You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-agents/includes/2-describe-agents.md
+13-13Lines changed: 13 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -35,32 +35,32 @@ Security Copilot includes agents that are seamlessly integrated with Microsoft s
35
35
36
36
#### Agents in the standalone experience
37
37
38
-
-**[Threat Intelligence Briefing Agent](https://learn.microsoft.com/copilot/security/threat-intel-briefing-agent)**: Automatically curates relevant and timely threat intelligence based on an organization’s unique attributes and threat exposure.
38
+
-**[Threat Intelligence Briefing Agent](/copilot/security/threat-intel-briefing-agent)**: Automatically curates relevant and timely threat intelligence based on an organization’s unique attributes and threat exposure.
39
39
40
40
#### Agents embedded in Microsoft Entra
41
41
42
42
-**[Conditional Access Optimization Agent](https://aka.ms/EntraAgent)**: Monitors for new users or apps not covered by existing policies, identifies necessary updates to close security gaps, and recommends quick fixes for identity teams to apply with a single click.
43
-
-**[Access Review Agent](https://learn.microsoft.com/entra/id-governance/access-review-agent)**: Configured in Microsoft Entra and available in Microsoft Teams, the agent delivers insights and recommendations so reviewers can make fast, accurate access decisions through a simple conversation.
43
+
-**[Access Review Agent](/entra/id-governance/access-review-agent)**: Configured in Microsoft Entra and available in Microsoft Teams, the agent delivers insights and recommendations so reviewers can make fast, accurate access decisions through a simple conversation.
44
44
45
45
#### Agents embedded in Microsoft Defender
46
46
47
-
-**[Phishing Triage Agent](https://learn.microsoft.com/defender-xdr/phishing-triage-agent)**: Helps security operations analysts triage and classify user-submitted phishing incidents autonomously, providing transparent rationale for classification verdicts in natural language.
48
-
-**[Threat Intelligence Briefing Agent](https://learn.microsoft.com/defender-xdr/threat-intel-briefing-agent-defender)**: Also available in the Defender portal, this agent gathers and synthesizes threat intelligence data to deliver concise and actionable insights to security operations teams.
49
-
-**[Threat Hunting Agent](https://learn.microsoft.com/defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent)**: Enables threat hunting using natural language, generates KQL queries, interprets results, and guides analysts through full hunting sessions.
50
-
-**[Dynamic Threat Detection Agent (preview)](https://learn.microsoft.com/defender-xdr/dynamic-threat-detection-agent)**: An always-on adaptive service that uncovers hidden threats across Defender and Microsoft Sentinel environments by correlating alerts, events, and threat intelligence.
47
+
-**[Phishing Triage Agent](/defender-xdr/phishing-triage-agent)**: Helps security operations analysts triage and classify user-submitted phishing incidents autonomously, providing transparent rationale for classification verdicts in natural language.
48
+
-**[Threat Intelligence Briefing Agent](/defender-xdr/threat-intel-briefing-agent-defender)**: Also available in the Defender portal, this agent gathers and synthesizes threat intelligence data to deliver concise and actionable insights to security operations teams.
49
+
-**[Threat Hunting Agent](/defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent)**: Enables threat hunting using natural language, generates KQL queries, interprets results, and guides analysts through full hunting sessions.
50
+
-**[Dynamic Threat Detection Agent (preview)](/defender-xdr/dynamic-threat-detection-agent)**: An always-on adaptive service that uncovers hidden threats across Defender and Microsoft Sentinel environments by correlating alerts, events, and threat intelligence.
51
51
52
52
#### Agents embedded in Microsoft Purview (preview)
53
53
54
-
-**[Alert Triage Agent in Data Loss Prevention](https://learn.microsoft.com/purview/copilot-in-purview-agents)**: Evaluates DLP alerts based on sensitivity risk, exfiltration risk, and policy risk, then sorts them into prioritized categories.
55
-
-**[Triage Agent in Insider Risk Management](https://learn.microsoft.com/purview/copilot-in-purview-agents)**: Evaluates IRM alerts based on user risk, file risk, and activity risk, then sorts them into prioritized categories.
56
-
-**[Data Security Posture Management Agent](https://learn.microsoft.com/purview/copilot-in-purview-posture-agent-get-started)**: Helps identify and address data security posture risks by providing proactive insights and recommendations.
54
+
-**[Alert Triage Agent in Data Loss Prevention](/purview/copilot-in-purview-agents)**: Evaluates DLP alerts based on sensitivity risk, exfiltration risk, and policy risk, then sorts them into prioritized categories.
