Security Copilot with Microsoft Sentinel

 







Introduction

Microsoft Security Copilot is a platform that assists in in protecting an organization at scale and machine speed. The extensive security data from Microsoft Sentinel is a great resource for Copilot to use when analyzing incidents and creating hunting queries. 

Microsoft Sentinel incidents and data, when combined with other Security Copilot sources, gives a broader understanding of threats as well as context. 

Security Copilot Integration with Microsoft Sentinel

This integration primarily supports standalone experience accessed via https://securitycopilot.microsoft.com, where interaction is done in a chat-like experience to summarize incidents and get other answers about security data. 

Key Features

Microsoft Sentinel data integrates with Security in following two ways:
  • In Microsoft's unified security operations platform, Copilot in Microsoft Defender XDR benefits from unified incidents integrated with Microsoft Sentinel.

  • In the standalone experience, Microsoft Sentinel offers Microsoft Sentinel (Preview) and Natural language to KQL for Microsoft Sentinel (Preview) to integrate with Security Copilot. 

Enable Security Copilot Integration with Microsoft Sentinel

To maximize Security Copilot integration with Microsoft Sentinel:

  • Configure a default Microsoft Sentinel workspace
    • Navigate to Security Copilot at https://securitycopilot.microsoft.com/.
    • Open Sources in the prompt bar.
    • On the Manage plugins page, set the toggle On.
    • Select the gear icon on the Microsoft Sentinel (preview) plugin.
    • Configure the default workspace name.

  • Integrate Microsoft Sentinel with Copilot in Defender- use the Microsoft Defender portal with Microsoft Sentinel data for an embedded Security Copilot experience. Microsoft Sentinel's unique data sources flowing into Microsoft Defender XDR unified incidents allow Copilot in Defender to maximize its capabilities. 

Provide Feedback

Feedback is vital to guide the current and planned development of the product. The best way to provide feedback is directly in the product. 

Conclusion

All the main information about Security Copilot integration with Microsoft Sentinel is discussed above.











































Comments

Popular posts from this blog

Deployment (Part 3)

Deployment (Part 1)

Deployment (Part 2)