TrustRadius: an HG Insights company

Microsoft Security Copilot Reviews & Insights

Score8.5 out of 10

35 Reviews and Ratings

Community Insights for Microsoft Security Copilot

Synthesised from 19 verified reviews.


Synthesised from 19 reviews


Microsoft Security Copilot is primarily deployed by organizations to enhance security operations, particularly in streamlining incident investigation and response. Over half of reviewers, 53%, leverage its capabilities to quickly address security alerts, filter notifications, and summarize incidents for faster resolution. The platform excels in threat analysis and hunting, with 47% of users noting its effectiveness in quickly analyzing alerts, detecting threats, and applying AI-powered insights from user behavior and network logs. This analytical prowess, combined with its ability to automate routine security tasks, a benefit cited by 37% of reviewers, significantly reduces manual effort and improves Security Operations Center (SOC) efficiency. Reviewers frequently highlight the substantial operational benefits, with 68% noting significant time savings and increased efficiency due to faster incident response and task automation. This efficiency translates into an improved security posture for 16% of users, who observe better protection against threats and proactive remediation. The solution also contributes to scalability by enabling less experienced analysts to handle more complex tasks, as reported by 16% of the user base. Furthermore, its seamless integration within the broader Microsoft ecosystem, such as with Defender and Sentinel, provides comprehensive data correlation and actionable insights, a key advantage for 21% of users. Beyond security operations, 21% of reviewers find value in its code generation and assistance features, boosting developer productivity. However, Microsoft Security Copilot presents notable challenges, particularly regarding its cost. A significant concern for 21% of reviewers is the product's high cost, often perceived as prohibitive, especially for smaller businesses, compounded by a lack of transparency in add-on pricing. The initial setup process and associated learning curve were described as complex and time-consuming by 16% of reviewers. Additionally, the accuracy of AI recommendations was a point of contention for 16% of users, who reported instances of incorrect threat assessments or overconfident explanations, necessitating human oversight. Deep, multi-step complex investigations and integrating the tool with existing environments, particularly across multiple tenants, were also identified as cumbersome by 16% of reviewers, suggesting areas for refinement in user experience and interoperability.


  • Streamlined incident investigation and response acceleration
  • Enhanced threat analysis and hunting with AI-powered insights
  • Automation of routine security tasks and operational efficiency
  • Seamless integration with the broader Microsoft security ecosystem
  • Significant time savings and improved security posture
  • High cost and lack of pricing transparency
  • Complex initial setup and steep learning curve
  • Inconsistent accuracy of AI recommendations, requiring human oversight
  • Difficulties with deep, multi-step complex investigations
  • Cumbersome integration and configuration with multi-tenant environments
What other products like Microsoft Security Copilot have you used or evaluated?

From 19 reviews

Reviewers evaluating Microsoft Security Copilot frequently cited experience with other artificial intelligence tools, primarily Google Gemini and ChatGPT. These tools were mentioned as alternative or complementary solutions in the security and operational intelligence space. Google Gemini was noted by 3 of 19 reviewers, suggesting a nascent but present awareness of its capabilities in a security context, particularly when paired with Google Security Operations [3 of 19 reviewers]. Similarly, ChatGPT was identified by 2 of 19 reviewers as another large language model they have utilized alongside or in comparison to Microsoft's offering. The overall sentiment regarding these alternative tools was positive, indicating that users are exploring a range of AI-driven platforms for security operations and general AI assistance, often seeing them as comparable or complementary in their evaluative processes. The limited number of mentions for each product suggests that while these are recognized, a broad consensus on direct competitors or widely adopted alternatives is not yet established within this review sample.

Google Gemini

Google Gemini and ChatGPT

ChatGPT

ChatGPT and Google Gemini

What functions are particularly difficult or cumbersome to perform using Microsoft Security Copilot?

From 19 reviews

Reviewers identified several functions within Microsoft Security Copilot that presented difficulties or were perceived as cumbersome to perform. The most frequently cited challenges, each noted by 3 of 19 reviewers, involved deep, multi-step complex investigations and the integration and configuration of the tool with existing environments. Specifically, some users found it challenging to conduct in-depth code analysis or investigations requiring pivots across various data sources. Similarly, integrating the system with multiple tenants and navigating unintuitive graphical user interface settings were reported as problematic. Less frequently, but still noted by 2 of 19 reviewers, were difficulties related to customizing responses for specific organizational contexts and handling sensitive decision-making during real-time incidents. These observations suggest areas for refinement in user experience, especially concerning complex analytical tasks and system interoperability within varied enterprise settings.

Complex Investigations

Deep, multi‑step investigations that require pivots across multiple data sources

Integration and Configuration

Many different systems in-place and connected them all is confusing

Customization and Context

Sourcing of internal vs external info

What functions are particularly easy or elegant to perform using Microsoft Security Copilot?

From 19 reviews

Microsoft Security Copilot is noted by reviewers for its ability to streamline complex security operations, particularly in incident response and threat analysis. A key strength highlighted by 3 of 19 reviewers is its effectiveness in incident summarization, quickly providing accurate overviews of security events. This capability is complemented by its utility in log and query analysis, where 2 of 19 reviewers found it adept at translating intricate data, such as KQL queries or raw logs, into more understandable language. The platform's overall ease of use, mentioned by 2 of 19 reviewers, further contributes to its perceived elegance, suggesting that once configured, it simplifies daily security tasks. These functions collectively enhance efficiency for security professionals by reducing the manual effort involved in understanding and responding to security incidents.

Incident Summarization

Summarizing incidents pasted from sentinel with decent accuracy

Log and Query Analysis

Analyzing scripts or logs for malicious behavior

Ease of Use

Easy to use

Microsoft Security Copilot includes built-in agents capable of automating key security tasks, with dozens available from Microsoft and partners, plus the option to build your own. Is your organization using Security Copilot agents? If so, what use cases have you explored, and what’s been your experience?

