You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-core-features/includes/2-describe-standalone-experience.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -39,11 +39,11 @@ From the home menu, the user can navigate as follows:
39
39
40
40
- Owner settings. These settings include the option to switch Security Compute Units (SCUs) capacity, select the workspace for Copilot agents, configure data sharing options to help improve Copilot, allow logging audit data in Microsoft Purview, and configure who can upload files.
41
41
42
-
# [Swtich capacity](#tab/switch-capacity)
42
+
# [Switch capacity](#tab/switch-capacity)
43
43
:::image type="content" source="../media/owner-settings-capacity.png" lightbox="../media/owner-settings-capacity.png" alt-text="Screen capture showing the owner settings, specifically focused on capacity information.":::
44
44
45
45
# [Agent workspaces](#tab/agent-worksapces)
46
-
:::image type="content" source="../media/agent-workspaces.png" lightbox="../media/agent-workspaces.png" alt-text="Screen capture showing the workspace that will be used for Security Copilot agent experiences in Microsoft Defender, Microsoft Entra, Microsoft Purview and Microsoft Intune.":::
46
+
:::image type="content" source="../media/agent-workspaces.png" lightbox="../media/agent-workspaces.png" alt-text="Screen capture showing the workspace that will be used for Security Copilot agent experiences in Microsoft Defender, Microsoft Entra, Microsoft Purview, and Microsoft Intune.":::
47
47
48
48
# [Improve Copilot](#tab/improve-copilot)
49
49
:::image type="content" source="../media/owner-settings-improve-copilot.png" lightbox="../media/owner-settings-improve-copilot.png" alt-text="Screen capture showing the owner settings, specifically focused on data sharing options.":::
@@ -85,7 +85,7 @@ From the home menu, the user can navigate as follows:
85
85
86
86
- Usage monitoring, which provides a dashboard showing how SCUs are consumed over a period of time by your Microsoft Security Copilot workloads. The usage monitoring dashboard provides visibility, for a selected workspace, into the number of units used, the specific plugins employed during sessions, and the initiators of those sessions. The dashboard also allows you to apply filters and export usage data seamlessly. The dashboard includes up to 90 days of data. Security Copilot supports both provisioned SCUs for predictable workloads and overage SCUs that provide flexible, on-demand capacity billed only when used. Overage SCUs ensure additional capacity is available when initially provisioned units are depleted during unexpected workload spikes. When an analyst is in the middle of an investigation and the usage is nearing the provisioned capacity limit (90%), a notification is displayed to the analyst while entering the prompt. The notification informs the analyst to contact the owner to increase the capacity or limit the number of prompts to avoid disruptions. These notifications are also shown in the Security Copilot embedded experiences.
87
87
88
-
When the provisioned capacity is crossed, the analyst sees an error message stating that due to high usage in organization, they cannot submit additional prompts. The analyst is asked to contact the owner to increase the provisioned SCUs.
88
+
When the provisioned capacity is crossed, the analyst sees an error message stating that due to high usage in the organization, they can't submit additional prompts. The analyst is asked to contact the owner to increase the provisioned SCUs.
@@ -134,7 +134,7 @@ Selecting the ellipses on the bottom left corner of the navigation panel, allows
134
134
---
135
135
136
136
137
-
- Tenant switcher. The tenant, which is provisioned for Copilot doesn't need to be the tenant your security analyst logs in from. Also a user may have access to Security Copilot across multiple tenants. In the screenshot that follows, the user is provisioned only in the "Zava - Private" tenant. If the user had been provisioned in other tenants, they would be listed and the user would be able to select any of the available tenants.
137
+
- Tenant switcher. The tenant, which is provisioned for Copilot doesn't need to be the tenant your security analyst logs in from. Also a user may have access to Security Copilot across multiple tenants. In the screenshot that follows, the user is provisioned only in the "Zava - Private" tenant. If the user had been provisioned in other tenants, they would be listed and the user would be able to select any of the available tenants.
138
138
139
139
:::image type="content" source="../media/tenant-switcher-v4.png" lightbox="../media/tenant-switcher-v4.png" alt-text="Screen capture showing the tenant switching window, with multiple tenants listed.":::
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-core-features/includes/2a-describe-session-features.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ Copilot has features that are common across all sessions and the individual prom
9
9
10
10
### Process log
11
11
12
-
For every prompt Copilot runs, Copilot generates a process log that is visible to the user. The user can see what capability is used to generate the response. This is important because it enables the user to determine whether the response was generated from a trusted source. In the screenshot that follows, the process log shows that Copilot chose the Incident Analysis capability. The process log also shows that the final output went through safety checks, which is part of Microsoft’s commitment to responsible AI.
