Agent Foskett Academy β€’ Microsoft Security Copilot

Microsoft Security Copilot Academy.

Security operations are no longer just about reading alerts one by one.

Modern security teams are expected to understand incidents quickly, connect evidence across tools, explain what happened and respond with confidence.

The Agent Foskett Microsoft Security Copilot Academy is designed to help learners use AI safely and effectively inside Microsoft security investigations, while still understanding the evidence, validating the output and applying human analyst judgement.

Agent Foskett Microsoft Security Copilot Academy
Academy overview

Learn how Microsoft Security Copilot helps security teams accelerate investigations, summarise incidents, generate hunting pivots and improve SOC workflows across Microsoft security platforms.

AI-assisted incident investigation
Prompt engineering for security
Incident summaries and evidence review
KQL assistance and analyst validation

What you will learn

This Academy focuses on practical Security Copilot concepts that help analysts investigate faster, ask better questions, validate AI-assisted output and use Microsoft security context responsibly.
AI-assisted investigationsUnderstand how Security Copilot can summarise incidents, explain alerts and help analysts move from evidence to investigation pivots faster.
Prompt engineering for securityLearn how to write focused security prompts, ask follow-up questions, request evidence and avoid vague or misleading AI responses.
PromptbooksLearn how promptbooks can standardise repeatable investigation workflows for phishing, identity compromise, endpoint alerts and cloud incidents.
Threat intelligence supportUse Copilot to summarise threat intelligence, explain attacker techniques and connect external context to internal security evidence.
KQL and hunting supportExplore how Security Copilot can help generate KQL ideas, explain queries and support hunting workflows while analysts validate every result.
Responsible analyst validationLearn why AI-assisted investigations still require human review, source validation, evidence checking and security judgement.
πŸ”Ž Put Security Copilot to work inside the SOC.
Continue into the SOC Analyst Academy and combine human judgement with Security Copilot, KQL, Defender XDR, Sentinel and Entra across realistic alert triage, investigation, containment and escalation scenarios.
Open SOC Analyst Academy β†’

