Skip to content

Commit 645ae1f

Browse files
committed
updated text
1 parent d9eb0ea commit 645ae1f

File tree

2 files changed

+6
-16
lines changed

2 files changed

+6
-16
lines changed

defender-xdr/phishing-triage-agent.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection:
1414
- tier1
1515
- security-copilot
1616
- magic-ai-copilot
17-
ms.topic: how-to
17+
ms.topic: concept-article
1818
search.appverid:
1919
- MOE150
2020
- MET150
@@ -36,9 +36,9 @@ Phishing remains one of the most common ways attackers gain initial access. It a
3636

3737
To help security teams address phishing efficiently, Microsoft Security Copilot is introducing the Phishing Triage Agent in Microsoft Defender. This AI-powered virtual agent is designed to scale security teams' response in triaging and classifying user-submitted phishing incidents, allowing organizations to improve their efficiency by reducing manual effort and streamlining their phishing response.
3838

39-
The Phishing Triage Agent uses advanced large language model (LLM)-based analysis to understand the content of reported emails and autonomously determine whether a submission is a genuine phishing attempt or a false alarm. Unlike rule-based systems, it does not rely on predefined input or code to operate. Instead, it applies dynamic reasoning to analyze and act on incoming reports at scale.
39+
The Phishing Triage Agent uses advanced large language model (LLM)-based analysis to understand the content of reported emails and autonomously determine whether a submission is a genuine phishing attempt or a false alarm. Unlike rule-based systems, it doesn't rely on predefined input or code to operate. Instead, it applies dynamic reasoning to analyze and act on incoming reports at scale.
4040

41-
By removing false positives from the queue, the agent significantly reduces the team's manual workload and allows them to focus on higher-priority tasks. With this automation, security teams can more efficiently process hundreds or thousands of phishing submissions, accelerating detection and response for incidents that require immediate attention
41+
By removing false alarms from the queue, the agent significantly reduces the team's manual workload and allows them to focus on higher-priority tasks. With this automation, security teams can more efficiently process hundreds or thousands of phishing submissions, accelerating detection and response for incidents that require immediate attention.
4242

4343
## Overview
4444

defender-xdr/security-copilot-agents-defender.md

Lines changed: 3 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -33,30 +33,20 @@ Microsoft Security Copilot agents are available in Microsoft Defender to help yo
3333

3434
## Agents in Microsoft Defender
3535

36-
> [!IMPORTANT]
37-
> Some information in this article relates to a prereleased product, which may be substantially modified before it's commercially released. Microsoft makes no warranties expressed or implied, with respect to the information provided here.
38-
3936
### Phishing Triage Agent
4037

4138
The [Phishing Triage Agent](phishing-triage-agent.md) helps security operations analysts to triage and classify user-submitted phishing incidents. The agent operates autonomously, provides a transparent rationale for its classification verdicts in natural language, and continuously learns and improves its accuracy based on feedback provided by analysts.
4239

4340
#### Trigger
4441

45-
The agent is triggered when a user in your organization submits a phishing incident. The agent automatically analyzes the submitted email to classify them as either phishing or not phishing based on its training and the context of the organization.
46-
47-
#### Role-based access
48-
49-
A Security Administrator role is required to setup and manage the agent. Users with the same permissions as the agent can view the agent's output.
50-
51-
#### Identity
52-
53-
The agent runs in the context of the identity you associate with it. The agent uses the identity to access the data it needs to perform its tasks.
42+
The agent is triggered when a user in your organization submits a phishing incident. The agent autonomously analyzes the submitted email to classify them as either phishing or not phishing based on its training and the context of the organization.
5443

5544
#### Products
5645

5746
Tenants must have the following products enabled to use the agent:
5847

59-
- Microsoft Defender for Office 365 Plan 2
48+
- An active subscription to Security Copilot and provisioned capacity in Security Compute Units (SCU) to power Security Copilot workload. See [Get started with Security Copilot](/copilot/security/get-started-security-copilot) for more information.
49+
- Microsoft Defender for Office 365 Plan 2 deployed
6050

6151
#### Plugins
6252

0 commit comments

Comments
 (0)