Easm Copilot
In brief
The page now uses clearer bold headings and expanded descriptions for attack-surface snapshots, risk and CVE prioritization, Security Copilot insights, and attack-surface curation. Image markup was also updated, and several example prompt rows were removed.
What Defender admins need to know
Administrators get a more scannable reference when using Defender EASM with Security Copilot; no configuration change is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
The EASM Security Copilot integration can help you:
Get a snapshot of your external attack surface and generate insights into potential
risks.risks: You can get a quick view of your external attack surface by analyzing internet-available information combined with the Defender EASM proprietary discovery algorithm. It provides an easy-to-understand natural language explanation of the organization's externally facing assets, such as hosts, domains, webpages, and IP addresses. It highlights the critical risks associated with each.
Prioritize remediation efforts based on asset risk and Common Vulnerabilities and Exposures (CVEs) list
items.items: Defender EASM helps security teams prioritize their remediation efforts by helping them understand which assets and CVEs pose the greatest risk in their environment. It analyzes vulnerability and infrastructure data to showcase key areas of concern, providing a natural language explanation of the risks and recommended actions.
Use Security Copilot to surface
insights.insights: You can use Security Copilot to ask about insights by using natural language and extract insights from Defender EASM about your organization's attack surface. Query details like the number of Secure Sockets Layer (SSL) certificates that aren't secure, ports that are detected, and specific vulnerabilities that affect the attack surface.
Expedite attack surface
curation.curation: Use Security Copilot to curate your attack surface by using labels, external IDs, and state modifications for a set of assets. This process speeds up curation, so you can organize your inventory faster and more efficiently.
Enable Security Copilot integration
Access Security Copilot and ensure that you're authenticated.
Select the Security Copilot plugin icon on the upper-right side of the prompt input bar.
:::image type="content" source="media/copilot-2.png" alt-text="Screenshot of the Security Copilot plugin icon.":::
Under Microsoft, locate Defender External Attack Surface Management. Select On to connect.
:::image type="content" source="media/copilot-4.png" alt-text="Screenshot of Defender EASM activated in Security Copilot.":::
If you want Security Copilot to pull data from your Defender EASM resource, select the gear icon to open the plugin settings. Enter or select values by using the values from your resource's Essentials section on the Overview pane.
:::image type="content" source="media/copilot-6.png" alt-text="Screenshot of the Defender EASM fields that must be configured in Security Copilot." lightbox="media/copilot-6.png":::
| Capability | Description | Inputs | Behaviors |
|---|---|---|---|
| Get attack surface summary | Returns the attack surface summary for either the customer’s Defender EASM resource or a specific company name. | Example inputs: Optional inputs: CompanyName |
If your plugin is configured to an active Defender EASM resource and no other company is specified: If another company name is provided: |
| Get attack surface insights | Returns the attack surface insights for either the customer’s Defender EASM resource or a specific company name. | Example inputs: Required inputs: PriorityLevel (the priority level must be high, medium, or low; if not provided, it defaults to high) Optional inputs: CompanyName (the company name) |
If your plugin is configured to an active Defender EASM resource and no other company is specified: If another company name is provided: |
| Get assets affected by a CVE | Returns the assets affected by a CVE for either the customer's Defender EASM resource or a specific company name. | Example inputs: Required inputs: CveId Optional inputs: CompanyName |
If your plugin is configured to an active Defender EASM resource and no other company is specified: If another company name is provided: |
| Get assets affected by a CVSS | Returns the assets affected by a Common Vulnerability Scoring System (CVSS) score for either the customer’s Defender EASM resource or a specific company name. | Example inputs: Required inputs: CvssPriority (the CVSS priority must be critical, high, medium, or low) Optional inputs: CompanyName |
If your plugin is configured to an active Defender EASM resource and no other company is specified: If another company name is provided: |
| Get expired domains | Returns the number of expired domains for either the customer’s Defender EASM resource or a specific company name. | Example inputs: Optional inputs: CompanyName |
