{"id":20623,"date":"2025-10-16T09:05:00","date_gmt":"2025-10-16T16:05:00","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=20623"},"modified":"2026-06-17T09:19:50","modified_gmt":"2026-06-17T16:19:50","slug":"vuln-ai-our-ai-powered-leap-into-vulnerability-management-at-microsoft","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/vuln-ai-our-ai-powered-leap-into-vulnerability-management-at-microsoft\/","title":{"rendered":"Vuln.AI: Our AI-powered leap into vulnerability management at Microsoft"},"content":{"rendered":"\n

In today\u2019s hyperconnected enterprise landscape, vulnerability management is no longer a back-office function\u2014it\u2019s a frontline defense. With thousands of devices from a multitude of vendors, and a relentless stream of Common Vulnerabilities and Exposures (CVEs), here at Microsoft we faced a challenge familiar to every IT decision maker: how to scale vulnerability response without scaling cost, complexity, or risk.<\/p>\n\n\n\n

\"A<\/figure>\n\n\n\n
\n

\u201cWhile AI enables amazing capabilities for knowledge workers, it also increases the threat landscape, since bad actors using AI are constantly probing for vulnerabilities. Vuln.AI helps keep Microsoft safe by identifying and accelerating the mitigation of vulnerabilities in our environment.\u201d<\/p>\nBrian Fielder, vice president, Microsoft Digital <\/cite><\/blockquote>\n\n\n\n

Enter Vuln.AI, an intelligent agentic system developed by our team in Microsoft Digital\u2014the company\u2019s IT organization\u2014to transform how we identify, prioritize, and resolve vulnerabilities across our enterprise network.<\/p>\n\n\n\n

Manual methods can\u2019t keep up<\/h2>\n\n\n\n

As a company, we detect over 600 million cybersecurity threats every day, according to our latest Digital Defense Report<\/a>. Some of those signals are bad actors probing our internal network and infrastructure looking for unpatched vulnerabilities. Our infrastructure supports over 300,000 employees and vendors, 25,000 network devices, and over 560 buildings across 102 countries. This scale means we face a constant stream of vulnerabilities\u2014each requiring triage, impact analysis, and remediation.<\/p>\n\n\n\n

\u201cWhile AI enables amazing capabilities for knowledge workers, it also increases the threat landscape, since bad actors using AI are constantly probing for vulnerabilities. Vuln.AI helps keep Microsoft safe by identifying and accelerating the mitigation of vulnerabilities in our environment,\u201d says Brian Fielder, a vice president within Microsoft Digital. <\/p>\n\n\n\n

Historically, our Infrastructure, Networking, and Tenant team here in Microsoft Digital relied on manual assessments to determine which network devices were impacted by new vulnerabilities. Traditional vulnerability scanning tools generate a lot of false positives and false negatives, and a significant amount of analysis still falls to security engineers, requiring manual validation before any vulnerability impact can be communicated to device owners. These manual methods were time-consuming, error-prone, and reactive\u2014our security engineers were spending hours on each vulnerability, at times missing critical threats or sinking too much time into false alarms.<\/p>\n\n\n\n

\"A<\/figure>\n\n\n\n
\n

\u201cAI\u2019s true power lies in the problem it\u2019s applied to. Start by identifying the most time-consuming or painful task in your organization-then explore how AI can augment or improve it. Begin with a small, targeted enhancement and iterate continuously.\u201d<\/p>\nAnkit Bansal, senior product manager, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n

With the vast number of vulnerabilities coming in every day, security engineers needed a scalable way to quickly analyze, prioritize, and respond.<\/p>\n\n\n\n

The solution: Vuln.AI<\/h2>\n\n\n\n

We already achieved dramatic impact with our AI Ops and Network Infrastructure Copilot<\/a>, which is on track to save us over 11,000 hours of network service management time per year. We built Vuln.AI on top of that investment:<\/p>\n\n\n\n

    \n
  1. The Research Agent<\/strong> analyzes vulnerability feeds and network metadata from our Infrastructure Data Lakehouse (IDL) built on top of Azure Data Explorer, which regularly ingests data from our device vendors and other sources. Once new vulnerabilities are detected, it automates the identification of impacted devices and integrates with other internal tooling for validation and reporting.<\/li>\n\n\n\n
  2. The Interactive Agent<\/strong> acts as a gateway for engineers and device owners to ask follow-up questions and initiate remediation. Through agent-to-agent interaction, it leverages our Network Infrastructure Copilot to query the research agent\u2019s findings. This agentic interface enables real-time decision-making and contextual insights.<\/li>\n<\/ol>\n\n\n\n

    Together, these agents are significantly improving our network security operations. The results we\u2019re seeing so far are compelling:<\/p>\n\n\n\n