Microsoft announced its Copilot for Security service will be generally available on April 1. Analysts noted that experienced security practitioners will receive most of the benefits from this generative artificial intelligence (genAI) and large language model (LLM) (LLM)-based tool.
The tech giant introduced the Microsoft Security Copilot for early access review last March. The service offers a variety of capabilities, including:
- Human-readable explanations of vulnerabilities, threats, and alerts from Microsoft’s security products and later from third-party tools.
- Answering questions about the enterprise environment and the incidents using natural language.
- Summarizing incident analysis and offering recommendations on next steps.
- Enabling users to edit the prompt to correct or adjust the responses, and share the findings with others.
Copilot for Security offers insights informed by large-scale data and threat intelligence, including Microsoft’s 78 trillion security signals processed daily, up from 65 trillion when introduced last year.
Getting ramped up to use itThe company’s recent Copilot for Security economic study showed experienced security professionals are 22% faster and 7% more accurate when using the service, while 97% of the surveyed said they want to use Copilot for Security the next time they do the same task.
“Experienced practitioners will reap the most rewards from the capabilities Microsoft offers, and while it’s unlikely to identify threats SOC [security operation center] teams would miss, it does make investigation and response faster,” Forrester VP and Principal Analyst Jeff Pollard said in a statement.
However, he added even most seasoned practitioners are expected to go through a fair amount of change management and training to take full advantage of the Microsoft Copilot for Security. “Expect it to take around 40 hours of training to get security practitioners comfortable with using Copilot for Security. In addition, we heard that it takes four or more weeks — with many stops and starts — to get practitioners comfortable with the technology.”
As for Microsoft's claim that it will lower the barrier to entry into the cybersecurity industry from diverse backgrounds and attract more diverse talent, Pollard wrote in a blog post, “Though large language models and generative AI may level the playing field and allow for accelerated security talent development, no amount of out-of-the-box prompt books and guided response steps replace fundamental security knowledge, skills, and experience.”
Pros and cons of Microsoft Copilot for SecurityPollard listed what Microsoft early-access clients loved about Copilot for Security, including the following:
- Makes script analysis easier by de-obfuscating and explaining contents.
- Accelerates threat hunting by helping write queries based on adversary methods.
- Speeds up and simplifies complex KQL queries or PowerShell script creation.
- Analyzes phishing submissions by verifying true positives and providing inbox details.
- Improves analyst experience by reducing the need to swap between various tools.
- Generates executive-ready incident report summaries efficiently.
He also noted there are several downsides of this tool. For example, it currently requires multiple instances for users that want to silo data between business units, operating companies or geographies, and the instances do not roll into a single interface at launch.
“Not only is that problematic for multinationals or complex corporations, but it’s also a challenge for service provider partners offering MDR [managed detection and response], SOCaaS [security operations center-as-a-service], or managed SIEM [security information and event management] services on Copilot for Security,” he said.
In addition, the integration of Copilot for Security is limited for now. “Copilot can call Power Automate, and vice versa, but in neither case are the calls bidirectional. Copilot cannot auto-quarantine an infected host today,” according to Pollard.
Copilot gets new capabilitiesVasu Jakkal, corporate VP of compliance, identity, management, and privacy, noted as part of the launch that Microsoft added the following new features to its Copilot for Security:
- Custom promptbooks, which allow teams to create and save their own natural language prompts for common security workstreams and tasks.
- Knowledge integrations (in preview), which enable connecting Copilot for Security to customers’ logic and perform activities based on their step-by-step guides.
- Multilanguage support, which processes prompts and responds in eight languages, with 25 languages supported in the interface.
- Integration with customers’ curated external attack surface from Microsoft Defender External Attack Surface Management to identify and analyze the most up-to-date information.
- Summarization in natural language of additional insights from Microsoft Entra audit logs and diagnostic logs for a security investigation or IT issue analysis related to a specific user or event.
- Usage dashboards to provide reporting on how teams interact with Copilot.
For organizations or security teams already using Microsoft security services such as Sentinel, Defender, Entra, Priva, Intune and Purview, the Microsoft Security Copilot is “a no-brainer add-on” that will help their productivity, Pollard wrote.
However, he recommends these teams learn about the “pay as you go” licensing model and the training requirements.
“The pay-as-you-go model — a polite way of saying consumption pricing — will challenge already stretched CISO budgets, and it fits best for organizations already heavily invested in the Microsoft ecosystem of tools and technologies,” Pollard said.
As for organizations that use other vendors, “it may not be worth sinking much investment into secure compute units (for now); instead, turn to whatever your current portfolio player vendor calls its generative AI solution,” he added.
Comments