Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Information about AI agents and their properties from various platforms
| Attribute | Value |
|---|---|
| Category | Security, XDR |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes |
| Azure Monitor Tables Reference | View Documentation |
| Defender XDR Advanced Hunting Schema | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AgentId | string | Unique identifier for the agent |
| Availability | string | The deployment scope of the agent (that is, whether deployed to all users, specific groups, or individual users). |
| Capabilities | dynamic | The intents, actions, skills, and orchestrations of the agent. |
| Channels | dynamic | The channels or surfaces where the agent can operate, such as Microsoft 365 applications or APIs. |
| ConnectedAgents | dynamic | List of other agents connected to the agent for multi-agent orchestration. |
| CreatedDateTime | datetime | Date and time when the agent was created. |
| DeclaredDataSources | dynamic | The data repositories and knowledge sources the agent can access. |
| DeclaredTools | dynamic | Functional tools the agent can invoke at runtime. |
| Description | string | Description of the agent as displayed in the agent's source. |
| Endpoints | dynamic | List of agent runtime endpoints, including URL, transport type, and external connectivity flag. |
| EntraAgentID | string | The agent's unique enterprise application object identifier by Microsoft Entra ID |
| EntraBlueprintID | string | The unique identifier by Microsoft Entra ID for the agent identity blueprint, which serves as the template from which the agent's identity was created. |
| Guardrails | dynamic | Guardrails attached to the agent and their coverage. |
| InstanceCount | int | Number of agent instances created from the same Microsoft Entra ID agent identity blueprint. |
| Instructions | string | The agent's system prompt that defines its default behavior, persona, and operating boundaries. |
| LastPublishedDateTime | datetime | Date and time when the agent was last published or deployed. |
| LastUpdatedDateTime | datetime | Date and time when the agent's metadata was last modified. |
| LifecycleStatus | string | The agent's current operational state in the tenant; possible values: Active, Blocked, Uninstalled, Deleted. |
| McpServers | dynamic | The Model Context Protocol (MCP) servers connected to the agent, including server URLs and credential configuration. |
| Memory | dynamic | The agent's declarative memory store configuration. |
| Model | string | The AI model powering the agent. |
| ObservabilityID | dynamic | Unique identifier used to correlate the agent with its usage and activity data in Microsoft Agent 365. |
| Owners | dynamic | Primary owners of the agent. |
| Permissions | dynamic | Permissions record of the agent, including those that have been requested and granted, their approval state, and consent enumeration. |
| Platform | string | The platform that provided the information about the agent. |
| PublishedStatus | string | The agent's publications status: Draft, Published. |
| RawAgentInfo | dynamic | Additional information about the agent, in JSON format. |
| SharedWith | dynamic | The users and security groups the agent has been shared with. |
| Skills | dynamic | Skills attached to the agent. |
| SourceAgentId | string | Native identifier assigned by the platform where the agent originated. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | Date and time the event was recorded by the MDE agent on the endpoint. |
| Timestamp | datetime | Date and time the agent information was recorded. |
| ToolsAuthenticationType | dynamic | Structured summary of agent identity, authentication, and authorization model. |
| Triggers | dynamic | List of the agent's triggers. |
| Type | string | The name of the table |
| Version | string | Version of the agent. |
Official Microsoft Learn documentation for field/column information:
GitHub Only:
| Hunting Query | Selection Criteria |
|---|---|
| AI Agents - Hard-coded credentials in Tools or Configuration | LifecycleStatus != "Deleted" |
| AI Agents - Instructions changed on previously published agent | |
| AI Agents - MCP Tool Configured | LifecycleStatus != "Deleted" |
| AI Agents - Missing Tools in Instructions | Instructions != "N/A" |
| AI Agents - Newly observed MCP server on existing agent | |
| AI Agents - Organization-wide Shared | LifecycleStatus != "Deleted" |
| AI Agents - Orphaned Agents with Disabled Owners | LifecycleStatus != "Deleted" |
| AI Agents - Owner added to MCP-enabled agent | |
| AI Agents - Published Agents with Short Instructions | Instructions != "N/A"LifecycleStatus != "Deleted"PublishedStatus == "Published" |
| AI Agents - Published Agents without Instructions | Instructions == "N/A"LifecycleStatus != "Deleted"PublishedStatus == "Published" |
| AI Agents - Sharing expanded to organization-wide |
References by type: 0 connectors, 7 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
LifecycleStatus != "Deleted" |
- | 4 | - | - | 4 |
Instructions != "N/A" |
- | 1 | - | - | 1 |
Instructions == "N/A"LifecycleStatus != "Deleted"PublishedStatus == "Published" |
- | 1 | - | - | 1 |
Instructions != "N/A"LifecycleStatus != "Deleted"PublishedStatus == "Published" |
- | 1 | - | - | 1 |
| Total | 0 | 7 | 0 | 0 | 7 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= N/A |
- | 2 | - | - | 2 |
N/A |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= Deleted |
- | 6 | - | - | 6 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Published |
- | 2 | - | - | 2 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