Reading view

There are new articles available, click to refresh the page.

Microsoft 2.5: New security business chief Hayete Gallot on the company’s push into the agentic era

Hayete Gallot, now executive vice president of Microsoft Security, speaks at a Microsoft event in France in 2024. (Microsoft Photo)

GeekWire is profiling over the next few weeks some of the people and teams that are shaping the evolution of Microsoft in what we’re calling its “Microsoft 2.5” era.

AI has had an impact on just about every tech-product category, but especially security. Attackers are using AI; customers are looking to defend with AI. The goalposts keep shifting. “Agentic security” is now the holy grail, and Hayete Gallot, the newly minted executive vice president of Microsoft Security, is leading the charge toward it.

Gallot, a 16-plus-year Microsoft veteran who rejoined the company in February after a 1.5-year Google detour, replaced Charlie Bell, who came to Microsoft from AWS in 2021 and continues at the company as an individual contributor focused on engineering quality.

“Customers care about two things: solving for security and being able to afford it,” Gallot said when I asked during our interview this week why she came back to Microsoft.

“I am a problem solver. And an engineer at heart (and by training). Security is the most important problem right now — and Microsoft is the only place with all of the puzzle pieces to help our customers.”

Since her return, Gallot hasn’t been shy about shaking things up. As noted recently by The Information, at least nine corporate vice presidents who previously reported to Bell have left the company this year.

“We’re making changes to ensure we’re in the best formation to go after this opportunity,” she acknowledged.

“I’m motivated by doing the right thing for our customers, my teams, and tech outcomes,” she said. “I like to move quickly: days and weeks, not months and years, learning through execution, iterating rapidly, and adjusting based on real customer signals.”

The company isn’t starting from scratch. As of 2021, Microsoft claimed security was a $10 billion business for the company. By 2023, security had reached a $20 billion annual revenue rate, officials said.

Those claims haven’t been without controversy. Microsoft has built a huge business in finding and fixing security problems which some customers felt were of the company’s own making.

Microsoft has a wide-ranging and rather unwieldy security portfolio, encompassing identity management (Entra), endpoint protection (Defender), endpoint management (Intune), security information and event management (Sentinel), and compliance (Purview), among others.

In 2023, Microsoft introduced its Security Copilot set of AI analysis services that integrated with some of its existing security offerings. But a portal-based solution like Security Copilot doesn’t offer the kind of end-to-end coverage that an agentic security platform can, Gallot said.

The problem is that attackers are using agents, too. Customers need real-time insight into what’s happening in their environment, and the ability to act just as quickly, Gallot said.

Agentic security is about “taking the signals and turning them into a graph that is useful,” Gallot said. “If you’re trying to reason about 100 trillion signals, it’s not really effective.” The graph, she said, lets agents pick the right model for each threat and close the loop.

In practice, that means the system can quarantine a device or revoke access on its own, for example, rather than waiting for a human.

Microsoft’s core existing security products will continue to play a role as the landscape evolves, both spotting the problems and acting on them. Security Copilot isn’t going away in the process: “You’ll have Copilot and you’ll have agentic security,” she said.

The company’s new Agent 365 “control plane” — a central console for tracking every AI agent a company runs — fits in by letting customers see the “blast radius” of an agent, meaning everything a hijacked agent could reach, Gallot said. It’s similar in concept to Zero Trust, the “never trust, always verify” security model that limited how far an attacker could get with a stolen employee login, but applied now to agents rather than people.

So what exactly is this ‘agentic security’ thing? Microsoft has a whole website dedicated to the very topic.

Traditional AI security and agentic AI security are fundamentally different, Microsoft says. Agentic security doesn’t just protect models and training data; it also can protect tools, workflows, memory, connected systems and more. Because agents can take action, the potential positive and negative stakes are higher.

While AI has helped businesses make strides in finding and fixing vulnerabilities, it hasn’t gone much beyond that. Microsoft introduced its multi-model agentic scanning harness (MDASH) as its first step into the agentic security space, Gallot said.

