Lesson 3 — Navigating the Microsoft Security Copilot Interface
Microsoft Security Copilot can open in different landing experiences depending on your tenant, licence, role and Microsoft rollout stage.
Some users begin in an agents-first experience, while others begin in a chat-first experience with the prompt bar visible immediately.
This lesson explains the common navigation landmarks so analysts can move confidently between agents, sessions, promptbooks, sources, process logs, pinned evidence, settings and shared results.

What you will learn
This lesson introduces the main navigation areas used during Security Copilot investigations and workflows.
Security Copilot navigation model
↓
Identify the landing experience
↓
Agents-first: select or discover an agent
OR
Chat-first: begin from the prompt bar
↓
Use Home to access agents, promptbooks, Build, All history, settings and owner areas
↓
Start or resume a session
↓
Select sources and enabled plugins
↓
Enter a prompt or run a promptbook
↓
Review the process log and source links
↓
Pin important findings
↓
Share or export reviewed results
↓
Return to the source evidence before taking action
Interface landmarks
| Landmark | Purpose | Analyst use |
|---|---|---|
| Home menu | Access the major Security Copilot areas. | Move between Agents, Promptbooks, Build, history and settings. |
| All history | Show previous sessions and create a new chat. | Resume or separate investigations. |
| Prompt bar | Accept natural-language instructions. | Ask ad-hoc security questions. |
| Sources | Control plugins and file inputs. | Select relevant security context. |
| Process log | Show actions, capabilities, sources and processing time. | Understand how a response was produced. |
| Pin board | Collect important responses and summaries. | Maintain the concise case record. |
| Share | Create a link to the entire session. | Collaborate with authorised team members. |
Learning objectives
- Recognise agents-first and chat-first experiences.
- Navigate the Home menu.
- Start and resume chat sessions.
- Use the prompt bar and Sources.
- Read the process log.
- Pin, share and organise results.
Interface rollout can differ
Your homepage may not look exactly like another analyst’s because Microsoft can roll out experiences at different times.
Agents-first experience
In newer experiences, Agents can be the primary landing page and recommended starting point for structured workflows.
Chat-first experience
In the chat-first experience, the prompt bar appears on the homepage as the main entry point.
Common navigation areas
Both experiences use the Home menu to reach the major Security Copilot areas.
Home
Home returns the user to the initial page for the current experience.
Agents
The Agents area provides the agent library, workspace agents and role-appropriate setup or management options.
When to use an agent
Use agents for structured workflows, guided steps and repeatable tasks.
When to use chat
Use a chat session for ad-hoc questions, interactive exploration and investigation pivots.
All history
All history provides access to previous sessions and allows the analyst to create a new session.
Start a clean session
Create a new session for a different incident so earlier context does not influence the new task.
Resume an investigation
Open an existing session when the same case requires follow-up analysis or additional evidence.
Name sessions clearly
Use meaningful names so investigations can be found later without opening every session.
Session context
Follow-up prompts build on information already introduced in the active session.
Context drift
Restate the scope or start a new session when the investigation changes user, device, incident or tenant.
Prompt bar
The prompt bar accepts natural-language requests in an active chat session.
Send a prompt
Enter the request, select Send or press Enter, then review the response as it forms.
Prompt controls
Prompts can be cancelled, edited or deleted during response generation.
Follow-up prompts
Use follow-ups to refine a result, request evidence, change format or explore another hypothesis.
Prompts control
The Prompts control provides access to individual prompts, system capabilities and promptbooks.
System capabilities
Search or use See all system capabilities to review prompts exposed by enabled plugins.
Sources
Sources manages active plugins and supported file inputs used by Security Copilot.
Enable relevant plugins
Turn on the plugins required for the investigation and disable unnecessary sources when tighter scope is useful.
Plugin categories
Sources can include Microsoft, non-Microsoft, website and custom plugins.
Restricted plugins
Preinstalled plugins that the current user cannot access can appear as Restricted.
Plugin settings
Supported plugins can provide personal settings, such as choosing a default Microsoft Sentinel workspace.
File sources
Where uploads are allowed, files can provide additional context when prompts refer to them.
Process log
The process log appears below the prompt and shows what Security Copilot is doing as the response forms.
Selected capability
The process log can reveal which plugin and capability were selected for the prompt.
Actions and sources
Review actions, source use and processing time to understand how the answer was produced.
Direct source links
Many responses include links back to data supplied by the Microsoft service plugin.
Validate in the source product
Open the original product data to confirm that the response represents the evidence accurately.