Microsoft Security Copilot Academy roadmap

The Academy is now a complete 40-lesson learning path. It begins with Security Copilot foundations, moves into practical investigations and threat hunting, and finishes with operational governance and AI-enabled SOC practices.
40 Published practical lessons
4 Structured learning modules
Complete 40 of 40 lessons published
Module 1 β€” Foundations Understand what Microsoft Security Copilot is, how it works, how analysts interact with it and how to validate AI-assisted output responsibly.
Lessons 1–10 Microsoft Security Copilot Agent Foskett Academy
Lesson available
Lesson 1
What is Microsoft Security Copilot? Understand the purpose of Security Copilot, where it fits in a modern SOC and why analyst judgement remains essential.
Lesson available
Lesson 2
How Microsoft Security Copilot Works Explore how prompts, grounding, plugins, permissions and connected security data work together to produce AI-assisted responses.
Lesson available
Lesson 3
Navigating the Microsoft Security Copilot Interface Learn the Security Copilot workspace, agents, sessions, prompt bar, sources, process log, promptbooks, sharing and investigation workflow.
Lesson available
Lesson 4
Prompting Fundamentals for Security Analysts Learn how goals, context, sources and expectations combine to create effective Security Copilot prompts for real-world investigations.
Lesson available
Lesson 5
Writing Better Security Prompts Learn how to refine investigation prompts using stronger context, precise constraints, evidence requests, iterative follow-up questions and reusable prompt patterns.
Lesson available
Lesson 6
Understanding Security Copilot Promptbooks Learn how promptbooks organise reusable sequences of prompts, inputs and plugins for consistent security investigations and repeatable analyst workflows.
Lesson available
Lesson 7
Responsible AI and Analyst Validation Learn how Microsoft’s Responsible AI principles, human oversight, evidence validation and source verification help analysts make trustworthy security decisions.
Lesson available
Lesson 8
Using Security Copilot Across Microsoft Security Discover how Security Copilot integrates across Microsoft Defender XDR, Sentinel, Entra, Defender for Cloud, Intune and Purview to support unified, cross-product security investigations.
Lesson available
Lesson 9
Understanding Security Copilot Plugins Learn how Microsoft, third-party and custom plugins extend Security Copilot with new capabilities, data sources and AI-powered security workflows.
Lesson available
Lesson 10
Security Copilot Best Practices Bring prompting, permissions, plugin management, source validation, responsible AI and investigation discipline together into a reliable Security Copilot operating method.
Module 2 β€” AI-Assisted Investigations Apply Security Copilot to incident triage, identity, endpoint, phishing, cloud, threat intelligence and evidence correlation workflows.
Lessons 11–20 Microsoft Security Copilot Agent Foskett Academy
Lesson available
Lesson 11
Summarising Security Incidents Learn how to create accurate, evidence-driven incident summaries using Microsoft Security Copilot by identifying the attack story, key entities, business impact and unresolved investigation questions.
Lesson available
Lesson 12
Investigating Identity Compromise Learn how to investigate identity compromise using Microsoft Security Copilot by analysing risky users, suspicious sign-ins, authentication changes, privilege escalation, mailbox activity and endpoint evidence.
Lesson available
Lesson 13
Investigating Endpoint Incidents Learn how to investigate endpoint incidents using Microsoft Security Copilot by analysing device timelines, process trees, scripts, files, persistence, network activity and response actions.
Lesson available
Lesson 14
Investigating Phishing Attacks Learn how to investigate phishing attacks using Microsoft Security Copilot by analysing email authentication, URLs, attachments, user interaction, mailbox activity and post-delivery evidence.
Lesson available
Lesson 15
Investigating Cloud Security Incidents Learn how to investigate cloud security incidents using Microsoft Security Copilot by analysing alerts, affected resources, attack paths, workload context, sensitive-data exposure and remediation priorities.
Lesson available
Lesson 16
Threat Intelligence with Copilot Learn how to use Microsoft Security Copilot to investigate threat actors, campaigns, indicators, infrastructure and tactics while connecting external intelligence to internal Defender and Sentinel evidence.
Lesson available
Lesson 17
Evidence Correlation Techniques Learn how to connect users, devices, IP addresses, domains, alerts, incidents and cloud resources across Microsoft Defender XDR, Microsoft Sentinel, Entra and Defender for Cloud to build a validated attack timeline.
Lesson available
Lesson 18
Building Investigation Timelines Learn how to build a chronological attack story by correlating identity, endpoint, email, cloud and SIEM evidence while validating timestamps, sequence, gaps and conflicting evidence.
Lesson available
Lesson 19
Producing Executive Incident Summaries Learn how to translate validated technical findings into concise executive updates covering incident scope, business impact, response status, remaining risk and required decisions.
Lesson available
Lesson 20
AI-Assisted Triage Workflows Learn how to use Microsoft Security Copilot to prioritise incidents, group related alerts, identify immediate actions and reduce repetitive review while preserving analyst validation and accountability.
Module 3 β€” Hunting & Response Use Security Copilot to support KQL, threat hunting, IOC enrichment, MITRE ATT&CK analysis, malware review and end-to-end response.
Lessons 21–30 Microsoft Security Copilot Agent Foskett Academy
Lesson available
Lesson 21
KQL Assistance with Copilot Learn how to generate, explain, refine and troubleshoot KQL with Microsoft Security Copilot while validating tables, fields, syntax, logic, performance and returned evidence.
Lesson available
Lesson 22
Hunting Across Microsoft Defender XDR Learn how to use Microsoft Security Copilot to develop hunting hypotheses, pivot across endpoint, identity, email, cloud app and alert telemetry, and validate evidence before escalating discoveries.
Lesson available
Lesson 23
Hunting in Microsoft Sentinel Learn how to use Microsoft Security Copilot to develop Sentinel hunting hypotheses, explore workspace data, build queries and interpret evidence across Microsoft and third-party telemetry.
Lesson available
Lesson 24
Prompting for Threat Hunting Learn how to turn threat-hunting hypotheses into focused Microsoft Security Copilot prompts that define behaviours, entities, time ranges, evidence expectations, exclusions and validation requirements.
Lesson available
Lesson 25
IOC Enrichment Learn how to enrich IP addresses, domains, URLs, file hashes, certificates and other indicators while validating freshness, relevance, internal sightings, provenance and confidence.
Lesson available
Lesson 26
Explaining MITRE ATT&CK Techniques Learn how to use Microsoft Security Copilot to explain MITRE ATT&CK tactics, techniques and sub-techniques, map observed behaviours, validate supporting evidence and identify detection opportunities.
Lesson available
Lesson 27
Malware Analysis Assistance Learn how to use Microsoft Security Copilot to analyse suspicious files, scripts, processes, commands, behaviours and indicators while validating execution, prevalence, sandbox evidence and response decisions.
Lesson available
Lesson 28
Building Investigation Playbooks Learn how to design repeatable investigation workflows that combine Security Copilot prompts, evidence checks, hunting pivots, decisions, response actions, review gates and governed automation.
Lesson available
Lesson 29
Validating AI Investigation Results Learn how to validate Microsoft Security Copilot claims against source data, identify unsupported conclusions, verify entities and timelines, and document confidence, uncertainty and operational decisions.
Lesson available
Lesson 30
End-to-End Incident Investigation Learn how to bring incident triage, identity, endpoint, email, cloud, Sentinel hunting, evidence validation, containment and reporting into one complete Microsoft security investigation workflow.
Module 4 β€” Operational Security Copilot Operationalise Security Copilot through promptbooks, governance, data protection, advanced prompting, measurement and sustainable SOC adoption.
Lessons 31–40 Microsoft Security Copilot Agent Foskett Academy
Lesson available
Lesson 31
Building SOC Promptbooks Learn how to create reusable Microsoft Security Copilot promptbooks for phishing, compromised accounts, endpoint alerts, OAuth abuse, cloud incidents and threat hunting while preserving evidence validation and analyst accountability.
Lesson available
Lesson 32
Automating Repetitive Investigations Learn how to identify repeatable analyst tasks that can be accelerated using Microsoft Security Copilot, promptbooks and governed automation while preserving evidence validation, review gates and human accountability.
Lesson available
Lesson 33
Working with Microsoft Defender Experts Learn how Microsoft Security Copilot, Microsoft Defender Experts and the internal SOC can work together across managed investigation, proactive threat hunting, response recommendations and security operations.
Lesson available
Lesson 34
Security Copilot in Daily Operations Learn how to integrate Microsoft Security Copilot into daily SOC operations including shift handovers, incident review, threat hunting, reporting, knowledge transfer and analyst development.
Lesson available
Lesson 35
Measuring Analyst Efficiency Learn how to measure time saved, investigation quality, consistency, depth, analyst workload and operational outcomes without relying on prompt volume as a productivity metric.
Lesson available
Lesson 36
Governance and Access Control Learn how to plan Security Copilot roles, least privilege, plugin access, auditing, ownership, acceptable-use controls and periodic access reviews.
Lesson available
Lesson 37
Protecting Sensitive Information Learn how to handle prompts, evidence, personal information, confidential data, uploaded files, secrets and regulated content safely while preserving investigation quality.
Lesson available
Lesson 38
Advanced Prompt Engineering Use decomposition, iterative prompting, structured outputs, role context, constraints and evidence-driven refinement to build precise, testable Security Copilot investigations.
Lesson available
Lesson 39
Common Mistakes and Pitfalls Avoid over-trust, vague prompts, confirmation bias, missing context, weak validation, unnecessary data exposure and poor operational adoption.
Lesson available
Lesson 40
Becoming an AI-Enabled Security Analyst Bring investigation knowledge, prompting, KQL, validation, governance and human judgement together into a mature AI-enabled security operating model.
Lessons will be linked as they are published. The roadmap may be refined when Microsoft changes Security Copilot capabilities, interfaces or integrations, but the four-module learning progression will remain intact.

