Skip to content

Commit 22d395a

Browse files
authored
Merge pull request #1080 from millenniumfalcone/main
Update SecOps pillar docs
2 parents ca06b51 + 0345e66 commit 22d395a

9 files changed

Lines changed: 177 additions & 0 deletions

File tree

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# Provision Security Copilot Units (SCUs)
2+
3+
**Implementation Effort:** Medium — Provisioning SCUs requires IT and Security Operations teams to configure and manage capacity through Azure or the Security Copilot portal.
4+
**User Impact:** Low — All actions occur at the admin level; non‑privileged users do not need to take any action.
5+
6+
## Overview
7+
Security Compute Units (SCUs) provide the required capacity for Microsoft Security Copilot to run AI-driven security analysis workloads. Organizations that do not have Microsoft 365 E5 licensing must provision SCUs to enable Security Copilot. Administrators can increase or decrease SCUs from the Azure portal or the Security Copilot portal, and a usage monitoring dashboard helps them understand consumption over time. If SCUs are not provisioned—or the capacity is insufficient—Security Copilot may not operate or may perform poorly, weakening detection and investigation capabilities during active threats. This activity supports the **Zero Trust “Assume Breach”** principle by ensuring enough analytic capacity to rapidly detect, investigate, and respond to attacks.
8+
Security Copilot uses Microsoft Entra ID role-based access control (RBAC) to authorize access, and Microsoft recommends using the Microsoft Security roles group, which provides balanced access and administrative efficiency. This planning step protects sensitive security insights, prevents accidental exposure, and reduces the risk of unauthorized operations if roles are poorly scoped.
9+
10+
### Where to configure this setting
11+
- **Azure Portal** — Adjust SCU quantity and configure overage.
12+
- **Security Copilot Portal** — Track usage, view capacity dashboards, and tune allocation.
13+
*(No configuration images are available in the source documentation.)*
14+
15+
## Reference
16+
- [Security Compute Units and capacity](https://learn.microsoft.com/en-us/copilot/security/security-compute-units-capacity)
17+
- [Get started with Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/get-started-security-copilot)
18+
- [Onboarding to Security Copilot for non-Microsoft 365 E5 customers](https://learn.microsoft.com/en-us/copilot/security/manual-onboarding)
19+
- [Understand authentication in Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/authentication)
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
# Manage and Monitor Usage of Security Compute Units (SCUs)
2+
3+
**Implementation Effort:** Medium — Administrators only need to perform targeted actions in the Security Copilot or Azure portal to view usage or adjust capacity.
4+
**User Impact:** Low — Only administrators make changes; non-privileged users do not need to take any action.
5+
6+
## Overview
7+
Security Compute Units (SCUs) define the processing capacity available to Microsoft Security Copilot. They determine how many security analyses, reasoning tasks, and automated workflows the service can run. Administrators can view real‑time and historical SCU consumption through built‑in dashboards in both the Security Copilot portal and the Azure portal. They can also scale SCUs up or down to meet operational needs.
8+
9+
If SCU usage is not monitored or managed, organizations risk hitting capacity limits, which can delay or block Copilot‑assisted investigations, threat analysis, and automated responses. Ensuring SCU capacity is healthy supports the Zero Trust *Assume Breach* principle by maintaining continuous operational readiness for detection and response workflows.
10+
11+
### Where to enable or configure
12+
- **Security Copilot Portal** → Usage dashboard (shows SCU consumption trends).
13+
- **Azure Portal** → Security Copilot resource → **Capacity** (modify provisioned SCUs).
14+
15+
16+
## Reference
17+
- [Manage security compute unit usage in Security Copilot](https://learn.microsoft.com/en-us/copilot/security/manage-usage)
18+
- [Security Compute Units and capacity in Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/security-compute-units-capacity)
19+
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Manage Plugins in Microsoft Security Copilot
2+
3+
**Implementation Effort:** Medium — Admins must configure, approve, and govern plugin access, which requires a defined project effort.
4+
