Security Copilot with Microsoft Sentinel
Introduction
Microsoft Security Copilot is a platform that assists in in protecting an organization at scale and machine speed. The extensive security data from Microsoft Sentinel is a great resource for Copilot to use when analyzing incidents and creating hunting queries.
Microsoft Sentinel incidents and data, when combined with other Security Copilot sources, gives a broader understanding of threats as well as context.
Security Copilot Integration with Microsoft Sentinel
This integration primarily supports standalone experience accessed via https://securitycopilot.microsoft.com, where interaction is done in a chat-like experience to summarize incidents and get other answers about security data.
Key Features
Microsoft Sentinel data integrates with Security in following two ways:
- In Microsoft's unified security operations platform, Copilot in Microsoft Defender XDR benefits from unified incidents integrated with Microsoft Sentinel.
- In the standalone experience, Microsoft Sentinel offers Microsoft Sentinel (Preview) and Natural language to KQL for Microsoft Sentinel (Preview) to integrate with Security Copilot.
Enable Security Copilot Integration with Microsoft Sentinel
To maximize Security Copilot integration with Microsoft Sentinel:
- Configure a default Microsoft Sentinel workspace
- Navigate to Security Copilot at https://securitycopilot.microsoft.com/.
- Open Sources in the prompt bar.
- On the Manage plugins page, set the toggle On.
- Select the gear icon on the Microsoft Sentinel (preview) plugin.
- Configure the default workspace name.
- Integrate Microsoft Sentinel with Copilot in Defender- use the Microsoft Defender portal with Microsoft Sentinel data for an embedded Security Copilot experience. Microsoft Sentinel's unique data sources flowing into Microsoft Defender XDR unified incidents allow Copilot in Defender to maximize its capabilities.
- Navigate to Security Copilot at https://securitycopilot.microsoft.com/.
- Open Sources in the prompt bar.
- On the Manage plugins page, set the toggle On.
- Select the gear icon on the Microsoft Sentinel (preview) plugin.
- Configure the default workspace name.
Provide Feedback
Feedback is vital to guide the current and planned development of the product. The best way to provide feedback is directly in the product.
Conclusion
All the main information about Security Copilot integration with Microsoft Sentinel is discussed above.
Comments
Post a Comment