Lesson 8 — Using Security Copilot Across Microsoft Security
Microsoft Security Copilot can be used through a standalone experience and through embedded experiences inside supported Microsoft security products.
Its value becomes most visible when an investigation crosses identity, endpoint, email, cloud, SIEM, device-management and data-security evidence.
This lesson explains how Security Copilot supports workflows across Microsoft Defender XDR, Sentinel, Entra, Defender for Cloud, Intune and Purview while keeping permissions, product context and source evidence intact.

What you will learn
This lesson maps Security Copilot to the Microsoft security products analysts use during real investigations.
Microsoft Security Copilot ecosystem model
↘
Microsoft Sentinel — SIEM, logs and hunting
↘
Microsoft Entra — identity and access
↘
Defender for Cloud — resources, posture and attack paths
↘
Microsoft Intune — device compliance and configuration
↘
Microsoft Purview — data security and compliance
↓
Security Copilot standalone, embedded, plugin and agent experiences
↓
AI-assisted summary, explanation, correlation and workflow support
↓
Analyst validates each claim in the original product
Microsoft security product map
| Product | Primary evidence | Security Copilot use |
|---|---|---|
| Microsoft Defender XDR | Incidents, alerts, entities, advanced hunting and cross-domain evidence. | Summarise and investigate endpoint, identity, email and cloud app activity. |
| Microsoft Sentinel | SIEM incidents, analytics, logs, hunting, KQL and workspace context. | Triage incidents and investigate broader organisational telemetry. |
| Microsoft Entra | Sign-ins, identity risk, access, authentication and privileged activity. | Investigate suspected identity compromise and access changes. |
| Defender for Cloud | Cloud posture, recommendations, alerts, attack paths and resources. | Understand workload exposure and cloud attack context. |
| Microsoft Intune | Device compliance, configuration, security baselines and administration. | Explain device state and policy outcomes. |
| Microsoft Purview | DLP, information protection, insider risk and data-security evidence. | Investigate sensitive data use and policy activity. |
Learning objectives
- Distinguish standalone and embedded experiences.
- Understand product-specific Security Copilot workflows.
- Recognise the role of plugins and permissions.
- Correlate identity, endpoint, email, cloud and data evidence.
- Use process logs and source links.
- Avoid false cross-product correlation.
- Build a verified unified timeline.
Standalone experience
Use the dedicated Security Copilot portal for broad investigations, promptbooks, agents, plugins and cross-product reasoning.
Embedded experiences
Use Security Copilot inside supported Microsoft security products where the current page, alert or incident provides immediate context.
Context follows the workflow
Embedded experiences reduce portal switching because the AI assistance appears inside the product where the analyst is already working.
Permissions still define visibility
Security Copilot uses the signed-in user’s permissions and cannot retrieve product data the analyst is not authorised to access.
Microsoft Defender XDR
Use Security Copilot to support incident summaries, alert explanations, entity review, script analysis and cross-domain investigations.
Defender incident summaries
Create an initial narrative from alerts, users, devices, mailboxes and cloud app activity, then verify each claim.
Defender alert explanation
Ask Copilot to explain unfamiliar detections, behaviours, severity and recommended investigation pivots.
Defender entity investigation
Use users, devices, mailboxes, IP addresses, files and cloud applications as pivots through the incident.
Defender advanced hunting
Use Copilot to assist with KQL ideas, query explanation and refinement while validating tables, fields and results.
Microsoft Sentinel
Use Security Copilot to support SIEM incident triage, log analysis, hunting, KQL development and response workflows.
Sentinel incident triage
Summarise incident scope, analytics rules, entities, evidence and unresolved questions before deeper investigation.
Sentinel KQL assistance
Generate or explain KQL against the intended workspace and tables, then test the query and inspect returned rows.
Sentinel workspace context
Confirm the selected workspace, connected data sources, retention and permissions before trusting the answer.
Unified security operations
Sentinel incidents can be investigated alongside Defender XDR context where the unified security operations experience is enabled.
Microsoft Entra
Use Security Copilot to support identity, sign-in, access, Conditional Access and privileged-role investigations.
