Microsoft today announced at its Ignite 2023 event that it's combining security information and event management (SIEM), extended detection and response (XDR) and generative artificial intelligence (genAI) into a unified security operations platform. The vendor is also expanding its genAI-powered Security Copilot integration into its identity and data security and management services.
“By bringing together Microsoft Sentinel, Microsoft Defender XDR (previously Microsoft 365 Defender) and Microsoft Security Copilot, security analysts now have a unified incident experience that streamlines triage and provides a complete, end-to-end view of threats across the digital estate,” Vasu Jakkal, corporate VP of compliance, identity, management and privacy at Microsoft, wrote in a blog post.
The unified security operations platform is designed to offer a single experience with higher efficiency and ease of use for security teams. Jakkal added the genAI capabilities from the Security Copilot can help create a single set of automation rules and security playbooks, which makes coordinating responses easier and quicker for analysts of any level.
Additionally, the unified threat-hunting capability allows security analysts to query all SIEM and XDR data in one place to uncover threats and take appropriate remediation action, she said.
The platform is now in private preview and is expected to move to public preview next year. Existing Microsoft SIEM and XDR customers can add Microsoft Sentinel to their Defender portal with no migration required, while Sentinel users can continue to use the Azure portal.
Embedding AI-powered Microsoft Security CopilotMicrosoft unveiled its Security Copilot in March, which is built on the latest innovations in large language models and OpenAI’s genAI capabilities to support all levels of human analysts.
The tech giant claims, in a recent randomized controlled trial, surveyed “new in career” analysts reported using Security Copilot brought 44% more accurate responses and were 26% faster across all tasks.
Microsoft now is further integrating this technology into its security portfolio. “Microsoft Security Copilot is natively embedded into the analyst experience supporting both SIEM and XDR and equipping analysts with step-by-step guidance and automation for investigating and resolving incidents,” Jakkal said.
With the technology, analysts can use natural language to analyze malicious scripts or craft KQL queries to hunt across data in Microsoft Sentinel and Defender XDR, create incident summaries and reports, and provide support throughout the investigation and remediation process.
Security Copilot integration goes beyond SOCThe vendor also embedded the Security Copilot beyond the security operations center (SOC) to identity and data security and management, Microsoft Chief Communications Officer Frank Shaw said in a prebriefing of the new announcements with the press.
The AI capabilities from Security Copilot are incorporated with the following:
- Microsoft Intune for simplifying device, policy and app management tasks for IT admins and security analysts and quick assessments and recommendations to ensure security and compliance.
- Microsoft Entra for assisting in investigating identity risks and quicker identity access troubleshooting.
- Microsoft Purview for summarization capabilities directly within data loss prevention and insider risk management and richer context about the data security alerts.
“These new scenarios help guide IT administrators, compliance teams and identity teams to manage access more effectively, resolve issues faster and improve governance, again at the speed of AI,” Shaw said
Rebranding Microsoft Defender 365 to XDRMicrosoft Defender 365 is rebranded as Defender XDR, reflecting the vendor’s XDR capabilities spanning beyond the Microsoft 365 suite.
The Microsoft Defender XDR now covers devices across Windows, Linux, macOS, Android and iOS, and multicloud across Microsoft Azure, Amazon Web Services (AWS) and Google Cloud Platform (GCP).
“We are building on the native XDR experience by including cloud workload signals and alerts from Microsoft Defender for Cloud — a leading cloud native application protection platform (CNAPP) so analysts can conduct investigations that span across their multicloud infrastructure (Azure, AWS and GCP environments) and identities, email and collaboration tools, SaaS [software as a service] apps and multiplatform endpoints,” Jakkal said.
Comments