Security assistant powered by generative AI, used in its own portal or embedded in Intune, Entra, Defender and Purview, and extensible with agents and plugins.
Also called Security Copilot.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Security Copilot in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Generative AI
AI that produces new content such as code, text, audio or images in response to a prompt. Predicting a class or a numeric value is predictive machine learning rather than generative AI.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
Related terms
- Copilot in Defender
Inside the Defender portal, Microsoft Security Copilot summarises incidents, suggests guided response steps and analyses suspicious files or scripts.
- Copilot in Intune
Puts Security Copilot inside Intune's admin center. Admins can ask questions of their data in plain English, get policy and device summaries, and have device query KQL drafted for them; it consumes Security Copilot compute units, and scope tags and RBAC still apply.
- Data security objectives
Step-by-step goals in DSPM, for example stopping oversharing or Copilot data exposure. Each comes with its own remediation plan, Security Copilot agents and policies you can create in one click.
- Defender Chat
Opened with the Copilot button, this preview panel lets you ask Security Copilot anything in the Defender portal, with answers shaped by whichever page is open.
- Guided responses
On an incident page in Defender, Security Copilot proposes next steps sorted under triage, containment, investigation and remediation, and points out anything automation has done already.
- Microsoft Copilot experiences
A location you can pick in retention policies and in Communication Compliance to capture what people ask Microsoft-built Copilots and what those Copilots answer, covering, for example, Copilot Studio, Security Copilot, Copilot in Fabric and Microsoft Copilot. Copilot messages used to fall under the older Teams chats and Copilot interactions location.
- Microsoft Sentinel MCP server
Lets AI assistants like Security Copilot or Visual Studio Code ask questions of Sentinel data lake data in everyday language, investigate entities and help triage incidents. Microsoft runs it for you; most of its tools assume you have onboarded to the data lake and hold Security Reader.
- On-behalf-of authentication
Security Copilot relies on this OAuth flow so that a plugin never exceeds what the signed-in user may see. As a result, users need data roles too, Microsoft Sentinel Reader for example.