Risky sign-ins
Review location, IP ownership, authentication method, MFA, device context and user risk before declaring compromise.
Identity changes
Investigate password resets, authentication-method changes, consent grants, role assignments and account modifications.
Conditional Access
Use Copilot to explain policy behaviour and sign-in outcomes, then validate against the actual policy configuration.
Privileged access
Review privileged roles, activation, assignment, approval and audit activity with heightened validation.
Microsoft Defender for Cloud
Use Security Copilot to understand cloud posture, recommendations, alerts, resources and attack-path context.
Cloud recommendations
Ask for the purpose, affected resources, severity and remediation implications of Defender for Cloud recommendations.
Cloud attack paths
Use attack-path context to understand relationships between exposure, identities, permissions and reachable resources.
Cloud workload alerts
Summarise alerts for virtual machines, containers, storage, databases and other protected resources.
Resource ownership
Confirm subscription, resource group, owner, workload purpose and business criticality before recommending remediation.
Microsoft Intune
Use Security Copilot for device-management, compliance, configuration and endpoint-administration workflows.
Device compliance
Explain why a device is noncompliant and identify the policy, setting, user and remediation evidence involved.
Configuration review
Summarise configuration profiles, security baselines and policy conflicts while validating the actual assignments.
Endpoint administration
Use Copilot to support troubleshooting and investigation without bypassing change control or approval.
Microsoft Purview
Use Security Copilot to support data security, information protection, compliance and investigation workflows.
Data loss prevention
Summarise DLP alerts, matched policies, sensitive information types, users, locations and response actions.
Insider risk context
Use Copilot to organise signals and evidence while avoiding assumptions about user intent.
Information protection
Explain labels, policies and data exposure while checking scope, ownership and regulatory requirements.
Microsoft Defender for Office 365
Use Security Copilot to investigate phishing, malicious URLs, attachments, delivery, user clicks and post-delivery actions.
Email authentication
Review SPF, DKIM, DMARC and sender-domain evidence without treating one passing control as proof of legitimacy.
Safe Links and Safe Attachments
Summarise URL and attachment analysis, detonation and user interaction evidence.
Microsoft Defender for Identity
Use identity telemetry to support investigations involving domain controllers, lateral movement and suspicious authentication.
Lateral movement
Correlate identities, devices, sessions and remote activity before mapping a movement path.
Threat intelligence
Use Microsoft threat intelligence to enrich actors, campaigns, indicators, tactics and techniques.
Indicator enrichment
Enrich domains, IP addresses, URLs and hashes while checking freshness, confidence and relevance to the environment.
Microsoft Priva
Where available, Security Copilot can support privacy workflows alongside the broader Microsoft data and compliance ecosystem.
Agents across Microsoft security
Agents can automate repeatable security and IT tasks across supported Microsoft products while remaining subject to configured permissions and governance.
Plugins connect capabilities
Plugins provide access to Microsoft, non-Microsoft and custom security capabilities used by prompts and workflows.
Cross-product correlation
Security Copilot can help connect identity, endpoint, email, cloud, SIEM and data evidence into one investigation story.
Correlation needs common entities
Use users, devices, IP addresses, domains, files, applications and resources as verified links between products.
Time normalisation
Confirm time zones and event timestamps before combining evidence from multiple portals.
Product-specific evidence remains authoritative
The original alert, sign-in, query result, resource record or policy configuration remains the source of truth.
Different products answer different questions
Defender may explain endpoint behaviour, Entra identity activity, Sentinel broader log context, Purview data events and Intune device state.
Do not force false correlation
Events from several products may be unrelated even when they occur close together.
Use the process log
Review which plugin, capability and source supplied each part of the response.
Use follow-up prompts by domain
After the initial summary, investigate identity, endpoint, email, cloud and data evidence separately.
Build a unified timeline
Create one chronological view, then label which product supplied each event.
Record confidence per finding
A cross-product summary should not apply one confidence level to every claim.
Escalate missing visibility
Document products, workspaces, tenants, permissions or connectors that were unavailable.
