Lesson 10 — Security Copilot Best Practices
Security Copilot is most effective when it is used as part of a disciplined investigation process.
Clear prompts, correct permissions and relevant plugins improve the response, but the analyst must still inspect process logs, open original sources, validate evidence and control consequential actions.
This lesson brings Module 1 together into a repeatable operating method for reliable, responsible and evidence-driven use of Microsoft Security Copilot.

What you will learn
This lesson combines the Module 1 foundations into one reliable working method.
Agent Foskett Security Copilot operating cycle
Confirm tenant, permissions, plugins, product health and scope
↓
PROMPT
Define goal, context, source and expectations
↓
INSPECT
Review the process log, capabilities and source links
↓
VALIDATE
Check evidence, entities, timestamps, context and alternatives
↓
DECIDE
Apply confidence, review gates, approvals and business impact
↓
DOCUMENT
Record facts, inference, uncertainty, Copilot contribution and ownership
↓
IMPROVE
Capture corrections, measure outcomes and update workflows
Best-practice framework
| Stage | Core activity | Expected result |
|---|---|---|
| Prepare | Confirm tenant, product health, permissions, plugins and scope. | Correct context before prompting. |
| Prompt | Use goal, context, source and expectations. | A clear, neutral and focused request. |
| Inspect | Review process logs, selected capabilities and source links. | Transparency into how the answer was produced. |
| Validate | Check facts, entities, timestamps, business context and alternatives. | An evidence-supported conclusion. |
| Decide | Apply review gates, approvals and impact assessment. | An accountable human response decision. |
| Improve | Capture corrections, measure quality and update workflows. | A more reliable operating model over time. |
Learning objectives
- Prepare Security Copilot correctly.
- Use a repeatable prompt method.
- Inspect plugins, process logs and sources.
- Validate evidence across products.
- Control high-impact actions.
- Document accountability and uncertainty.
- Improve workflows continuously.
Begin with the investigation objective
Define the security question, intended audience and decision the output must support before opening a session.
Use Security Copilot for the right task
Use Copilot to accelerate analysis, explanation, correlation and drafting rather than replacing evidence collection or accountable decisions.
Confirm the active tenant
Check that the current tenant contains the security data required for the task.
Confirm the workspace
For Sentinel and other scoped products, verify that the correct workspace, subscription or environment is selected.
Check data health
Confirm connectors, sensors, retention, onboarding and product health before treating missing evidence as proof that nothing happened.
Apply least privilege
Assign only the Security Copilot and connected-product permissions needed for the analyst’s role.
Separate platform and product access
Access to Security Copilot does not automatically grant access to Defender, Sentinel, Entra, Intune, Purview or other product data.
Choose relevant plugins
Enable the plugins needed for the task and avoid unnecessary sources that can complicate selection or scope.
Review plugin settings
Check workspaces, tenants, filters, authentication and other plugin-specific configuration.
Start a clean session
Use a new session for a new incident or materially different investigation to avoid context drift.
Name sessions clearly
Use incident IDs, dates or investigation subjects so sessions can be found and reviewed later.
Protect session content
Treat prompts, responses, uploaded files, pinned items, exports and shared links as security records.
Use the four prompt elements
Build prompts around goal, context, source and expectations.
Use strong action verbs
Start with instructions such as summarise, compare, explain, investigate, correlate, generate or validate.
State the security context
Explain why the information is needed and how the result will be used.
Identify the source
Specify the incident, user, device, alert, file, workspace, time range or plugin that should ground the response.
Set output expectations
Define the format, audience, depth, evidence requirements and desired next steps.
Keep prompts neutral
Do not write compromise, malicious intent or guilt into the question before the evidence is reviewed.
Control the scope
Limit time range, entities, products and expected output to reduce noise.
Break complex work into stages
Use separate prompts for orientation, evidence collection, analysis, validation and reporting.
Use iterative prompting
Refine the result through focused follow-up questions rather than forcing every task into one prompt.
