Lesson 40 — Becoming an AI-Enabled Security Analyst
Forty lessons ago, we began with a simple question: what is Microsoft Security Copilot, and where does it fit in modern security operations?
We have since moved through prompting, plugins, incident investigation, identity, endpoint, phishing, cloud incidents, threat intelligence, timelines, KQL, hunting, promptbooks, automation, governance, sensitive information and advanced operational practice.
The final lesson brings everything together. Becoming an AI-enabled security analyst is not about handing investigations to AI. It is about combining Microsoft security expertise, good questions, evidence, validation, governance and human judgement into a stronger way of working.

What you will bring together
The complete Security Copilot analyst operating model.
The AI-enabled analyst operating model
↓
Define scope, entities and time range
↓
COLLECT EVIDENCE
Defender • Sentinel • Entra • Email • Cloud • Other telemetry
↓
USE COPILOT
Summarise • Explain • Correlate • Generate pivots • Assist with KQL
↓
VALIDATE
Return to source telemetry • Test queries • Check identifiers
↓
CHALLENGE
Alternative explanations • Contradictory evidence • Missing data
↓
DECIDE
Human analyst applies security judgement
↓
RESPOND
Approved actions with accountability
↓
COMMUNICATE
Technical findings • Handover • Executive summary
↓
LEARN
Improve promptbooks • Queries • Controls • Analyst capability
From traditional analyst to AI-enabled analyst
| Capability | Traditional approach | AI-enabled approach |
|---|---|---|
| Triage | Manually review every initial detail | Use Copilot to accelerate orientation, then validate. |
| Investigation | Manually build pivots and summaries | Use AI to develop pivots while retaining evidence control. |
| KQL | Write and troubleshoot every query manually | Generate and explain ideas, then test every query. |
| Hunting | Develop hypotheses and telemetry mapping manually | Use AI to broaden hypotheses and relevant evidence sources. |
| Reporting | Rewrite technical findings for each audience | Generate audience-specific drafts from validated findings. |
| Knowledge | Search documentation and notes | Use Copilot to accelerate explanation and knowledge transfer. |
| Decision | Human judgement | Still human judgement. |
Learning objectives
Bring investigation knowledge, prompting, validation, governance and human judgement together into a mature Security Copilot operating model.
The AI-enabled analyst
An AI-enabled security analyst uses Copilot to accelerate reasoning and repetitive work while remaining responsible for evidence, decisions and outcomes.
Start with investigation fundamentals
Identity, endpoint, email, cloud and network evidence still need to be understood before AI assistance can be used well.
Know the Microsoft security ecosystem
Effective Copilot use depends on understanding where evidence lives across Defender XDR, Sentinel, Entra, Intune, Purview and connected services.
Know what telemetry can prove
Different logs answer different questions. A generated narrative cannot compensate for missing or inappropriate telemetry.
Ask better questions
Strong analysts convert vague alerts into precise questions about entities, behaviours, time, sequence and evidence.
Use Copilot to accelerate triage
Incident summaries and contextual explanations can reduce the time required to understand the starting point.
Use Copilot to accelerate investigation
Prompts can help develop pivots, timelines, hypotheses and questions for further evidence collection.
Use Copilot to accelerate hunting
AI can help turn hypotheses into hunting ideas and KQL, provided the analyst validates the query and results.
Use Copilot to accelerate reporting
Technical findings can be transformed into analyst handovers and executive summaries without losing evidence boundaries.
Use Copilot to accelerate learning
Explanations of KQL, commands, techniques and security concepts can help analysts develop their own capability.
Do not outsource understanding
If the analyst cannot explain why a query, conclusion or response action makes sense, Copilot has not solved the underlying problem.
Prompt with purpose
Every prompt should contribute to an investigation objective rather than generate activity for its own sake.
Provide relevant context
Include the entities, time range and evidence needed to answer the question.
Use constraints
Tell Copilot what evidence it may use, what it must not assume and how uncertainty should be represented.
Use decomposition
Break complex incidents into smaller identity, endpoint, email, cloud and correlation tasks.