If your plugin is configured to an active Defender EASM resource and no other company is specified: If another company name is provided: |
| Get expired certificates | Returns the number of expired SSL certificates for either the customer’s Defender EASM resource or a specific company name. | Example inputs: Optional inputs: CompanyName |
If your plugin is configured to an active Defender EASM resource and no other company is specified: If another company name is provided: |
| Get SHA1 certificates | Returns the number of SHA1 SSL certificates for either the customer’s Defender EASM resource or a specific company name. | Example inputs: Optional inputs: CompanyName |
If your plugin is configured to an active Defender EASM resource and no other company is specified: If another company name is provided: |
| Translate natural language to a Defender EASM query | Translates any natural language question into a Defender EASM query and returns the assets that match the query. | Example inputs: <[email protected]>? |
If your plugin is configured to an active Defender EASM resource: |
Switch between resource data and company data
Even though we added resource integration for our skills, we still support pulling data from prebuilt attack surfaces for specific companies. To improve the Security Copilot accuracy in determining when a customer wants to pull from their attack surface or from a prebuilt, company attack surface, we recommend using my, my attack surface, and so on, to convey that you want to use your resource. Use their, specific company name, and so on,on to convey that you want to use a prebuilt attack surface. Although this approach does improveimproves the experience in a single session, we strongly recommend using two separate sessions to avoid any confusion.
Provide feedback
Your feedback on Security Copilot generally, and the Defender EASM plugin specifically, is vital to guide current and planned development of the product. The optimal way to provide this feedback is directly in the product, using the feedback buttons at the bottom of each completed prompt. Select Looks right, Needs improvement, or Inappropriate. We recommend that you choose Looks right when the result matches expectations, Needs improvement when it doesn't, and Inappropriate when the result is harmful in some way.
Whenever possible, and especially when the result you select is Needs improvement, please write a few words to explain what we can do to improve the outcome. This request also applies when you expect Security Copilot to invoke the Defender EASM plugin, but a different plugin is engaged instead.
Related content
@@ -41,21 +41,13 @@ This article introduces you to Security Copilot and includes sample prompts that The EASM Security Copilot integration can help you: -- Get a snapshot of your external attack surface and generate insights into potential risks.+- **Get a snapshot of your external attack surface and generate insights into potential risks**: You can get a quick view of your external attack surface by analyzing internet-available information combined with the Defender EASM proprietary discovery algorithm. It provides an easy-to-understand natural language explanation of the organization's externally facing assets, such as hosts, domains, webpages, and IP addresses. It highlights the critical risks associated with each. - You can get a quick view of your external attack surface by analyzing internet-available information combined with the Defender EASM proprietary discovery algorithm. It provides an easy-to-understand natural language explanation of the organization's externally facing assets, such as hosts, domains, webpages, and IP addresses. It highlights the critical risks associated with each.+- **Prioritize remediation efforts based on asset risk and Common Vulnerabilities and Exposures (CVEs) list items**: Defender EASM helps security teams prioritize their remediation efforts by helping them understand which assets and CVEs pose the greatest risk in their environment. It analyzes vulnerability and infrastructure data to showcase key areas of concern, providing a natural language explanation of the risks and recommended actions. -- Prioritize remediation efforts based on asset risk and Common Vulnerabilities and Exposures (CVEs) list items.+- **Use Security Copilot to surface insights**: You can use Security Copilot to ask about insights by using natural language and extract insights from Defender EASM about your organization's attack surface. Query details like the number of Secure Sockets Layer (SSL) certificates that aren't secure, ports that are detected, and specific vulnerabilities that affect the attack surface. - Defender EASM helps security teams prioritize their remediation efforts by helping them understand which assets and CVEs pose the greatest risk in their environment. It analyzes vulnerability and infrastructure data to showcase key areas of concern, providing a natural language explanation of the risks and recommended actions.--- Use Security Copilot to surface insights.