12
+
For every prompt Copilot runs, Copilot generates a process log that's visible to the user. The user can see what capability is used to generate the response. This is important because it enables the user to determine whether the response was generated from a trusted source. In the screenshot that follows, the process log shows that Copilot chose the Incident Analysis capability. The process log also shows that the final output went through safety checks, which is part of Microsoft’s commitment to responsible AI.
13
13
14
14
:::image type="content" source="../media/process-log-new.png" lightbox="../media/process-log-new.png" alt-text="Screen capture showing process log, which shows the selected skill and that a safety check was run on the composed message.":::
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-core-features/includes/3-describe-microsoft-plugins.md
+10-10Lines changed: 10 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -80,11 +80,11 @@ The Azure AI Search plugin allows you to connect your company’s knowledge base
80
80
81
81
Microsoft Entra is a family of multicloud identity and network access solutions that enables organizations to protect any identity and secure access to any resource. It provides a unified platform for identity and network access management, making it easier to secure identities and access to resources across multicloud and hybrid environments.
82
82
83
-
Security Copilot integrates with Microsoft Entra. With the Entra plugin enabled, security analysts can instantly get a risk summary, steps to remediate, and recommended guidance for each identity at risk, in natural language. Analysts can use Copilot to guide in the creation of a lifecycle workflow to streamline the process of creating and issuing user credentials and access rights. These and many other Entra capabilities are supported by Copilot.
83
+
Security Copilot integrates with Microsoft Entra. With the Microsoft Entra plugin enabled, security analysts can instantly get a risk summary, steps to remediate, and recommended guidance for each identity at risk, in natural language. Analysts can use Copilot to guide in the creation of a lifecycle workflow to streamline the process of creating and issuing user credentials and access rights. These and many other Microsoft Entra capabilities are supported by Copilot.
84
84
85
85
Microsoft Entra capabilities in Copilot are built-in prompts that you can use but you can also enter your own prompts based on the capabilities supported.
86
86
87
-
:::image type="content" source="../media/entra-skills.png" lightbox="../media/entra-skills.png" alt-text="Screen capture of the Entra capabilities that can be run in the standalone experience.":::
87
+
:::image type="content" source="../media/entra-skills.png" lightbox="../media/entra-skills.png" alt-text="Screen capture of the Microsoft Entra capabilities that can be run in the standalone experience.":::
88
88
89
89
With the plugin enabled, Copilot integration with Microsoft Entra can also be experienced through the embedded experience. The scenarios supported through the embedded experience are described in more detail in the module titled, "Describe the embedded experiences of Microsoft Security Copilot."
90
90
@@ -122,7 +122,7 @@ With the plugin enabled, Copilot integration with Microsoft Intune can also be e
122
122
123
123
Microsoft Defender XDR is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.
124
124
125
-
There are two separate plugins in Copilot that relate to Microsoft Defender XDR (the user interface may still show Microsoft 365 Defender):
125
+
There are two separate plugins in Copilot that relate to Microsoft Defender XDR:
126
126
127
127
- Microsoft Defender XDR
128
128
- Natural language to KQL for Microsoft Defender XDR
@@ -211,23 +211,23 @@ Copilot capabilities can also be experienced directly from within Purview soluti
211
211
212
212
Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise. With Microsoft Sentinel, you get a single solution for attack detection, threat visibility, proactive hunting, and threat response.
213
213
214
-
There are two separate plugins in Copilot that relate to Sentinel:
214
+
There are two separate plugins in Copilot that relate to Microsoft Sentinel:
215
215
216
216
- Microsoft Sentinel
217
217
- Natural language to Microsoft Sentinel KQL
218
218
219
-
:::image type="content" source="../media/sentinel-skills-v3.png" lightbox="../media/sentinel-skills-v3.png" alt-text="Screen capture of the Sentinel and NL2KQK in Sentinel plugin.":::
219
+
:::image type="content" source="../media/sentinel-skills-v3.png" lightbox="../media/sentinel-skills-v3.png" alt-text="Screen capture of the Microsoft Sentinel and NL2KQK in Microsoft Sentinel plugin.":::
220
220
221
221
***Microsoft Sentinel***
222
222
223
-
To utilize the Sentinel plugin, the user would need to be assigned a role permission that grants access to Copilot and a Sentinel specific role like Microsoft Sentinel Reader to access incidents in the workspace.
223
+
To utilize the Microsoft Sentinel plugin, the user would need to be assigned a role permission that grants access to Copilot and a Microsoft Sentinel specific role like Microsoft Sentinel Reader to access incidents in the workspace.