Use iteration
Refine questions as new evidence changes the investigation.
Use structured outputs
Timelines, evidence tables and confirmed-versus-unconfirmed findings make AI output easier to validate.
Challenge the answer
Ask what contradicts the current theory and what benign explanations remain possible.
Look for missing evidence
A mature analyst notices what the data cannot yet answer.
Return to source evidence
Important conclusions must remain traceable to Defender, Sentinel, Entra, email, cloud or other authoritative telemetry.
Validate KQL
Generated queries must be checked for tables, fields, syntax, filters, joins, logic and returned results.
Validate identifiers
Check usernames, domains, IPs, hashes, process names and timestamps before they become part of the incident record.
Preserve uncertainty
Do not allow polished AI wording to turn a possibility into a confirmed fact.
Preserve the original evidence
Generated summaries are derivative artefacts, not replacements for source telemetry.
Apply least privilege
Security Copilot platform roles and underlying product permissions should both reflect the user's actual duties.
Govern plugins
Integrations should have approved scope, ownership, authentication and data-handling controls.
Protect sensitive information
Use the minimum necessary personal, confidential and regulated information in prompts, uploads and reports.
Protect secrets
Credentials, tokens, API keys and private keys require strict handling and should not be casually placed into prompts.
Use approved promptbooks
Reusable workflows improve consistency when they have owners, inputs, outputs, versions and review dates.
Automate carefully
Repetitive tasks can be accelerated, but automation should not remove necessary evidence checks or approval gates.
Keep humans on consequential decisions
Containment, access changes, customer communications and other high-impact actions require authorised human judgement.
Build peer review into important cases
A second analyst can challenge assumptions, evidence gaps and overly confident conclusions.
Use Copilot in shift handovers
Summarise confirmed findings, unresolved questions, actions completed, ownership and next steps.
Use Copilot in daily operations
Integrate AI assistance where it reduces friction without making the SOC dependent on generated output.
Measure time saved
Track whether Copilot genuinely reduces repetitive analyst effort.
Measure quality
Check whether investigations become more complete, consistent and evidence-driven.
Measure depth
Determine whether analysts examine more relevant telemetry and test more plausible hypotheses.
Measure outcomes
The goal is better security decisions, not more prompts.
Measure analyst development
Copilot should help people learn to investigate, query and reason more effectively.
Avoid dependency
Analysts should still be able to investigate when Copilot is unavailable or inappropriate.
Train continuously
Prompting, product capabilities, governance and security threats all evolve.
Review access continuously
Roles, plugins and permissions should change when responsibilities change.
Review workflows continuously
Promptbooks and operational procedures should evolve as the SOC learns what works.
Review platform changes
New Security Copilot capabilities should be evaluated before broad production adoption.
Document operating principles
Teams should agree how AI is used, validated, governed and attributed.
Make accountability explicit
Every investigation and response decision still belongs to an authorised human role.
Build trust through evidence
Trust in AI-assisted security operations comes from repeatable validation, not from confident language.
Use AI where it adds value
Not every security task needs Copilot; sometimes the fastest route is a direct query or portal investigation.
Know when to stop prompting
If evidence is missing, collect evidence instead of asking the same question again.
Develop investigation instinct
Experienced analysts recognise unusual sequences, weak assumptions and missing telemetry quickly.
Develop KQL skill
Understanding queries makes AI-generated hunting and investigation work far more useful.
Develop communication skill
Analysts need to explain technical evidence clearly to engineers, managers and executives.
Develop governance awareness
Modern security analysts must understand privacy, access control, auditing and responsible AI use.
Develop healthy scepticism
Question AI output without dismissing the productivity and insight it can provide.
Build repeatability
Good investigations should be reproducible by another analyst using the same evidence and process.
Build defensibility
Important conclusions should be explainable later to management, auditors, customers or regulators.
Build resilience
The operating model should continue to work when staff, tools, plugins or platform capabilities change.
Move from AI user to AI-enabled analyst
The difference is not how often someone prompts Copilot; it is how well they combine AI assistance with security expertise.
