Skip to content

Commit 895df12

Browse files
committed
insert note for each unit.
1 parent f04ff1e commit 895df12

File tree

6 files changed

+22
-15
lines changed

6 files changed

+22
-15
lines changed

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/1-introduction.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,9 @@ The embedded experience is also a great place to start a security investigation.
88

99
In this module, you learn about the scenarios supported by the embedded experiences of Microsoft Security Copilot.
1010

11+
> [!NOTE]
12+
>This module is intended to give you a flavor of just a few of the Security Copilot embedded experiences. The list of Microsoft Security solutions in which Copilot is embedded is continually growing. For information about Copilot embedded in a given security solutions, refer to training for that specific solution.
13+
1114
After completing this module, you'll be able to:
1215

1316
- Describe Copilot in Microsoft Defender XDR.

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/2-copilot-for-defender.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11

2-
Microsoft Security Copilot is embedded in Microsoft Defender XDR to enable security teams to quickly and efficiently investigate and respond to incidents. Microsoft Copilot for Microsoft Defender XDR supports the following features.
2+
Microsoft Security Copilot is embedded in Microsoft Defender XDR to enable security teams to quickly and efficiently investigate and respond to incidents. Security Copilot capabilities embedded in Microsoft Defender XDR include:
33

44
- Summarize incidents
55
- Guided responses
@@ -9,6 +9,9 @@ Microsoft Security Copilot is embedded in Microsoft Defender XDR to enable secur
99
- Analyze files
1010
- Device summary
1111

12+
> [!NOTE]
13+
>The list of Copilot capabilities embedded in Microsoft Defender XDR is continually growing. This unit provides just a sampling of some of those Copilot capabilities. For more information, see documentation on Microsoft Defender XDR.
14+
1215
There are also some options that are common across all these features, including the ability to provide feedback on prompt responses and seamlessly moving to the standalone experience.
1316

1417
As described in the introduction unit, in the embedded experience Copilot is able to invoke the product specific capabilities directly, providing processing efficiency. That said, to ensure access to these Microsoft Security Copilot features, the Microsoft Defender XDR plugin needs to be enabled and this is done through the standalone experience. To learn more, refer to [Describe the features available in the standalone experience of Microsoft Security Copilot](/training/modules/security-copilot-describe-core-features/2-describe-standalone-experience).

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/3-copilot-for-purview.md

Lines changed: 5 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,9 @@
11
Microsoft Security Copilot is now accessible from within Microsoft Purview data security solutions, as part of the embedded experience. With Copilot in Microsoft Purview, data security and compliance admins can use the power of AI to assess risk exposure more quickly than is otherwise possible, directly from within Microsoft Purview solutions.
22

3-
The scenarios supported as part of the embedded experience are:
3+
> [!NOTE]
4+
>The list of Copilot capabilities embedded in Microsoft Purview is continually growing. This unit provides just a sampling of those capabilities. For more information, see documentation on Microsoft Purview.
5+
6+
Some of the scenarios supported as part of the embedded experience include:
47

58
- Gain comprehensive summary of Data Loss Prevention alerts.
69
- Gain comprehensive summary of Insider Risk Management alerts.
@@ -11,7 +14,7 @@ For all use cases supported through the embedded experience, as is the case with
1114

1215
:::image type="content" source="../media/purview-plugin-requirement-new.png" lightbox="../media/purview-plugin-requirement-new.png" alt-text="Screen capture of the setting to allow Security Copilot to access data from your Microsoft 365 services, which is required to enable the Microsoft Purview plugin.":::
1316

14-
Additionally, users must have the appropriate role permissions for both Copilot and the Purview solutions. For Copilot, users need, at a minimum, the Copilot workspace contributor role or the Entra Security operator role. For Microsoft Purview, as is true for a Microsoft solution enabled via a plugin, Copilot assumes the permissions of the user when it tries to access the data to answer the queries, so you need to have the required permissions to access the data.
17+
Additionally, users must have the appropriate role permissions for both Copilot and the Purview solutions. For Copilot, users need, at a minimum, the Copilot workspace contributor role or the Microsoft Entra Security operator role. For Microsoft Purview, as is true for a Microsoft solution enabled via a plugin, Copilot assumes the permissions of the user when it tries to access the data to answer the queries, so you need to have the required permissions to access the data.
1518

1619
### Gain comprehensive summary of alerts
1720

@@ -97,14 +100,3 @@ For any AI generated content, you can provide feedback and accuracy of the conte
97100

