Microsoft Security Copilot is now generally available for purchase (as of April 1, 2024). Originally introduced alongside a range of updates and new features for Microsoft’s Copilot portfolio in March 2023, this new resource promises to enhance business security with next-level AI.
Microsoft’s latest Copilot is the industry’s first generative AI tool to support security and IT teams. The tech giant says the solution will help professionals move faster, catch threats others miss, and enhance their expertise.
Informed by large-scale data, threat intelligence, and more than 78 million security signals, Security Copilot could change how we manage risk in the modern world. In particular, it could help address the security skill gap at a time when more than 3.4 million security roles are currently left unfilled.
I examined this potentially revolutionary tool more closely to determine precisely what it can accomplish for today’s security professionals.
What is Microsoft Security Copilot?
Microsoft Security Copilot, or “Copilot for Security” is the latest generative AI solution created by Microsoft, as part of its broader copilot ecosystem. It was introduced at the inaugural Microsoft Secure Event in 2023 and became generally available to purchase in April 2024.
According to the tech giant, the solution empowers security defenders to improve outcomes at machine-level speed and scale without compromising on compliance. It provides a natural language experience, similar to Microsoft’s other Copilot tools.
Designed with a focus on flexibility and extensibility, Microsoft Security Copilot offers a standalone experience and integrates seamlessly with products in Microsoft’s broader security portfolio. For instance, it can connect with:
- Microsoft’s Unified Security Operations Platform
- Microsoft Defender Threat Intelligence
- Microsoft Sentinel
- Microsoft Defender XDR
- Microsoft Intune
- Microsoft Entra
- Microsoft Purview
- Microsoft Defender External Attack Surface Management
Plus, the solution benefits from access to Copilot’s broad ecosystem of more than 100 software partners and managed security service providers. The system also offers a multilingual interface for up to 25 languages and can respond to prompts in 8 languages.
How Does Microsoft Copilot for Security Work?
Like many of the top LLM-powered generative AI models, Microsoft Security Copilot is simple to use. You can access capabilities through the standalone experience or other Microsoft security products.
The language model and Microsoft’s proprietary technologies work together in a comprehensive system, meaning users can experiment with Security Copilot through Microsoft’s security solutions (as mentioned above) and plugins from Microsoft and third parties. Plugins can bring more context to Security Copilot from event logs, incidents, alerts, and policies.
Plus, Copilot can access authoritative content and threat intelligence through plugins that can search through Microsoft Defender articles and reports. Interacting with the solution is similar to interacting with Microsoft’s Bing or Teams Copilot tools.
Users can submit prompts to a conversational interface, which Security Copilot processes via the “grounding” process. This improves the specificity of the prompt to ensure you get answers relevant to your specific needs. The Copilot then takes the response from the language model and post-processes it before returning the response to the user.
How the AI System Works
Here’s a quick rundown of what working with Microsoft Security Copilot looks like:
- Step 1: A user sends a prompt to the Copilot for Security from Microsoft’s security products.
- Step 2: Copilot then pre-processes the prompt through a “grounding” process, improving the specificity of the input to ensure a relevant and actionable response.
- Step 3: Copilot accesses your plugins for pre-processing and then sends the modified prompt to Microsoft’s language model.
- Step 4: Copilot for Security takes the response from the language model and post-processes, gathering contextual information from plugins.
- Step 5: The AI app returns the response to the user.
What Can Security Copilot Do?
After an initial beta testing and early access phase, Microsoft has already proven how valuable its new AI solution can be. In a “Copilot for Security” economic study, the tech giant discovered that experienced security professionals were 22% faster at analyzing threats using Copilot.
They were also 7% more accurate when completing tasks, and 97% said they wanted to continue using the solution going forward. Even novice analysts were 44% more accurate in their work.
Primarily, Microsoft Security Copilot empowers IT professionals and security teams to catch threats faster, access critical guidance in seconds to mitigate risks, and even strengthen team expertise.
Some of the primary use cases for the AI app include:
- Incident summarization: Users can rapidly leverage generative AI to distill comprehensive security alerts into concise summaries for quicker response times.
- Impact analysis: Microsoft’s toolkit leverages AI to assess the potential threat level of different security incidents, highlighting affected data, and systems.
- Reverse engineer scripts: With Copilot, users don’t have to reverse engineer malware manually. They can quickly analyze complex command line scripts and translate them into easy-to-understand language, explaining each action clearly.
- Guided response: Both expert and novice security professionals can receive step-by-step guidance from Copilot on how to respond to a threat. The bot can offer directions for triage processes, investigation, remediation, containment, and more.
The Latest Updates to the AI
Alongside announcing general availability in April 2024, Microsoft also announced a handful of new product capabilities, such as:
- Custom prompt books: Allowing users to create, save, and share prompts for security processes with their entire team.
- Knowledge base integrations (In preview): This allows users to integrate Copilot with business information to search for risks in proprietary content.
- Multi-language support: Copilot can now respond to prompts in 8 languages, and the interface supports 25 languages.
- Upgraded third-party integrations: The number of third-party plugins and integrations is currently increasing at a rapid pace. Some new plugins and integrations include Netskope, Tanium, Valence Security, Cyware, and SGNL solutions.
- Usage reporting: Admins can now access dashboards for insights into how their teams use Copilot so that they can find opportunities for resource optimization.
- Microsoft Entra audit logs and diagnostic logs: Users can access these features to gain additional insights into IT issues and security investigations with audit logs.
- Defender External Attack Surface Management: This new integration allows users to identify and analyze up-to-date information on external attack surface risks.
How to Access Microsoft Security Copilot
Microsoft Copilot for Security is now available worldwide, although the company is still working on adding support for new languages.
Like most of Microsoft’s Copilot tools, the security app isn’t free to access. The Security Copilot offering is pay-as-you-go. You can use your existing Azure subscription to access Security Copilot, and Microsoft estimates most users will pay around $4 per hour for the service.
You can find the full pricing information for Security Copilot here.
Once you have your subscription, you will be prompted to take a few additional steps to enable Security Copilot. First, you need an Azure subscription (which you can create for free). Next, you’ll need to ensure you have the right “capacity” for your needs.
You can manage capacity by decreasing or increasing provisioned Security Compute Units (SCUs) for Copilot within Azure or the Copilot for Security portals.