Keep response actions in the source product
Containment and remediation should follow approved procedures and product-specific controls.
Cross-product reporting
Translate verified findings into analyst handovers and executive updates without losing source attribution.
Cross-product investigation workflow
2. Ask for a concise scope summary
3. Identify users, devices, mailboxes, IP addresses, files and resources
4. Confirm which Microsoft products contain relevant evidence
5. Review enabled plugins and permissions
6. Investigate each evidence domain separately
7. Open original product records
8. Normalise timestamps and time zones
9. Correlate only verified common entities
10. Build a unified timeline with source attribution
11. Record confirmed facts, inference and missing visibility
12. Approve response actions through product-specific procedures
Agent Foskett investigation: “The attacker touched six Microsoft products…”
↓
Defender for Office 365 recorded the sender, URL and user click
↓
Microsoft Entra recorded an unfamiliar sign-in and new authentication method
↓
Defender XDR recorded PowerShell and suspicious network activity on the user’s device
↓
Microsoft Sentinel correlated identity and endpoint events into an incident
↓
Defender for Cloud showed an exposed cloud resource accessible by the compromised identity
↓
Microsoft Purview recorded access to sensitive documents
↓
Security Copilot produced a cross-product summary
↓
Agent Foskett opened each original source
↓
The email and identity events were connected
↓
The cloud recommendation existed before the attack and did not prove exploitation
↓
The Purview event was legitimate access from another user
↓
The final timeline included four confirmed stages, one exposure condition and one unrelated data event
↓
Copilot brought the evidence together
↓
Product-level validation kept the story accurate
Cross-product validation checklist
| Area | Question | Validation action |
|---|---|---|
| Tenant | Are all products using the intended tenant? | Confirm tenant and workspace context. |
| Permissions | Can the analyst access every required source? | Document unavailable data. |
| Plugins | Which capabilities supplied the response? | Review the process log. |
| Identity | Is the same user or service principal involved? | Match immutable identifiers where possible. |
| Device | Is the same endpoint represented across products? | Confirm device ID, hostname and owner. |
| Time | Are events normalised to one time zone? | Convert and order timestamps. |
| Network | Are IP addresses and domains correctly attributed? | Check VPN, proxy and ownership context. |
| Cloud | Does exposure prove exploitation? | Separate posture from observed activity. |
| Data | Does access belong to the same actor? | Confirm user, session and document evidence. |
| Action | Is the recommendation approved and reversible? | Follow source-product response procedures. |
Key takeaways
- Security Copilot supports standalone and embedded experiences across Microsoft security.
- Embedded experiences provide AI assistance in the context of the current product workflow.
- Defender XDR supports incidents, alerts, entities and advanced hunting scenarios.
- Sentinel supports SIEM triage, KQL, hunting and broader log analysis.
- Entra supports identity and access investigations.
- Defender for Cloud supports posture, recommendation, alert, resource and attack-path analysis.
- Intune supports device compliance and configuration workflows.
- Purview supports data-security and compliance investigations.
- Plugins, permissions, tenant context and data health determine what Copilot can access.
- Cross-product summaries must be validated in each original source product.
What Agent Foskett checked
- Email delivery
- URL click
- Entra sign-in
- Authentication changes
- Endpoint process tree
- Sentinel incident
- Cloud exposure
- Purview activity
- Unified timeline
- Source attribution
Best practices
- Confirm tenant context.
- Check product permissions.
- Use relevant plugins.
- Investigate by evidence domain.
- Open original records.
- Normalise timestamps.
- Verify common entities.
- Separate exposure from exploitation.
- Document missing visibility.
- Approve actions in the source product.
Related Agent Foskett resources
Continue the Microsoft Security Copilot Academy
How is Microsoft Security Copilot used across Microsoft security?
Security Copilot supports standalone and embedded workflows across Microsoft Defender XDR, Sentinel, Entra, Defender for Cloud, Intune and Purview.
Cross-product Microsoft security investigations
Analysts can use Security Copilot to correlate identity, endpoint, email, cloud, SIEM, device-management and data-security evidence while validating every claim in the original product.
