Get started with Microsoft Security Copilot (original) (raw)

Microsoft Security Copilot is a generative AI security product that empowers security and IT professionals to respond to cyber threats, process signals, and assess risk exposure at the speed and scale of AI. For an overview, see What is Microsoft Security Copilot?.

Note

Disclaimer: This documentation is only intended for customers using commercial clouds. Currently, Security Copilot isn't designed for use by customers using US government clouds, including but not limited to GCC, GCC High, DoD, and Microsoft Azure Government. For more information, consult with your Microsoft representative.

Note

When you first sign in to Security Copilot, your experience might differ depending on your onboarding and rollout stage.

In the agents-first experience, you access chat from All history instead of the homepage.

There are two categories of Security Copilot customers:

What you see when you first sign in

In some environments, Security Copilot opens with an agents-first homepage and a role-based welcome experience.

To get started with Security Copilot, use the following guidance:

Image of getting started with Security Copilot flow

This illustration describes the steps to get started with Security Copilot:

Step 1: Identify which customer category applies to you

Before you begin onboarding to Microsoft Security Copilot, you must first determine what type of Security Copilot customer you are.

Your onboarding experience depends on this license status:

Step 2: Follow the path applicable to your organization

After you have confirmed your Microsoft 365 E5 and E7 license status, use the following guidance to continue.

Microsoft 365 E5 and E7 Security Copilot included customers Non–Microsoft 365 E5 and E7 Security Copilot customers
Microsoft has auto provisioned Security Copilot. You can start using Security Copilot in your workflows. For more information, see Understand how Security Copilot is auto provisioned for Microsoft 365 E5 and E7 customers. Follow the manual onboarding steps. For more information, see Onboarding for non-Microsoft 365 E5 and E7 customers.

Start using Security Copilot

After onboarding is complete, you can begin using Security Copilot:

Role-based onboarding guidance

In the agents-first experience, the initial guidance can vary by role:

First thing to do

When you first open Security Copilot, start by choosing how you want to work.

Agents are the primary entry point in newer experiences. They help you perform structured and repeatable tasks.

  1. Select Home.
  2. Select an agent or choose Discover agents.
  3. Run the agent to begin your workflow.

Use agents when you want to:


Start a chat session

If you want to explore or investigate using prompts, start a chat session.

  1. Select History
  2. Select New session
  3. Enter your prompt

Use prompts when you want to:


What to try next

Next steps

Once you've completed onboarding, you're ready to start using Security Copilot. Depending on your experience, you might begin with agents or start a chat session from All history.

Use the following Security Copilot articles for guidance: