Skip to content

Commit e925481

Browse files
authored
Merge pull request #271738 from ElazarK/wi236734-copilot-in-mdc
copilot RSA
2 parents 89a1fb7 + 27f1725 commit e925481

21 files changed

+388
-3
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -263,6 +263,9 @@
263263
- name: AI security posture management (Preview)
264264
displayName: AI, security, posture, management
265265
href: ai-security-posture.md
266+
- name: Copilot for Security in Defender for Cloud
267+
displayName: copilot, security, recommendations
268+
href: copilot-security-in-defender-for-cloud.md
266269
- name: Security recommendations
267270
items:
268271
- name: Reference list of Azure recommendations
@@ -354,6 +357,23 @@
354357
href: remediate-server-secrets.md
355358
- name: Remediate cloud deployment secrets
356359
href: remediate-cloud-deployment-secrets.md
360+
- name: Improve security posture with Copilot for Security
361+
items:
362+
- name: Analyze recommendations with Copilot for Security
363+
displayName: copilot, security, recommendations, analyze
364+
href: analyze-with-copilot.md
365+
- name: Summarize recommendations with Copilot for Security
366+
displayName: copilot, security, recommendations, summarize
367+
href: summarize-with-copilot.md
368+
- name: Remediate recommendations with Copilot for Security
369+
displayName: copilot, security, recommendations, remediate
370+
href: remediate-with-copilot.md
371+
- name: Delegate recommendations with Copilot for Security
372+
displayName: copilot, security, recommendations, delegate
373+
href: delegate-with-copilot.md
374+
- name: Remediate code with Copilot for Security
375+
displayName: copilot, security, recommendations, code, remediate, iac, infrastructure as code
376+
href: remediate-code-with-copilot.md
357377
- name: Manage security standards and recommendations
358378
items:
359379
- name: Choose standards for your compliance dashboard
Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
---
2+
title: Analyze recommendations with Copilot for Security
3+
author: Elazark
4+
ms.author: elkrieger
5+
description: Learn how to analyze recommendations with Copilot in Microsoft Defender for Cloud and improve your security posture.
6+
ms.topic: how-to
7+
ms.date: 06/10/2024
8+
#customer intent: As a security professional, I want to understand how to use Copilot to analyze recommendations in Defender for Cloud so that I can improve my security posture.
9+
---
10+
11+
# Analyze recommendations with Copilot for Security
12+
13+
Microsoft Defender for Cloud's integration with Microsoft Copilot for Security allows you to analyze all of the recommendations presented on the recommendations page. By narrowing the scope of the recommendations page, you can focus on specific recommendations and get a better understanding of your security posture.
14+
15+
Once the list of recommendations is filtered, you can investigate specific recommendations and gain a better understanding of the risks and vulnerabilities that are present in your environment.
16+
17+
## Prerequisites
18+
19+
- [Enable Defender for Cloud on your environment](connect-azure-subscription.md).
20+
21+
- [Have access to Azure Copilot](../copilot/overview.md).
22+
23+
- [Have Security Compute Units assigned for Copilot for Security](/copilot/security/get-started-security-copilot).
24+
25+
## Analyze a recommendation
26+
27+
Copilot for Security gives you the ability to analyze your recommendations. Through the use of prompts, you can filter and refine the presented recommendations to focus on specific areas of interest.
28+
29+
1. Sign in to the [Azure portal](https://portal.azure.com).
30+
31+
1. Search for and select **Microsoft Defender for Cloud**.
32+
33+
1. Navigate to **Recommendations**.
34+
35+
1. Select **Analyze with Copilot**.
36+
37+
:::image type="content" source="media/analyze-with-copilot/analyze-with-copilot.png" alt-text="Screenshot of the recommendations page that shows where the Analyze with Copilot button is located." lightbox="media/analyze-with-copilot/analyze-with-copilot.png":::
38+
39+
1. Select one of the suggested prompts or enter a prompt in natural language.
40+
41+
Some sample prompts include:
42+
43+
- Show risks for publicly exposed resources
44+
- Show risks for resources with sensitive data
45+
- Show risks for critical resources
46+
- Show risk to data
47+
48+
1. Review the provided answer.
