Microsoft Security Copilot in Defender for Cloud (Preview)

 






Introduction

Both Microsoft Security Copilot and Microsoft Copilot for Azure are included into Microsoft Defender for Cloud. These connections allow you to ask security-related questions, get answers, and immediately activate the skills required to use natural language prompts for analysis, summarization, remediation, and suggestion delegation.

Cloud-based AI technologies that offer a natural language copilot experience are Security Copilot and Copilot for Azure. They help security experts fix or assign jobs, fix code misconfigurations, and comprehend the context and impact of recommendations. 

You may improve your security posture and reduce risks in your environments by integrating Defender for Cloud with Security Copilot and Copilot for Azure on the suggestions page. This integration improves the effectiveness and efficiency of your security management by streamlining the process of comprehending and putting recommendations into practice. 

Key Features

Data Processing Workflow

When you use Security Copilot in Defender for Cloud, the following data processing workflow occurs:
  1. A user enters a prompt in the Copilot interface.
  2. Copilot for Azure receives the prompt.
  3. Copilot for Azure evaluates the prompt and the active page, to determine the skills needed to resolve prompt.
  4. If the prompt is security related and the skill is available, Security Copilot executes the skills and sends back a response to Copilot in Azure for presentation.
  5. If a security-related prompt is received but the skill is unavailable, Azure Copilot searches all of its available skills to find the most relevant skills to resolve the prompt. A response is then sent to the user. 

Enable Security Copilot Integration in Defender for Cloud

Security Copilot in Defender for Cloud is independent of any Defender for Cloud plans. Security Copilot is available for all users when you:
  1. Enable Defender for Cloud on your environment.
  2. Have access to Azure Copilot.
  3. Have Security Compute Units assigned for Security Copilot.

However, we advise turning on the Defender for Cloud Security Posture Management (DCSPM) plan on your environments to take advantage of Security Copilot's entire suite of features. Numerous more security elements, including attack path analysis and risk prioritization, are included in the DCSPM plan. Security Copilot can be used to browse and manage these features. You can use Security Copilot in Defender for Cloud without the DCSPM plan, but only to a limited extent. 

Provide Feedback

Your feedback on the Defender for Cloud Security integration Copilot facilitates growth. In Copilot, choose "How's this response?" to offer feedback. Choose from the options provided at the bottom of each completed prompt. 







































Comments

Popular posts from this blog

Deployment (Part 3)

Deployment (Part 1)

Deployment (Part 2)