55
+
-**[Triage Agent in Insider Risk Management](/purview/copilot-in-purview-agents)**: Evaluates IRM alerts based on user risk, file risk, and activity risk, then sorts them into prioritized categories.
56
+
-**[Data Security Posture Management Agent](/purview/copilot-in-purview-posture-agent-get-started)**: Helps identify and address data security posture risks by providing proactive insights and recommendations.
57
57
58
58
#### Agents embedded in Microsoft Intune
59
59
60
-
-**[Vulnerability Remediation Agent](https://learn.microsoft.com/intune/agents/vulnerability-remediation-agent)**: Uses Defender data to identify vulnerabilities on managed devices, prioritize remediation, and provide step-by-step guidance.
61
-
-**[Change Review Agent](https://learn.microsoft.com/intune/agents/change-review-agent)**: Evaluates the effect of Multi Admin Approval requests in Intune and makes recommendations for actions to take.
62
-
-**[Device Offboarding Agent](https://learn.microsoft.com/intune/agents/device-offboarding-agent)**: Identifies stale or misaligned devices across Intune and Microsoft Entra ID, providing actionable insights before offboarding.
63
-
-**[Policy Configuration Agent](https://learn.microsoft.com/intune/agents/policy-configuration-agent)**: Converts plain-language documents and industry baselines into recommended Intune settings and policies.
60
+
-**[Vulnerability Remediation Agent](/intune/agents/vulnerability-remediation-agent)**: Uses Defender data to identify vulnerabilities on managed devices, prioritize remediation, and provide step-by-step guidance.
61
+
-**[Change Review Agent](/intune/agents/change-review-agent)**: Evaluates the effect of Multi Admin Approval requests in Intune and makes recommendations for actions to take.
62
+
-**[Device Offboarding Agent](/intune/agents/device-offboarding-agent)**: Identifies stale or misaligned devices across Intune and Microsoft Entra ID, providing actionable insights before offboarding.
63
+
-**[Policy Configuration Agent](/intune/agents/policy-configuration-agent)**: Converts plain-language documents and industry baselines into recommended Intune settings and policies.
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-agents/includes/4-describe-conditional-access-optimization-agent.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,7 +29,7 @@ The following agents are currently available for Microsoft Entra. Due to the fas
29
29
30
30
#### Conditional Access Optimization Agent
31
31
32
-
The [Conditional Access Optimization Agent](https://learn.microsoft.com/entra/security-copilot/conditional-access-agent-optimization) ensures comprehensive user protection by analyzing your Conditional Access policies and recommending improvements. The agent evaluates your current policy configuration against Microsoft best practices and Zero Trust principles.
32
+
The [Conditional Access Optimization Agent](/entra/security-copilot/conditional-access-agent-optimization) ensures comprehensive user protection by analyzing your Conditional Access policies and recommending improvements. The agent evaluates your current policy configuration against Microsoft best practices and Zero Trust principles.
33
33
34
34
| Attribute | Description |
35
35
|-----------|-------------|
@@ -42,7 +42,7 @@ The [Conditional Access Optimization Agent](https://learn.microsoft.com/entra/se
42
42
43
43
#### Access Review Agent
44
44
45
-
The [Access Review Agent](https://learn.microsoft.com/entra/id-governance/access-review-agent) with Microsoft Entra ID Governance empowers reviewers to make fast and accurate access decisions. It delivers insights and recommendations so reviewers can complete their work through a simple conversation, right inside Microsoft Teams.
45
+
The [Access Review Agent](/entra/id-governance/access-review-agent) with Microsoft Entra ID Governance empowers reviewers to make fast and accurate access decisions. It delivers insights and recommendations so reviewers can complete their work through a simple conversation, right inside Microsoft Teams.
46
46
47
47
| Attribute | Description |
48
48
|-----------|-------------|
@@ -55,7 +55,7 @@ The [Access Review Agent](https://learn.microsoft.com/entra/id-governance/access
55
55
56
56
#### Identity Risk Management Agent (preview)
57
57
58
-
The [Identity Risk Management Agent](https://learn.microsoft.com/entra/id-protection/identity-risk-management-agent-get-started) in Microsoft Entra ID Protection helps administrators investigate potential risks, learn about potential effects, and take decisive action to protect their organization’s critical assets.
58
+
The [Identity Risk Management Agent](/entra/id-protection/identity-risk-management-agent-get-started) in Microsoft Entra ID Protection helps administrators investigate potential risks, learn about potential effects, and take decisive action to protect their organization's critical assets.