49+
50+
1. (Optional) You can select a suggested prompt or enter a unique prompt to further refine the results.
51+
52+
1. Select **Apply filter** to view the updated recommendations.
53+
54+
:::image type="content" source="media/analyze-with-copilot/show-results-copilot.png" alt-text="Screenshot that shows where the Apply filter button is located in the Copilot window." lightbox="media/analyze-with-copilot/show-results-copilot.png":::
55+
56+
The recommendations page updates with the appropriate filters applied based on the prompt you provided. Copilot remains open and you can enter other prompts as needed.
57+
58+
## Next step
59+
60+
> [!div class="nextstepaction"]
61+
> [Summarize recommendations with Copilot for Security](summarize-with-copilot.md)
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
---
2+
title: Copilot for Security in Defender for Cloud (Preview)
3+
description: Learn about the benefits of copilot in Microsoft Defender for Cloud and how it applies to analyzing your security posture.
4+
ms.date: 06/10/2024
5+
author: dcurwin
6+
ms.author: dacurwin
7+
ms.topic: concept-article
8+
# customer intent: As a security professional, I want to understand the benefits of Copilot in Microsoft Defender for Cloud and how it can help me analyze my security posture.
9+
---
10+
11+
# Copilot for Security in Defender for Cloud (Preview)
12+
13+
Microsoft Copilot for Security is a cloud-based AI platform that provides natural language copilot experience. It can help support security professionals to understand the context of a recommendation, the effect of implementing a recommendation, assist with remediating or delegating a recommendation, and assist with the remediation of misconfigurations in code. For more information about what it can do, go to [What is Microsoft Copilot for Security?](/copilot/security/microsoft-security-copilot)
14+
15+
**Copilot for Security integrates with Microsoft Defender for Cloud**
16+
17+
Microsoft Defender for Cloud's integration with Copilot for Security on the recommendations page, allows users to comprehend the security posture of connected environments and aids users in their ability to grasp the reason for the recommendation and facilitate the remediation process of those recommendations.
18+
19+
## How Copilot works in Defender for Cloud
20+
21+
Defender for Cloud has integrated Copilot directly in to the Defender for Cloud experience. This integration allows you to analyze, summarize, remediate, and delegate your recommendations with natural language prompts
22+
23+
:::image type="content" source="media/copilot-security-in-defender-for-cloud/analyze-copilot.png" alt-text="Screenshot that shows where the Analyze with copilot button located on the recommendations page." lightbox="media/copilot-security-in-defender-for-cloud/analyze-copilot.png":::
24+
25+
When you open Copilot, you can use natural language prompts to ask questions about the recommendations. Copilot provides you with a response in natural language that helps you understand the context of the recommendation, the effect of implementing the recommendation, and the steps to take to implement the recommendation.
26+
27+
Some sample prompts include:
28+
29+
- Show critical risks for publicly exposed resources
30+
- Show critical risks to sensitive data
31+
- Show resources with high severity vulnerabilities
32+
33+
Copilot can also assist with each recommendation and can refine your recommendations, provide a summary of individual recommendations, remediation steps for recommendations, and allow you to delegate recommendations.
34+
35+
:::image type="content" source="media/copilot-security-in-defender-for-cloud/summarize-copilot.png" alt-text="Screenshot of a recommendation that shows where the Summarize with Copilot button is located." lightbox="media/copilot-security-in-defender-for-cloud/summarize-copilot.png":::
36+
37+
## Copilot's capabilities in Defender for Cloud
38+
39+
Copilot for Security in Defender for Cloud isn't reliant on any of the available plans in Defender for Cloud and is available for all users when you:
40+
41+
1. [Enable Defender for Cloud on your environment](connect-azure-subscription.md).
42+
1. [Have access to Azure Copilot](../copilot/overview.md).
43+
1. [Have Security Compute Units assigned for Copilot for Security](/copilot/security/get-started-security-copilot).