Pin board
The pin board keeps important prompt-response pairs visible within the session.
Pin verified findings
Pin conclusions, timelines, queries and evidence summaries that should remain in the case record.
Automatic session summary
When the first response is pinned, Security Copilot creates a session summary for the pin board.
Expand the summary
Pin additional prompt-response pairs to expand the information represented in the summary.
Share a session
The Share control creates a link to the entire Security Copilot session for team collaboration.
Full-session scope
A shared link references the entire session, including content added after the link was created.
Sharing risk
Review the whole session and share only with authorised people in the tenant.
Promptbooks
The Promptbooks area displays prebuilt and user-created promptbooks available to the organisation.
Promptbook library
The library can show name, owner, description, prompt count, required plugins and visibility.
Build
Users with appropriate permissions can access Build to create or manage custom agents.
Owner functions
The Owner area is available only to Security Copilot Owners and can include owner settings, plugin settings, role assignment and usage monitoring.
Personal settings
Settings includes preferences such as theme, time zone and language.
Tenant switching
Tenant switching allows an appropriately authorised user to work with security data held in another tenant.
Confirm the active tenant
Before investigating, confirm that Security Copilot is using the tenant containing the required security data.
Get help
The Help menu provides access to documentation, training and support options.
Expect interface changes
Microsoft may change labels or placement, so learn each landmark’s function rather than only its screen position.
Example analyst navigation workflow
↓
Confirm the active tenant
↓
Select Home
↓
Choose All history
↓
Start a new session for Incident 2147
↓
Name the session clearly
↓
Open Sources
↓
Confirm Microsoft Defender XDR and required plugins are enabled
↓
Enter a focused incident-summary prompt
↓
Review the process log
↓
Open direct links to the original evidence
↓
Pin the verified timeline and confirmed entities
↓
Share the reviewed session with the response team
Agent Foskett investigation: “The wrong tenant looked perfectly normal…”
↓
He searched for a critical Microsoft Sentinel incident
↓
The session returned no matching evidence
↓
The prompt was rewritten
↓
The Sentinel plugin was checked
↓
The process log showed the expected capability
↓
But the result still looked empty
↓
Agent Foskett checked the active tenant
↓
Security Copilot was connected to the home tenant
↓
The incident data existed in another authorised tenant
↓
He switched to the tenant containing the security data
↓
He started a clean session
↓
The incident and evidence appeared
↓
The prompt was not the problem
↓
The interface context was wrong
↓
Navigation solved the case before another query was written
Interface validation checklist
| Area | Check | Reason |
|---|---|---|
| Experience | Identify agents-first or chat-first. | The starting workflow differs. |
| Tenant | Confirm the tenant containing the data. | The wrong tenant can produce empty results. |
| Session | Start a clean session for a new case. | Old context can influence prompts. |
| Sources | Confirm plugins and files. | Missing sources reduce context. |
| Process log | Review capabilities, actions and sources. | The log explains response generation. |
| Evidence | Open direct source links. | Source data validates the answer. |
| Pin board | Pin only reviewed outputs. | The board becomes the case summary. |
| Sharing | Review the whole session first. | The link references the full session. |
Key takeaways
- Security Copilot can use agents-first or chat-first landing experiences.
- Home provides access to Agents, Promptbooks, Build, All history, settings and owner functions.
- All history allows analysts to resume or create sessions.
- Sources controls plugins and supported file inputs.
- The process log shows selected capabilities, actions, sources and processing time.
- Direct source links help validate responses.
- The pin board preserves important findings and produces a session summary.
- Shared links reference the full session.
- The active tenant and session context should be checked before rewriting a failed prompt.
What Agent Foskett checked
- Landing experience
- Active tenant
- Session history
- Prompt bar
- Enabled sources
- Process log
- Evidence links
- Pin board
- Sharing scope
Best practices
- Confirm the active tenant.
- Use clean sessions for new cases.
- Name sessions clearly.
- Enable only relevant sources.
- Review the process log.
- Open source evidence.
- Pin verified findings.
- Review before sharing.
- Expect interface changes.
Related Agent Foskett resources
Continue the Microsoft Security Copilot Academy
How do you navigate Microsoft Security Copilot?
Microsoft Security Copilot navigation includes agents-first and chat-first experiences, Home, Agents, Promptbooks, Build, All history, the prompt bar, Sources, the process log, pin board, sharing, settings and tenant switching.
Microsoft Security Copilot process log
The process log shows actions, selected capabilities, source use and processing time so analysts can understand how a response was produced.
