Agent Foskett Academy • Microsoft Security Copilot • Module 1 • Lesson 3

Lesson 3 — Navigating the Microsoft Security Copilot Interface

Microsoft Security Copilot can open in different landing experiences depending on your tenant, licence, role and Microsoft rollout stage.

Some users begin in an agents-first experience, while others begin in a chat-first experience with the prompt bar visible immediately.

This lesson explains the common navigation landmarks so analysts can move confidently between agents, sessions, promptbooks, sources, process logs, pinned evidence, settings and shared results.

The interface may change. The investigation landmarks remain: task, context, sources, process, evidence and decision.
Agent Foskett navigating Microsoft Security Copilot interface lesson
What you will learn

This lesson introduces the main navigation areas used during Security Copilot investigations and workflows.

✓ Agents-first and chat-first experiences
✓ Home, All history and new sessions
✓ Sources, prompts and process logs
✓ Pinning, sharing, promptbooks and settings

Security Copilot navigation model

Sign in to Microsoft Security Copilot

Identify the landing experience

Agents-first: select or discover an agent
OR
Chat-first: begin from the prompt bar

Use Home to access agents, promptbooks, Build, All history, settings and owner areas

Start or resume a session

Select sources and enabled plugins

Enter a prompt or run a promptbook

Review the process log and source links

Pin important findings

Share or export reviewed results

Return to the source evidence before taking action

Interface landmarks

LandmarkPurposeAnalyst use
Home menuAccess the major Security Copilot areas.Move between Agents, Promptbooks, Build, history and settings.
All historyShow previous sessions and create a new chat.Resume or separate investigations.
Prompt barAccept natural-language instructions.Ask ad-hoc security questions.
SourcesControl plugins and file inputs.Select relevant security context.
Process logShow actions, capabilities, sources and processing time.Understand how a response was produced.
Pin boardCollect important responses and summaries.Maintain the concise case record.
ShareCreate a link to the entire session.Collaborate with authorised team members.

Learning objectives

  • Recognise agents-first and chat-first experiences.
  • Navigate the Home menu.
  • Start and resume chat sessions.
  • Use the prompt bar and Sources.
  • Read the process log.
  • Pin, share and organise results.

Interface rollout can differ

Your homepage may not look exactly like another analyst’s because Microsoft can roll out experiences at different times.

Agents-first experience

In newer experiences, Agents can be the primary landing page and recommended starting point for structured workflows.

Chat-first experience

In the chat-first experience, the prompt bar appears on the homepage as the main entry point.

Common navigation areas

Both experiences use the Home menu to reach the major Security Copilot areas.

Home

Home returns the user to the initial page for the current experience.

Agents

The Agents area provides the agent library, workspace agents and role-appropriate setup or management options.

When to use an agent

Use agents for structured workflows, guided steps and repeatable tasks.

When to use chat

Use a chat session for ad-hoc questions, interactive exploration and investigation pivots.

All history

All history provides access to previous sessions and allows the analyst to create a new session.

Start a clean session

Create a new session for a different incident so earlier context does not influence the new task.

Resume an investigation

Open an existing session when the same case requires follow-up analysis or additional evidence.

Name sessions clearly

Use meaningful names so investigations can be found later without opening every session.

Session context

Follow-up prompts build on information already introduced in the active session.

Context drift

Restate the scope or start a new session when the investigation changes user, device, incident or tenant.

Prompt bar

The prompt bar accepts natural-language requests in an active chat session.

Send a prompt

Enter the request, select Send or press Enter, then review the response as it forms.

Prompt controls

Prompts can be cancelled, edited or deleted during response generation.

Follow-up prompts

Use follow-ups to refine a result, request evidence, change format or explore another hypothesis.

Prompts control

The Prompts control provides access to individual prompts, system capabilities and promptbooks.

System capabilities

Search or use See all system capabilities to review prompts exposed by enabled plugins.

Sources

Sources manages active plugins and supported file inputs used by Security Copilot.

Enable relevant plugins

Turn on the plugins required for the investigation and disable unnecessary sources when tighter scope is useful.

Plugin categories

Sources can include Microsoft, non-Microsoft, website and custom plugins.

Restricted plugins

Preinstalled plugins that the current user cannot access can appear as Restricted.

Plugin settings

Supported plugins can provide personal settings, such as choosing a default Microsoft Sentinel workspace.

File sources

Where uploads are allowed, files can provide additional context when prompts refer to them.

Process log

The process log appears below the prompt and shows what Security Copilot is doing as the response forms.

Selected capability

The process log can reveal which plugin and capability were selected for the prompt.

Actions and sources

Review actions, source use and processing time to understand how the answer was produced.

Direct source links

Many responses include links back to data supplied by the Microsoft service plugin.

Validate in the source product

Open the original product data to confirm that the response represents the evidence accurately.

Pin board

The pin board keeps important prompt-response pairs visible within the session.

