Agent Foskett Academy β’ Microsoft Security Copilot
Microsoft Security Copilot Academy.
Security operations are no longer just about reading alerts one by one.
Modern security teams are expected to understand incidents quickly, connect evidence across tools, explain what happened and respond with confidence.
The Agent Foskett Microsoft Security Copilot Academy is designed to help learners use AI safely and effectively inside Microsoft security investigations, while still understanding the evidence, validating the output and applying human analyst judgement.
Learn how Microsoft Security Copilot helps security teams accelerate investigations, summarise incidents, generate hunting pivots and improve SOC workflows across Microsoft security platforms.
AI-assisted incident investigation
Prompt engineering for security
Incident summaries and evidence review
KQL assistance and analyst validation
What you will learn
This Academy focuses on practical Security Copilot concepts that help analysts investigate faster, ask better questions, validate AI-assisted output and use Microsoft security context responsibly.
AI-assisted investigationsUnderstand how Security Copilot can summarise incidents, explain alerts and help analysts move from evidence to investigation pivots faster.
Prompt engineering for securityLearn how to write focused security prompts, ask follow-up questions, request evidence and avoid vague or misleading AI responses.
PromptbooksLearn how promptbooks can standardise repeatable investigation workflows for phishing, identity compromise, endpoint alerts and cloud incidents.
Threat intelligence supportUse Copilot to summarise threat intelligence, explain attacker techniques and connect external context to internal security evidence.
KQL and hunting supportExplore how Security Copilot can help generate KQL ideas, explain queries and support hunting workflows while analysts validate every result.
Responsible analyst validationLearn why AI-assisted investigations still require human review, source validation, evidence checking and security judgement.
π Put Security Copilot to work inside the SOC. Continue into the SOC Analyst Academy and combine human judgement with Security Copilot, KQL, Defender XDR, Sentinel and Entra across realistic alert triage, investigation, containment and escalation scenarios.
The Academy is now a complete 40-lesson learning path. It begins with Security Copilot foundations, moves into practical investigations and threat hunting, and finishes with operational governance and AI-enabled SOC practices.
40Published practical lessons
4Structured learning modules
Complete40 of 40 lessons published
Module 1 β FoundationsUnderstand what Microsoft Security Copilot is, how it works, how analysts interact with it and how to validate AI-assisted output responsibly.
Lessons 1β10Microsoft Security CopilotAgent Foskett Academy
Lesson available
Lesson 1
What is Microsoft Security Copilot?
Understand the purpose of Security Copilot, where it fits in a modern SOC and why analyst judgement remains essential.
How Microsoft Security Copilot Works
Explore how prompts, grounding, plugins, permissions and connected security data work together to produce AI-assisted responses.
Understanding Security Copilot Promptbooks
Learn how promptbooks organise reusable sequences of prompts, inputs and plugins for consistent security investigations and repeatable analyst workflows.
Responsible AI and Analyst Validation
Learn how Microsoftβs Responsible AI principles, human oversight, evidence validation and source verification help analysts make trustworthy security decisions.
Using Security Copilot Across Microsoft Security
Discover how Security Copilot integrates across Microsoft Defender XDR, Sentinel, Entra, Defender for Cloud, Intune and Purview to support unified, cross-product security investigations.
Understanding Security Copilot Plugins
Learn how Microsoft, third-party and custom plugins extend Security Copilot with new capabilities, data sources and AI-powered security workflows.
Security Copilot Best Practices
Bring prompting, permissions, plugin management, source validation, responsible AI and investigation discipline together into a reliable Security Copilot operating method.
Module 2 β AI-Assisted InvestigationsApply Security Copilot to incident triage, identity, endpoint, phishing, cloud, threat intelligence and evidence correlation workflows.
Lessons 11β20Microsoft Security CopilotAgent Foskett Academy
Lesson available
Lesson 11
Summarising Security Incidents
Learn how to create accurate, evidence-driven incident summaries using Microsoft Security Copilot by identifying the attack story, key entities, business impact and unresolved investigation questions.
Investigating Identity Compromise
Learn how to investigate identity compromise using Microsoft Security Copilot by analysing risky users, suspicious sign-ins, authentication changes, privilege escalation, mailbox activity and endpoint evidence.
Investigating Endpoint Incidents
Learn how to investigate endpoint incidents using Microsoft Security Copilot by analysing device timelines, process trees, scripts, files, persistence, network activity and response actions.
Investigating Phishing Attacks
Learn how to investigate phishing attacks using Microsoft Security Copilot by analysing email authentication, URLs, attachments, user interaction, mailbox activity and post-delivery evidence.
Investigating Cloud Security Incidents
Learn how to investigate cloud security incidents using Microsoft Security Copilot by analysing alerts, affected resources, attack paths, workload context, sensitive-data exposure and remediation priorities.
Threat Intelligence with Copilot
Learn how to use Microsoft Security Copilot to investigate threat actors, campaigns, indicators, infrastructure and tactics while connecting external intelligence to internal Defender and Sentinel evidence.
Evidence Correlation Techniques
Learn how to connect users, devices, IP addresses, domains, alerts, incidents and cloud resources across Microsoft Defender XDR, Microsoft Sentinel, Entra and Defender for Cloud to build a validated attack timeline.
Building Investigation Timelines
Learn how to build a chronological attack story by correlating identity, endpoint, email, cloud and SIEM evidence while validating timestamps, sequence, gaps and conflicting evidence.
AI-Assisted Triage Workflows
Learn how to use Microsoft Security Copilot to prioritise incidents, group related alerts, identify immediate actions and reduce repetitive review while preserving analyst validation and accountability.