**User Impact:** Low — All actions occur on the admin side; non‑privileged users do not need to take action.
5+
6+
## Overview
7+
Managing plugins in Microsoft Security Copilot allows administrators to control which external systems, security tools, threat‑intelligence sources, and internal data sources Copilot can access. Plugins extend Copilot’s ability to retrieve security context, execute actions, and connect to approved services. If plugins are not managed, the organization risks reduced Copilot effectiveness, inconsistent user experiences, or exposure of sensitive data to unapproved integrations.
8+
9+
This supports the Zero Trust principle of **Verify Explicitly**, because each plugin must be explicitly reviewed and authorized before use.
10+
11+
Admins can:
12+
- Enable or disable Microsoft, third‑party, and custom plugins
13+
- Review plugin permissions
14+
- Manage Model Context Protocol (MCP) plugins
15+
- Control which integrations are available across the organization
16+
17+
## Reference
18+
- [Manage plugins in Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/manage-plugins)
19+
- [Use plugins in Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/use-plugins)
20+
- [Plugins overview for Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/plugin-overview)
21+
- [Model Context Protocol (MCP) plugins in Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/plugin-mcp)
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# Threat Hunting Agent (Microsoft Defender)
2+
3+
**Implementation Effort: Medium** – This requires IT and Security Operations teams to configure access and incorporate the Threat Hunting Agent into existing Defender XDR hunting workflows, which is a project rather than a long‑term operational program.
4+
**User Impact: Low** – Only administrators and security analysts interact with this capability; standard users do not need to take action.
5+
6+
## Overview
7+
The Microsoft Security Copilot **Threat Hunting Agent** enhances Defender XDR’s advanced hunting by letting analysts ask questions in natural language and automatically generating, interpreting, and guiding threat‑hunting queries. It improves analyst efficiency by surfacing insights and walking them through end‑to‑end hunting sessions. Not deploying this tool may lead to slower threat detection, inconsistent query quality, and missed attacker activity because analysts must manually construct complex queries.
8+
This capability supports the **Assume Breach** principle by improving visibility, accelerating threat detection, and helping analysts quickly investigate suspicious activity.
9+
10+
### Where to configure/use it in the product
11+
You can access the Threat Hunting Agent in the Microsoft Defender portal:
12+
**Microsoft Defender portal → Advanced hunting → Security Copilot Threat Hunting Agent**
13+
14+
15+
## Reference
16+
- [Microsoft Security Copilot Threat Hunting Agent in Advanced Hunting](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent)
17+
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# Defender Threat Intelligence Agent
2+
3+
**Implementation Effort:** Medium — IT and Security Operations teams must enable and integrate Microsoft Defender for Endpoint and Defender External Attack Surface Management so the agent has the required telemetry to operate effectively.
4+
**User Impact:** Low — All actions occur within admin/SecOps workflows; non‑privileged users do not need to take any action or be notified.
5+
6+
## Overview
7+
The Defender Threat Intelligence Agent (referred to in Microsoft Learn as the *Threat Intelligence Briefing Agent*) is an AI‑driven capability in Microsoft Security Copilot that generates tailored threat intelligence summaries based on signals from Microsoft Defender for Endpoint and Microsoft Defender External Attack Surface Management. It provides analysts with context-rich information on adversary activity, threat infrastructure, and relevant indicators, helping teams speed up investigations and identify active risks.
8+
If this capability is not leveraged, security teams may miss correlations across Defender signals or spend more time manually gathering intelligence, increasing the risk of delayed detection and slower response.
9+
This capability aligns to the Zero Trust principle of **Assume breach** by enhancing visibility, exposing attacker infrastructure, and improving threat detection quality.
10+
11+
12+
13+
## Reference
14+
- [Threat Intelligence Briefing Agent — Microsoft Defender XDR](https://learn.microsoft.com/en-us/defender-xdr/threat-intel-briefing-agent-defender)
