Agent Foskett Academy • Microsoft Security Copilot • Module 4 • Lesson 40

Lesson 40 — Becoming an AI-Enabled Security Analyst

Forty lessons ago, we began with a simple question: what is Microsoft Security Copilot, and where does it fit in modern security operations?

We have since moved through prompting, plugins, incident investigation, identity, endpoint, phishing, cloud incidents, threat intelligence, timelines, KQL, hunting, promptbooks, automation, governance, sensitive information and advanced operational practice.

The final lesson brings everything together. Becoming an AI-enabled security analyst is not about handing investigations to AI. It is about combining Microsoft security expertise, good questions, evidence, validation, governance and human judgement into a stronger way of working.

The goal was never to replace the analyst. The goal was to build a better analyst.
Agent Foskett Becoming an AI-Enabled Security Analyst final lesson
What you will bring together

The complete Security Copilot analyst operating model.

✓ Investigation knowledge
✓ Prompting and KQL
✓ Validation and governance
✓ Human judgement

The AI-enabled analyst operating model

SECURITY QUESTION

Define scope, entities and time range

COLLECT EVIDENCE
Defender • Sentinel • Entra • Email • Cloud • Other telemetry

USE COPILOT
Summarise • Explain • Correlate • Generate pivots • Assist with KQL

VALIDATE
Return to source telemetry • Test queries • Check identifiers

CHALLENGE
Alternative explanations • Contradictory evidence • Missing data

DECIDE
Human analyst applies security judgement

RESPOND
Approved actions with accountability

COMMUNICATE
Technical findings • Handover • Executive summary

LEARN
Improve promptbooks • Queries • Controls • Analyst capability

From traditional analyst to AI-enabled analyst

CapabilityTraditional approachAI-enabled approach
TriageManually review every initial detailUse Copilot to accelerate orientation, then validate.
InvestigationManually build pivots and summariesUse AI to develop pivots while retaining evidence control.
KQLWrite and troubleshoot every query manuallyGenerate and explain ideas, then test every query.
HuntingDevelop hypotheses and telemetry mapping manuallyUse AI to broaden hypotheses and relevant evidence sources.
ReportingRewrite technical findings for each audienceGenerate audience-specific drafts from validated findings.
KnowledgeSearch documentation and notesUse Copilot to accelerate explanation and knowledge transfer.
DecisionHuman judgementStill human judgement.

Learning objectives

Bring investigation knowledge, prompting, validation, governance and human judgement together into a mature Security Copilot operating model.

The AI-enabled analyst

An AI-enabled security analyst uses Copilot to accelerate reasoning and repetitive work while remaining responsible for evidence, decisions and outcomes.

Start with investigation fundamentals

Identity, endpoint, email, cloud and network evidence still need to be understood before AI assistance can be used well.

Know the Microsoft security ecosystem

Effective Copilot use depends on understanding where evidence lives across Defender XDR, Sentinel, Entra, Intune, Purview and connected services.

Know what telemetry can prove

Different logs answer different questions. A generated narrative cannot compensate for missing or inappropriate telemetry.

Ask better questions

Strong analysts convert vague alerts into precise questions about entities, behaviours, time, sequence and evidence.

Use Copilot to accelerate triage

Incident summaries and contextual explanations can reduce the time required to understand the starting point.

Use Copilot to accelerate investigation

Prompts can help develop pivots, timelines, hypotheses and questions for further evidence collection.

Use Copilot to accelerate hunting

AI can help turn hypotheses into hunting ideas and KQL, provided the analyst validates the query and results.

Use Copilot to accelerate reporting

Technical findings can be transformed into analyst handovers and executive summaries without losing evidence boundaries.

Use Copilot to accelerate learning

Explanations of KQL, commands, techniques and security concepts can help analysts develop their own capability.

Do not outsource understanding

If the analyst cannot explain why a query, conclusion or response action makes sense, Copilot has not solved the underlying problem.

Prompt with purpose

Every prompt should contribute to an investigation objective rather than generate activity for its own sake.

Provide relevant context

Include the entities, time range and evidence needed to answer the question.

Use constraints

Tell Copilot what evidence it may use, what it must not assume and how uncertainty should be represented.

Use decomposition

Break complex incidents into smaller identity, endpoint, email, cloud and correlation tasks.

Use iteration

Refine questions as new evidence changes the investigation.