Ask for evidence
Require supporting alerts, entities, logs, source links or product records for major conclusions.
Ask for uncertainty
Request missing context, conflicting evidence, limitations and anything that cannot be verified.
Ask for alternatives
Compare malicious and legitimate explanations for suspicious behaviour.
Ask for confidence
Require an evidence-based confidence level rather than accepting a fluent conclusion.
Review the process log
Inspect the actions, selected capabilities, plugins, sources and processing time used for the response.
Open direct source links
Validate claims in the original Microsoft security product or approved external source.
Validate timestamps
Check time zones, sequence, gaps and whether events genuinely overlap.
Validate identities
Confirm users, service principals, administrators and authentication context.
Validate devices
Confirm device IDs, hostnames, owners, operating systems and endpoint timelines.
Validate network context
Check IP ownership, VPNs, proxies, domains, ports and expected network paths.
Validate email evidence
Confirm delivery, sender authentication, URLs, attachments, clicks and post-delivery actions.
Validate cloud evidence
Separate posture findings and attack paths from observed exploitation.
Validate data-security evidence
Confirm users, locations, labels, policies and document access before attributing risk.
Validate generated KQL
Check tables, fields, syntax, filters, joins, time windows, performance and returned rows.
Treat summaries as drafts
An incident summary is an orientation aid, not a final case conclusion.
Treat recommendations as proposals
Assess business impact, technical risk, reversibility and approval requirements.
Use human review gates
Require approval before consequential actions such as account disablement, device isolation or destructive remediation.
Use peer review for high-impact cases
A second analyst, incident commander or system owner should review critical findings.
Document fact, inference and unknowns
Keep confirmed evidence separate from likely interpretation and unresolved questions.
Record the role of Copilot
Investigation notes should identify where Copilot generated summaries, queries, explanations or recommendations.
Record decision ownership
Document who reviewed the evidence and who authorised the final response.
Protect sensitive information
Include only the personal, confidential or regulated data required for the task.
Review shared sessions
Shared links can expose the full session, so review all content before distribution.
Protect exports
Apply classification, retention, access and distribution controls to exported reports.
Use promptbooks for repeatable work
Standardise deterministic workflows while validating every intermediate response.
Use chat for exploration
Use ad-hoc sessions when the investigation direction is uncertain or changing.
Use agents with governance
Deploy agents only with clear scope, permissions, human oversight and approval controls.
Test promptbooks and agents
Use realistic, benign, malicious and failure scenarios before broad deployment.
Do not hide failures
Plugin errors, missing context and failed promptbook steps must remain visible.
Measure quality, not prompt volume
Evaluate time saved, investigation depth, consistency, accuracy and operational outcomes.
Capture corrected conclusions
When Copilot is wrong, record the correction and improve the prompt, promptbook or procedure.
Maintain a prompt library
Keep approved prompts for common incidents, reporting tasks and hunting scenarios.
Version operational workflows
Track changes to prompts, plugin dependencies, schemas, permissions and expected outputs.
Retire outdated content
Remove prompts and workflows that depend on deprecated portals, APIs, tables or product behaviour.
Train analysts on source products
Copilot users still need Defender, Sentinel, Entra, cloud, endpoint, email and KQL knowledge.
Avoid dependency
Analysts should be able to reproduce critical conclusions without relying solely on AI output.
Create an escalation path
Define what analysts should do when Copilot is unavailable, inconsistent or unable to access required data.
Review audit information
Use available auditing and governance records to understand platform activity and support oversight.
Optimise capacity responsibly
Remove redundant prompts and inefficient promptbooks while preserving investigation quality.
Close the session properly
Pin verified findings, document limitations, export only approved content and record the final human decision.