224
224
225
-
The Sentinel plugin also requires the user to configure the Sentinel workspace, the subscription name, and the resource group name.
225
+
The Microsoft Sentinel plugin also requires the user to configure the Microsoft Sentinel workspace, the subscription name, and the resource group name.
226
226
227
-
:::image type="content" source="../media/sentinel-plugin-settings-v2.png" lightbox="../media/sentinel-plugin-settings-v2.png" alt-text="Screen capture of the Sentinel plugin settings page.":::
227
+
:::image type="content" source="../media/sentinel-plugin-settings-v2.png" lightbox="../media/sentinel-plugin-settings-v2.png" alt-text="Screen capture of the Microsoft Sentinel plugin settings page.":::
228
228
229
-
The Sentinel plugin capabilities are focused on incidents and workspaces. Additionally, Copilot includes a promptbook for Microsoft Sentinel incident investigation. This promptbook includes prompts for getting a report about a specific incident, along with related alerts, reputation scores, users, and devices.
229
+
The Microsoft Sentinel plugin capabilities are focused on incidents and workspaces. Additionally, Copilot includes a promptbook for Microsoft Sentinel incident investigation. This promptbook includes prompts for getting a report about a specific incident, along with related alerts, reputation scores, users, and devices.
230
230
231
231
***Natural language to Microsoft Sentinel KQL***
232
232
233
-
The natural language to Sentinel KQL (NL2KQLSentinel) plugin converts any natural-language question in the context of threat hunting, into a ready-to-run KQL query. This saves security teams time by generating a KQL query that can then be automatically run or further tweaked according to the analyst’s needs.
233
+
The natural language to Microsoft Sentinel KQL (NL2KQLSentinel) plugin converts any natural-language question in the context of threat hunting, into a ready-to-run KQL query. This saves security teams time by generating a KQL query that can then be automatically run or further tweaked according to the analyst’s needs.
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-core-features/includes/5a-describe-knowledge-base-connections.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -73,13 +73,13 @@ To create the connection to an existing Azure AI Search index, configure the Azu
73
73
- Name of Azure AI Search service – This is the name of your search service.
74
74
- Name of index – This is the name of the index, within your Azure AI search instance, that will be searched.
75
75
- Name of vector field in index – This is the name of the field in the index containing the vector of embeddings.
76
-
- Name of text field in index – This is the name of the text field in the index. The contents of this field, in your index, represents the text to search. If your index was created using the Import and vectorize data wizard, the name of the field containing the text to search may be referred to as chunk, as a default. The reason is that the wizard will chunk your data so that it doesn't exceed the token limit size of the embedding model. The default index field name, chunk, is referring to a chunk of text.
76
+
- Name of text field in index – This is the name of the text field in the index. The contents of this field, in your index, represents the text to search. If your index was created using the Import and vectorize data wizard, the name of the field containing the text to search may be referred to as chunk, as a default. The reason is that the wizard will chunk your data so that it doesn't exceed the token limit size of the embedding model. The default index field name, chunk, is referring to a chunk of text.
77
77
- Name of title field in index – This is the name of the title field in the index and represents the title of each document to display as a source (optional).
78
78
- Value – This is the access identifier for API authentication.
79
79
80
80
:::image type="content" source="../media/ai-search-plugin-settings.png" lightbox="../media/ai-search-plugin-settings.png" alt-text="Screen capture of the Azure AI Search plugin parameters.":::
81
81
82
-
1. To obtain the information that you'll use for the plugin settings, you need to go to the Azure portal. Open a new browser tab to go to the Azure portal (https://portal.azure.com).
82
+
1. To obtain the information that you use for the plugin settings, you need to go to the Azure portal. Open a new browser tab to go to the Azure portal (https://portal.azure.com).
83
83
84
84
1. From the Azure portal, search for and navigate to Azure AI Search.
85
85
@@ -112,7 +112,7 @@ To create the connection to an existing Azure AI Search index, configure the Azu
112
112
1. Check that all your parameters are correct for the search instance and index you want to connect to then select save.
113
113
114
114
> [!IMPORTANT]
115
-
> Currently, Copilot does not validate your credentials when you save your settings. If they are not correct, you will see an error later when Copilot attempts to run the Azure AI Search plugin. Close the Azure AI Search settings window.
115
+
> Currently, Copilot doesn't validate your credentials when you save your settings. If they aren't correct, you see an error later when Copilot attempts to run the Azure AI Search plugin. Close the Azure AI Search settings window.
116
116
117
117
Once connected, prompt Copilot to look for information in the Azure AI Search index. Make sure to mention "Azure AI Search" in the prompt. For example:
0 commit comments