Summary and resources

Completed

In this module, you explored how Microsoft Security Copilot agents automate and enhance security workflows across Microsoft's security ecosystem. You learned about the different types of agents, how they're categorized, and their role in streamlining security operations across identity management, threat detection, data protection, and endpoint security.

You explored agent identities and permissions, understanding the difference between dedicated agent identities using Microsoft Entra Agent ID and connecting with existing user accounts. You also learned about the role-based access controls that govern what agents can do.

You then examined Security Copilot agents across multiple Microsoft security products:

  • Microsoft Entra agents that automate identity and access management tasks, including Conditional Access optimization, access reviews, and identity risk management.
  • Microsoft Defender agents that carry out security operations tasks like phishing triage, threat intelligence briefing, threat hunting, and dynamic threat detection.
  • Microsoft Purview agents that help triage insider risk management and data loss prevention alerts.
  • Microsoft Intune agents that enhance enterprise endpoint security by automating vulnerability remediation, change review, device offboarding, and policy configuration.

Finally, you learned how Security Copilot supports building your own custom agents through multiple development experiences, including natural language, YAML upload, and Model Context Protocol (MCP) tools.

After completing this module, you're able to:

  • Describe the role and functionality of Microsoft Security Copilot agents in automating security workflows.
  • Describe agent identities and permissions in Microsoft Security Copilot.
  • Describe the Threat Intelligence Briefing Agent in the Security Copilot standalone experience.
  • Describe Security Copilot agents in Microsoft Entra, Microsoft Defender, Microsoft Purview, and Microsoft Intune.
  • Describe how Security Copilot supports building your own agents.

Learn more: