Agent Foskett Academy • Microsoft Security Copilot • Module 1 • Lesson 8

Lesson 8 — Using Security Copilot Across Microsoft Security

Microsoft Security Copilot can be used through a standalone experience and through embedded experiences inside supported Microsoft security products.

Its value becomes most visible when an investigation crosses identity, endpoint, email, cloud, SIEM, device-management and data-security evidence.

This lesson explains how Security Copilot supports workflows across Microsoft Defender XDR, Sentinel, Entra, Defender for Cloud, Intune and Purview while keeping permissions, product context and source evidence intact.

One investigation can cross many products. The evidence still belongs to each source.
Agent Foskett Using Security Copilot Across Microsoft Security lesson
What you will learn

This lesson maps Security Copilot to the Microsoft security products analysts use during real investigations.

✓ Standalone and embedded experiences
✓ Defender, Sentinel, Entra and cloud workflows
✓ Intune, Purview and data-security workflows
✓ Cross-product evidence correlation

Microsoft Security Copilot ecosystem model

Microsoft Defender XDR — incidents, alerts and entities

Microsoft Sentinel — SIEM, logs and hunting

Microsoft Entra — identity and access

Defender for Cloud — resources, posture and attack paths

Microsoft Intune — device compliance and configuration

Microsoft Purview — data security and compliance

Security Copilot standalone, embedded, plugin and agent experiences

AI-assisted summary, explanation, correlation and workflow support

Analyst validates each claim in the original product

Microsoft security product map

ProductPrimary evidenceSecurity Copilot use
Microsoft Defender XDRIncidents, alerts, entities, advanced hunting and cross-domain evidence.Summarise and investigate endpoint, identity, email and cloud app activity.
Microsoft SentinelSIEM incidents, analytics, logs, hunting, KQL and workspace context.Triage incidents and investigate broader organisational telemetry.
Microsoft EntraSign-ins, identity risk, access, authentication and privileged activity.Investigate suspected identity compromise and access changes.
Defender for CloudCloud posture, recommendations, alerts, attack paths and resources.Understand workload exposure and cloud attack context.
Microsoft IntuneDevice compliance, configuration, security baselines and administration.Explain device state and policy outcomes.
Microsoft PurviewDLP, information protection, insider risk and data-security evidence.Investigate sensitive data use and policy activity.

Learning objectives

  • Distinguish standalone and embedded experiences.
  • Understand product-specific Security Copilot workflows.
  • Recognise the role of plugins and permissions.
  • Correlate identity, endpoint, email, cloud and data evidence.
  • Use process logs and source links.
  • Avoid false cross-product correlation.
  • Build a verified unified timeline.

Standalone experience

Use the dedicated Security Copilot portal for broad investigations, promptbooks, agents, plugins and cross-product reasoning.

Embedded experiences

Use Security Copilot inside supported Microsoft security products where the current page, alert or incident provides immediate context.

Context follows the workflow

Embedded experiences reduce portal switching because the AI assistance appears inside the product where the analyst is already working.

Permissions still define visibility

Security Copilot uses the signed-in user’s permissions and cannot retrieve product data the analyst is not authorised to access.

Microsoft Defender XDR

Use Security Copilot to support incident summaries, alert explanations, entity review, script analysis and cross-domain investigations.

Defender incident summaries

Create an initial narrative from alerts, users, devices, mailboxes and cloud app activity, then verify each claim.

Defender alert explanation

Ask Copilot to explain unfamiliar detections, behaviours, severity and recommended investigation pivots.

Defender entity investigation

Use users, devices, mailboxes, IP addresses, files and cloud applications as pivots through the incident.

Defender advanced hunting

Use Copilot to assist with KQL ideas, query explanation and refinement while validating tables, fields and results.

Microsoft Sentinel

Use Security Copilot to support SIEM incident triage, log analysis, hunting, KQL development and response workflows.

Sentinel incident triage

Summarise incident scope, analytics rules, entities, evidence and unresolved questions before deeper investigation.

Sentinel KQL assistance

Generate or explain KQL against the intended workspace and tables, then test the query and inspect returned rows.

Sentinel workspace context

Confirm the selected workspace, connected data sources, retention and permissions before trusting the answer.

Unified security operations

Sentinel incidents can be investigated alongside Defender XDR context where the unified security operations experience is enabled.

Microsoft Entra

Use Security Copilot to support identity, sign-in, access, Conditional Access and privileged-role investigations.

