On October 1, 2026, Microsoft published its annual security report, the Microsoft Digital Defense Report 2026. Its central theme is that AI has begun to spread across both offense and defense. Attackers are using AI for reconnaissance, phishing and malware development, but so far mostly to speed up parts of existing attack workflows. At the same time, the AI agents that companies are rolling out have become something that must be protected.
Where Attackers Are Using AI
According to the report, threat actors are applying AI to reconnaissance, social engineering, the development of malware and exploit code, and activity after a breach. For now, the report describes this as making specific steps of established attack workflows more efficient, rather than AI running an entire attack on its own.
What AI mainly adds is speed, scale and ease of tailoring. Phishing messages and fake contacts can be crafted more precisely for each target, and automating parts of the technical work shortens attack preparation. Even so, the entry points attackers go after remain the traditional ones: people, identities, exposed systems and trusted access.
The Threat Landscape in Numbers
The report also conveys the scale of what Microsoft observes. It processes more than 165 trillion security signals per day, analyzes an average of 31 million identity-risk detections per day, blocks 4.7 million net-new malware files per day and screens 5.2 billion emails per day.
On the attacks themselves, the report cites the following figures.
- Among intrusions using valid accounts, 52.2 percent were followed by credential theft.
- More than 46 million attacks impersonating business contacts were detected over 12 months.
- The median time between a vulnerability being discovered and being exploited in the wild has fallen well below 24 hours.
By sector, government agencies accounted for 27 percent of observed activity, up from 17 percent in 2025.
In other words, attacks are getting faster, yet the way in is still old-fashioned account takeover and impersonation. The numbers suggest that attacks on basic weaknesses still cause more damage than flashy new techniques.
Securing AI Agents
The report urges readers to treat AI not as a standalone model but as part of the enterprise system. Agents connect to internal data, applications, APIs and tools, with different levels of access and autonomy depending on design. The connections that make them useful also widen what must be protected.
The items it examines are the agent's own identity, appropriate access, authentication between agents, attribution of actions, and whether access can be revoked at any time. It also covers AI-specific issues such as prompt injection, memory, models and data, agent behavior, and the integrity of software and services.
According to commentary on the report, 88 percent of enterprises are already experimenting with AI agents, and the risks fall into five groups: prompt and intent manipulation, sensitive data exposure, identity and privilege compromise, excessive agency, and operational integrity.
What Administrators Can Do Now
The report puts more weight on thoroughly applying the basics than on hunting for new countermeasures. Identity and authorization, data protection, least privilege, monitoring, testing and secure software development remain the foundation in the AI era. Commentary lists concrete steps for administrators such as these.
- Adopt phishing-resistant authentication such as passkeys
- Inventory service principals, app registrations and agents together with their permissions
- Prepare procedures to revoke agent access quickly
- Apply sensitivity-aware access controls before expanding AI rollouts
- Continuously monitor newly exposed cloud assets
- Audit and control browser extensions
- Correlate identity, endpoint, email and cloud logs
- Train staff against voice phishing and QR-code deception
Summary
The Microsoft Digital Defense Report 2026 shows that AI makes attacks faster, broader and more tailored, while the places being targeted are still the familiar ones, such as identities and exposed systems. As AI agent adoption grows, managing and revoking agent permissions becomes more important. Reviewing your own identity management and permission inventory looks like the first step for the AI era.
