|
| 1 | +--- |
| 2 | +title: Upload organization-specific guidelines for Microsoft Security Copilot guided response |
| 3 | +description: Learn how to upload your organization's specific guidelines to Microsoft Security Copilot to enhance guided response recommendations. |
| 4 | +ms.service: defender-xdr |
| 5 | +ms.author: guywild |
| 6 | +author: guywi-ms |
| 7 | +ms.localizationpriority: medium |
| 8 | +ms.collection: |
| 9 | + - m365-security |
| 10 | + - tier1 |
| 11 | + - security-copilot |
| 12 | + - magic-ai-copilot |
| 13 | +ms.topic: install-set-up-deploy |
| 14 | +search.appverid: |
| 15 | + - MOE150 |
| 16 | + - MET150 |
| 17 | +ms.date: 11/18/2024 |
| 18 | +appliesto: |
| 19 | +- Microsoft Defender XDR |
| 20 | +- Microsoft Sentinel with Defender XDR in the Microsoft Defender portal |
| 21 | +--- |
| 22 | + |
| 23 | +# Upload organization-specific guidelines for Microsoft Security Copilot guided response |
| 24 | + |
| 25 | +[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)] |
| 26 | + |
| 27 | +[Microsoft Security Copilot](/security-copilot/microsoft-security-copilot) in the Microsoft Defender portal supports incident response teams in immediately resolving incidents with guided responses. Copilot in Defender uses AI and machine learning capabilities to contextualize an incident and learn from previous investigations to generate appropriate response actions. |
| 28 | + |
| 29 | +This guide outlines how to upload your organization's specific guidelines to Microsoft Security Copilot to enhance the relevance and effectiveness of the guided response recommendations. |
| 30 | + |
| 31 | +## Prerequisites |
| 32 | + |
| 33 | +- You must have appropriate permissions to upload files in the Microsoft Defender portal. Typically, this requires being assigned a role such as Security Administrator. |
| 34 | +- Your organization-specific guidelines should be in a supported format (PDF, DOCX, TXT) and should not exceed the maximum file size limit of 3 MB. |
| 35 | + |
| 36 | +## Steps to upload organization-specific guidelines |
| 37 | + |
| 38 | +Upload your guidebook from Copilot settings. You can get there in one of two ways: |
| 39 | + |
| 40 | +- From the Microsoft Defender portal, select **System** > **Settings** > **Copilot in Defender** > **Custom guidebooks**. |
| 41 | + |
| 42 | + :::image type="content" source="./media/security-upload-guide/add-from-settings.png" alt-text="Screenshot of adding custom guidebooks from settings."::: |
| 43 | + |
| 44 | +- From the Copilot tasks pane inside an incident, go to **Create tasks from your own guidebook** and select **Open Copilot settings**. |
| 45 | + |
| 46 | + :::image type="content" source="./media/security-upload-guide/add-from-incident.png" alt-text="Screenshot of opening Copilot settings from the tasks pane."::: |
| 47 | + |
| 48 | +Then follow these steps: |
| 49 | + |
| 50 | +1. Select **Add new guidebook**. |
| 51 | +1. Select **Upload file**. |
| 52 | +1. Browse to the file location, choose the file, and then select **Generate**. |
| 53 | +1. After the file is uploaded, go to the **Pending review** tab. |
| 54 | + |
| 55 | + :::image type="content" source="{source}" alt-text="{alt-text}"::: |
| 56 | + |
| 57 | +1. The pending review tab shows the new recommendations based on the uploaded guidebook. Review the file to ensure it meets your organization's standards. Select the guidebook name and review the suggested generated tasks. |
| 58 | + |
| 59 | + |
| 60 | + :::image type="content" source="./media/security-upload-guide/pending-review.png" alt-text="Screenshot of the pending review tab for uploaded guidebooks."::: |
| 61 | + |
| 62 | +1. If the guidebook meets your standards, select **Approve and activate** to make it available for use in guided responses. If it does not meet your standards, select **Delete** to remove it. |
| 63 | + |
| 64 | + :::image type="content" source="./media/security-upload-guide/approve-guidebook.png" alt-text="Screenshot of the approve and activate button for uploaded guidebooks."::: |
| 65 | + |
| 66 | +Copilot uses the most relevant guidance it has for each incident. A banner shows which guidebook is being used for the current recommendation. |
| 67 | + |
| 68 | +## Considerations and limitations |
| 69 | + |
| 70 | +- You must be at least a security administrator to upload, approve or delete files. Security operators can review the guidebooks but not manage them. |
| 71 | +- |
0 commit comments