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-agents/includes/5-describe-phishing-triage-agent.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ The following Microsoft Security Copilot agents are available in the Microsoft D
13
13
14
14
#### Phishing Triage Agent
15
15
16
-
The [Phishing Triage Agent](https://learn.microsoft.com/defender-xdr/phishing-triage-agent) helps security operations analysts triage and classify user-submitted phishing incidents. The agent operates autonomously, provides a transparent rationale for its classification verdicts in natural language, and continuously learns and improves its accuracy based on feedback from analysts.
16
+
The [Phishing Triage Agent](/defender-xdr/phishing-triage-agent) helps security operations analysts triage and classify user-submitted phishing incidents. The agent operates autonomously, provides a transparent rationale for its classification verdicts in natural language, and continuously learns and improves its accuracy based on feedback from analysts.
17
17
18
18
| Attribute | Description |
19
19
|-----------|-------------|
@@ -27,7 +27,7 @@ The [Phishing Triage Agent](https://learn.microsoft.com/defender-xdr/phishing-tr
27
27
28
28
#### Threat Intelligence Briefing Agent
29
29
30
-
The [Threat Intelligence Briefing Agent](https://learn.microsoft.com/defender-xdr/threat-intel-briefing-agent-defender) provides security operations teams with regular, customized threat intelligence briefings. The agent autonomously gathers and synthesizes relevant threat intelligence data from various sources, delivering concise and actionable insights to help analysts stay informed about emerging threats and trends.
30
+
The [Threat Intelligence Briefing Agent](/defender-xdr/threat-intel-briefing-agent-defender) provides security operations teams with regular, customized threat intelligence briefings. The agent autonomously gathers and synthesizes relevant threat intelligence data from various sources, delivering concise and actionable insights to help analysts stay informed about emerging threats and trends.
31
31
32
32
| Attribute | Description |
33
33
|-----------|-------------|
@@ -41,9 +41,9 @@ The [Threat Intelligence Briefing Agent](https://learn.microsoft.com/defender-xd
41
41
42
42
#### Threat Hunting Agent
43
43
44
-
The [Threat Hunting Agent](https://learn.microsoft.com/defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent) enables you to investigate threats using natural language from start to finish. It not only generates Kusto Query Language (KQL) queries but also interprets results, surfaces insights, and guides you through full hunting sessions. These capabilities empower you to hunt threats faster, more accurately, and with greater confidence.
44
+
The [Threat Hunting Agent](/defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent) enables you to investigate threats using natural language from start to finish. It not only generates Kusto Query Language (KQL) queries but also interprets results, surfaces insights, and guides you through full hunting sessions. These capabilities empower you to hunt threats faster, more accurately, and with greater confidence.
45
45
46
46
#### Dynamic Threat Detection Agent
47
47
48
-
The [Dynamic Threat Detection Agent](https://learn.microsoft.com/defender-xdr/dynamic-threat-detection-agent) in the Defender portal is an always-on, adaptive backend service that uncovers hidden threats across Defender and Microsoft Sentinel environments. It uses AI to identify gaps and uncover false negatives by correlating alerts, events, anomalies, and threat intelligence. When the agent identifies a gap, it generates a dynamic alert with the full context in the alert details, including natural language explanations, mapped MITRE ATT&CK techniques, and tailored remediation steps.
48
+
The [Dynamic Threat Detection Agent](/defender-xdr/dynamic-threat-detection-agent) in the Defender portal is an always-on, adaptive backend service that uncovers hidden threats across Defender and Microsoft Sentinel environments. It uses AI to identify gaps and uncover false negatives by correlating alerts, events, anomalies, and threat intelligence. When the agent identifies a gap, it generates a dynamic alert with the full context in the alert details, including natural language explanations, mapped MITRE ATT&CK techniques, and tailored remediation steps.
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-agents/includes/5a-describe-purview-agents.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ The following Microsoft Security Copilot agents are available in Microsoft Purvi
9
9
10
10
#### Triage Agent in Insider Risk Management
11
11
12
-
The [Triage Agent in Insider Risk Management](https://learn.microsoft.com/purview/copilot-in-purview-agents) helps security teams by evaluating alerts based on user risk, file risk, and activity risk. The agent then sorts the triaged alerts into categories that are presented in the insider risk management solution on the **Alerts** tab.
12
+
The [Triage Agent in Insider Risk Management](/purview/copilot-in-purview-agents) helps security teams by evaluating alerts based on user risk, file risk, and activity risk. The agent then sorts the triaged alerts into categories that are presented in the insider risk management solution on the **Alerts** tab.
