Skip to content

Commit 430eab9

Browse files
Merge pull request #19189 from paolomatarazzo/pm-20251120-agents
[Agents] Feedback CCP
2 parents f495996 + 77b3c2c commit 430eab9

File tree

8 files changed

+37
-8
lines changed

8 files changed

+37
-8
lines changed

intune/agents/change-review-agent-use.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -137,15 +137,14 @@ Security Copilot logs include all agent management actions and permission failur
137137

138138
[!INCLUDE [errors](includes/errors.md)]
139139

140-
### Security Copilot couldnt retrieve details for this factor at this time
140+
### Security Copilot couldn't retrieve details for this factor at this time
141141

142142
The agent was unable to retrieve details related to the specified factor. The exact reason for this failure is unknown.
143143

144144
### Couldn't complete your request. Security Copilot doesn't currently support that type of request
145145

146146
The agent cannot proceed because the request violates Microsoft's Responsible AI policies. This typically occurs when the system detects a prohibited action, like a prompt injection attempt.
147147

148-
149148
## Related content
150149

151150
- [Change Review Agent in Intune](change-review-agent.md)

intune/agents/change-review-agent.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.reviewer: zinebtakafi
1010

1111
# Change Review Agent overview
1212

13-
In public preview, the Microsoft Intune Change Review Agent uses Microsoft Security Copilots generative AI to evaluate Multi Admin Approval requests for PowerShell scripts on Windows devices. It provides risk-based recommendations and contextual insights to help administrators understand script behavior and associated risks. These insights help Intune administrators make informed decisions more quickly about whether to approve or deny requests.
13+
In public preview, the Microsoft Intune Change Review Agent uses Microsoft Security Copilot's generative AI to evaluate Multi Admin Approval requests for PowerShell scripts on Windows devices. It provides risk-based recommendations and contextual insights to help administrators understand script behavior and associated risks. These insights help Intune administrators make informed decisions more quickly about whether to approve or deny requests.
1414

1515
To generate these recommendations, the agent aggregates signals from multiple sources:
1616

@@ -111,7 +111,7 @@ The agent analyzes these signals to assess the potential risk associated with ea
111111
>
112112
> For details about mapping permissions to the Unified RBAC Security Reader role, see [Microsoft Entra Global roles access](/defender-xdr/compare-rbac-roles#microsoft-entra-global-roles-access) in the *Map Microsoft Defender XDR Unified role-based access control (RBAC)* article in the Defender documentation.
113113
>
114-
> Ensure the agents identity is scoped in Microsoft Defender to include all relevant device groups. The agent can't access or report on devices outside its assigned scope.
114+
> Ensure the agent's identity is scoped in Microsoft Defender to include all relevant device groups. The agent can't access or report on devices outside its assigned scope.
115115
>
116116
> :::image type="icon" source="../media/icons/admin-center/copilot.svg" border="false"::: Security Copilot roles:
117117
> - [Copilot owner](/copilot/security/authentication#security-copilot-roles)
@@ -160,27 +160,27 @@ At a high level, the agent does the following steps each time it runs:
160160
- Needs more info - Risk couldn't be fully assessed. This request requires further review.
161161

162162
Each recommendation includes supporting details that explain:
163-
- The rationale behind the agents recommendation.
163+
- The rationale behind the agent's recommendation.
164164
- What the script is intended to accomplish or do.
165165
- A detailed list of factors that the agent reviewed as part of its process.
166166

167167
## Agent identity
168168

169-
The agent runs under the identity and permissions of the Intune admin account used during setup. The agents actions are limited to the permissions of that account, and the identity refreshes with each run. If the agent doesnt run for 90 consecutive days, its authentication expires, and subsequent runs fail until its renewed. To maintain functionality, renew the agent identity before the 90-day limit.
169+
The agent runs under the identity and permissions of the Intune admin account used during setup. The agent's actions are limited to the permissions of that account, and the identity refreshes with each run. If the agent doesn't run for 90 consecutive days, its authentication expires, and subsequent runs fail until its renewed. To maintain functionality, renew the agent identity before the 90-day limit.
170170

