Empowering Security: The Next Evolution of Microsoft Security Copilot
In today’s fast-paced digital landscape, the integration of artificial intelligence (AI) in security is no longer just an option; it’s a necessity for organizations across the globe. At Microsoft, we believe in a future secured by our AI-first, end-to-end security platform designed to help organizations combat the evolving threat landscape.
The Launch of Security Copilot
Just a year ago, we introduced Microsoft Security Copilot—a game-changing tool designed to enhance the capabilities of security teams in detecting, investigating, and swiftly responding to incidents. We’re thrilled to unveil the next step in this evolution with the introduction of AI agents that can autonomously assist with key areas like phishing, data security, and identity management. As the pace and complexity of cyberattacks continue to escalate, leveraging AI as a supportive ally is essential.
For instance, phishing attacks remain a critical concern; in 2024 alone, Microsoft identified over 30 billion phishing emails targeting users. This staggering volume overwhelms security teams relying on outdated, manual processes, making it increasingly difficult to react promptly and leverage crucial insights for broader cyber risk management.
With the introduction of the Phishing Triage Agent in Security Copilot, organizations can automate the handling of routine phishing alerts. This allows human defenders to focus on more complex threats, transforming the way we approach security.
Expanding Security Copilot’s Capabilities
Microsoft Threat Intelligence is already processing a jaw-dropping 84 trillion signals each day, indicating the need for a robust defense mechanism against cyberattacks. To address this, we are set to expand Security Copilot with six new security agents developed by Microsoft, along with five additional agents from our trusted partners, available for preview in April 2025.
Six New Microsoft Security Agents
Our latest security agents are designed to autonomously tackle high-volume security and IT tasks while integrating seamlessly with the Microsoft Security ecosystem. Each agent is crafted to learn and adapt from feedback, ultimately driving efficiency and enhancing an organization’s security posture:
-
Phishing Triage Agent in Microsoft Defender: Accurately identifies real cyberthreats and false alarms, continuously improving based on admin feedback.
-
Alert Triage Agents in Microsoft Purview: Handles data loss prevention and insider risk alerts, prioritizing critical incidents.
-
Conditional Access Optimization Agent in Microsoft Entra: Monitors for new users or apps, recommending necessary updates to close security gaps.
-
Vulnerability Remediation Agent in Microsoft Intune: Prioritizes app and policy vulnerabilities for swift remediation, expediting Windows OS patches with admin approval.
- Threat Intelligence Briefing Agent in Security Copilot: Curates timely threat intelligence tailored to an organization’s unique cyberthreat exposure.
Five Partner Agents
In our commitment to security as a shared effort, we will also introduce five agents from our partners:
-
Privacy Breach Response Agent by OneTrust: Assists teams in navigating data breaches and meeting regulatory needs.
-
Network Supervisor Agent by Aviatrix: Conducts root cause analyses of connectivity issues.
-
SecOps Tooling Agent by BlueVoyant: Enhances security operations by offering actionable recommendations.
-
Alert Triage Agent by Tanium: Provides necessary context for rapid decision-making on alerts.
- Task Optimizer Agent by Fletch: Helps to prioritize critical cyberthreat alerts, combating alert fatigue.
Innovations in Data Security and AI Governance
As organizations adopt generative AI, the importance of securing and governing these new technologies cannot be overstated. According to our report, “Secure employee access in the age of AI,” 57% of organizations have experienced an uptick in security incidents due to AI use. Many organizations are recognizing this urgent need but have yet to implement necessary controls.
AI Security Posture Management
We are taking pivotal steps to fortify the security of AI sourced from various models and running in multi-cloud environments. Starting from May 2025, Microsoft Defender will extend AI security posture management across platforms, including Google VertexAI, alongside existing supports for Azure and AWS.
Addressing Emerging AI Threats
With the rise of AI comes the emergence of new risks. Beginning in May 2025, we’ll enhance our detection and protective measures for new threats identified by the Open Worldwide Application Security Project (OWASP), such as indirect prompt injection attacks and sensitive data exposure.
Guarding Against Shadow AI
With the unregulated rise of AI applications in the workplace, commonly referred to as “shadow AI,” organizations face new data leakage risks. We are therefore introducing the AI web category filter within Microsoft Entra to manage access and the preview of browser data loss prevention controls in Microsoft Edge for Business to curb data leaks into unauthorized AI applications.
Phishing Protection Within Microsoft Teams
Recognizing that collaboration platforms are now prime targets for cyberattackers, we are enhancing protections in Microsoft Teams. In April 2025, Microsoft Defender for Office 365 will offer real-time protection against phishing and advanced cyber threats through inline defenses.
Join Us on this Security Journey
At Microsoft, our mission is rooted in innovation, driven by the principles of our Secure Future Initiative. We are committed to providing robust security solutions that empower organizations to protect and govern their AI investments effectively.
To see these innovations come to life, we invite you to join us for the Microsoft Secure digital event on April 9, 2025, where we will dive deeper into security in the age of AI.
The AI Buzz Hub team is excited to see where these breakthroughs take us. Want to stay in the loop on all things AI? Subscribe to our newsletter or share this article with your fellow enthusiasts.