Microsoft Sentinel Defender Portal
In brief
The AI-assisted SOC row now lists Native Security Copilot references for automated incident summaries, guided response actions, and script analysis.
What Defender admins need to know
Administrators can use the updated documentation links for these Security Copilot capabilities. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
| Capability area | Sentinel in Azure portal | Sentinel in Defender portal | Benefits |
|---|---|---|---|
| Advanced hunting | Sentinel-only (Log Analytics) | Unified advanced hunting for SIEM, Defender, and the data lake, with Security Copilot in advanced hunting for KQL generation. Supports hunting in the tenant and workspaces and reuse of existing Sentinel workspace queries and functions. | Broader dataset, richer context, no context-switching |
| AI-assisted SOC (Security Copilot) | Not available | Native Security Copilot: automated incident summary, guided response actions, script analysis, file analysis, incident reports, and autonomous Security Copilot agents for alert triage, threat intelligence briefing, and |
Faster investigation, lower skill barrier, agentic defense |
| Post-incident recommendations | Not available | Tailored recommendations via Exposure Management, including attack path analysis to identify exploitable vulnerabilities. | Proactive posture improvement |
@@ -61,7 +61,7 @@ The following tables compare Microsoft Sentinel capabilities in the Azure portal | **Capability area** | **Sentinel in Azure portal** | **Sentinel in Defender portal** | **Benefits** | |----|----|----|----| | Advanced hunting | Sentinel-only (Log Analytics) | Unified [advanced hunting](https://go.microsoft.com/fwlink/p/?linkid=2264410) for SIEM, Defender, and the data lake, with [Security Copilot in advanced hunting](/defender-xdr/advanced-hunting-security-copilot) for KQL generation. Supports hunting in the tenant and workspaces and reuse of existing Sentinel workspace queries and functions. | Broader dataset, richer context, no context-switching |-| AI-assisted SOC (Security Copilot) | Not available | Native Security Copilot: [automated incident summary](/defender-xdr/security-copilot-m365d-incident-summary), [guided response actions](/defender-xdr/security-copilot-m365d-guided-response), [script analysis](/defender-xdr/security-copilot-m365d-script-analysis), [file analysis](/defender-xdr/copilot-in-defender-file-analysis), [incident reports](/defender-xdr/security-copilot-m365d-create-incident-report), and [autonomous Security Copilot agents](/defender-xdr/security-copilot-agents-defender) for alert triage, threat intelligence briefing, and [threat hunting](/defender-xdr/advanced-hunting-security-copilot-threat-hunting-agent). [Included capacity for E5/E7 customers](/copilot/security/security-copilot-inclusion). | Faster investigation, lower skill barrier, agentic defense |+| AI-assisted SOC (Security Copilot) | Not available | Native Security Copilot: [automated incident summary](/defender-xdr/security-copilot-m365d-incident-summary), [guided response actions](/defender-xdr/security-copilot-m365d-guided-response), [script analysis](/defender-xdr/security-copilot-m365d-script-analysis), [file analysis](/defender-xdr/copilot-in-defender-file-analysis), [incident reports](/defender-xdr/security-copilot-m365d-create-incident-report), and [autonomous Security Copilot agents](/defender-xdr/security-copilot-agents-defender) for alert triage, threat intelligence briefing, and [threat hunting](/defender-xdr/advanced-hunting-security-copilot-threat-hunting-assistant). [Included capacity for E5/E7 customers](/copilot/security/security-copilot-inclusion). | Faster investigation, lower skill barrier, agentic defense | | Post-incident recommendations | Not available | Tailored recommendations via [Exposure Management](/unified-secops-platform/overview-msem-strategy), including attack path analysis to identify exploitable vulnerabilities. | Proactive posture improvement | 