-renewal.


Scroll down to the Tags section. This is optional. Click Next to continue.


On the Deployment configuration page, click Next.


Review the Order details.


Scroll down to review the Deployment details. Click Place order.



The order is complete in the security store. Click Use in Security Copilot so that we can get started.

Setting up the agent


We're directed back to Security Copilot where the agent requires further action. Click Start approval.


Review the permissions the agent needs and click Approve.


Now we can see that the agents is ready to be set up. Click Set up.


More information about the agent is displayed. Click Set up again.


Sign in with an account that is able to assign the relevant permissions.


Click Next to start setting up the agent.


You are invited to customize the agent by adding an Analysis type and Target name. This is optional and not required at this time. You can add these details when you choose the run the agent.


Click Finish.


The agent is ready. You can select Go to agent.


Alternatively, you could select Go to agent from the agent list in Security Copilot.


Now we can run the agent.

Using the agent


Click the ellipses (three dots) beside Run and select One time.


Now you can enter the details you want. I want to know more about how the Intune Company Portal is deployed in my test tenant. Click Submit.


The job is In progress.


After a short while, the job has completed. Click on the job to see the details. The results are interesting.


First we get an executive summary and target overview.


We get an assignment analysis of direct assignments and exclusions. We can see that the Company Portal is assigned to All users. 


We get an impact assessment of devices and users affected. The assessment tells me that app is targeted at 0 users. I'm not so sure about that.


We get a logic visualization of the assignments.


We get optimization recommendations.


We get a targeting explanation.


Finally we have a section on potential issues. A warning tells us that the member count of All users is 0. That's not quite right. However some of the other information in the results looks quite useful.

I hope this helps you to explore the available agents in the security store. Until next time........


Monday, 6 July 2026

My first look at Intune Agents (part4) - IVRA

This is the fourth is a series of blog posts about Intune Agents. Intune Agents (also known as Security Copilot agents) are AI-powered assistants, available in the Intune Admin Center, that enhance enterprise security. They automate tasks for endpoint protection, identity management, threat intelligence, and device configuration, and they help IT teams quickly address vulnerabilities, policy gaps, and emerging threats.

The first post in the series introduced Security Copilot and SCUs, and then took a closer look at the Change Review Agent. The second post concentrated on the Device Offboarding Agent. The third post looked at the Policy Configuration Agent, which helps IT admins to translate complex requirements and industry standard documents into actionable Intune settings. 

In this post, I'll have a look at the Vulnerability Remediation Agent in Microsoft Intune, also known as IVRA. IVRA uses data from Microsoft Defender Vulnerability Management to identify Common Vulnerabilities and Exposures (CVEs) on your managed devices. The results are prioritized for remediation and include step-by-step instructions to guide you in using Intune to remediate the threat. It can help you reduce the time it takes to investigate, identify, and remediate threats, ultimately improving your organization's overall security posture.


IVRA recently appeared in my tenant as public preview.

So, how do we get started? There are some prerequisites.


Licensing
  • Intune subscription (check)
  • Microsoft Security Copilot with sufficient SCUs (check)
  • Microsoft Defender Vulnerability Management - This capability is provided by Microsoft Defender for Endpoint P2 or Defender Vulnerability Management Standalone. (mmm, I don't have this in my test tenant. I'll get back to this shortly)

Roles and permissions

To set up and manage the agent, use an account with the following roles:

Intune roles:
  • Read Only Operator or a Custom role with the following permissions:
    • Security Tasks / read
    • Mobile apps / read
    • Device configurations / read
    • Organization / read
Security Copilot roles:
  • Copilot owner
I have all this covered. I'm signed into Intune with an Intune Administrator account which is also a Security Copilot Owner.

To run the agent, the agentic user must be delegated the following permissions. 