98101
:::image type="content" source="../media/ai-accuracy-feedback-data-loss-prevention-summary.png" lightbox="../media/ai-accuracy-feedback-data-loss-prevention-summary.png" alt-text="Screen capture of the feedback options. The options are: confirmed, it looks great, off target, inaccurate, or potentially harmful, inappropriate.":::
99102

100-
### Limitations of Copilot in Microsoft Purview
101-
102-
The Microsoft Purview use cases supported by Copilot have the following limitations:
103-
104-
- The Copilot capabilities supported by Microsoft Purview eDiscovery are supported only with Microsoft Purview eDiscovery (Premium).
105-
106-
- Copilot activities aren't discoverable in Purview eDiscovery. You can’t search and preserve Copilot activities.
107-
108-
- No audit activities are available for Copilot activities.
109-
110-
- Content summarization length is currently limited 20,000 tokens, which is approximately 15,000 words.

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/4-copilot-for-entra.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,10 @@
11

22
Identity risk investigation is a crucial step to defend an organization. Microsoft Entra ID Protection applies the capabilities of Microsoft Security Copilot to summarize a user's risk level, provide insights relevant to the incident at hand, and provide recommendations for rapid mitigation.
33

4-
Before you get started with Copilot in Microsoft Entra, your organization must be onboarded to Security Copilot, the Entra plugin must be enabled in Copilot, and users must have the appropriate role permissions. Copilot assumes the permissions of the user when it tries to access the data to answer the queries, so you need to have the required permissions to access the Entra data.
4+
> [!NOTE]
5+
>The list of Copilot capabilities embedded in Microsoft Entra is continually growing. This unit provides just a sampling of those capabilities. For more information, see documentation on Microsoft Entra.
6+
7+
Before you get started with Copilot in Microsoft Entra, your organization must be onboarded to Security Copilot, the Microsoft Entra plugin must be enabled in Copilot, and users must have the appropriate role permissions. Copilot assumes the permissions of the user when it tries to access the data to answer the queries, so you need to have the required permissions to access the Microsoft Entra data.
58

69
To view and investigate a user’s risky sign-ins:
710

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/5-copilot-for-intune.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,9 @@ Microsoft Intune has capabilities that are powered by Microsoft Security Copilot
22

33
Access to your Intune data is supported through Microsoft Security Copilot, referred to as the standalone experience, or embedded within the Intune admin center, referred to as Copilot in Intune. This unit focuses on the embedded experience.
44

5+
> [!NOTE]
6+
>The list of Copilot capabilities embedded in Microsoft Intune is continually growing. This unit provides just a sampling of those capabilities. For more information, see documentation on Microsoft Intune.
7+
58
### Before you begin
69

710
To enable Copilot to access your Intune data, for either the embedded or standalone experience, Microsoft Security Copilot must be configured, the Microsoft Intune plugin must be enabled, and you need to have appropriate role permissions. You need a role permission that grants access to Copilot and you also need a separate Intune service-specific role like the Intune Endpoint Security Manager role. There isn't a built-in Intune role that includes access to Copilot.

learn-pr/wwl-sci/security-copilot-embedded-experiences/includes/5a-copilot-for-defender-cloud.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,9 @@ Copilot in Defender for Cloud is available for all users when you:
88

99
Copilot in Defender for Cloud isn't reliant on any of the available plans in Defender. However, in order to enjoy the full range of Copilot's capabilities in Defender for Cloud, we recommend enabling the Defender for Cloud Security Posture Management (DCSPM) plan on your environments. The DCSPM plan includes many extra security features such as Attack path analysis, Risk prioritization and more, all of which can be navigated and managed using Security Copilot. Without the DCSPM plan, you're still able to use Copilot in Defender for Cloud, but in a limited capacity.
1010

11+
> [!NOTE]
12+
>The list of Copilot capabilities embedded in Microsoft Defender for Cloud is continually growing. This unit provides just a sampling of those capabilities. For more information, see documentation on Microsoft Defender for Cloud.
13+
1114
### Analyze recommendations with Security Copilot
1215

1316
Microsoft Defender for Cloud's integration with Security Copilot allows you to analyze all of the recommendations presented on the recommendations page. By narrowing the scope of the recommendations page, you can focus on specific recommendations and get a better understanding of your security posture.

0 commit comments

Comments
 (0)