Microsoft launches a Security Store with SaaS tools and AI agents from Darktrace and others, and now lets Security Copilot users build their own AI agents
Tom Warren / The Verge :
Context & Ripple Effects
Microsoft had already consolidated Security Copilot, Sentinel and Defender XDR into a unified security operations platform, creating a common operating surface for AI-assisted investigations. It later broadened the agent model with an Agent Store for Researcher and Analyst, making a dedicated security marketplace a targeted extension rather than a standalone launch.
The new store matters because it combines third-party security software distribution with customer-built Copilot agents in the same Microsoft environment. That places vendor tools and bespoke workflows closer to the security operations stack enterprises already use.
First-order effects
- Security Copilot customers can create agents for their own security workflows, while vendors such as Darktrace gain a Microsoft-operated route to reach those customers through the Security Store.
- Microsoft expands Security Copilot from an assistant for investigation and reporting into a platform that can host both partner offerings and customer-specific automation.
Second-order effects
- Security vendors face stronger incentives to package integrations and agents for Microsoft’s store, while buyers can evaluate third-party tools within the environment where their security data and workflows already reside.
- Security teams must weigh the convenience of reusable and custom agents against added review, access-control and monitoring work, since each agent can act on sensitive operational context.
Third-order effects
- If adoption persists, security platforms may compete less on a single built-in copilot and more on the quality of their agent ecosystem, integration controls and governance layer.
- The move strengthens the broader shift toward security operations as an agent-managed environment, where platform owners become important gatekeepers for third-party automation and enterprise-built agents.
The trend: Enterprise security is evolving from standalone AI assistants toward governed marketplaces of vendor and customer-built agents embedded in core operations platforms.