Use structured outputs

Timelines, evidence tables and confirmed-versus-unconfirmed findings make AI output easier to validate.

Challenge the answer

Ask what contradicts the current theory and what benign explanations remain possible.

Look for missing evidence

A mature analyst notices what the data cannot yet answer.

Return to source evidence

Important conclusions must remain traceable to Defender, Sentinel, Entra, email, cloud or other authoritative telemetry.

Validate KQL

Generated queries must be checked for tables, fields, syntax, filters, joins, logic and returned results.

Validate identifiers

Check usernames, domains, IPs, hashes, process names and timestamps before they become part of the incident record.

Preserve uncertainty

Do not allow polished AI wording to turn a possibility into a confirmed fact.

Preserve the original evidence

Generated summaries are derivative artefacts, not replacements for source telemetry.

Apply least privilege

Security Copilot platform roles and underlying product permissions should both reflect the user's actual duties.

Govern plugins

Integrations should have approved scope, ownership, authentication and data-handling controls.

Protect sensitive information

Use the minimum necessary personal, confidential and regulated information in prompts, uploads and reports.

Protect secrets

Credentials, tokens, API keys and private keys require strict handling and should not be casually placed into prompts.

Use approved promptbooks

Reusable workflows improve consistency when they have owners, inputs, outputs, versions and review dates.

Automate carefully

Repetitive tasks can be accelerated, but automation should not remove necessary evidence checks or approval gates.

Keep humans on consequential decisions

Containment, access changes, customer communications and other high-impact actions require authorised human judgement.

Build peer review into important cases

A second analyst can challenge assumptions, evidence gaps and overly confident conclusions.

Use Copilot in shift handovers

Summarise confirmed findings, unresolved questions, actions completed, ownership and next steps.

Use Copilot in daily operations

Integrate AI assistance where it reduces friction without making the SOC dependent on generated output.

Measure time saved

Track whether Copilot genuinely reduces repetitive analyst effort.

Measure quality

Check whether investigations become more complete, consistent and evidence-driven.

Measure depth

Determine whether analysts examine more relevant telemetry and test more plausible hypotheses.

Measure outcomes

The goal is better security decisions, not more prompts.

Measure analyst development

Copilot should help people learn to investigate, query and reason more effectively.

Avoid dependency

Analysts should still be able to investigate when Copilot is unavailable or inappropriate.

Train continuously

Prompting, product capabilities, governance and security threats all evolve.

Review access continuously

Roles, plugins and permissions should change when responsibilities change.

Review workflows continuously

Promptbooks and operational procedures should evolve as the SOC learns what works.

Review platform changes

New Security Copilot capabilities should be evaluated before broad production adoption.

Document operating principles

Teams should agree how AI is used, validated, governed and attributed.

Make accountability explicit

Every investigation and response decision still belongs to an authorised human role.

Build trust through evidence

Trust in AI-assisted security operations comes from repeatable validation, not from confident language.

Use AI where it adds value

Not every security task needs Copilot; sometimes the fastest route is a direct query or portal investigation.

Know when to stop prompting

If evidence is missing, collect evidence instead of asking the same question again.

Develop investigation instinct

Experienced analysts recognise unusual sequences, weak assumptions and missing telemetry quickly.

Develop KQL skill

Understanding queries makes AI-generated hunting and investigation work far more useful.

Develop communication skill

Analysts need to explain technical evidence clearly to engineers, managers and executives.

Develop governance awareness

Modern security analysts must understand privacy, access control, auditing and responsible AI use.

Develop healthy scepticism

Question AI output without dismissing the productivity and insight it can provide.

Build repeatability

Good investigations should be reproducible by another analyst using the same evidence and process.

Build defensibility

Important conclusions should be explainable later to management, auditors, customers or regulators.

Build resilience

The operating model should continue to work when staff, tools, plugins or platform capabilities change.

Move from AI user to AI-enabled analyst

The difference is not how often someone prompts Copilot; it is how well they combine AI assistance with security expertise.

The analyst remains the control plane

Tools can summarise, correlate and suggest, but the analyst decides what evidence means and what happens next.

Final Academy principle

Use Security Copilot to make human security judgement faster, broader and more consistent — never to make human judgement optional.