-- You can use Security Copilot to ask about insights by using natural language and extract insights from Defender EASM about your organization's attack surface. Query details like the number of Secure Sockets Layer (SSL) certificates that aren't secure, ports that are detected, and specific vulnerabilities that affect the attack surface.--- Expedite attack surface curation.-- Use Security Copilot to curate your attack surface by using labels, external IDs, and state modifications for a set of assets. This process speeds up curation, so you can organize your inventory faster and more efficiently.+- **Expedite attack surface curation**: Use Security Copilot to curate your attack surface by using labels, external IDs, and state modifications for a set of assets. This process speeds up curation, so you can organize your inventory faster and more efficiently. ## Enable Security Copilot integration @@ -73,15 +65,15 @@ To enable integration, you need to have these prerequisites: 1. Access [Security Copilot](https://securitycopilot.microsoft.com/) and ensure that you're authenticated. 1. Select the **Security Copilot plugin** icon on the upper-right side of the prompt input bar. - + :::image type="content" source="media/copilot-2.png" alt-text="Screenshot of the Security Copilot plugin icon."::: 1. Under **Microsoft**, locate **Defender External Attack Surface Management**. Select **On** to connect. - + :::image type="content" source="media/copilot-4.png" alt-text="Screenshot of Defender EASM activated in Security Copilot."::: 1. If you want Security Copilot to pull data from your Defender EASM resource, select the gear icon to open the plugin settings. Enter or select values by using the values from your resource's **Essentials** section on the **Overview** pane. - [](media/copilot-6.png#lightbox)+ :::image type="content" source="media/copilot-6.png" alt-text="Screenshot of the Defender EASM fields that must be configured in Security Copilot." lightbox="media/copilot-6.png"::: > [!NOTE] > You can use your Defender EASM skills even if you haven't purchased Defender EASM. For more information, see [Plugin capabilities reference](#plugin-capabilities-reference).@@ -113,22 +105,22 @@ For more information on writing Security Copilot prompts, see [Security Copilot | Capability | Description | Inputs | Behaviors | | ----------------- | ------------------------------- | --------------------- | -------------------------------------- |-| **Get attack surface summary** | Returns the attack surface summary for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> • Get attack surface for LinkedIn. <br> • Get my attack surface. <br> • What is the attack surface for Microsoft? <br> • What is my attack surface? <br> • What are the externally facing assets for Azure? <br> • What are my externally facing assets? <br> <br> **Optional inputs**: <br> • `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> • Returns an attack surface summary for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> • If no exact for match for company name is found, returns a list of possible matches. <br> • If there's an exact match, returns the attack surface summary for the company name. |-| **Get attack surface insights** | Returns the attack surface insights for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> • Get high-priority attack surface insights for LinkedIn. <br> • Get my high-priority attack surface insights. <br> • Get low priority attack surface insights for Microsoft. <br> • Get low priority attack surface insights. <br> • Do I have high-priority vulnerabilities in my external attack surface for Azure? <br><br> **Required inputs**: <br> • `PriorityLevel` (the priority level must be high, medium, or low; if not provided, it defaults to high) <br><br>**Optional inputs**: <br> • `CompanyName` (the company name) | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> • Returns attack surface insights for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> • If no exact for match for company name is found, returns a list of possible matches. <br> • If there's an exact match, returns the attack surface insights for the company name. |-| **Get assets affected by a CVE** | Returns the assets affected by a CVE for either the customer's Defender EASM resource or a specific company name. | **Example inputs**: <br><br> • Get assets affected by CVE-2023-0012 for LinkedIn. <br> • Which assets are affected by CVE-2023-0012 for Microsoft? <br> • Is Azure's external attack surface impacted by CVE-2023-0012? <br> • Get assets affected by CVE-2023-0012 for my attack surface. <br> • Which of my assets are affected by CVE-2023-0012? <br> • Is my external attack surface impacted by CVE-2023-0012? <br><br>**Required inputs**: <br> • `CveId` <br><br> **Optional inputs**: <br> • `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> • If plugin settings aren't filled out, fail graciously and remind customers. <br> • If plugin settings