TL;DR: Agentic SOC platforms for Microsoft Sentinel now differentiate on investigation depth, not just alert ingestion, as D3 says its Morpheus triages up to 95% of alerts in under two minutes while Copilot remains strongest in narrower, partly previewed workflows. The governance issue is whether teams need an assistant that summarizes or an agentic layer that completes evidence-backed investigations across Microsoft and non-Microsoft telemetry.
NHIMG editorial — based on content published by D3: LLMjacking: How Attackers Hijack AI Using Compromised NHIs
By the numbers:
- D3 says Morpheus triages up to 95% of Sentinel alerts in under two minutes.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope.
Questions worth separating out
Q: How should security teams decide whether a Sentinel agent is operationally ready?
A: Treat readiness as an evidence-completion test.
Q: Why do mixed Microsoft and non-Microsoft estates need a different agentic SOC model?
A: Because attack paths do not stop at the SIEM boundary.
Q: What do teams get wrong about Copilot-style SOC assistance?
A: They confuse assisted triage with autonomous investigation.
Practitioner guidance
- Test investigation completion, not just triage speed. Run the same Sentinel alert through candidate platforms and verify whether each one reaches an evidence-backed conclusion across identity, endpoint, email, and cloud.
- Map your estate type before comparing platforms. Classify the environment as pure Microsoft, Microsoft-primary, or multi-vendor with Sentinel, then score each tool against that reality.
- Require governed handoff conditions. Define the confidence threshold, uncertainty trigger, and human escalation point before deployment.
What's in the full article
D3's full article covers the operational detail this post intentionally leaves for the source:
- Platform-by-platform evaluation criteria for Microsoft Sentinel agentic SOC options
- GA versus preview status for Microsoft Security Copilot agents and what that means operationally
- Estate-type comparisons for pure Microsoft, Microsoft-primary, and multi-vendor environments
- Pricing and procurement considerations, including Azure committed spend and marketplace eligibility
👉 Read D3's analysis of agentic SOC options for Microsoft Sentinel →
Microsoft Sentinel agentic SOCs: are your investigations complete?
Explore further
Investigation completion is now the control plane, not alert ingestion. Sentinel already solves collection and correlation; the question is whether a platform can carry an alert all the way to a defensible conclusion. That shifts value from detection volume to investigation depth, and it changes how teams should judge any agentic SOC claim. Practitioners should treat incomplete investigations as an operational gap, not a feature gap.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: Who should own the governance of an agentic SOC platform?
A: SOC, IAM, and security architecture should own it together. Once a platform can inspect identity evidence, trigger response, and preserve audit trails, it becomes part of the identity control plane. Procurement alone is not enough because operating boundaries and escalation rules define the real risk.
👉 Read our full editorial: Agentic SOC for Microsoft Sentinel exposes the investigation gap