Unless you’ve been living under a proverbial technology-blocking rock, you’ve heard about Microsoft Copilot or at least ChatGPT by now. In essence, Copilot is designed to be an assistant (not a replacement) to users as they do their daily tasks. It integrates with common tools they use and assists in creating content, analyzing content, searching for information, and much more. It is not meant to replace workers but to enhance their deliverables and make things more efficient. Copilot even extends into the security space and provides additional support to analysts by reviewing and analyzing signals for threats and risks, supporting incident response, and assisting at scale with the overall security posture of an organization. In this first of my many (hopefully) posts on the subject, I will provide an overview of Copilot for Security.
As always, please be aware of my blog disclaimer
Brief History of Copilot
As early as 2021, we would get rumblings of AI work within Microsoft. But if you think about it, the path started even sooner than that with Azure Cognitive Services. Azure Cognitive Services was first released in 2016 and provided developers with a method to add speech and language understanding (though a bit primitive by today’s standards) to their applications. It was built on a consumption basis, so a standing license wasn’t required; it just billed you as you used it. I remember building a Digital Asset Management System (DAM) for an organization built on SharePoint. SharePoint itself, while great for the storage of content, missed a few of the key features of a DAM. One of those features was a keyword system. To mitigate this, I developed a process that allowed a picture to pass through Azure Cognitive Services as it was saved to SharePoint. The service then scanned the image and provided keywords to describe it to assist users in searching for content later. It actually worked pretty well even back then (this was around 2019).
Fast-forward a few years, and we hear stories of Microsoft building on Machine Learning. Things like AI Builder for the Power Platform were being released. For those of us lucky enough to be part of a select group, Project Cortex was quietly being developed at Microsoft. It eventually morphed into Viva Topics and SharePoint Syntex (SharePoint Premium now).
In the backend, we heard about the development of LUIS. LUIS stands for Language Understanding Intelligent Service, and while you may think it is highly integrated with Copilot, it actually isn’t. However, the concepts from which it is built are the same as those of Copilot.
In late 2022 and early 2023, we heard that Microsoft had its own “ChatGPT”. In March of 2023, we found out the name was Copilot, and Microsoft planned for it to be EVERYWHERE in its infrastructure. It was released in Microsoft Office, Power Platform, Developer Tools, Microsoft 365, and more. At the time of the announcement, Microsoft also said there would be a Copilot that could assist an organization’s security at AI speeds to scale. This, however, wasn’t released until late 2023, around July.
Overview of Copilot for Security
As stated above, Copilot for Security was released later than Microsoft 365 Copilot in July of the same year. As with M365 Copilot, Copilot for Security is not meant to replace the capabilities of an analyst or consultant. In fact, its goal is to assist the analyst in finding the information they need to protect the organization. Its purpose is to increase efficiencies and allow the organization to respond faster. Microsoft 365 and Azure gather so much data across many workloads that finding the flags or reviewing the content takes time. Like Copilot in general, we saw the beginnings of Copilot for Security in different tools developed by Microsoft years ago. Insider Risk Management (IRM) is a great example of this. It uses machine learning and internal algorithms to collate data across many workloads to create central alerts focused on a user’s behavior. Are they acting in a way that is risky to the organization? IRM was released three years before Copilot, but in hindsight, it shows where Microsoft’s thinking was going. Copilot for Security is similar but on a grander scale and is not just focused on data. It monitors traffic and activities across the organization. It helps to decipher code from malicious scripts to help analysts determine the threat. It even allows teams to build repetitive tasks to assist in the organization’s security.
In future posts about Copilot for Security, I’ll focus on data security. I’ll also demonstrate how you can build a test environment with Copilot for Security. We’ll learn how Copilot for Security can assist you in protecting your organization.
Availability of Copilot for Security
Copilot for Security is not yet available worldwide. Currently you can only provision it in specific regions. At the writing of this post, those regions include:
- East US
- UK South
- West Europe
- Australia East
This means that if you have rules that your environments can’t exist outside of your nation’s borders, you may not yet be able to provision Copilot for Security within your tenant.
Thanks for reading!

Leave a Reply