Agent Configuration and Access Policy Tampering Detection
This rule detects potentially malicious modifications to agent configurations by monitoring for multiple significant changes within a short time frame (2 days) compared to a 14-day baseline. Monitored indicators include: changes to instructions, addition of new Model Context Protocol (MCP) servers, addition of new owners, and expansion of access permissions to include the entire organization. An alert is triggered when an agent exhibits at least two of these signals simultaneously. The query builds a 14-day baseline snapshot and a 2-day current snapshot per agent from AgentsInfo, computes the four signals independently, then correlates them by AgentId and surfaces only agents with 2 or more signals firing in the same window. Output is a prioritized triage list instead of four separate alert streams.
Microsoft Sentinel (KQL)

