Azure Firewall Integration in Microsoft Security Copilot (preview)

 





Introduction

A generative AI-powered security solution called Security Copilot helps security professionals become more effective and capable of enhancing security outcomes at machine speed and scale. It supports security professionals in end-to-end scenarios like incident response, threat hunting, intelligence gathering, and posture management by offering an assistive copilot experience in natural language.

Security Copilot Integration in Azure Firewall

Azure Firewall is an intelligent network firewall security service that is cloud-native and offers the best threat protection for your Azure cloud workloads. It is a fully stateful firewall as a service that offers unlimited cloud scalability and built-in high availability. 

Security Copilot's Azure Firewall integration enables analysts to use natural language queries to conduct in-depth analyses of the malicious traffic that their firewall's IDPS feature intercepted across their whole fleet. This integration can be used in Security Copilot portal (standalone experience) and Copilot in Azure (embedded experience) in the Azure portal. 

Key Features

There are built-in system features in Security Copilot that can get data from the different plugins that are turned on. Follow the below procedure to view these system capabilities:
  1. In the prompt bar, choose Prompts icon.
  2. Go for See all system capabilities.
  3. The Azure Firewall section lists of all the available capabilities will appear for use.

Enable the Azure Firewall Integration in Security Copilot

  1. Make sure the Azure Firewall is configured correctly. 
  2. Go to Security Copilot and sign-in with your credentials. 
  3. Ensure that the Azure Firewall plugin is turned on. Select the Sources icon, in the prompt bar. In the Manage sources pop-up window that appears, confirm that the Azure Firewall toggle is turned on. Then, close the window. 
  4. Enter prompt in the prompt bar on either the Security Copilot portal or via the Copilot in Azure experience in the Azure portal. 

Provide Feedback

Feedback is vital to guide the current and planned development of the product. The best way to provide this feedback is directly in the product.

Privacy & Data Security in Security Copilot

Azure Firewall data is pulled by Security Copilot when interaction happens via either the Security Copilot portal or the Copilot in Azure experience. The Copilot service processes and stores the prompts, the data that is retrieved, and the output displayed in the prompt results. 

Conclusion

Here we learned about Azure Firewall integration in Microsoft Security Copilot and its key features.


























































Comments

Popular posts from this blog

Deployment (Part 3)

Deployment (Part 1)

Deployment (Part 2)