are filled out, returns the assets affected by a CVE for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> • If no exact for match for company name is found, returns a list of possible matches. <br> • If there's an exact match, returns the assets affected by a CVE for the specific company name. |-| **Get assets affected by a CVSS** | Returns the assets affected by a Common Vulnerability Scoring System (CVSS) score for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> • Get assets affected by high-priority CVSS scores in LinkedIn’s attack surface. <br> • How many assets have critical CVSS score for Microsoft? <br> • Which assets have critical CVSS scores for Azure? <br> • Get assets affected by high-priority CVSS scores in my attack surface. <br> • How many of my assets have critical CVSS scores? <br> • Which of my assets have critical CVSS scores? <br><br> **Required inputs**: <br> • `CvssPriority` (the CVSS priority must be *critical*, *high*, *medium*, or *low*) <br><br> **Optional inputs**: <br> • `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> • If plugin settings aren't filled out, fail graciously and remind customers. <br> • If plugin settings are filled out, returns the assets affected by a CVSS score for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> • If no exact for match for company name is found, returns a list of possible matches. <br> • If there's an exact match, returns the assets affected by a CVSS score for the specific company name. |-| **Get expired domains** | Returns the number of expired domains for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> • How many domains are expired in LinkedIn’s attack surface? <br> • How many assets are using expired domains for Microsoft? <br> • How many domains are expired in my attack surface? <br> • How many of my assets are using expired domains for Microsoft? <br><br> **Optional inputs**: <br> • `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> • Returns the number of expired domains for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> • If no exact for match for company name is found, returns a list of possible matches. <br> • If there's an exact match, returns the number of expired domains for the specific company name. |-| **Get expired certificates** | Returns the number of expired SSL certificates for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> • How many SSL certificates are expired for LinkedIn? <br> • How many assets are using expired SSL certificates for Microsoft? <br> • How many SSL certificates are expired for my attack surface? <br> • What are my expired SSL certificates? <br><br> **Optional inputs**: <br> • `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> • Returns the number of SSL certificates for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> • If no exact for match for company name is found, returns a list of possible matches. <br> • If there's an exact match, returns the number of SSL certificates for the specific company name. |-| **Get SHA1 certificates** | Returns the number of SHA1 SSL certificates for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> • How many SSL SHA1 certificates are present for LinkedIn? <br> • How many assets are using SSL SHA1 for Microsoft? <br> • How many SSL SHA1 certificates are present for my attack surface? <br> • How many of my assets are using SSL SHA1? <br><br> **Optional inputs**: <br> • `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> • Returns the number of SHA1 SSL certificates for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> • If no exact for match for company name is found, returns a list of possible matches. <br> • If there's an exact match, returns the number of SHA1 SSL certificates for the specific company name. |-| **Translate natural language to a Defender EASM query** | Translates any natural language question into a Defender EASM query and returns the assets that match the query. | **Example inputs**: <br> • What assets are using jQuery version 3.1.0? <br> • Get the hosts with port 80 open in my attack surface. <br> • Find all the page, host, and ASN assets in my inventory that have an IP address that is IP *X*, IP *Y*, or IP *Z*. <br> • Which of my assets have a registrant email of `<[email protected]>`? | If your plugin is configured to an active Defender EASM resource: <br> • Returns the assets matching with the translated query. |+| **Get attack surface summary** | Returns the attack surface summary for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> - Get attack surface for LinkedIn. <br> - Get my attack surface. <br> - What is the attack surface for Microsoft? <br> - What is my attack surface? <br> - What are the externally facing assets for Azure? <br> - What are my externally facing assets? <br> <br> **Optional inputs**: <br> - `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> - Returns an attack surface summary for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> - If no