15+
- [Threat Intelligence Briefing Agent — Microsoft Security Copilot](https://learn.microsoft.com/en-us/copilot/security/threat-intel-briefing-agent)
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
# View Incident Summaries and Use Guided Response to Remediate
2+
3+
**Implementation Effort:** Low — Security administrators only need to perform targeted actions in Microsoft Defender XDR to view AI‑generated summaries and guided remediation steps.
4+
**User Impact:** Low — Actions occur only within the admin/security team; no non‑privileged users are affected or notified.
5+
6+
## Overview
7+
Security Copilot in Microsoft Defender XDR uses generative AI to summarize security incidents and provide guided remediation actions. Defender XDR automatically produces a clear, high‑value summary of the incident attack story, enabling analysts to understand what happened quickly. Security Copilot also uses AI and machine learning to contextualize the incident and generate recommended steps analysts can follow to investigate and remediate threats. These summaries and guided steps appear automatically in the Security Copilot pane within the attack story, helping teams reduce investigation time and improve response consistency.
8+
9+
If not implemented, analysts must manually correlate data across multiple Defender components, slowing down response and increasing the risk of delayed containment.
10+
11+
**Zero Trust Principle:** *Assume Breach* — This capability helps reduce the blast radius by accelerating detection, investigation, and remediation.
12+
13+
### Where to Enable / Configure
14+
You can access these capabilities directly in the **Microsoft Defender portal**:
15+
1. Open **Microsoft Defender XDR**
16+
2. Go to **Incidents**
17+
3. Select an incident
18+
4. The **Security Copilot** pane on the right displays the summary and guided response steps
19+
20+
21+
## Reference
22+
- [Summarize an incident with Microsoft Copilot in Microsoft Defender](https://learn.microsoft.com/en-us/defender-xdr/security-copilot-m365d-incident-summary)
23+
- [Triage and investigate incidents with guided responses](https://learn.microsoft.com/en-us/defender-xdr/security-copilot-m365d-guided-response)
24+
- [Incident response and remediation with Security Copilot](https://learn.microsoft.com/en-us/copilot/security/use-case-incident-response-remediation)
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
# Analyze Potentially Malicious Files, Scripts, and Code with Microsoft Security Copilot
2+
3+
**Implementation Effort:** Low — Security teams only need to enable and use built‑in Security Copilot capabilities, requiring targeted actions rather than ongoing programs.
4+
5+
**User Impact:** Low — Only administrators and security analysts need to take action; no notification or action is required from end users.
6+
7+
## Overview
8+
Microsoft Security Copilot provides AI-driven analysis for suspicious files, scripts, and command lines within the Microsoft Defender portal. Copilot can summarize file behavior, highlight suspicious elements, display certificates, API calls, strings, and provide contextual detection information to speed up investigation efforts. It also analyzes scripts by identifying malicious patterns, evaluating behavior, and producing security assessments with recommended remediation guidance. This accelerates the investigation process and reduces the time to identify threats.
9+
10+
If this capability is not deployed, analysts must rely on manual reverse-engineering and static/dynamic analysis processes, which take more time and increase the risk that threats remain undetected, spread laterally, or exfiltrate data.
11+
12+
**Zero Trust Connection — Assume Breach:**
13+
This aligns with the “assume breach” principle by continuously validating potentially harmful code and enhancing threat detection visibility through AI-powered analysis.
14+
15+
## Reference
16+
- [File analysis with Microsoft Copilot in Microsoft Defender](https://learn.microsoft.com/en-us/defender-xdr/copilot-in-defender-file-analysis)
17+
- [Script analysis with Microsoft Copilot in Microsoft Defender](https://learn.microsoft.com/en-us/defender-xdr/security-copilot-m365d-script-analysis)
18+
- [Investigate an incident's malicious script](https://learn.microsoft.com/en-us/copilot/security/investigate-incident-malicious-script)
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Review and Understand Details About Identities and Devices Using Microsoft Security Copilot
2+
3+