Intune roles:
  • Read Only Operator or a Custom role with the following permissions:
    • Mobile apps / read
    • Device configurations / read
Defender roles:

The agentic user must be assigned permissions that align with Microsoft Defender XDR RBAC configurations:
  • Granular RBAC: Custom RBAC role with permissions equivalent to the Unified RBAC Security Reader role
I don't really understand what this means at this stage. What is the agentic user? We'll move on and perhaps this will become clear later on.


Defender Vulnerability Management add-on trial

OK, so back to licensing. I don't have Microsoft Defender Vulnerability Management in my tenant so I can sign up for a trial.


This is very straightforward. Navigate to the Microsoft Defender portal (https://security.microsoft.com) and select Trials. I have M365 E5 licensing in my tenant so I can see the Defender Vulnerability Management add-on. Choose Try now


You'll see further information about the 90 day trial. Click Begin Trial.


The trial is being prepared. Click Done


It can take up to 6 hours for everything to be ready.


However the trial is effective immediately. You can end the trial whenever you like.


The Defender Vulnerability Management add-on is now ready to be assigned to your users.


Set up the Vulnerability Remediation Agent

OK, so we can navigate to the Intune Admin Center to get started with the Vulnerability Remediation Agent. 


Click on AgentsVulnerability Remediation Agent/ View details. 


We are invited to Set up agent.


Here we can see the agent requirements. In particular we are told that the agent will create a new Agentic user to run the agent with and this account must be configured with the correct permissions. We mentioned that before. Let's see what that looks like. Click Set up agent.

The agent has been set up but Run is greyed out. We also see a message that the agent can't complete a run until the required permissions are assigned. What do we need to do here? We can select Go to permissions or navigate to Settings > Permissions.


Ok, now I'll Run readiness check to see where I am.

The Readiness check has failed for Defender and Intune. I can see the Intune Vulnerability Remediation (Security Copilot) identity. This is the Agentic users account which we referred to earlier and it needs to be assigned Intune and Defender permissions. Click on Manage agentic user to take you to the account in Entra ID.


This is the Agentic user account.


Permissions for Agentic user account

I created a static Entra group "IVRA Agent".


I added the Agentic user account to the IVRA Agent group.


The Intune Read Only Operator role satisfies the requirement so I created a role assignment and assigned to the IVRA Agent group.

Next we need to work on the Defender XDR permissions.


In the Defender admin center, navigate to System > Permissions. Under Microsoft Defender XDR, click on Roles.


I clicked to Create custom role.


I named the Role and clicked Next.


I kept in simple and chose All read-only permissions. The documentation list the requirement as: "the agentic user must be assigned permissions that align with Microsoft Defender XDR RBAC configurations: Granular RBAC: Custom RBAC role with permissions equivalent to the Unified RBAC Security Reader role", which isn't particularly clear. Click Apply.


I selected each permission group in turn and chose All read-only permissions. Click Next.


Click Create assignment.


I named the assignment and selected the IVRA agent group. I also kept the default setting of selecting all data sources. Click Add.


Now that the role assignment has been done click Next.


Review the configuration and click
Submit.


The role and assignment have been created. Click
Done.


At this point I ran the readiness check again but it still failed for Intune. Intune role assignments can take some time to take effect.


After a few hours I ran the readiness check again and all the connection tests were successful. Run was no longer greyed out.


Using the Vulnerability Remediation Agent

After you set up the agent, you can run vulnerability assessments, review prioritized suggestions, and track your remediation progress over time.


Click Run.


You can see that the agent is running.


After the agent completes a run, the Overview tab updates with the top vulnerabilities that you should review and address. This tab shows only a few suggestions at a time.


You can view the full list on the Suggestions tab. Use either tab to drill down and review or manage recommendations.


Suggestion 1: update Edge Chromium-based to version 149.0.4022.80 with instructions to remediate.


Suggestion 2: update Google Chrome to version 149.0.7827.155 with instructions to remediate.


Suggestion 3: update Windows 11 (OS and built-in applications), with instructions to remediate.

I hope this helps. Until next time.........