44+
45+
However, in order to enjoy the full range of Copilot for Security's capabilities in Defender for Cloud, we recommend enabling the [Defender for Cloud Security Posture Management (DCSPM) plan](concept-cloud-security-posture-management.md#cspm-features) on your environments. The DCSPM plan includes many extra security features such as [Attack path analysis](how-to-manage-attack-path.md), [Risk prioritization](risk-prioritization.md) and more, all of which can be navigated and managed using Copilot for Security. Without the DCSPM plan, you're still able to use Copilot for Security in Defender for Cloud, but in a limited capacity.
46+
47+
## Monitor your usage
48+
49+
Copilot for Security has a usage limit. When the usage in your organization is nearing its limit, you're notified when you submit a prompt. To avoid a disruption of service, you need to contact the Azure capacity owner or contributor to increase the Security Compute Units (SCU) or limit the number of prompts.
50+
51+
Learn more about [usage limits](/copilot/security/manage-usage).
52+
53+
## Related content
54+
55+
- [Analyze recommendations with Copilot for Security](analyze-with-copilot.md)
56+
- [Summarize recommendations with Copilot for Security](summarize-with-copilot.md)
57+
- [Remediate recommendations with Copilot for Security](remediate-with-copilot.md)
58+
- [Delegate recommendations with Copilot for Security](delegate-with-copilot.md)
59+
- [Remediate code with Copilot for Security](remediate-code-with-copilot.md)
Lines changed: 58 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,58 @@
1+
---
2+
title: Delegate recommendations with Copilot for Security
3+
author: Elazark
4+
ms.author: elkrieger
5+
description: Learn how to delegate recommendations with Copilot in Microsoft Defender for Cloud and improve your security posture.
6+
ms.topic: how-to
7+
ms.date: 06/10/2024
8+
#customer intent: As a security professional, I want to understand how to use Copilot to delegate recommendations in Defender for Cloud so that I can improve my security posture.
9+
---
10+
11+
# Delegate recommendations with Copilot for Security
12+
13+
Microsoft Defender for Cloud's integration with Microsoft Copilot for Security allows you to delegate recommendations that are present on the recommendations page with natural language prompts. Recommendations can be delegated to another person or team.
14+
15+
Delegating recommendations can improve your security posture by having the right people address the risks and vulnerabilities presented by the recommendations that are present in your environment.
16+
17+
## Prerequisites
18+
19+
- [Enable Defender for Cloud on your environment](connect-azure-subscription.md).
20+
21+
- [Have access to Azure Copilot](../copilot/overview.md).
22+
23+
- [Have Security Compute Units assigned for Copilot for Security](/copilot/security/get-started-security-copilot).
24+
25+
## Delegate a recommendation
26+
27+
You can use Copilot to delegate recommendations to ensure the right person or team is handling the risks and vulnerabilities that are present in your environment.
28+
29+
1. Sign in to the [Azure portal](https://portal.azure.com).
30+
31+
1. Search for and select **Microsoft Defender for Cloud**.
32+
33+
1. Navigate to **Recommendations**.
34+
35+
1. Select a recommendation.
36+
37+
1. Select **Summarize with Copilot**.
38+
39+
1. Review the summary.
40+
41+
1. Select **Delegate the remediation to the resource owner**.
42+
43+
:::image type="content" source="media/delegate-with-copilot/delegate-recommendation.png" alt-text="Screenshot that shows where the Delegate the recommendation prompt is located." lightbox="media/delegate-with-copilot/delegate-recommendation.png":::
44+
45+
1. Review the result.
46+
47+
1. Select **here** to send an email to your colleague.
48+
49+
1. Review the email and add recipients.
50+
51+
1. Select **Send**.
52+
53+
Once the recommendation is delegated, you can monitor the progress of the remediation on Defender for Cloud's recommendations page. Copilot remains open and you can enter other prompts as needed.
54+
55+
## Next step
56+
57+
> [!div class="nextstepaction"]
58+
> [Remediate code with Copilot for Security](remediate-code-with-copilot.md)
298 KB
Loading
52.3 KB
Loading
299 KB
Loading
86.1 KB
Loading
158 KB
Loading
323 KB
Loading

0 commit comments

Comments
 (0)