You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/firewall/firewall-copilot.md
+21-12Lines changed: 21 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Azure Firewall integration in Microsoft Security Copilot (preview)
3
3
description: Learn about using Microsoft Security Copilot to investigate traffic flagged by Azure Firewall with IDPS and threat intelligence.
4
4
keywords: security copilot, copilot for security, threat intelligence, IDPS, intrusion detection and prevention system, plugin, integration, azure firewall, firewall copilot, open ai, openai, co-pilot
5
5
author: abhinavsriram
6
-
ms.author: abhinavsriram
6
+
ms.author: asriram
7
7
ms.date: 11/19/2024
8
8
ms.topic: conceptual
9
9
ms.service: azure-firewall
@@ -37,16 +37,14 @@ The Azure Firewall integration in Security Copilot helps analysts perform detail
37
37
38
38
You can use this integration in the [Security Copilot portal](https://securitycopilot.microsoft.com) (also called the standalone experience):
39
39
40
-
:::image type="content" source="media/firewall-copilot/security-copilot-overview-image.png" alt-text="Screenshot of the prompt bar in Microsoft Security Copilot with the Prompts icon highlighted.":::
40
+
:::image type="content" source="media/firewall-copilot/security-copilot-overview-image.png" alt-text="Screenshot of the Security Copilot portal with a prompt relevant to Firewall.":::
41
41
42
42
and via the [Copilot in Azure](/azure/copilot/overview) experience on the [Azure portal](https://portal.azure.com/) (also called the embedded experience):
43
43
44
-
:::image type="content" source="media/firewall-copilot/azure-copilot-overview-image.png" alt-text="Screenshot of the prompt bar in Microsoft Security Copilot with the Prompts icon highlighted.":::
44
+
:::image type="content" source="media/firewall-copilot/azure-copilot-overview-image.png" alt-text="Screenshot of the Azure portal with a prompt relevant to Firewall.":::
45
45
46
46
For more information, see [Microsoft Security Copilot experiences](/security-copilot/experiences-security-copilot).
47
47
48
-
This article introduces you to Copilot and includes sample prompts that can help Azure Firewall users.
49
-
50
48
## Key features
51
49
Security Copilot has built-in system features that can get data from the different plugins that are turned on.
52
50
@@ -68,7 +66,7 @@ To view the list of built-in system capabilities for Azure Firewall, use the fol
68
66
## Enable the Azure Firewall integration in Security Copilot
69
67
70
68
1. Ensure your Azure Firewall is configured correctly:
71
-
-[Azure Structured Firewall Logs](firewall-structured-logs.md#resource-specific-mode) – the Azure Firewalls to be used with Security Copilot must be configured with resource specific structured logs for IDPS and these logs must be sent to a Log Analytics workspace.
69
+
-[Azure Firewall Structured Logs](firewall-structured-logs.md#resource-specific-mode) – the Azure Firewalls to be used with Security Copilot must be configured with resource specific structured logs for IDPS and these logs must be sent to a Log Analytics workspace.
72
70
-[Role Based Access Control for Azure Firewall](https://techcommunity.microsoft.com/t5/azure-network-security-blog/role-based-access-control-for-azure-firewall/ba-p/2245598) – the users using the Azure Firewall plugin in Security Copilot must have the appropriate Azure RBAC roles to access the Firewall and associated Log Analytics workspace(s).
73
71
2. Go to [Security Copilot](https://go.microsoft.com/fwlink/?linkid=2247989) and sign in with your credentials.
74
72
3. Ensure that the Azure Firewall plugin is turned on. In the prompt bar, select the **Sources** icon.
@@ -81,9 +79,10 @@ To view the list of built-in system capabilities for Azure Firewall, use the fol
81
79
82
80
No additional configuration is necessary, as long as structured logs are being sent to a Log Analytics workspace and you have the right RBAC permissions, Copilot will find the data it needs to answer your questions.
83
81
84
-
4. Enter your prompt in the prompt bar on either the [Security Copilot portal](https://securitycopilot.microsoft.com) or via the [Copilot in Azure](TBD) experience on the [Azure portal](https://portal.azure.com/).
82
+
4. Enter your prompt in the prompt bar on either the [Security Copilot portal](https://securitycopilot.microsoft.com) or via the [Copilot in Azure](/azure/copilot/overview) experience on the [Azure portal](https://portal.azure.com/).