Module 3 β Hunting & ResponseUse Security Copilot to support KQL, threat hunting, IOC enrichment, MITRE ATT&CK analysis, malware review and end-to-end response.
Lessons 21β30Microsoft Security CopilotAgent Foskett Academy
Lesson available
Lesson 21
KQL Assistance with Copilot
Learn how to generate, explain, refine and troubleshoot KQL with Microsoft Security Copilot while validating tables, fields, syntax, logic, performance and returned evidence.
Hunting Across Microsoft Defender XDR
Learn how to use Microsoft Security Copilot to develop hunting hypotheses, pivot across endpoint, identity, email, cloud app and alert telemetry, and validate evidence before escalating discoveries.
Hunting in Microsoft Sentinel
Learn how to use Microsoft Security Copilot to develop Sentinel hunting hypotheses, explore workspace data, build queries and interpret evidence across Microsoft and third-party telemetry.
Prompting for Threat Hunting
Learn how to turn threat-hunting hypotheses into focused Microsoft Security Copilot prompts that define behaviours, entities, time ranges, evidence expectations, exclusions and validation requirements.
IOC Enrichment
Learn how to enrich IP addresses, domains, URLs, file hashes, certificates and other indicators while validating freshness, relevance, internal sightings, provenance and confidence.
Explaining MITRE ATT&CK Techniques
Learn how to use Microsoft Security Copilot to explain MITRE ATT&CK tactics, techniques and sub-techniques, map observed behaviours, validate supporting evidence and identify detection opportunities.
Malware Analysis Assistance
Learn how to use Microsoft Security Copilot to analyse suspicious files, scripts, processes, commands, behaviours and indicators while validating execution, prevalence, sandbox evidence and response decisions.
Validating AI Investigation Results
Learn how to validate Microsoft Security Copilot claims against source data, identify unsupported conclusions, verify entities and timelines, and document confidence, uncertainty and operational decisions.
End-to-End Incident Investigation
Learn how to bring incident triage, identity, endpoint, email, cloud, Sentinel hunting, evidence validation, containment and reporting into one complete Microsoft security investigation workflow.
Module 4 β Operational Security CopilotOperationalise Security Copilot through promptbooks, governance, data protection, advanced prompting, measurement and sustainable SOC adoption.
Lessons 31β40Microsoft Security CopilotAgent Foskett Academy
Lesson available
Lesson 31
Building SOC Promptbooks
Learn how to create reusable Microsoft Security Copilot promptbooks for phishing, compromised accounts, endpoint alerts, OAuth abuse, cloud incidents and threat hunting while preserving evidence validation and analyst accountability.
Automating Repetitive Investigations
Learn how to identify repeatable analyst tasks that can be accelerated using Microsoft Security Copilot, promptbooks and governed automation while preserving evidence validation, review gates and human accountability.
Working with Microsoft Defender Experts
Learn how Microsoft Security Copilot, Microsoft Defender Experts and the internal SOC can work together across managed investigation, proactive threat hunting, response recommendations and security operations.
Security Copilot in Daily Operations
Learn how to integrate Microsoft Security Copilot into daily SOC operations including shift handovers, incident review, threat hunting, reporting, knowledge transfer and analyst development.
Measuring Analyst Efficiency
Learn how to measure time saved, investigation quality, consistency, depth, analyst workload and operational outcomes without relying on prompt volume as a productivity metric.
Governance and Access Control
Learn how to plan Security Copilot roles, least privilege, plugin access, auditing, ownership, acceptable-use controls and periodic access reviews.
Protecting Sensitive Information
Learn how to handle prompts, evidence, personal information, confidential data, uploaded files, secrets and regulated content safely while preserving investigation quality.
Becoming an AI-Enabled Security Analyst
Bring investigation knowledge, prompting, KQL, validation, governance and human judgement together into a mature AI-enabled security operating model.
Lessons will be linked as they are published. The roadmap may be refined when Microsoft changes Security Copilot capabilities, interfaces or integrations, but the four-module learning progression will remain intact.
Related Agent Foskett Academies
Security Copilot connects naturally with every Microsoft security academy because it sits across investigation, hunting, response and reporting.
Microsoft Sentinel AcademySentinel provides SIEM, SOAR, incident management and hunting workflows that Security Copilot can help analysts reason through.
Microsoft Entra Security AcademyIdentity, access, risky sign-ins and account compromise investigations are strong candidates for Security Copilot-assisted workflows.
Defender for Endpoint AcademyEndpoint telemetry gives Security Copilot rich evidence for process, file, network and device-level investigation summaries.
Final thought
Security Copilot is not a replacement for the analyst. It is a force multiplier for analysts who understand the evidence, ask better questions and validate what the AI returns.
Agent Foskett mindsetDo not treat AI output as evidence by itself. Use Security Copilot to accelerate the investigation, then validate the source data, timeline and conclusions.
SOC Analyst AcademyTake AI-assisted investigation into realistic SOC operations, where Copilot accelerates the work but the analyst still owns the evidence, decisions and response.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD
Microsoft Security Copilot Academy
The Agent Foskett Microsoft Security Copilot Academy teaches AI-assisted security investigations, prompt engineering, promptbooks, incident summaries, KQL support, threat intelligence workflows and responsible analyst validation.
Learn Microsoft Security Copilot
Microsoft Security Copilot helps security teams accelerate investigations, summarise evidence, reason across Microsoft security signals and improve SOC workflows using AI-assisted analysis.
Microsoft Security Copilot training for security analysts
This Academy supports learners working with Microsoft Security Copilot, Defender XDR, Microsoft Sentinel, Microsoft Entra, KQL hunting, prompt engineering, promptbooks and AI-assisted incident response. The SOC Analyst Academy then brings these capabilities together inside realistic security operations workflows.