End-to-end analyst checklist
2. Confirm required product data is healthy and available
3. Verify Security Copilot and product permissions
4. Enable only relevant plugins
5. Start a clean, clearly named session
6. Define the investigation objective
7. Write the prompt using goal, context, source and expectations
8. Request evidence, uncertainty and alternative explanations
9. Review the process log and selected capabilities
10. Open original source records
11. Validate entities, timestamps and business context
12. Test generated KQL and recommendations
13. Separate facts, inference and unknowns
14. Assign evidence-based confidence
15. Apply peer review and approval gates
16. Document the final human decision
17. Capture corrections and update the workflow
Agent Foskett investigation: “Everything worked—and the answer was still wrong…”
↓
The required plugins were enabled
↓
The analyst had the necessary permissions
↓
The prompt was clear and well structured
↓
The process log showed the expected capabilities
↓
Security Copilot produced a confident incident summary
↓
The summary linked a suspicious email to a PowerShell event
↓
Agent Foskett opened the original email evidence
↓
The message had been quarantined before delivery
↓
The PowerShell event occurred on a different device and user
↓
The events were close in time but not connected
↓
Every technical component had operated correctly
↓
The interpretation was still wrong
↓
The incident was separated into two unrelated investigations
↓
The promptbook was updated to validate delivery and entity identity before correlation
↓
Best practice succeeded because the analyst checked the evidence
Security Copilot best-practice checklist
| Area | Question | Required action |
|---|---|---|
| Environment | Are tenant, workspace and product health correct? | Resolve context and telemetry issues first. |
| Access | Does the analyst have only the required permissions? | Apply least privilege. |
| Plugins | Are relevant plugins enabled and configured? | Review Sources and settings. |
| Prompt | Does it include goal, context, source and expectations? | Rewrite vague or leading instructions. |
| Transparency | Can the response be traced through the process log? | Inspect actions and source links. |
| Evidence | Do original records support every major claim? | Validate independently. |
| Uncertainty | Are gaps and conflicts visible? | Document limitations and confidence. |
| Impact | Could the action disrupt users or systems? | Require review and approval. |
| Privacy | Is sensitive information appropriately minimised? | Protect prompts, sessions and exports. |
| Improvement | Were errors and lessons captured? | Update prompts, promptbooks and procedures. |
Module 1 key takeaways
- Security Copilot is an AI-powered security solution that augments analyst expertise.
- Prompts should include goal, context, source and expectations.
- Standalone, embedded, promptbook, plugin and agent experiences support different workflows.
- Permissions and enabled plugins determine what data and capabilities are available.
- The process log provides transparency into actions and sources.
- AI-generated output can be inaccurate even when the platform is configured correctly.
- Original alerts, logs, entities, policies and product records remain authoritative.
- Human oversight is required for consequential actions.
- Responsible use requires privacy, least privilege, transparency and accountability.
- A mature operating method prepares, prompts, inspects, validates, decides, documents and improves.
What Agent Foskett checked
- Tenant and workspace
- Plugin configuration
- User permissions
- Prompt structure
- Process log
- Email delivery
- User identity
- Device identity
- Timeline correlation
- Final approval
Best practices
- Prepare before prompting.
- Use focused neutral prompts.
- Request evidence and uncertainty.
- Review process logs.
- Open original records.
- Validate KQL and recommendations.
- Apply review gates.
- Protect sensitive data.
- Document decisions.
- Improve continuously.
Related Agent Foskett resources
Continue the Microsoft Security Copilot Academy
Microsoft Security Copilot best practices
Security Copilot best practices include confirming tenant and permissions, selecting relevant plugins, writing focused prompts, reviewing process logs, validating original evidence and keeping humans accountable for response decisions.
Reliable Security Copilot investigations
A reliable workflow prepares the environment, prompts with goal, context, source and expectations, inspects sources, validates claims, applies review gates and documents the final human decision.
Security Copilot analyst workflow
Analysts should measure quality and operational outcomes, maintain approved prompt libraries, test promptbooks and agents, protect sensitive information and continuously improve workflows after errors or corrections.