85
83
86
84
> [!NOTE]
85
+
> Use of Copilot in Azure to query Azure Firewall is included with Security Copilot and requires [security compute units (SCUs)](copilot/security/get-started-security-copilot#security-compute-units). You can provision SCUs and increase or decrease them at any time. For more information on SCUs, see [Get started with Microsoft Security Copilot](/security-copilot/get-started-security-copilot).
87
86
> If you do not have Security Copilot properly configured but ask a question relavent to the Azure Firewall capabilities via the Copilot in Azure experience then you will see the following error message:
88
87
> :::image type="content" source="media/firewall-copilot/azure-copilot-error-message.png" alt-text="Screenshot showing the Copilot in Azure error message when Security Copilot is not properly configured.":::
89
88
@@ -142,28 +141,38 @@ Get **information from documentation** about using Azure Firewall's IDPS feature
142
141
- If I want to make sure all my Firewalls are protected against attacks from signature ID _\<ID number\>_, how do I do this?
143
142
- What is the difference in risk between alert only and alert and block modes for IDPS?
144
143
145
-
:::image type="content" source="media/firewall-copilot/copilot-capability-4-embedded.png" alt-text="Screenshot showing the Look for a given IDPS signature across your tenant, subscription, or resource group capability.":::
144
+
:::image type="content" source="media/firewall-copilot/copilot-capability-4-embedded.png" alt-text="Screenshot showing the Generate recommendations to secure your environment using Azure Firewall's IDPS feature capability.":::
146
145
147
146
> [!NOTE]
148
-
>Security Copilot may also use the *Ask Microsoft Documentation* capability to provide information on how to use Azure Firewall's IDPS feature to secure your environment. When using this capability via the Copilot in Azure experience, the *Get Information* capability may be used to provide information.
147
+
>Security Copilot may also use the *Ask Microsoft Documentation* capability to provide this information and when using this capability via the Copilot in Azure experience, the *Get Information* capability may be used to provide this information.
149
148
150
149
151
150
## Provide feedback
152
151
153
-
Your feedback is vital to guide the current and planned development of the product. The best way to provide this feedback is directly in the product. Select **How’s this response?** at the bottom of each completed prompt and choose any of the following options:
152
+
Your feedback is vital to guide the current and planned development of the product. The best way to provide this feedback is directly in the product.
153
+
154
+
### Via Security Copilot
155
+
Select **How’s this response?** at the bottom of each completed prompt and choose any of the following options:
154
156
-**Looks right** - Select if the results are accurate, based on your assessment.
155
157
-**Needs improvement** - Select if any detail in the results is incorrect or incomplete, based on your assessment.
156
158
-**Inappropriate** - Select if the results contain questionable, ambiguous, or potentially harmful information.
157
159
158
160
For each feedback option, you can provide more information in the next dialog box that appears. Whenever possible, and especially when the result is **Needs improvement**, write a few words explaining what can be done to improve the outcome. If you entered prompts specific to Azure Firewall and the results aren't related, then include that information.
159
161
162
+
:::image type="content" source="media/firewall-copilot/security-copilot-feedback.png" alt-text="Screenshot showing the feedback options in Security Copilot.":::
163
+
164
+
### Via Copilot in Azure
165
+
Use the **like and dislike** buttons at the bottom of each completed prompt. For either feedback option, you can provide more information in the next dialog box that appears. Whenever possible, and especially when you **dislike** a response, write a few words explaining what can be done to improve the outcome. If you entered prompts specific to Azure Firewall and the results aren't related, then include that information.
166
+
167
+
:::image type="content" source="media/firewall-copilot/azure-copilot-feedback.png" alt-text="Screenshot showing the feedback options in Azure Copilot.":::
168
+
160
169
## Privacy and data security in Security Copilot
161
170
162
-
When you interact with Security Copilot to get Azure Firewall data, Copilot pulls that data from Azure Firewall. The prompts, the data retrieved, and the output shown in the prompt results are processed and stored within the Copilot service. For more information, see [Privacy and data security in Microsoft Security Copilot](/copilot/security/privacy-data-security).
171
+
When you interact with Security Copilot (via the Security Copilot portal or via the Copilot in Azure experience) to get Azure Firewall data, Copilot pulls that data from Azure Firewall. The prompts, the data retrieved, and the output shown in the prompt results are processed and stored within the Copilot service. For more information, see [Privacy and data security in Microsoft Security Copilot](/copilot/security/privacy-data-security).
163
172
164
173
## Related content
165
174
166
-
-[What is Microsoft Security Copilot?](/copilot/security/microsoft-security-copilot)
175
+
-[What is Microsoft Security Copilot?](/security-copilot/microsoft-security-copilot)
0 commit comments