TrustRadius: an HG Insights company

Microsoft Security Copilot

Score8.3 out of 10

34 Reviews and Ratings

What is Microsoft Security Copilot?

Microsoft Security Copilot helps security and IT teams to protect organizations at the speed and scale of AI. It is available in a standalone experience or embedded into other Microsoft Security products.

Media

Defender USX guided response
Defender USX incident summary
the homepage - capabilities menu
the homepage
MDTI threat intel
session - incident summary

1 / 6

Microsoft Security Copilot Review

Use Cases and Deployment Scope

So we use it to react more quickly to security alerts and issues. Filter through unnecessary alerts, resolve security alerts or issues that come up much quicker. So it does most of the level one triage, and we can focus on level two and level three.

Pros

  • Save money, save time, increase security, and SOC operations. Those are the things that it does well.

Cons

  • Takes a little longer than some other AI tools to configure. And you need quite a bit of knowledge of the Microsoft Stack, which has its cons, but we're a Microsoft partner. But that's about it.

Return on Investment

  • Increased revenue
  • Increased efficiency
  • Reduced overhead

Usability

These Custom security agents could be the future

Use Cases and Deployment Scope

I'm currently assigned to a Phising triage agent improvement project. We're using Copilot's agent capabilities which are autonomous workflows to 1. Automatically investigate 2. then close low priority phishing alerts.

My other use cares are around analyzing clients' security postures in Microsoft Intune environments

Pros

  • consistency with context switching and documentation
  • Democratizing expertise. This is what I mean by that: I can just type in natural language and it drafts the KQL for me. This was unheard of in the last couple of years

Cons

  • Copilot can only operate within the permissions of the logged in user

Return on Investment

  • MTTR reduction
  • Risk reduction and scalability
  • it makes talents like myself more scalable

Usability

Other Software Used

Microsoft Sentinel, Splunk Enterprise Security

Microsoft AI based security product.

Use Cases and Deployment Scope

It is an in-built AI-based security assistant in the Microsoft ecosystem. It detects threats and responds very quickly. It investigates the security issues and gives us the alerts. It finds out the root cause of the threats by doing the analysis. It reduces human efforts and automatically generates incident reports. It also gives real-time threat intelligence and ensures system security. Addresses the suspicious activities.

Pros

  • Quickly analyze alerts by doings simple analysis or from different inbuilt security tools.
  • Smart threat investigation use AI for analyzing user behavior, activity and network logs.
  • Automated generate reports and gives the steps to fix the threats.

Cons

  • Costing is a major concern for small businesses.
  • Sometimes AI gives wrong recommendations related to the threats.

Return on Investment

  • Improves security and efficiency.
  • Saves times and detects the abnormal activities.
  • Reduce errors rates by giving the guidance.

Usability

MS Security Copilot Review.

Use Cases and Deployment Scope

Security Copilot helps our security teams manage overwhelming volumes of alerts by summarizing and correlating data across Microsoft Defender, Sentinel, and other platforms. We use it for incident investigation, threat hunting, posture assessments, and executive reporting. It also allows us to offload some tasks to more junior members of our team.

Pros

  • Incident investigation.
  • Threat hunting.
  • Reporting

Cons

  • We would like more integrations with third-party tools.
  • There are situations where Copilot does not execute the remediation steps in an automation correctly.

Return on Investment

  • Shift workload to more junior analysts on our team.
  • Faster response times to incidents and alerts.

Usability

Microsoft Security Copilot your assistant to navigate the future.

Use Cases and Deployment Scope

Drafting Documents, Slide Decks or sourcing information from meetings is important. I use Microsoft Security Copilot truly as a tool assisted gatherer. It’s easy to lose track on coordination and team efforts. By incorporating tools like Microsoft Security Copilot you can reduce time to obtain info and help others get unblocked by sharing resources.

Pros

  • Analysis of Code
  • Summarizing key points
  • Transcribing videos
  • Generate images
  • Translate

Cons

  • Quality of contextual information
  • Depth of conversation
  • Bias of information

Return on Investment

  • Time spent on projects
  • Reaction in engineering hours
  • Improvement in creativity

Usability

Alternatives Considered

ChatGPT and Google Gemini

Other Software Used

ChatGPT, Azure OpenAI Service