Microsoft Defender XDR
Incidents and response

Summarize an incident with Microsoft Copilot in Microsoft Defender

In brief

The documentation now refers to Microsoft Defender instead of Microsoft Defender XDR in descriptions of Security Copilot-powered incident summaries and Defender correlation capabilities.

What Defender admins need to know

Administrators will see updated product terminology when reviewing incident summary guidance; no configuration changes are required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Summarize an incident with Microsoft Copilot in Microsoft Defender

Microsoft Defender XDR applies the capabilities of Security Copilot to summarize incidents. Incident summaries provide impactful information and insights to simplify investigation tasks. Investigations are often time-consuming and involve numerous steps.

This guide outlines how to access the summarizing capability of Copilot in Defender and what information is included in the summary, including information on providing feedback.

Incident responders can access the right context to investigate and remediate incidents through Defender XDR's correlation capabilities and Security Copilot's AI-powered data processing and contextualization. With an incident summary, responders get important information quickly to help in their investigation.

Security Copilot integration in Microsoft Defender