exact for match for company name is found, returns a list of possible matches. <br> - If there's an exact match, returns the attack surface summary for the company name. |+| **Get attack surface insights** | Returns the attack surface insights for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> - Get high-priority attack surface insights for LinkedIn. <br> - Get my high-priority attack surface insights. <br> - Get low priority attack surface insights for Microsoft. <br> - Get low priority attack surface insights. <br> - Do I have high-priority vulnerabilities in my external attack surface for Azure? <br><br> **Required inputs**: <br> - `PriorityLevel` (the priority level must be high, medium, or low; if not provided, it defaults to high) <br><br>**Optional inputs**: <br> - `CompanyName` (the company name) | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> - Returns attack surface insights for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> - If no exact for match for company name is found, returns a list of possible matches. <br> - If there's an exact match, returns the attack surface insights for the company name. |+| **Get assets affected by a CVE** | Returns the assets affected by a CVE for either the customer's Defender EASM resource or a specific company name. | **Example inputs**: <br><br> - Get assets affected by CVE-2023-0012 for LinkedIn. <br> - Which assets are affected by CVE-2023-0012 for Microsoft? <br> - Is Azure's external attack surface impacted by CVE-2023-0012? <br> - Get assets affected by CVE-2023-0012 for my attack surface. <br> - Which of my assets are affected by CVE-2023-0012? <br> - Is my external attack surface impacted by CVE-2023-0012? <br><br>**Required inputs**: <br> - `CveId` <br><br> **Optional inputs**: <br> - `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> - If plugin settings aren't filled out, fail graciously and remind customers. <br> - If plugin settings are filled out, returns the assets affected by a CVE for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> - If no exact for match for company name is found, returns a list of possible matches. <br> - If there's an exact match, returns the assets affected by a CVE for the specific company name. |+| **Get assets affected by a CVSS** | Returns the assets affected by a Common Vulnerability Scoring System (CVSS) score for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> - Get assets affected by high-priority CVSS scores in LinkedIn’s attack surface. <br> - How many assets have critical CVSS score for Microsoft? <br> - Which assets have critical CVSS scores for Azure? <br> - Get assets affected by high-priority CVSS scores in my attack surface. <br> - How many of my assets have critical CVSS scores? <br> - Which of my assets have critical CVSS scores? <br><br> **Required inputs**: <br> - `CvssPriority` (the CVSS priority must be *critical*, *high*, *medium*, or *low*) <br><br> **Optional inputs**: <br> - `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> - If plugin settings aren't filled out, fail graciously and remind customers. <br> - If plugin settings are filled out, returns the assets affected by a CVSS score for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> - If no exact for match for company name is found, returns a list of possible matches. <br> - If there's an exact match, returns the assets affected by a CVSS score for the specific company name. |+| **Get expired domains** | Returns the number of expired domains for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> - How many domains are expired in LinkedIn’s attack surface? <br> - How many assets are using expired domains for Microsoft? <br> - How many domains are expired in my attack surface? <br> - How many of my assets are using expired domains for Microsoft? <br><br> **Optional inputs**: <br> - `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> - Returns the number of expired domains for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> - If no exact for match for company name is found, returns a list of possible matches. <br> - If there's an exact match, returns the number of expired domains for the specific company name. |+| **Get expired certificates** | Returns the number of expired SSL certificates for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> - How many SSL certificates are expired for LinkedIn? <br> - How many assets are using expired SSL certificates for Microsoft? <br> - How many SSL certificates are expired for my attack surface? <br> - What are my expired SSL certificates? <br><br> **Optional inputs**: <br> - `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> - Returns the number of SSL certificates for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> - If no exact for match for company name is found, returns a list of possible matches. <br> - If there's an exact match, returns the number of SSL certificates for the specific company name. |+| **Get SHA1 certificates** | Returns