All posts

Red, Blue, and Green: Microsoft Just Named the Job

Red finds the path, blue decides what is real risk, green applies the fix, and the next scan proves it held.

Microsoft published Rethinking security for the age of AI today, written by Hayete Gallot, Executive Vice President of Microsoft Security. It introduces Project Perception, an agentic security architecture that enters public preview on August 3, 2026. Read it. It is the clearest statement I have seen from a major vendor about where defense actually has to go, and one small piece of vocabulary in it matters as much as the product.

Microsoft splits its security agents into three teams. Not two.

Red finds. Blue decides. Green fixes.

Here is how the post defines them, in Microsoft's own words:

“Red team agents identify potential paths to compromise before an attacker can exploit them.”
“Blue team agents investigate, reason over context and determine what represents meaningful risk.”
“Green team agents take corrective actions and strengthen defenses across the environment.”

For thirty years our industry has talked about red and blue. Red breaks in, blue defends. That framing produced an enormous amount of good work, and it also produced the defining pathology of enterprise security: we got very good at generating findings and stayed bad at closing them. The finding was the deliverable. Somebody else, later, would do the fixing, and that somebody was usually an IT team with a ticket queue and no context for why row 400 mattered more than row 12.

Naming the green team is a small act with a large consequence. It says corrective action is a first-class part of security, owned inside the security system rather than handed over the wall. Microsoft is right about this, and the line in that post I think will age best is this one:

“The defining characteristic of the next generation of security systems will not be their ability to generate more alerts.”

The rest of the architecture is right too

Context sits under the models on purpose. Microsoft describes a new cyber stack of six layers: signals and sensors, context, models, harness, agents, and actuators. Agents reason only as well as the picture they are handed, and a picture assembled from three disconnected tools is three pictures. We reached the same conclusion from the other direction building Senserva: configuration, patching and CVEs, and logs have to live in one connected model before any AI on top of them is worth trusting. Risk lives in the overlap. A weak setting is worse on an unpatched machine, and worse still when the logs show it being probed. No amount of model quality recovers context you never joined.

Safety before autonomy. Microsoft states that Project Perception “is built in alignment with Microsoft's Responsible AI principles and inherits the security, compliance, governance and operational controls our customers already rely on.” An agent that can change your tenant is a serious thing to build. The answer is not to slow it down, it is to make every action validated, attributable, and reversible. We hold ourselves to the same bar with Senserva Trustworthy AI: every fix is checked against your real findings before it is offered, and a person approves before anything is applied.

Where Senserva already lives: blue and green

Here is the honest positioning, and the reason I am writing this instead of just resharing the post.

Senserva does not do red. We do not attack your tenant or simulate an adversary. What we have built is a blue team and a green team that share one brain.

The blue half: what is actually real. Senserva runs 650+ checks across Microsoft 365, Intune, Defender, Entra ID, and Purview, reads the patch and CVE state of the estate, and reads the sign-in, audit, and directory logs alongside them. Then it ranks, not by CVSS in isolation, but by what attackers are doing right now, using the CISA Known Exploited Vulnerabilities catalog and FIRST EPSS, weighed against your configuration. That is Microsoft's definition of a blue team agent almost word for word: investigate, reason over context, determine what represents meaningful risk.

The green half: the part most tools skip. Every finding arrives with a plain-language explanation, the control it maps to, and a validated, ready-to-run fix. You review it, you apply it, and the next scan proves the gap closed, which is what turns a fix into evidence. Remediation is not a feature we bolted on to look modern. It is the reason the product exists. A finding you cannot act on is a complaint.

Both halves run off the same model, which is why the ranking is honest and why the fix fits your environment instead of a generic template. When the fix lands, its mapping to CISA SCuBA, the Microsoft cloud security benchmark, NIST, CIS, SOC 2, and HIPAA comes with it, so the audit conversation is a byproduct of the work rather than a separate project.

What this means if you run a small team

Most of the organizations I talk to do not have a red team, a blue team, and a green team. They have three people, or one person, and a Microsoft estate that grew faster than the headcount. The agentic future Microsoft is describing is genuinely good news for them, but only if the green half arrives with it. Alerts scale beautifully. Human remediation capacity does not.

That has been the thesis at Senserva from the start. I spent years at Shavlik Technologies building the first widely used Windows patch scanner, and the lesson I took from it was not about scanning. Finding the problem is the cheap half. Companies of every size deserve the expensive half too, and automation is the only way that math ever works for a team of three.

So read Microsoft's post, and watch Project Perception when it reaches public preview on August 3. If you want the blue and green halves working on your Microsoft 365 tenant this week instead of next year, that part already exists.

Sources

Senserva
Three Free Unlimited Audits
1 scan to find, 2 to review your fixes.
Setup and running in minutes. Your data stays local, in a results database only you hold. Someone from Senserva will work with you.
Everything Siemserva by Senserva does: every missing patch ranked by real attacks, all 650+ security checks, and full reports.
All users · All settings · All patches · All tenants · Rich Claude MCP support
Includes our extensive Claude MCP: everything you need to run full audits.

Free registration is all it takes, no card. Want it always on? Summer Special: unlimited use, up to 50 tenants, $600/mo or $6,500/yr.

Not ready to scan? Follow the work instead: Senserva Watch is free, one email when Microsoft CVEs and KBs change, plus the Patch Tuesday wire on release day.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.