Risky sign-ins

Review location, IP ownership, authentication method, MFA, device context and user risk before declaring compromise.

Identity changes

Investigate password resets, authentication-method changes, consent grants, role assignments and account modifications.

Conditional Access

Use Copilot to explain policy behaviour and sign-in outcomes, then validate against the actual policy configuration.

Privileged access

Review privileged roles, activation, assignment, approval and audit activity with heightened validation.

Microsoft Defender for Cloud

Use Security Copilot to understand cloud posture, recommendations, alerts, resources and attack-path context.

Cloud recommendations

Ask for the purpose, affected resources, severity and remediation implications of Defender for Cloud recommendations.

Cloud attack paths

Use attack-path context to understand relationships between exposure, identities, permissions and reachable resources.

Cloud workload alerts

Summarise alerts for virtual machines, containers, storage, databases and other protected resources.

Resource ownership

Confirm subscription, resource group, owner, workload purpose and business criticality before recommending remediation.

Microsoft Intune

Use Security Copilot for device-management, compliance, configuration and endpoint-administration workflows.

Device compliance

Explain why a device is noncompliant and identify the policy, setting, user and remediation evidence involved.

Configuration review

Summarise configuration profiles, security baselines and policy conflicts while validating the actual assignments.

Endpoint administration

Use Copilot to support troubleshooting and investigation without bypassing change control or approval.

Microsoft Purview

Use Security Copilot to support data security, information protection, compliance and investigation workflows.

Data loss prevention

Summarise DLP alerts, matched policies, sensitive information types, users, locations and response actions.

Insider risk context

Use Copilot to organise signals and evidence while avoiding assumptions about user intent.

Information protection

Explain labels, policies and data exposure while checking scope, ownership and regulatory requirements.

Microsoft Defender for Office 365

Use Security Copilot to investigate phishing, malicious URLs, attachments, delivery, user clicks and post-delivery actions.

Email authentication

Review SPF, DKIM, DMARC and sender-domain evidence without treating one passing control as proof of legitimacy.

Safe Links and Safe Attachments

Summarise URL and attachment analysis, detonation and user interaction evidence.

Microsoft Defender for Identity

Use identity telemetry to support investigations involving domain controllers, lateral movement and suspicious authentication.

Lateral movement

Correlate identities, devices, sessions and remote activity before mapping a movement path.

Threat intelligence

Use Microsoft threat intelligence to enrich actors, campaigns, indicators, tactics and techniques.

Indicator enrichment

Enrich domains, IP addresses, URLs and hashes while checking freshness, confidence and relevance to the environment.

Microsoft Priva

Where available, Security Copilot can support privacy workflows alongside the broader Microsoft data and compliance ecosystem.

Agents across Microsoft security

Agents can automate repeatable security and IT tasks across supported Microsoft products while remaining subject to configured permissions and governance.

Plugins connect capabilities

Plugins provide access to Microsoft, non-Microsoft and custom security capabilities used by prompts and workflows.

Cross-product correlation

Security Copilot can help connect identity, endpoint, email, cloud, SIEM and data evidence into one investigation story.

Correlation needs common entities

Use users, devices, IP addresses, domains, files, applications and resources as verified links between products.

Time normalisation

Confirm time zones and event timestamps before combining evidence from multiple portals.

Product-specific evidence remains authoritative

The original alert, sign-in, query result, resource record or policy configuration remains the source of truth.

Different products answer different questions

Defender may explain endpoint behaviour, Entra identity activity, Sentinel broader log context, Purview data events and Intune device state.

Do not force false correlation

Events from several products may be unrelated even when they occur close together.

Use the process log

Review which plugin, capability and source supplied each part of the response.

Use follow-up prompts by domain

After the initial summary, investigate identity, endpoint, email, cloud and data evidence separately.

Build a unified timeline

Create one chronological view, then label which product supplied each event.

Record confidence per finding

A cross-product summary should not apply one confidence level to every claim.

Escalate missing visibility

Document products, workspaces, tenants, permissions or connectors that were unavailable.

Keep response actions in the source product

Containment and remediation should follow approved procedures and product-specific controls.

Cross-product reporting

Translate verified findings into analyst handovers and executive updates without losing source attribution.

