Event banner
Copilot for Security: Customize your Copilot
Event details
Explore some of the latest ways to customize Microsoft Copilot for Security for your team. Now generally available, Copilot is the generative AI-powered assistant for daily security operations, and it is more effective when integrated with your workflows. We'll start with a deep dive and walk you through creating custom promptbooks, adding your organization's knowledge bases, and using logic apps to write back updates to your tools. We'll then transition into Ask Microsoft Anything (AMA) so post your questions early and often!
This session is part of the Microsoft Secure Tech Accelerator. Add it to your calendar, RSVP for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
94 Comments
- Do I need kql query plugin if I don't have any queries already stored in my environment?
- Char_CheesmanBronze Contributor
Thanks for participating in Copilot for Security: Customize your Copilot! For reference, the panel covered this topic at around 22:30.
- Fish_TacosBrass ContributorHow does AI contribute to real-time security analytics and incident response? I notice that some logs are 10-60 minutes behind from being displayed on the incident and alert tabs. How long does it take for the AI to ingest and analyze the alerts if I am getting them delayed?
- craigfreyman-msft
Microsoft
Copilot for Security can speed up the time it takes for a number of incident response workflows. Data can be returned in as little as a few seconds to a few minutes for more complex questions.
- Any additional cost for adding plugins? both Microsoft and third party?
- klavalleeFormer EmployeeHi Yusuf - no there is not an additional cost for adding Microsoft or third-party plugins.
- Fish_TacosBrass ContributorWhat's the Hallucination rate for the AI?
- MFilipsFormer EmployeeCopilot for Security uses the latest LLMs as well as many other design elements in the Compound AI system. Copilot for Security brings in multiple rounds of grounding in security context and underlying plugins, as well as alignment to our responsible AI principles.
- Char_CheesmanBronze Contributor
Thanks for participating in Copilot for Security: Customize your Copilot! For reference, the panel covered this topic at around 30:15.
- Fish_TacosBrass ContributorDo I get a cookie? LOL. Thanks for hosting!
- Fish_TacosBrass ContributorHow do you bring in other Threat Intel like Greynoise into the AI?
- MFilipsFormer Employee3rd party plugins are how Copilot for Security interacts with external, non-Microsoft information. There are several that were just announced and many more in the in progress. Greynoise if one of them. You can view these which are in progress here: https://securitypartners.transform.microsoft.com/copilot-private-preview-partners
- devjsCopper ContributorWe have blocked OpenAI. Can Copilot be connected to Microsoft OpenAI in the Azure tenant?
- Heather_Poulsen
Community Manager
Welcome to Copilot for Security: Customize your Copilot and the Microsoft Secure Tech Accelerator. Let's get started with the deep dive! Have questions? Post them below i the Comments and we'll answer in the AMA portion!
- Fish_TacosBrass ContributorDoes the AI for Security utilize the content it receives, such as prompts, answers, and tenant data, for training purposes?
- Trevor_Rusher
Community Manager
Hi there! Please post your questions in separate threads in this comment section to make it easier on our panel! Thank you.
- Fish_TacosBrass ContributorHow does AI contribute to real-time security analytics and incident response? I notice that some logs are 10-60 minutes behind from being displayed on the incident and alert tabs. How long does it take for the AI to ingest and analyze the alerts if I am getting them delayed?
- Trevor_Rusher
Community Manager
Hi there! Please post your questions in separate threads in this comment section to make it easier on our panel! Thank you.
- I've set up CfS using the Microsoft Copilot for Security portal, but I can't find any Microsoft copilot for security compute resources in any of my Azure Subscriptions, how do I find it?
- My question was addressed in the open AMA, but the question was not understood by the team. I am looking for the SCU that get's provisioned for running Copilot for security ($4/Hour) resource in Azure.
- Char_CheesmanBronze Contributor
Hi Matthew, thanks for asking your question! The panel covered it at around 20:55, and I'll also find someone to follow up this question too.
- stevlarsCopper Contributor
Please address FedRAMP authorization and the Customer Responsibility Matrix needed to run the product securely.
- craigfreyman-msft
Microsoft
Hi Steve, thanks for asking! At this time, we don't have anything to share on FedRAMP authorization or the Customer Responsibility Matrix.
- Trevor_Rusher
Community Manager
We are very excited to bring you this session tomorrow! Reminder: If you have questions about the session, post them in advance here in the Comments to give our live AMA panel something to kick off with. Thanks!- Fish_TacosBrass ContributorHow does AI contribute to real-time security analytics and incident response? I notice that some logs are 10-60 minutes behind from being displayed on the incident and alert tabs. How long does it take for the AI to ingest and analyze the alerts if I am getting them delayed?
- Fish_TacosBrass ContributorDoes the AI for Security utilize the content it receives, such as prompts, answers, and tenant data, for training purposes?
- klavalleeFormer EmployeeNo, the prompts, answers, and tenant data are not used for training of the foundation AI model.