171171
## Operational considerations
172172

173173
Before setting up and starting the agent for the first time, review the following considerations:
174174

175-
- An admin must manually start the agent. Once started, theres no option to stop or pause it.
175+
- An admin must manually start the agent. Once started, there's no option to stop or pause it.
176176
- The agent can only be started from the Microsoft Intune admin center.
177177
- Session details in the [Microsoft Security Copilot portal](https://go.microsoft.com/fwlink/?linkid=2247989) are visible only to the user who set up the agent.
178178
- The agent reviews and then provides recommendations for a maximum of 10 requests per run.
179179
- Only one agent instance is supported per tenant/user context.
180180

181181
## Set up the agent
182182

183-
The agent operates under the identity and permissions of the Intune admin account used during setup. Its operations are limited to the permissions of that account, and the identity refreshes with each run. Any changes to the accounts permissions affect the agents capabilities during its next run.
183+
The agent operates under the identity and permissions of the Intune admin account used during setup. Its operations are limited to the permissions of that account, and the identity refreshes with each run. Any changes to the account's permissions affect the agent's capabilities during its next run.
184184

185185
**To set up the Change Review Agent:**
186186

@@ -199,6 +199,8 @@ To learn more about using the agent, see [Use the Change Review Agent](change-re
199199
<!-- ## Remove the agent -- H2 header is in the Include: -->
200200
[!INCLUDE [remove](includes/remove.md)]
201201

202+
[!INCLUDE [feedback](includes/feedback.md)]
203+
202204
## Related content
203205

204206
- [Use the Change Review Agent](/intune/agents/change-review-agent-use)

intune/agents/device-offboarding-agent.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -243,6 +243,8 @@ Include only devices with last activity before […]
243243

244244
[!INCLUDE [remove](includes/remove.md)]
245245

246+
[!INCLUDE [feedback](includes/feedback.md)]
247+
246248
## Next steps
247249

248250
> [!div class="nextstepaction"]

intune/agents/icons/feedback.svg

Lines changed: 9 additions & 0 deletions
Loading

intune/agents/includes/feedback.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
author: paolomatarazzo
3+
ms.author: paoloma
4+
ms-topic: include
5+
ms.date: 11/20/2025
6+
---
7+
8+
## :::image type="icon" source="../icons/feedback.svg" border="false"::: Help shape the future of Intune agents
9+
10+
Join our **Intune Agents Feedback Forum** to share insights and influence upcoming capabilities in Microsoft Intune.
11+
12+
Sign up and learn more: https://aka.ms/IntuneAgentsForum

intune/agents/index.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,7 @@ While this article focuses on Intune agents, similar agents are available across
9393

9494
- [Microsoft Security Copilot agents overview](/copilot/security/agents-overview)
9595

96+
[!INCLUDE [feedback](includes/feedback.md)]
9697

9798
<!-- admin center links -->
9899

intune/agents/policy-configuration-agent.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -197,6 +197,8 @@ When it completes, the agent is ready to use. To learn more about using the agen
197197

198198
[!INCLUDE [remove](includes/remove.md)]
199199

200+
[!INCLUDE [feedback](includes/feedback.md)]
201+
200202
## Related content
201203

202204
- [Use the Policy Configuration Agent](policy-configuration-agent-use.md)

intune/agents/vulnerability-remediation-agent.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -219,6 +219,8 @@ To assign a new identity, in the [Intune admin center](https://go.microsoft.com/
219219
> [!NOTE]
220220
> To remove the agent instance, your account must be a Security Copilot *Owner*.
221221
222+
[!INCLUDE [feedback](includes/feedback.md)]
223+
222224
## Next steps
223225

224226
> [!div class="nextstepaction"]

0 commit comments

Comments
 (0)