Skip to content

Commit 9105a2a

Browse files
authored
Merge pull request #54506 from ceperezb/CEPEREZB-sc5006-security-copilot-embedded
update module
2 parents 56a47ea + b22985f commit 9105a2a

15 files changed

Lines changed: 98 additions & 34 deletions

learn-pr/wwl-sci/security-copilot-embedded-experiences/1-introduction.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: Describe the embedded experiences of Microsoft Security Copilot.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot

learn-pr/wwl-sci/security-copilot-embedded-experiences/2-copilot-for-defender.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ metadata:
66
description: Describe Copilot in Microsoft Defender XDR.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot
13-
durationInMinutes: 9
13+
durationInMinutes: 14
1414
content: |
1515
[!include[](includes/2-copilot-for-defender.md)]

learn-pr/wwl-sci/security-copilot-embedded-experiences/3-copilot-for-purview.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ metadata:
66
description: Copilot in Microsoft Purview.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot
13-
durationInMinutes: 10
13+
durationInMinutes: 8
1414
content: |
1515
[!include[](includes/3-copilot-for-purview.md)]

learn-pr/wwl-sci/security-copilot-embedded-experiences/4-copilot-for-entra.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ metadata:
66
description: Copilot in Microsoft Entra.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot
13-
durationInMinutes: 10
13+
durationInMinutes: 6
1414
content: |
1515
[!include[](includes/4-copilot-for-entra.md)]

learn-pr/wwl-sci/security-copilot-embedded-experiences/5-copilot-for-intune.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,10 @@ metadata:
66
description: Copilot in Microsoft Intune.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot
13-
durationInMinutes: 10
13+
durationInMinutes: 5
1414
content: |
1515
[!include[](includes/5-copilot-for-intune.md)]

learn-pr/wwl-sci/security-copilot-embedded-experiences/5a-copilot-for-defender-cloud.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
### YamlMime:ModuleUnit
22
uid: learn.security-copilot-embedded-experiences.copilot-for-defender-cloud
3-
title: Copilot in Microsoft Defender for Cloud (Preview)
3+
title: Copilot in Microsoft Defender for Cloud
44
metadata:
5-
title: Copilot in Microsoft Defender for Cloud (Preview)
5+
title: Copilot in Microsoft Defender for Cloud
66
description: Copilot in Microsoft Defender for Cloud.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot

learn-pr/wwl-sci/security-copilot-embedded-experiences/6-knowledge-check.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: Check your knowledge on the embedded experiences of Microsoft Security Copilot.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot
@@ -39,7 +39,7 @@ quiz:
3939
- content: The organization needs to be licensed for Microsoft Purview eDiscovery (Standard), as a minimum.
4040
isCorrect: false
4141
explanation: Incorrect. To use Security Copilot functionality with Microsoft Purview eDiscovery, the organization must be licensed for Microsoft Purview eDiscovery (Premium).
42-
- content: After enabling the Entra plugin in Copilot and assigning the appropriate role permissions, an admin navigates to the Risky users report to investigate a user's risky sign-ins. What should the admin do next to view the Copilot generated summary?
42+
- content: After enabling the Microsoft Entra plugin in Copilot and assigning the appropriate role permissions, an admin navigates to the Risky users report to investigate a user's risky sign-ins. What should the admin do next to view the Copilot generated summary?
4343
choices:
4444
- content: Select the 'Export' option to download the user's risk details.
4545
isCorrect: false
@@ -61,7 +61,7 @@ quiz:
6161
- content: Information about individual settings, their impact, and recommended values.
6262
isCorrect: true
6363
explanation: Correct. When creating a new policy, Copilot can be used to learn more about individual settings, their impact, and recommended values.
64-
- content: Copilot in Defender for Cloud is available for all users when you enable Defender for Cloud in your environment, have access to Azure Copilot, and have SCUs assigned for Security Copilot. What additional requirement must be met to remediate code with Security Copilot?
64+
- content: Copilot in Defender for Cloud is available for all users when you enable Defender for Cloud in your environment, have access to Azure Copilot, and have Security Compute Units (SCUs) assigned for Security Copilot. What additional requirement must be met to remediate code with Security Copilot?
6565
choices:
6666
- content: You must enable all the cloud workload protection plans.
6767
isCorrect: false

learn-pr/wwl-sci/security-copilot-embedded-experiences/7-summary.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: Summary and resources on the embedded experiences of Microsoft Security Copilot.
77
author: wwlpublish
88
ms.author: ceperezb
9-
ms.date: 11/20/2024
9+
ms.date: 04/30/2026
1010
ms.topic: unit
1111
ms.collection:
1212
- wwl-ai-copilot

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/1-introduction.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
Microsoft Security Copilot is accessible directly from some Microsoft security products. This solution is referred to as the embedded experience. Currently, Copilot is embedded with Microsoft Defender XDR and Microsoft Purview, with more Microsoft security solutions embedding Copilot capabilities in the near term.
1+
Microsoft Security Copilot is accessible directly from some Microsoft security products. This solution is referred to as the embedded experience. Copilot is embedded with Microsoft Defender XDR, Microsoft Purview, Microsoft Entra, Microsoft Intune, Microsoft Defender for Cloud, and other Microsoft security solutions.
22

33
The Microsoft solution in which the Copilot capabilities are embedded determines the scenarios that are available through the embedded experiences. For example, in Microsoft Purview Communication Compliance, Copilot can provide a summary of a message and its attachments, in the context of the policy and classifier conditions that flagged the message.
44

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/2-copilot-for-defender.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@ Security Copilot capabilities embedded in Microsoft Defender XDR include:
1414
- Incident reports
1515
- Analyze files
1616
- Device summary
17+
- Threat intelligence
1718

1819
> [!NOTE]
1920
>The list of Copilot capabilities embedded in Microsoft Defender XDR is continually growing. This unit provides just a sampling of some of those Copilot capabilities. For more information, see documentation on Microsoft Defender XDR.
@@ -158,6 +159,14 @@ Similarly, Copilot in Microsoft Defender XDR can summarize identities.
158159

159160
---
160161

162+
### Threat intelligence
163+
164+
Copilot is embedded in the threat intelligence section of the Microsoft Defender portal, helping security teams make informed decisions by consolidating and summarizing threat intelligence data.
165+
166+
From the threat intelligence page, you can ask Copilot to summarize relevant threats impacting your environment, prioritize threats based on your organization's exposure levels, or identify threat actor groups that may be targeting your industry. Copilot uses the Microsoft Defender Threat Intelligence plugin to surface this information and can generate summaries of threat analytics reports, intel profiles, and vulnerability disclosures—all in natural language.
167+
168+
This capability is particularly useful for threat hunters and analysts who need broad situational awareness before diving into a specific incident investigation.
169+
161170
### Common functionality across key features
162171

163172
There are some options that are common across the features of Copilot for Microsoft Defender XDR.

0 commit comments

Comments
 (0)