What is Microsoft Security Copilot? (original) (raw)

Microsoft Security Copilot (Security Copilot) is a generative AI-powered security solution that helps increase the efficiency and capabilities of defenders to improve security outcomes at machine speed and scale.

Security Copilot provides a natural language, assistive copilot experience. Security Copilot helps support security professionals in various end-to-end scenarios such as incident response, threat hunting, intelligence gathering, posture management, and more. For more information, see Security Copilot primary use cases.

Designed with integration in mind, Security Copilot offers a standalone experience and also seamlessly integrates with products in the Microsoft Security portfolio. Security Copilot integrates with products such as Microsoft Defender XDR, Microsoft Sentinel, Microsoft Intune, Microsoft Entra, and other third-party services such as ServiceNow and Jamf. For more information, see Security Copilot experiences.

The solution leverages the full power of OpenAI architecture to generate a response to a user prompt by using security-specific plugins, including organization-specific information, authoritative sources, and global threat intelligence. By using plugins as data point sources, security professionals have wider visibility into threats and gain more context. Incident responders also have the opportunity to extend the solution's functionalities. For more information about plugins, read Manage plugins.

Note

Disclaimer: This documentation is only intended for customers using commercial clouds. Currently, Security Copilot is not designed for use by customers using US government clouds, including but not limited to GCC, GCC High, DoD, and Microsoft Azure Government. For more information, consult with your Microsoft representative.

Security Copilot primary use cases

Security Copilot focuses on making the following use cases easy to accomplish.

Read Use cases for Security Copilot to delve deeper into the different security team roles like CISOs, threat intelligence analysts, IT admins, and the like, who can benefit from each highlighted use case.

How does Security Copilot work?

Security Copilot capabilities can be accessed through an immersive standalone experience and through intuitive embedded experiences available in other Microsoft security products. The foundation language model and proprietary Microsoft technologies work together in an underlying system that helps increase the efficiency and capabilities of defenders.

Image of how Security Copilot works.

Here's an explanation of how Security Copilot works:

Security Copilot iteratively processes and orchestrates these sophisticated services to help produce results that are relevant to your organization because they're contextually based on your organizational data.

Next steps

Security Copilot training

Go to Enhance security operations by using Microsoft Security Copilot to learn about Microsoft Security Copilot, an AI-powered security analysis tool that enables analysts to process security signals and respond to threats at a machine speed, and the AI concepts upon which it's built.

Security Copilot Customer Connection Program

Join the Security Copilot Customer Connection Program (CCP) to stay up to date with Security Copilot. CCP community members have access to:

Opt in to join the community.