**Implementation Effort:** Low — Only targeted actions by administrators are required; there is no large deployment project.
4+
5+
**User Impact:** Low — No end‑user action or notification is needed; only administrators interact with this capability.
6+
7+
## Overview
8+
Microsoft Security Copilot provides AI‑generated summaries of identity and device information to help security analysts understand user activity, alerts, authentication patterns, device health, and risks. The identity summary capability offers contextual insights about a user's behavior and exposure, speeding investigations and improving clarity (supported by Microsoft Defender for Identity). Device summaries automatically provide details such as risk level, configuration, and recent activity when viewing a device in Microsoft Defender.
9+
10+
Security Copilot also assists in investigating identity‑based incidents and governance tasks within Microsoft Entra, including entitlement management, privileged identity workflows, and identity risk triage. Not enabling or using these capabilities can slow investigations, increase the chance of missed signals, and reduce visibility into identity and device security posture.
11+
12+
This feature aligns to the Zero Trust principle of **Verify Explicitly**, because it surfaces deep contextual data about identities and devices before making access decisions or taking investigative actions.
13+
14+
15+
16+
## Reference
17+
- [Summarize identity information with Microsoft Security Copilot](https://learn.microsoft.com/en-us/defender-xdr/security-copilot-defender-identity-summary)
18+
- [Summarize device information with Microsoft Security Copilot](https://learn.microsoft.com/en-us/defender-xdr/copilot-in-defender-device-summary)
19+
- [Security Copilot in Microsoft Entra](https://learn.microsoft.com/en-us/entra/security-copilot/security-copilot-in-entra)
20+
- [Investigate identity risk in Microsoft Security Copilot](https://learn.microsoft.com/en-us/entra/security-copilot/entra-investigate-incident)
21+
- [Identity Governance and optimization with Security Copilot](https://learn.microsoft.com/en-us/entra/security-copilot/entra-governance-optimization)
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Consider Microsoft Defender Experts for XDR
2+
3+
**Implementation Effort:** Medium – This requires IT and Security Operations teams to drive onboarding, validate licensing, and configure permissions for expert access.
4+
**User Impact:** Low – All actions occur within admin/SOC workflows; non‑privileged users do not need to take action.
5+
6+
## Overview
7+
Microsoft Defender Experts for XDR is a managed extended detection and response service that combines Microsoft’s automation and human security expertise to help SOC teams triage incidents, investigate threats, and accelerate response. It works across Microsoft Defender for Endpoint, Office 365, Identity, Cloud Apps, and Microsoft Entra ID. It reduces alert fatigue, improves prioritization, and ensures high‑severity threats are investigated with expert support [1](https://learn.microsoft.com/en-us/defender-xdr/dex-xdr-overview).
8+
9+
If this capability is not deployed, organizations risk slower threat detection, missed high‑priority incidents, insufficient SOC capacity, and reduced visibility into active threats.
10+
11+
**Zero Trust Alignment:**
12+
This capability supports the **Assume Breach** principle by adding continuous expert-driven monitoring, proactive threat hunting, and rapid containment actions to limit impact.
13+
14+
### Where to Enable/Configure
15+
- Go to the **Microsoft Defender portal****Settings > Defender Experts > Get started** to begin onboarding and grant required permissions [2](https://learn.microsoft.com/en-us/defender-xdr/get-started-xdr).
16+
17+
## Reference
18+
- [What is Microsoft Defender Experts for XDR](https://learn.microsoft.com/en-us/defender-xdr/dex-xdr-overview)
19+
- [Get started with Microsoft Defender Experts for XDR](https://learn.microsoft.com/en-us/defender-xdr/get-started-xdr)
20+
- [How to use Microsoft Defender Experts for XDR](https://learn.microsoft.com/en-us/defender-xdr/start-using-mdex-xdr)
21+
- [Before you begin using Defender Experts for XDR](https://learn.microsoft.com/en-us/defender-xdr/before-you-begin-xdr)
22+
- [Communicating with Microsoft Defender Experts](https://learn.microsoft.com/en-us/defender-xdr/communicate-defender-experts-xdr)
23+
- [Defender Experts for XDR Reports](https://learn.microsoft.com/en-us/defender-xdr/reports-xdr)

0 commit comments

Comments
 (0)