One of the most important characteristics of Copilot for Security is that it is not a standalone tool requiring analysts to switch context. It is embedded directly into the Microsoft security products analysts already work in.
Microsoft Sentinel
Within Microsoft Sentinel, Copilot for Security assists with incident investigation — summarizing complex incidents in plain language, suggesting investigative next steps, generating KQL queries from natural language descriptions, and helping analysts navigate large, multi-signal investigations without needing deep query expertise.
Analysts working an incident in Sentinel can ask Copilot to summarize what happened, explain a specific alert, generate a query to investigate a specific entity, or draft an incident report — all without leaving the Sentinel investigation workflow.
Microsoft Defender XDR
In Microsoft Defender XDR, Copilot for Security provides investigation support across the cross-domain incident view — summarizing unified incidents that span endpoints, identities, email, and cloud, explaining attack chains in plain language, and suggesting response actions based on investigation findings.
The Defender XDR integration also supports guided response — Copilot recommending specific containment or remediation actions based on the incident at hand, with one-click execution capability for supported actions.
Microsoft Defender for Endpoint
Within Defender for Endpoint, Copilot assists with endpoint-specific investigation — analyzing suspicious files and scripts, explaining the behavior of potentially malicious code in plain language, and helping analysts understand complex technical indicators without requiring reverse engineering expertise.
The ability to ask Copilot to explain a script or process in plain English is particularly valuable — making malware analysis and script investigation accessible to analysts who do not have deep malware analysis specialization.
Microsoft Entra ID
In Microsoft Entra ID, Copilot assists with identity investigation — summarizing unusual sign-in activity, explaining anomalous access patterns, and helping analysts assess the significance of identity-related alerts in the context of the specific user’s established behavioral baseline.
The Standalone Copilot for Security Portal
Beyond product-embedded experiences, Copilot for Security is accessible through a standalone portal — a dedicated interface where security professionals can interact with Copilot directly, upload files for analysis, run promptbooks, and access capabilities that span across multiple Microsoft security products in a single interface.
The standalone portal is particularly useful for tasks that span multiple security domains or require sustained, multi-turn investigation conversations — threat intelligence research, cross-product incident analysis, and complex scripting or detection engineering tasks.