What Can You Do Here?
Run Manual Investigations
Automate by Severity
Enable Gamebook Execution
Set Confidence Thresholds
Prerequisites
Before configuring Security Delivery Agents, ensure you meet the following requirements.| Requirement | Description |
|---|---|
| Agent Center Deployed | Microsoft Foundry infrastructure must be provisioned |
| ContraForce Roles | Organizational Admin and Workspace Owner roles required |
Phase 1: Manual Agent Execution
In this initial phase, you manually select individual incidents and trigger the agent to run investigations. This allows you to evaluate agent performance before enabling automation.Running Agent Investigation
Open an Incident
Access Actions Menu
Choose Investigation Type
- Run Agent Investigation — Agent analyzes the incident and provides findings without taking remediation actions
- Run Agent Investigation and Response — Agent analyzes the incident and executes recommended response actions
Review Results
Investigation Options
| Option | Description | When to Use |
|---|---|---|
| Run Agent Investigation | Analysis only, no response actions | When you want to review findings before taking action |
| Run Agent Investigation and Response | Analysis plus automated response | When you trust the agent to execute appropriate responses |
Phase 2: Automatic Execution Based on Severity
Once you’re comfortable with agent behavior, configure automatic execution based on incident severity and status.Configuring Automatic Execution
Navigate to Agent Center
Set Mode to On Queue
Configure Status Filters
- New — Agent runs on newly created incidents
- Active — Agent runs on incidents currently being worked
- Closed — Agent runs on closed incidents for retrospective analysis
Save Configuration
Status Filter Options
- New
- Active
- Closed
- Agent triggers immediately when incidents are created
- Provides rapid initial triage and analysis
- Recommended for high-volume environments
Phase 3: Automatic Gamebook Execution
In this advanced phase, you enable the agent to automatically execute gamebooks based on confidence thresholds.Enabling Automatic Gamebook Execution
Navigate to Agent Center
Enable Gamebook Execution
Set Confidence Level
Save Configuration
Understanding Confidence Levels
| Confidence Level | Behavior | Recommended For |
|---|---|---|
| High | Agent requires strong evidence before taking action | Production environments, sensitive systems |
| Medium | Balanced approach between automation and caution | Most standard deployments |
| Low | Agent takes action with less certainty | Test environments, high-volume low-risk scenarios |
Configuration Summary
- Phase 1
- Phase 2
- Phase 3
- User selects individual incidents
- User triggers agent via Actions menu
- User reviews results before any response
- Best for: Initial evaluation and building trust
Best Practices
Progress through phases sequentially
Progress through phases sequentially
Review agent outputs during manual execution
Review agent outputs during manual execution
Set conservative confidence levels initially
Set conservative confidence levels initially
Monitor automated actions regularly
Monitor automated actions regularly
Document your configuration choices
Document your configuration choices
Troubleshooting
Common Issues
| Issue | Possible Cause | Solution |
|---|---|---|
| Agent not processing incidents | Mode not set to On Queue | Verify Mode is set to On Queue in Agent Center |
| Gamebooks not executing | Feature not enabled | Confirm “Allow Agent to run gamebooks” is toggled on |
| Too many automated actions | Confidence threshold too low | Increase confidence level setting |
| Agent missing incidents | Status filters misconfigured | Review and adjust status filter selections |
| Investigation not starting | Missing permissions | Verify Organizational Admin and Workspace Owner roles |