The complete investigation prompt pattern

ROLE Act as a security analyst assisting with an incident investigation. OBJECTIVE State exactly what must be determined. SCOPE Define users, devices, applications, resources and time range. EVIDENCE Identify the telemetry or artefacts that may be used. TASKS 1. Build the relevant timeline. 2. Identify confirmed observations. 3. Separate interpretation from fact. 4. Identify evidence supporting the working hypothesis. 5. Identify contradictory or benign evidence. 6. Identify missing telemetry. 7. Recommend the next investigation pivots. CONSTRAINTS Do not invent missing evidence. Do not convert uncertainty into certainty. Do not recommend consequential action without supporting evidence. OUTPUT Timeline Confirmed findings Unconfirmed findings Contradictions Evidence gaps Next investigation steps VALIDATION Every important conclusion must be checked against source telemetry.

Agent Foskett's final investigation

The incident began with three alerts

A suspicious sign-in

A PowerShell process

And an unusual mailbox rule

At the beginning of the Academy they might have looked like three separate problems

Now the analyst started differently

He defined the user, device and time range

Copilot summarised the incidents

The analyst checked the source events

A timeline was built

The sign-in preceded an OAuth consent event

The browser later spawned PowerShell

A mailbox rule appeared shortly afterwards

Copilot suggested hunting pivots

The analyst generated KQL

Then tested and corrected the query

One event did not fit the attack theory

Instead of ignoring it, the analyst investigated it

It explained an apparent gap in the timeline

The evidence was correlated across identity, endpoint and email

Copilot drafted the incident summary

The analyst removed an unsupported conclusion

Added the evidence reference

And documented the remaining uncertainty

The response actions were approved by the responsible human team

The incident was contained

The promptbook was improved

The hunting query was saved

And the lessons were shared with the next shift

Copilot had helped at almost every stage

But the evidence had remained in control

And so had the analyst
That is what becoming an AI-enabled security analyst looks like.

The Agent Foskett analyst checklist

StageAsk yourself
QuestionWhat am I actually trying to determine?
ScopeWhich entities and time range matter?
EvidenceWhich telemetry can answer the question?
CopilotWhere can AI save time or broaden analysis?
ValidationWhich source events prove each important claim?
ChallengeWhat contradicts my theory?
GapWhat evidence am I missing?
DataAm I exposing only the information required?
GovernanceAre roles, plugins and actions authorised?
DecisionWhich human is accountable?
CommunicationCan another person understand and reproduce the reasoning?
LearningWhat should improve before the next incident?

Congratulations — you completed the 40-lesson Security Copilot Academy

You have progressed from Security Copilot foundations through prompting, plugins and responsible AI; into incident investigation across identity, endpoint, email, cloud and threat intelligence; through KQL, hunting, IOC enrichment, MITRE ATT&CK, malware assistance and end-to-end investigations; and finally into promptbooks, automation, daily SOC operations, measurement, governance, sensitive information and advanced prompting.

The technology will continue to change. The principles should remain familiar: ask good questions, understand your tools, protect the data, test the evidence, document uncertainty and keep accountable human judgement at the centre of the investigation.

40 lessons complete. The investigation continues.

Final key takeaways

  • Security Copilot is an analyst accelerator, not a replacement for the analyst.
  • Strong security fundamentals make AI assistance more valuable.
  • Precise questions produce more reviewable investigation results.
  • Complex incidents should be decomposed and validated in stages.
  • Generated KQL must be understood and tested.
  • Every important conclusion should remain traceable to source evidence.
  • Contradictions and uncertainty are part of good investigation practice.
  • Least privilege, plugin governance and sensitive-data protection remain essential.
  • Automation should preserve appropriate human review gates.
  • Success should be measured through security outcomes and analyst capability.
  • The best AI-enabled analysts become better investigators, not merely better prompters.
  • Human judgement and accountability remain at the centre of security operations.

Continue your Agent Foskett training

You have completed the Microsoft Security Copilot track. Continue developing your investigation skills across the wider Agent Foskett Academy.

Becoming an AI-enabled security analyst with Microsoft Security Copilot

An AI-enabled security analyst combines Microsoft security expertise, structured prompting, KQL, evidence validation, governance and human judgement to investigate incidents more efficiently without surrendering accountability.

Microsoft Security Copilot analyst operating model

A mature operating model uses Security Copilot to accelerate triage, investigation, hunting, reporting and knowledge transfer while preserving source validation, least privilege, sensitive-data controls and authorised human decision-making.