The analyst remains the control plane
Tools can summarise, correlate and suggest, but the analyst decides what evidence means and what happens next.
Final Academy principle
Use Security Copilot to make human security judgement faster, broader and more consistent — never to make human judgement optional.
The complete investigation prompt pattern
Agent Foskett's final investigation
↓
A suspicious sign-in
↓
A PowerShell process
↓
And an unusual mailbox rule
↓
At the beginning of the Academy they might have looked like three separate problems
↓
Now the analyst started differently
↓
He defined the user, device and time range
↓
Copilot summarised the incidents
↓
The analyst checked the source events
↓
A timeline was built
↓
The sign-in preceded an OAuth consent event
↓
The browser later spawned PowerShell
↓
A mailbox rule appeared shortly afterwards
↓
Copilot suggested hunting pivots
↓
The analyst generated KQL
↓
Then tested and corrected the query
↓
One event did not fit the attack theory
↓
Instead of ignoring it, the analyst investigated it
↓
It explained an apparent gap in the timeline
↓
The evidence was correlated across identity, endpoint and email
↓
Copilot drafted the incident summary
↓
The analyst removed an unsupported conclusion
↓
Added the evidence reference
↓
And documented the remaining uncertainty
↓
The response actions were approved by the responsible human team
↓
The incident was contained
↓
The promptbook was improved
↓
The hunting query was saved
↓
And the lessons were shared with the next shift
↓
Copilot had helped at almost every stage
↓
But the evidence had remained in control
↓
And so had the analyst
The Agent Foskett analyst checklist
| Stage | Ask yourself |
|---|---|
| Question | What am I actually trying to determine? |
| Scope | Which entities and time range matter? |
| Evidence | Which telemetry can answer the question? |
| Copilot | Where can AI save time or broaden analysis? |
| Validation | Which source events prove each important claim? |
| Challenge | What contradicts my theory? |
| Gap | What evidence am I missing? |
| Data | Am I exposing only the information required? |
| Governance | Are roles, plugins and actions authorised? |
| Decision | Which human is accountable? |
| Communication | Can another person understand and reproduce the reasoning? |
| Learning | What should improve before the next incident? |
Congratulations — you completed the 40-lesson Security Copilot Academy
You have progressed from Security Copilot foundations through prompting, plugins and responsible AI; into incident investigation across identity, endpoint, email, cloud and threat intelligence; through KQL, hunting, IOC enrichment, MITRE ATT&CK, malware assistance and end-to-end investigations; and finally into promptbooks, automation, daily SOC operations, measurement, governance, sensitive information and advanced prompting.
The technology will continue to change. The principles should remain familiar: ask good questions, understand your tools, protect the data, test the evidence, document uncertainty and keep accountable human judgement at the centre of the investigation.
Final key takeaways
- Security Copilot is an analyst accelerator, not a replacement for the analyst.
- Strong security fundamentals make AI assistance more valuable.
- Precise questions produce more reviewable investigation results.
- Complex incidents should be decomposed and validated in stages.
- Generated KQL must be understood and tested.
- Every important conclusion should remain traceable to source evidence.
- Contradictions and uncertainty are part of good investigation practice.
- Least privilege, plugin governance and sensitive-data protection remain essential.
- Automation should preserve appropriate human review gates.
- Success should be measured through security outcomes and analyst capability.
- The best AI-enabled analysts become better investigators, not merely better prompters.
- Human judgement and accountability remain at the centre of security operations.
Continue your Agent Foskett training
🏁 Microsoft Security Copilot Academy — Complete
Becoming an AI-enabled security analyst with Microsoft Security Copilot
An AI-enabled security analyst combines Microsoft security expertise, structured prompting, KQL, evidence validation, governance and human judgement to investigate incidents more efficiently without surrendering accountability.
Microsoft Security Copilot analyst operating model
A mature operating model uses Security Copilot to accelerate triage, investigation, hunting, reporting and knowledge transfer while preserving source validation, least privilege, sensitive-data controls and authorised human decision-making.