Cross-product investigation workflow

1. Open the primary incident or alert
2. Ask for a concise scope summary
3. Identify users, devices, mailboxes, IP addresses, files and resources
4. Confirm which Microsoft products contain relevant evidence
5. Review enabled plugins and permissions
6. Investigate each evidence domain separately
7. Open original product records
8. Normalise timestamps and time zones
9. Correlate only verified common entities
10. Build a unified timeline with source attribution
11. Record confirmed facts, inference and missing visibility
12. Approve response actions through product-specific procedures

Agent Foskett investigation: “The attacker touched six Microsoft products…”

A phishing message was delivered

Defender for Office 365 recorded the sender, URL and user click

Microsoft Entra recorded an unfamiliar sign-in and new authentication method

Defender XDR recorded PowerShell and suspicious network activity on the user’s device

Microsoft Sentinel correlated identity and endpoint events into an incident

Defender for Cloud showed an exposed cloud resource accessible by the compromised identity

Microsoft Purview recorded access to sensitive documents

Security Copilot produced a cross-product summary

Agent Foskett opened each original source

The email and identity events were connected

The cloud recommendation existed before the attack and did not prove exploitation

The Purview event was legitimate access from another user

The final timeline included four confirmed stages, one exposure condition and one unrelated data event

Copilot brought the evidence together

Product-level validation kept the story accurate
The products formed one investigation, but not every alert belonged to the attacker.

Cross-product validation checklist

AreaQuestionValidation action
TenantAre all products using the intended tenant?Confirm tenant and workspace context.
PermissionsCan the analyst access every required source?Document unavailable data.
PluginsWhich capabilities supplied the response?Review the process log.
IdentityIs the same user or service principal involved?Match immutable identifiers where possible.
DeviceIs the same endpoint represented across products?Confirm device ID, hostname and owner.
TimeAre events normalised to one time zone?Convert and order timestamps.
NetworkAre IP addresses and domains correctly attributed?Check VPN, proxy and ownership context.
CloudDoes exposure prove exploitation?Separate posture from observed activity.
DataDoes access belong to the same actor?Confirm user, session and document evidence.
ActionIs the recommendation approved and reversible?Follow source-product response procedures.

Key takeaways

  • Security Copilot supports standalone and embedded experiences across Microsoft security.
  • Embedded experiences provide AI assistance in the context of the current product workflow.
  • Defender XDR supports incidents, alerts, entities and advanced hunting scenarios.
  • Sentinel supports SIEM triage, KQL, hunting and broader log analysis.
  • Entra supports identity and access investigations.
  • Defender for Cloud supports posture, recommendation, alert, resource and attack-path analysis.
  • Intune supports device compliance and configuration workflows.
  • Purview supports data-security and compliance investigations.
  • Plugins, permissions, tenant context and data health determine what Copilot can access.
  • Cross-product summaries must be validated in each original source product.

What Agent Foskett checked

  • Email delivery
  • URL click
  • Entra sign-in
  • Authentication changes
  • Endpoint process tree
  • Sentinel incident
  • Cloud exposure
  • Purview activity
  • Unified timeline
  • Source attribution

Best practices

  • Confirm tenant context.
  • Check product permissions.
  • Use relevant plugins.
  • Investigate by evidence domain.
  • Open original records.
  • Normalise timestamps.
  • Verify common entities.
  • Separate exposure from exploitation.
  • Document missing visibility.
  • Approve actions in the source product.

Related Agent Foskett resources

Continue through the Security Copilot Academy and explore the dedicated Microsoft security academies that provide the evidence used in cross-product investigations.

Continue the Microsoft Security Copilot Academy

Lesson 8 maps Security Copilot across Microsoft security products. The next lesson explains Security Copilot plugins in greater detail.
⬅ Previous lesson
Lesson 7 — Responsible AI and Analyst ValidationApply human oversight, privacy, accountability and evidence-first validation.
🏠 Academy home
Microsoft Security Copilot AcademyReview the complete 40-lesson roadmap.
📚 Module 1
Lesson 9 — Understanding Security Copilot PluginsLearn how Microsoft, non-Microsoft and custom plugins provide capabilities and security context.

How is Microsoft Security Copilot used across Microsoft security?

Security Copilot supports standalone and embedded workflows across Microsoft Defender XDR, Sentinel, Entra, Defender for Cloud, Intune and Purview.

Cross-product Microsoft security investigations

Analysts can use Security Copilot to correlate identity, endpoint, email, cloud, SIEM, device-management and data-security evidence while validating every claim in the original product.