Microsoft Defender XDR
Fundamentals

Microsoft Security Copilot Security Analyst Agent overview

In brief

The article now explains how to switch to and from the Security Analyst Agent through the More actions menu, notes that switching resets the conversation, adds a Sentinel Log Analytics investigation prompt, and reorganizes report interpretation guidance.

What Defender admins need to know

Administrators and analysts should follow the updated navigation steps and account for conversation resets when switching agents. No configuration change is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Security Copilot Security Analyst Agent overview

[!INCLUDE Prerelease]

Access and setup requirements

Review the following access and setup requirements before configuring the agent.

  • Access Requirements

You must have read access to either Microsoft Defender XDR, Microsoft Sentinel Log Analytics Workspace, or Microsoft Sentinel Data Lake, depending on the data source you chose.

There are two methods for specifying the data source:

Natural language prompts: Add the data source to your instruction. For example:Use the following sample prompt to ask the agent to investigate whether privilege escalation or role elevation events are followed by sensitive data access using Sentinel Log Analytics data:

Analyze if there are privilege escalation or role elevation activities that are followed by sensitive data access in my enterprise. Please use Sentinel Log Analytics for this.

Configure the Security Analyst Agent (optional)

  1. Go to the Microsoft Defender portal, and then select Advanced hunting under Investigation and response.

  2. Open Copilot, select the three-dot menu (More actions) in the side pane, and then select Switch to Security Analyst Agent.

    :::image type="content" source="./media/security-analyst-agent/security-analyst-agent-select.png" alt-text="Screenshot of selectingthe More actions menu in the Security Copilot side pane, showing the Switch to Security Analyst Agent in Microsoft Defender Advanced hunting.option.":::

  3. Enter your security analysis prompt in natural language, or select one of the suggested prompts.

  4. Use the feedback buttons on the response to share whether the output was helpful.

InterpretingSwitch back to the Threat Hunting Assistant

To return to the Threat Hunting Assistant, select the three-dot menu (More actions) in the Security Copilot side pane, and then select Switch to Threat Hunting Assistant.

:::image type="content" source="./media/security-analyst-agent/security-analyst-agent-switch-back.png" alt-text="Screenshot of the More actions menu in the Security Analyst Agent side pane, showing the Switch to Threat Hunting Assistant option.":::

Interpret the Security Analyst Agent report

The report is organized into the following sections to help you review the analysis and supporting evidence.

ExecutiveReview the executive summary

TheIn the report, the Executive summary section provides a clear narrative of how the analysis was performed, outlining the steps taken and the data considered. It explains the filtering criteria, time ranges, and any ranking applied, all in straightforward language so readers can easily follow the process.

KeyReview key insights

Here you’ll find the most significant findings from the analysis, presented in a concise and meaningful way. Each insight includes a brief explanation of why it matters and, where relevant, references to supporting evidence.

VisualizationsInterpret report visualizations

The Visualizations section contains charts or graphs that add depth and clarity to the report, helping readers quickly interpret patterns or relationships in the data. Visuals are included only when they provide unique value to the analysis.

\ No newline at end of file

ArtifactsReview report artifacts

Artifacts are the supporting files that accompany the Security Analyst Agent report, such as a comprehensive CSV of all analyzed entities and, when applicable, detailed evidence files. These resources allow readers to explore the full dataset behind the findings. Artifacts include the KQL query that was used by the agent to retrieve the data (please note the agent only uses KQL for data retrieval, analysis is done in python), comprehensive plan that was formulated for performing the task. \ No newline at end of file \ No newline at end of file