The company used MDASH internally to boost finding and fixing Windows security issues, and it is now making it available to select customers in an expanded preview. MDASH will allow customers to use the best model for the right task to secure all different types of code bases, she said.

Microsoft is rumored to be readying a more comprehensive agentic security offering, of which MDASH is likely just one piece.

Microsoft is far from the only one doing this. AWS, Anthropic, and OpenAI are offering security tools on their platforms, and dedicated security vendors are building their own agentic platforms.

Microsoft has the advantage of scale in the enterprise. The question is whether Gallot and her new leadership team can turn that scale and emerging AI tools into both a bigger business for the company and better protection for its customers.

Microsoft 2.5: A new series on the people shaping the company’s future

Nearly 20 years ago (!), in 2007, I published my first and only book: Microsoft 2.0. It focused on changes I expected at the company in the “Post-Gates” era. What would remain the same and what likely would be different once co-founder and CEO Bill Gates had left the building?

CEO Satya Nadella has not exited the company (yet). But there’s no question that Microsoft and its mission have morphed considerably in the past year or two. I’m not quite ready to christen this the Microsoft 3.0 era, even though Nadella handed the reins of Microsoft’s dominant commercial business to Judson Althoff nearly a year ago.

That decision resulted in Nadella moving into more of a “founder mode” role, allowing him to focus less on the day-to-day work of running the business. (Microsoft historians may recall that Gates made a somewhat similar move back in 2000 when he became Microsoft’s chief software architect.)

While it might not yet be time for Microsoft 3.0, we arguably could be in the “Microsoft 2.5” era. Windows and Office are still around and still play a big role. Microsoft still builds and sells developer tools and databases. But there’s no question that the cloud and all things AI are at the top of the pecking order now.

I’m embarking on a series here at GeekWire that will focus on what matters to Microsoft and, by extension, to its customers, partners, investors, and employees these days. Who are some of the people shaping and leading the company? What are their opportunities and challenges right now?

Over the next few weeks, I will be profiling various Microsoft execs working on plans for Microsoft’s ongoing evolution. Some are company veterans; some are newcomers. I’ll be talking with top execs from Microsoft’s Security, Copilot, Windows + Devices, Xbox, GitHub, and more.

I’m interested in their strategies for Microsoft’s key products and technologies and how they plan to try to turn Microsoft’s ambitious vision into reality. What are their teams building? What do they see as their biggest challenges and opportunities? And where do they see the technologies in their respective areas heading?

I feel like many of us who’ve been keeping track of the biggest tech companies (myself included) have fallen into the trap of blaming or attributing everything a company does to AI. Layoffs? AI is the culprit. Price increases? It’s all thanks to AI. Changing sales strategies? Chalk it up to AI …

But upon further reflection, I believe Microsoft’s strategy is more nuanced than “AI or bust.” There’s no question that Microsoft’s AI ambitions are shaping its goals and tactics. But Microsoft, as a heavily enterprise-focused entity, can’t simply stop supporting products that aren’t built from the ground up with AI (as much as it might like to do so). Nor can it just leave behind customers who aren’t 100% onboard with its AI moves.

Couple those enterprise hurdles with some not-so-popular consumer decisions, like axing 3,200 people in the gaming unit, and Microsoft’s approach to turning the ship looks a lot trickier.

Read the first installment in the series, profiling new Microsoft Security EVP Hayete Gallot, who’s revamping the group’s leadership as the company pushes into the agentic security.

Mary Jo Foley: What’s a consumer-focused outsider doing at the helm of Microsoft’s AI push?

Jacob Andreou speaks onstage during TechCrunch Disrupt 2023. (Photo by Kimberly White/Getty Images for TechCrunch, CC By 2.0)

It’s not surprising that Microsoft is looking to turn its Copilot platform into a “Super App,” given that its rivals are doing the same. But Microsoft is going about the task in a way that doesn’t follow its usual playbook, by putting a big bet on a consumer-savvy hire from the outside with some feather-ruffling ways.