Related Agent Foskett Academies

Security Copilot connects naturally with every Microsoft security academy because it sits across investigation, hunting, response and reporting.
Microsoft Sentinel AcademySentinel provides SIEM, SOAR, incident management and hunting workflows that Security Copilot can help analysts reason through.
Microsoft Entra Security AcademyIdentity, access, risky sign-ins and account compromise investigations are strong candidates for Security Copilot-assisted workflows.
Defender for Endpoint AcademyEndpoint telemetry gives Security Copilot rich evidence for process, file, network and device-level investigation summaries.

Final thought

Security Copilot is not a replacement for the analyst. It is a force multiplier for analysts who understand the evidence, ask better questions and validate what the AI returns.
Agent Foskett mindsetDo not treat AI output as evidence by itself. Use Security Copilot to accelerate the investigation, then validate the source data, timeline and conclusions.
SOC Analyst AcademyTake AI-assisted investigation into realistic SOC operations, where Copilot accelerates the work but the analyst still owns the evidence, decisions and response.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD

Microsoft Security Copilot Academy

The Agent Foskett Microsoft Security Copilot Academy teaches AI-assisted security investigations, prompt engineering, promptbooks, incident summaries, KQL support, threat intelligence workflows and responsible analyst validation.

Learn Microsoft Security Copilot

Microsoft Security Copilot helps security teams accelerate investigations, summarise evidence, reason across Microsoft security signals and improve SOC workflows using AI-assisted analysis.

Microsoft Security Copilot training for security analysts

This Academy supports learners working with Microsoft Security Copilot, Defender XDR, Microsoft Sentinel, Microsoft Entra, KQL hunting, prompt engineering, promptbooks and AI-assisted incident response. The SOC Analyst Academy then brings these capabilities together inside realistic security operations workflows.