the number of SHA1 SSL certificates for either the customer’s Defender EASM resource or a specific company name. | **Example inputs**: <br> - How many SSL SHA1 certificates are present for LinkedIn? <br> - How many assets are using SSL SHA1 for Microsoft? <br> - How many SSL SHA1 certificates are present for my attack surface? <br> - How many of my assets are using SSL SHA1? <br><br> **Optional inputs**: <br> - `CompanyName` | If your plugin is configured to an active Defender EASM resource and no other company is specified: <br> - Returns the number of SHA1 SSL certificates for the customer’s Defender EASM resource. <br><br> If another company name is provided: <br> - If no exact for match for company name is found, returns a list of possible matches. <br> - If there's an exact match, returns the number of SHA1 SSL certificates for the specific company name. |+| **Translate natural language to a Defender EASM query** | Translates any natural language question into a Defender EASM query and returns the assets that match the query. | **Example inputs**: <br> - What assets are using jQuery version 3.1.0? <br> - Get the hosts with port 80 open in my attack surface. <br> - Find all the page, host, and ASN assets in my inventory that have an IP address that is IP *X*, IP *Y*, or IP *Z*. <br> - Which of my assets have a registrant email of `<[email protected]>`? | If your plugin is configured to an active Defender EASM resource: <br> - Returns the assets matching with the translated query. | ### Switch between resource data and company data -Even though we added resource integration for our skills, we still support pulling data from prebuilt attack surfaces for specific companies. To improve the Security Copilot accuracy in determining when a customer wants to pull from their attack surface or from a prebuilt, company attack surface, we recommend using **my**, **my attack surface**, and so on, to convey that you want to use your resource. Use **their**, ***specific company name***, and so on, to convey that you want to use a prebuilt attack surface. Although this approach does improve the experience in a single session, we strongly recommend using two separate sessions to avoid any confusion.+Even though we added resource integration for our skills, we still support pulling data from prebuilt attack surfaces for specific companies. To improve the Security Copilot accuracy in determining when a customer wants to pull from their attack surface or from a prebuilt, company attack surface, we recommend using **my**, **my attack surface**, and so on, to convey that you want to use your resource. Use **their**, ***specific company name***, and so on to convey that you want to use a prebuilt attack surface. Although this approach improves the experience in a single session, we strongly recommend using two separate sessions to avoid any confusion. ## Provide feedback -Your feedback on Security Copilot generally, and the Defender EASM plugin specifically, is vital to guide current and planned development of the product. The optimal way to provide this feedback is directly in the product, using the feedback buttons at the bottom of each completed prompt. Select **Looks right**, **Needs improvement**, or **Inappropriate**. We recommend that you choose **Looks right** when the result matches expectations, **Needs improvement** when it doesn't, and **Inappropriate** when the result is harmful in some way. +Your feedback on Security Copilot generally, and the Defender EASM plugin specifically, is vital to guide current and planned development of the product. The optimal way to provide this feedback is directly in the product, using the feedback buttons at the bottom of each completed prompt. Select **Looks right**, **Needs improvement**, or **Inappropriate**. We recommend that you choose **Looks right** when the result matches expectations, **Needs improvement** when it doesn't, and **Inappropriate** when the result is harmful in some way. Whenever possible, and especially when the result you select is **Needs improvement**, please write a few words to explain what we can do to improve the outcome. This request also applies when you expect Security Copilot to invoke the Defender EASM plugin, but a different plugin is engaged instead. @@ -140,6 +132,6 @@ For more information about data privacy in Security Copilot, see [Privacy and da ## Related content -- [Microsoft Security Copilot](/security-copilot/microsoft-security-copilot)-- [Privacy and data security in Microsoft Security Copilot](/security-copilot/privacy-data-security)-- [Query your attack surface with Defender EASM by using Azure Copilot](/azure/copilot/query-attack-surface)+- [What is Microsoft Security Copilot?](/copilot/security/microsoft-security-copilot)+- [Privacy and data security in Microsoft Security Copilot](/copilot/security/privacy-data-security)+- [Query your attack surface with Defender EASM using Azure Copilot](/azure/copilot/query-attack-surface) 
