Skip to content

Commit 9f32cc5

Browse files
committed
Added what's new, screenshots
1 parent f065633 commit 9f32cc5

File tree

4 files changed

+13
-2
lines changed

4 files changed

+13
-2
lines changed
72.2 KB
Loading
226 KB
Loading

articles/sentinel/sentinel-security-copilot-incident-summary.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,10 @@ Copilot automatically generates an incident summary when you open the incident's
6161

6262
:::image type="content" source="media/sentinel-security-copilot-incident-summary/copilot-sentinel-incident-summary.png" alt-text="Screenshot that shows the Copilot-generated incident summary on the details pane of the Microsoft Sentinel incident page." lightbox="media/sentinel-security-copilot-incident-summary/copilot-sentinel-incident-summary.png":::
6363

64+
Select **Show more** to expand the summary to see its complete content.
65+
66+
:::image type="content" source="media/sentinel-security-copilot-incident-summary/copilot-sentinel-incident-summary-expanded.png" alt-text="Screenshot that shows the expanded incident summary.":::
67+
6468
> [!TIP]
6569
> You can navigate to a file, IP, or URL page from the Copilot results pane by clicking on the evidence in the results.
6670

articles/sentinel/whats-new.md

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,10 +20,17 @@ The listed features were released in the last three months. For information abou
2020

2121
## April 2025
2222

23-
- [Multi workspace and multitenant support for Microsoft Sentinel in the Defender portal (preview)](#multi-workspace-and-multitenant-support-for-microsoft-sentinel-in-the-defender-portal-preview)
23+
- [Security Copilot generates incident summaries in Microsoft Sentinel in the Azure portal (Preview)](#security-copilot-generates-incident-summaries-in-microsoft-sentinel-in-the-azure-portal-preview)
24+
- [Multi workspace and multitenant support for Microsoft Sentinel in the Defender portal (Preview)](#multi-workspace-and-multitenant-support-for-microsoft-sentinel-in-the-defender-portal-preview)
2425
- [Microsoft Sentinel now ingests all STIX objects and indicators into new threat intelligence tables (Preview)](#microsoft-sentinel-now-ingests-all-stix-objects-and-indicators-into-new-threat-intelligence-tables-preview)
2526

26-
### Multi workspace and multitenant support for Microsoft Sentinel in the Defender portal (preview)
27+
### Security Copilot generates incident summaries in Microsoft Sentinel in the Azure portal (Preview)
28+
29+
Microsoft Sentinel in the Azure portal now features (in Preview) incident summaries generated by Security Copilot, bringing it in line with the Defender portal. These summaries give your security analysts the up-front information they need to quickly understand, triage, and start investigating developing incidents.
30+
31+
For more information, see [Summarize Microsoft Sentinel incidents with Security Copilot](sentinel-security-copilot-incident-summary.md).
32+
33+
### Multi workspace and multitenant support for Microsoft Sentinel in the Defender portal (Preview)
2734

2835
For preview, in the Defender portal, connect to one primary workspace and multiple secondary workspaces for Microsoft Sentinel. If you onboard Microsoft Sentinel with Defender XDR, a primary workspace's alerts are correlated with Defender XDR data. So incidents include alerts from Microsoft Sentinel's primary workspace and Defender XDR. All other onboarded workspaces are considered secondary workspaces. Incidents are created based on the workspace’s data and won't include Defender XDR data.
2936

0 commit comments

Comments
 (0)