Skip to content

Commit 4aa3cf9

Browse files
committed
Update phishing-triage-agent.md
1 parent 4f7e662 commit 4aa3cf9

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

defender-xdr/phishing-triage-agent.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -413,6 +413,28 @@ Administrators configure the agent’s identity and access levels during install
413413

414414
The Phishing Triage Agent operates within a zero-trust environment. The system enforces organizational policies on every agent action by evaluating the intent and scope of each operation. All decisions, reasoning, and actions taken by the agent are transparently documented as a decision tree within Defender and recorded in Microsoft Purview audit logs for traceability and compliance.
415415

416+
417+
### I want to try the Phishing Triage Agent - how do I set it up in Microsoft Defender?
418+
419+
To try the agent, you must first have access to **Security Copilot in Microsoft Defender**. If you don’t yet have Security Copilot, see [Get started with Security Copilot](/security-copilot/get-started-security-copilot) or contact your Microsoft representative.
420+
421+
After you enable Security Copilot, the agent setup option appears in the Microsoft Defender portal if your environment meets the necessary [prerequisites](#prerequisites). For more information on initiating see [setup documentation](#set-up-the-phishing-triage-agent):
422+
423+
424+
### I've tried the Phishing Triage Agent - how can I estimate the SCU capacity needed for the agent in my organization?**
425+
426+
If you've been using the trial, when your offer ends, the agent automatically starts to consume SCUs provisioned for the workspace in which it's deployed.
427+
428+
To evaluate SCU usage and plan capacity, see the [Usage monitoring dashboard in the Security Copilot portal](https://securitycopilot.microsoft.com/usage-monitoring). The dashboard shows:
429+
430+
- **Cost per email processed**
431+
- **Capacity consumption over time**
432+
433+
Ensure your organization has sufficient SCUs for healthy agent operation. For guidance, see [Get started with Security Copilot](/security-copilot/get-started-security-copilot) or contact your Microsoft representative.
434+
435+
If the agent is already running and you have sufficient capacity in your organization, no further action is required and the agent will keep running. If you choose to discontinue use, follow the [offboarding steps](#remove-the-agent) in the documentation.
436+
437+
416438
## Related content
417439

418440
- [Microsoft Security Copilot agents](/copilot/security/agents-overview)

0 commit comments

Comments
 (0)