Defender CSPM for AI Pricing: What AI-SPM, Defender for AI Services and Agent 365 Cost in 2026
Try it live
Watch AgentShield block an attack in real time.
Pick a scenario and drive the inspection lane yourself. No signup needed.
Run a request
Runs the live engine on your text. Nothing is stored, no account needed.
Inspection lane
INSPECTINGPolicy trace
High-risk action held for approval
Audit trail
- § · → → →
Securing AI in a Microsoft estate now takes up to three separate purchases: the Defender CSPM plan for AI security posture management at 0.007 USD per billable resource per hour, the Defender for AI Services plan for threat protection on model traffic at 0.0008 USD per 1,000 tokens, and, since July 1, 2026, a Microsoft Agent 365 license for anything at the agent level. Those are Azure list prices in US regions as published in Microsoft's retail price feed in September 2026. The third one is the line most budgets missed.
Microsoft's transition notice is blunt about it: "Effective July 1, 2026, AI agent security capabilities for Microsoft Copilot Studio and Microsoft Foundry agents require a Microsoft Agent 365 license. These capabilities are no longer covered by existing Defender for Cloud Apps or Defender for Cloud licenses." If your team signed off on Defender CSPM last year partly because it discovered Foundry agents, that coverage moved to a different SKU mid-year.
What each Microsoft meter covers, and what it costs
| Meter | List price (US, September 2026) | What it covers for AI | What it no longer covers |
|---|---|---|---|
| Defender CSPM plan | 0.007 USD per billable resource per hour, about 5.11 USD per resource per month | AI security posture management: an AI bill of materials and attack path analysis across Azure OpenAI, Azure AI Foundry, Azure Machine Learning, Amazon Bedrock and Google Vertex AI. It still discovers Foundry accounts and projects | Agent-level discovery and posture for Foundry agents, and discovery of third-party cloud agents through Defender for Cloud connectors |
| Defender for AI Services plan | 0.0008 USD per 1,000 tokens; the trial is capped at 30 days or 75 billion tokens, whichever comes first | Threat protection for model deployments. Microsoft states the plan "continues to support Foundry Models such as Azure OpenAI" | Agent-specific threat alerts for Foundry agents, which now run over Agent 365 observability logs |
| Microsoft Agent 365 | 15 USD per user per month on a yearly standalone plan; included in Microsoft 365 E7 | Agent registry, agent discovery and posture, agent threat detection and real-time protection rules for Copilot Studio and Foundry agents | Agents that do not integrate with its tooling, as Microsoft's own documentation notes |
One detail changes the arithmetic more than any price in that table. Defender CSPM bills only on compute, databases, storage and serverless resources, so the Azure OpenAI or Foundry resources it inventories for AI-SPM are not themselves the billable unit. You pay for posture on the servers, databases and functions around your AI workloads, and the AI coverage rides on that. For most Azure estates that already run Defender CSPM, AI-SPM costs nothing extra. For estates that never enabled it, AI-SPM is the reason to start paying for the whole plan.
A worked example for a mid-sized Azure estate
Take a US company with 300 Defender CSPM billable resources, about 1 billion model tokens a month through Azure OpenAI, and 500 employees who build or use agents in Copilot Studio and Foundry.
| Line item | Calculation | Monthly list cost |
|---|---|---|
| Defender CSPM, including AI-SPM | 300 resources x 0.007 USD x 730 hours | about 1,533 USD |
| Defender for AI Services | 1,000,000 thousand-token units x 0.0008 USD | 800 USD |
| Agent 365, standalone | 500 users x 15 USD | 7,500 USD |
| Total | about 9,833 USD |
The agent line is roughly three quarters of the bill, and it scales with headcount rather than with the number of agents you run. That is the real budgeting consequence of the July change: a team with 12 agents and 500 licensed users pays the same Agent 365 cost as a team with 200 agents and 500 users. Enterprise agreements, Microsoft 365 E7 bundling and Commit Units all move these numbers, so treat list prices as a ceiling for the conversation with your Microsoft account team, not a quote.
Defender charges land on the same Azure invoice as the workloads they protect, which makes them easy to lose inside a large bill. If you already break cloud spend down by service and team, tag these three meters separately so the AI security cost is visible on its own line when the renewal comes around.
The change that quietly turned off blocking
Pricing is the visible part of the transition. The operational part is worse for anyone who relied on Microsoft to stop an agent action. Microsoft's notice says: "Tenants currently configured to Block on existing Agent 365 rules will stop blocking on July 1, 2026." To resume blocking, rules have to be redefined under the new real-time protection policy experience in the Defender portal.
So there are three checks worth running this week, whatever you decide to buy.
- Confirm the licensing state of the tenant. Tenants without an Agent 365 eligible license lost agent discovery, posture and threat detection on July 1, 2026, and the Defender portal now shows licensing guidance in place of the agent inventory.
- Re-create any blocking rules. If you had Agent 365 real-time protection set to block, check whether anyone redefined those rules after July 1. If nobody did, the rules audit and nothing is stopped.
- Update hunting queries and third-party agent discovery. The
AIAgentsInfotable is being replaced byAgentsInfo, and third-party cloud agents now need the Agent 365 registry sync instead of Defender for Cloud connectors.
If you are evaluating Agent 365 now, Microsoft offers admin-led trials for 25 seats for 30 days. Our Microsoft Agent 365 security page covers what its rules do and do not stop, and Microsoft Agent 365 alternatives covers the options for teams that do not want per-user licensing for agent security.
Should you pay for all three?
Buy Defender CSPM if you run AI workloads on Azure and already use Defender for Cloud; buy Defender for AI Services if you expose Azure OpenAI deployments to untrusted input; buy Agent 365 only if most of your agents live in Copilot Studio and Foundry and you want Microsoft's registry as the source of truth. That is the honest answer, and it means many teams should buy at least one Microsoft meter before they buy anything from us.
| Your situation | What to buy | Why |
|---|---|---|
| Azure-centric estate, agents mostly in Copilot Studio and Foundry | Defender CSPM plus Agent 365 | Microsoft owns the inventory and the agent runtime; one console is worth a lot |
| Azure OpenAI apps exposed to customers, few agents | Defender CSPM plus Defender for AI Services | Token-priced threat protection matches the risk; per-user agent licensing does not |
| Agents spread across Azure, AWS, Google and custom code | A posture tool for discovery, plus a runtime control that works across clouds | Agent 365 is strongest on Microsoft-built agents; see our AI-SPM tools comparison for the cross-cloud options |
| Agents that issue refunds, change records or move money | Whatever you choose above, plus per-action authorization | Posture finds risk and threat detection raises alerts; neither decides whether this specific action should happen |
The last row is where AgentShield fits, and it is a narrow fit on purpose. Every Microsoft meter above either describes your AI estate or detects threats in it. None of them decides, per tool call, that this agent may read the order but not refund it, or that this refund above 500 USD waits for a person. That is AI agent permissions management and human approval gates, applied in the action path for agents on any cloud. For Foundry specifically, our Microsoft Foundry security page maps which Microsoft control covers which layer.
Our prices are on the pricing page, billed per plan rather than per user, so you can compare them to the Agent 365 line in the example above without a sales call.
See the firewall block an attack live.
Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.