From 19 reviews

Organizations are actively exploring and implementing Microsoft Security Copilot agents, primarily for automating various security tasks. Seven of 19 reviewers highlighted the potential for these agents to significantly enhance operational efficiency, particularly in areas like alert triage, incident response, and threat intelligence enrichment. While many anticipate substantial time savings for incident response teams, some reviewers also noted challenges, including the broad scope of agents being difficult to fully grasp, especially concerning internal security posture. A notable concern raised by one reviewer was the lack of visibility into the future costs associated with integrating add-ons into these agents. Additionally, a smaller group of reviewers, 2 of 19, expressed interest in developing custom agents to further tailor the security capabilities to their specific environments, indicating a desire to extend beyond the out-of-the-box functionalities.

Automating Security Tasks

So the use cases we have are to help us diagnose less-known alerts, which take more time for human investigation. So now we have those agents doing that investigation and coming up with a remediation.

Custom Agent Development

Yes, we can add custom agents by doing the prompt for better or advanced security to our systems.

What positive or negative impact (i.e. Return on Investment or ROI) has Microsoft Security Copilot had on your overall business objectives?

From 19 reviews

Microsoft Security Copilot appears to offer significant operational benefits, primarily through enhancing efficiency and reducing response times in security operations. A substantial majority of reviewers, 13 out of 19, highlighted time savings and increased efficiency as key positive impacts, attributing these gains to faster incident response and automation of tedious tasks. This efficiency gain is further supported by observations from 3 of 19 reviewers who noted an improved security posture, citing better protection against threats and proactive remediation. Additionally, the solution contributes to scalability by enabling less experienced analysts to handle more complex tasks, as noted by 3 of 19 reviewers. Despite these operational advantages, concerns regarding the financial investment required for the product were raised by 3 of 19 reviewers, who described it as expensive both for initial acquisition and ongoing training. A smaller number of reviewers, 2 of 19, also indicated a positive impact on revenue and business growth due to enhanced security services.

Time Savings and Efficiency

reduces a lot of time to bring the code into practice.

Improved Security Posture

Risk reduction and scalability

Scalability and Analyst Enablement

Shift workload to more junior analysts on our team.

Besides Microsoft Security Copilot, what other software do you regularly use? How likely would you be to recommend it to a friend or colleague?

From 19 reviews

Reviewers frequently mention a limited set of other software used alongside Microsoft Security Copilot, with two applications standing out in this small sample of 19 reviews. ChatGPT is the most commonly cited external tool, mentioned by 4 of 19 reviewers, indicating its presence in the workflow of a notable portion of users. While its usage is acknowledged, the specific reasons for its application or the nature of its impact are not detailed in the provided feedback, leading to a mixed sentiment assessment. Another tool, Microsoft Sentinel, is also identified by 2 of 19 reviewers, who generally hold a positive view of its complementary role. The limited number of distinct tools mentioned suggests that while some users integrate other software, the scope of frequently used external applications may be narrow or not extensively elaborated upon in this review set.

ChatGPT

ChatGPT

Microsoft Sentinel

Microsoft Sentinel

Describe how you use Microsoft Security Copilot in your organization. What are the business problems the product addresses and what is the scope of your use case?

From 19 reviews

Microsoft Security Copilot is primarily leveraged by organizations to enhance their security operations, with a strong focus on streamlining incident investigation and response. Over half of the reviewers (10 of 19) highlighted its utility in quickly addressing security alerts, filtering out unnecessary notifications, and summarizing incidents to facilitate faster resolution. This efficiency is often achieved through the product's ability to automate routine security tasks, a benefit noted by more than a third of reviewers (7 of 19). These automations extend to generating incident reports and monitoring server metrics, thereby reducing manual effort. Furthermore, the platform's capabilities in code generation and assistance, cited by four reviewers, contribute to increased productivity by helping developers with scripting and reviewing code. The seamless integration of Security Copilot within the broader Microsoft ecosystem, such as with Defender, Sentinel, and Intune, was also a key advantage for several reviewers (4 of 19), allowing for comprehensive data correlation and actionable insights from various security data sources.

Incident Investigation and Response

We can automate routine investigation that improves efficiency.

Automation of Routine Tasks

Copilot can quickly put together automations that can then be fine-tuned by users in a fraction of the time it takes to create a full script or automation from scratch.

Code Generation and Assistance

One of the main business problems we had was integrating Microsoft Security Copilot to write code. So that is really useful for speeding up coding time and reviewing it.

Please provide some detailed examples of areas where Microsoft Security Copilot has room for improvement.

From 19 reviews

Microsoft Security Copilot reviewers frequently identified several areas for improvement, particularly concerning its cost structure and initial deployment. A significant concern, cited by 4 of 19 reviewers, is the product's high cost, which is often perceived as prohibitive, especially for small businesses. This cost is compounded by a lack of transparency regarding add-on pricing and total utilization expenses. The initial setup process and associated learning curve also presented challenges for 3 of 19 reviewers, who described it as complex and time-consuming due to numerous prerequisite steps. Furthermore, the accuracy of AI recommendations was a point of contention among 3 of 19 reviewers, who reported instances of incorrect threat assessments or overconfident, inaccurate explanations, necessitating human oversight. Reviewers also noted limitations in permissions granularity and the product's context window, along with mixed experiences regarding third-party integrations and automation capabilities.

Cost and Pricing

It is super expensive, which can be a turn off for many small businesses looking to leverage its capabilities

Setup and Learning Curve

Initial setup takes time as well.

AI Accuracy and Recommendations

Sometimes it generate false miss threats, where human oversight needed.

Loading Reviews List....