Pin verified findings

Pin conclusions, timelines, queries and evidence summaries that should remain in the case record.

Automatic session summary

When the first response is pinned, Security Copilot creates a session summary for the pin board.

Expand the summary

Pin additional prompt-response pairs to expand the information represented in the summary.

Share a session

The Share control creates a link to the entire Security Copilot session for team collaboration.

Full-session scope

A shared link references the entire session, including content added after the link was created.

Sharing risk

Review the whole session and share only with authorised people in the tenant.

Promptbooks

The Promptbooks area displays prebuilt and user-created promptbooks available to the organisation.

Promptbook library

The library can show name, owner, description, prompt count, required plugins and visibility.

Build

Users with appropriate permissions can access Build to create or manage custom agents.

Owner functions

The Owner area is available only to Security Copilot Owners and can include owner settings, plugin settings, role assignment and usage monitoring.

Personal settings

Settings includes preferences such as theme, time zone and language.

Tenant switching

Tenant switching allows an appropriately authorised user to work with security data held in another tenant.

Confirm the active tenant

Before investigating, confirm that Security Copilot is using the tenant containing the required security data.

Get help

The Help menu provides access to documentation, training and support options.

Expect interface changes

Microsoft may change labels or placement, so learn each landmark’s function rather than only its screen position.

Example analyst navigation workflow

Open Microsoft Security Copilot

Confirm the active tenant

Select Home

Choose All history

Start a new session for Incident 2147

Name the session clearly

Open Sources

Confirm Microsoft Defender XDR and required plugins are enabled

Enter a focused incident-summary prompt

Review the process log

Open direct links to the original evidence

Pin the verified timeline and confirmed entities

Share the reviewed session with the response team

Agent Foskett investigation: “The wrong tenant looked perfectly normal…”

Agent Foskett opened Security Copilot

He searched for a critical Microsoft Sentinel incident

The session returned no matching evidence

The prompt was rewritten

The Sentinel plugin was checked

The process log showed the expected capability

But the result still looked empty

Agent Foskett checked the active tenant

Security Copilot was connected to the home tenant

The incident data existed in another authorised tenant

He switched to the tenant containing the security data

He started a clean session

The incident and evidence appeared

The prompt was not the problem

The interface context was wrong

Navigation solved the case before another query was written
Before changing the prompt, check the tenant, session, sources, plugins and process log.

Interface validation checklist

AreaCheckReason
ExperienceIdentify agents-first or chat-first.The starting workflow differs.
TenantConfirm the tenant containing the data.The wrong tenant can produce empty results.
SessionStart a clean session for a new case.Old context can influence prompts.
SourcesConfirm plugins and files.Missing sources reduce context.
Process logReview capabilities, actions and sources.The log explains response generation.
EvidenceOpen direct source links.Source data validates the answer.
Pin boardPin only reviewed outputs.The board becomes the case summary.
SharingReview the whole session first.The link references the full session.

Key takeaways

  • Security Copilot can use agents-first or chat-first landing experiences.
  • Home provides access to Agents, Promptbooks, Build, All history, settings and owner functions.
  • All history allows analysts to resume or create sessions.
  • Sources controls plugins and supported file inputs.
  • The process log shows selected capabilities, actions, sources and processing time.
  • Direct source links help validate responses.
  • The pin board preserves important findings and produces a session summary.
  • Shared links reference the full session.
  • The active tenant and session context should be checked before rewriting a failed prompt.

What Agent Foskett checked

  • Landing experience
  • Active tenant
  • Session history
  • Prompt bar
  • Enabled sources
  • Process log
  • Evidence links
  • Pin board
  • Sharing scope

Best practices

  • Confirm the active tenant.
  • Use clean sessions for new cases.
  • Name sessions clearly.
  • Enable only relevant sources.
  • Review the process log.
  • Open source evidence.
  • Pin verified findings.
  • Review before sharing.
  • Expect interface changes.

Related Agent Foskett resources

Continue through the Security Copilot Academy and review the previous lessons that explain the platform and response-processing model.

Continue the Microsoft Security Copilot Academy

Lesson 3 explains the interface and investigation landmarks. The next lesson introduces prompting fundamentals for security analysts.
⬅ Previous lesson
Lesson 2 — How Microsoft Security Copilot WorksUnderstand prompts, grounding, plugins, permissions, models and response generation.
🏠 Academy home
Microsoft Security Copilot AcademyReview the complete 40-lesson roadmap.
📚 Module 1
Lesson 4 — Prompting Fundamentals for Security AnalystsLearn how goals, context, scope, expectations and evidence requests shape a useful security prompt.

How do you navigate Microsoft Security Copilot?

Microsoft Security Copilot navigation includes agents-first and chat-first experiences, Home, Agents, Promptbooks, Build, All history, the prompt bar, Sources, the process log, pin board, sharing, settings and tenant switching.

Microsoft Security Copilot process log

The process log shows actions, selected capabilities, source use and processing time so analysts can understand how a response was produced.