13
13
14
14
| Attribute | Description |
15
15
|-----------|-------------|
@@ -23,7 +23,7 @@ The [Triage Agent in Insider Risk Management](https://learn.microsoft.com/purvie
23
23
24
24
#### Alert Triage Agent in Data Loss Prevention (preview)
25
25
26
-
The [Alert Triage Agent in Data Loss Prevention](https://learn.microsoft.com/purview/copilot-in-purview-agents) helps security teams by evaluating alerts based on the sensitivity risk, exfiltration risk, and policy risk. The agent then sorts the triaged alerts into categories that are presented in the DLP solution on the **Alerts** page.
26
+
The [Alert Triage Agent in Data Loss Prevention](/purview/copilot-in-purview-agents) helps security teams by evaluating alerts based on the sensitivity risk, exfiltration risk, and policy risk. The agent then sorts the triaged alerts into categories that are presented in the DLP solution on the **Alerts** page.
Copy file name to clipboardExpand all lines: learn-pr/wwl-sci/security-copilot-describe-agents/includes/5c-describe-intune-agents.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ The following Microsoft Security Copilot agents are available in Microsoft Intun
9
9
10
10
#### Vulnerability Remediation Agent
11
11
12
-
The [Vulnerability Remediation Agent](https://learn.microsoft.com/intune/agents/vulnerability-remediation-agent) uses data from Microsoft Defender Vulnerability Management to identify Common Vulnerabilities and Exposures (CVEs) on managed devices. The results are prioritized for remediation and include step-by-step instructions to guide you in using Intune to remediate the threat.
12
+
The [Vulnerability Remediation Agent](/intune/agents/vulnerability-remediation-agent) uses data from Microsoft Defender Vulnerability Management to identify Common Vulnerabilities and Exposures (CVEs) on managed devices. The results are prioritized for remediation and include step-by-step instructions to guide you in using Intune to remediate the threat.
13
13
14
14
| Attribute | Description |
15
15
|-----------|-------------|
@@ -22,7 +22,7 @@ The [Vulnerability Remediation Agent](https://learn.microsoft.com/intune/agents/
22
22
23
23
#### Change Review Agent
24
24
25
-
The [Change Review Agent](https://learn.microsoft.com/intune/agents/change-review-agent) evaluates Multi Admin Approval requests for PowerShell scripts on Windows devices. It aggregates signals from Microsoft Defender Vulnerability Management, Microsoft Entra ID, and Microsoft Intune to provide risk-based recommendations and contextual insights that help administrators make informed decisions about whether to approve or deny requests.
25
+
The [Change Review Agent](/intune/agents/change-review-agent) evaluates Multi Admin Approval requests for PowerShell scripts on Windows devices. It aggregates signals from Microsoft Defender Vulnerability Management, Microsoft Entra ID, and Microsoft Intune to provide risk-based recommendations and contextual insights that help administrators make informed decisions about whether to approve or deny requests.
26
26
27
27
| Attribute | Description |
28
28
|-----------|-------------|
@@ -35,7 +35,7 @@ The [Change Review Agent](https://learn.microsoft.com/intune/agents/change-revie
35
35
36
36
#### Device Offboarding Agent
37
37
38
-
The [Device Offboarding Agent](https://learn.microsoft.com/intune/agents/device-offboarding-agent) identifies stale or misaligned devices across Intune and Microsoft Entra ID. It provides actionable insights and requires admin approval before offboarding any devices. The agent complements existing Intune automation by surfacing insights and handling ambiguous cases where automated cleanup may not suffice.
38
+
The [Device Offboarding Agent](/intune/agents/device-offboarding-agent) identifies stale or misaligned devices across Intune and Microsoft Entra ID. It provides actionable insights and requires admin approval before offboarding any devices. The agent complements existing Intune automation by surfacing insights and handling ambiguous cases where automated cleanup may not suffice.
39
39
40
40
| Attribute | Description |
41
41
|-----------|-------------|
@@ -48,7 +48,7 @@ The [Device Offboarding Agent](https://learn.microsoft.com/intune/agents/device-
48
48
49
49
#### Policy Configuration Agent
50
50
51
-
The [Policy Configuration Agent](https://learn.microsoft.com/intune/agents/policy-configuration-agent) converts plain-language documents and industry baselines into recommended Intune settings and policies. Admins can upload compliance standards or organizational security policies, and the agent identifies relevant Intune settings catalog settings, recommends values, and guides the creation of configuration profiles.
51
+
The [Policy Configuration Agent](/intune/agents/policy-configuration-agent) converts plain-language documents and industry baselines into recommended Intune settings and policies. Admins can upload compliance standards or organizational security policies, and the agent identifies relevant Intune settings catalog settings, recommends values, and guides the creation of configuration profiles.
0 commit comments