The company’s newly minted Copilot Executive Vice President Jacob Andreou came to Microsoft from Greylock Partners and before that, Snapchat-maker Snap. Andreou currently oversees more than 11,000 Microsoft employees, according to a recent profile in Fortune.

Microsoft is bringing onboard another former Snap (and Discord) vice president, Peter Sellis, to help, GeekWire has learned. Sources say Sellis will be leading Copilot Design, Growth and Engineering, reporting to Andreou.

Andreou is part of a recently formed Copilot Leadership Team. His charter is to lead the “Copilot experience” by driving design, product, growth and engineering, as outlined in a March 2026 reorg memo from CEO Satya Nadella. He is one of a small group charged with shaping the future of Copilot, alongside others focused on the underlying Copilot platform and AI models.

Given Andreou’s Snap background, his plan to meld Microsoft’s consumer and enterprise Copilot experiences makes sense. It won’t be a snap, however. (See what I did there?)

Even though both share the Copilot brand, consumer Copilot and Microsoft 365 Copilot don’t work the same way or use the same data sources or architecture. To boot, Microsoft hasn’t had a lot of luck with this kind of consumer-enterprise unification, as evidenced by the low interest in and uptake of its free, consumer-focused Teams product compared to its business-focused Teams collaboration offering.

The 33-year-old, Los Angeles-based Andreou seemingly is undaunted by the challenge and is pushing some employees to clock 12-hour days to keep up with younger, AI-focused companies, Fortune reports.

Microsoft was infamous for requiring employees to work long hours and weekends during crunch times leading up to delivering Windows NT and Windows 95, but not so much in recent years. Microsoft is known as a place where outsiders often struggle to thrive compared to those who climb the corporate ladder for years, making Andreou’s approach feel even riskier.

Andreou has been a big backer of the Tasks productivity layer in consumer Copilot, which is still in public preview. Tasks, which enables Copilot to handle actionable items, is similar to the recently released Copilot Cowork layer that is part of Microsoft 365 Copilot. (I asked Microsoft if the two would merge as a single Cowork-type offering at some point but was told the company had no comment.)

However, the holy grail remains the “Super App.” With the Copilot Super App, Microsoft is looking to give consumers and business users a reason to stay within Copilot regardless of the AI task with which they – or their agents – are engaging.

“Come summer, we will be bringing coding to all knowledge work within one Copilot Super App. That’s really exciting. So you’re going to have Chat, Cowork, and Code all in Copilot,” Nadella told Microsoft Build conference attendees in early June.

Microsoft isn’t the only AI-focused company working on extending its AI coding capability beyond just developers. Nor is it the only one betting on the Super App concept.

  • OpenAI is working to turn ChatGPT into a Super App that brings together ChatGPT and Codex into a single environment that operates like a personal assistant.
  • Anthropic is extending Claude to become a Super App (though it hasn’t used that terminology), as well, by creating a single environment that combines productivity, development and automation tools.

The Copilot Super App isn’t Andreou’s only focus. He tells Fortune that AI model choice and home-grown AI model excellence also are among his key priorities.

Microsoft is expanding model choice in the Copilot Cowork feature beyond Anthropic to include OpenAI and soon, Microsoft’s own Cowork 1 model – which may be based on Microsoft’s hosted version of the open-source DeepSeek model. Cowork 1 will be the newest addition to Microsoft’s growing pool of Microsoft-developed models, seven of which debuted at Build this year. Microsoft is seeking to position itself as the champion of lower cost, efficient models built for those who are token-maxxed out.

Andreou definitely has his work cut out for him as a consumer guy in a heavily enterprise-centric company.

Microsoft 365 Copilot and consumer Copilot are just two of more than two dozen different “Copilot”-branded commercial offerings available across the various Microsoft product teams, which can feel overwhelming.

Microsoft also needs to give users a clearer way to find and use the quickly expanding stable of first- and third-party agents, like the OpenClaw-based Microsoft Scout personal assistant. Will Andreou and his Super App quest bring at least some order to the Copilot and agent madness? We’ll know more sometime this summer.

❌