Complete Guide to Microsoft Copilot for Security: Empower and Protect the Security Operations Center (SOC) by Microsoft Press
9h 26mIntermediate2024-12-05
Authors

Microsoft Press
Microsoft

Joseph Muniz

Eric Snyder
Course details
Microsoft Copilot for Security was designed to help security operation centers (SOCs) respond to security threats faster and more effectively at scale. In this course, instructors Joseph Muniz and Erik Snyder show you how to leverage Microsoft Copilot for Security to deliver better, safer, and more efficient security outcomes for your SOC. Discover the essentials of what you need to know to get started with Microsoft Copilot for Security, including how it works, how to set it up and turn it on, and how to use it to address security threats specifically targeted at your SOC. An ideal fit for anyone looking to advance their understanding of cybersecurity, AI, and cloud-based technology, this course prepares you to successfully enable Microsoft Copilot for Security and build an AI strategy that meets the needs of your environment.
Learning objectives
Apply core concepts using AI-driven tools within a security operation center.
Understand how Microsoft Copilot for Security works.
Enable Copilot for Security within your security environment.
Build a plan to successfully deploy AI security solutions based on your existing people, processes, and technology.
Leverage advanced skills to extend Copilot for Security using custom plugins and third-party tools.
Learning objectives
Apply core concepts using AI-driven tools within a security operation center.
Understand how Microsoft Copilot for Security works.
Enable Copilot for Security within your security environment.
Build a plan to successfully deploy AI security solutions based on your existing people, processes, and technology.
Leverage advanced skills to extend Copilot for Security using custom plugins and third-party tools.
Skills covered
Microsoft Security CopilotNetwork SecurityIncident ResponseCybersecurityMicrosoftOne-Off
Concepts
0. Introduction
- 01 - Complete guide to Microsoft Copilot for Security - Introduction
1. Preparing Your SOC for AI
- 02 - Module 1 - AI basics with Copilot for Security introduction
- 03 - Learning objectives
- 04 - 1.1 Welcome to your future with AI
- 05 - 1.2 The business case and ROI
- 06 - 1.3 Solving the cybersecurity problem
- 07 - 1.4 Responsible AI, data privacy, and protection
- 08 - 1.5 Security capabilities review
- 09 - 1.6 Building your AI use cases
2. AI Architectures - Monolithic and Compound
- 10 - Learning objectives
- 11 - 2.1 The history of AI and model architectures
- 12 - 2.2 Monolithic and compound models explained
- 13 - 2.3 Examples of monolith AI uses
- 14 - 2.4 Compound AI models
- 15 - 2.5 Compound AI in Copilot for Security
3. Prompt Engineering for Cybersecurity
- 16 - Learning objectives
- 17 - 3.1 Introducing prompt engineering
- 18 - 3.2 Tokens and why they matter
- 19 - 3.3 Prompt engineering examples - Sentinel
- 20 - 3.4 Prompt engineering examples - MDE
- 21 - 3.5 Prompt engineering examples - MDTI and EASM
- 22 - 3.6 Prompt engineering examples - Intune
- 23 - 3.7 Nested prompts and promptbooks
- 24 - 3.8 Nested prompt examples
4. Embedded Experiences
- 25 - Module 2 - Microsoft Copilot for Security introduction
- 26 - Learning objectives
- 27 - 4.1 Introduction to Copilot for Security
- 28 - 4.2 Microsoft security technologies
- 29 - 4.3 Overview of Copilot for Security experiences
5. Embedded Copilot in Action
- 30 - Learning objectives
- 31 - 5.1 Use case - Entra
- 32 - 5.2 Use case - Defender for XDR
- 33 - 5.3 Use case - Intune
- 34 - 5.4 Use case - Purview
6. An Immersive Copilot Experience
- 35 - Learning objectives
- 36 - 6.1 Introduction to immersive experience
- 37 - 6.2 Microsoft plugin review
- 38 - 6.3 Third-party and custom plugin review
- 39 - 6.4 Promptbooks
- 40 - 6.5 Promptbook examples
- 41 - 6.6 Developing custom promptbooks
7. Immersive Copilot in Action
- 42 - Learning objectives
- 43 - 7.1 Use case - Executive and technical summarization
- 44 - 7.2 Use case - Cross technology analysis
- 45 - 7.3 Use case - KQL code generation
- 46 - 7.4 Use case - Threat hunting
- 47 - 7.5 Use case - Incident response
- 48 - 7.6 Use case - Vulnerability management
8. Day Zero - Preparing for Copilot for Security
- 49 - Module 3 - Launching Copilot for Security
- 50 - Learning objectives
- 51 - 8.1 Requirements for enabling Copilot - Part 1
- 52 - 8.2 Requirements for enabling Copilot - Part 2
- 53 - 8.3 Azure services
- 54 - 8.4 Copilot for Security consumption model
- 55 - 8.5 Copilot for Security scaling
- 56 - 8.6 Copilot for Security and RBAC
- 57 - 8.7 Developing a Go Live plan
9. Day 1 - Going Live with Copilot for Security
- 58 - Learning objectives
- 59 - 9.1 Turning on Copilot
- 60 - 9.2 Setting up Copilot for Security
- 61 - 9.3 Testing embedded capabilities
- 62 - 9.4 Enabling and testing immersive capabilities
- 63 - 9.5 Session and sharing sessions
- 64 - 9.6 Usage dashboard review
- 65 - 9.7 Opening tickets and finding help
10. Custom Plugins
- 66 - Module 4 - Extending Copilot for Security introduction
- 67 - Learning objectives
- 68 - 10.1 Introduction to plugin development
- 69 - 10.2 API-based plugins
- 70 - 10.3 Logic Apps
- 71 - 10.4 Upload your data files and knowledge
- 72 - 10.5 Bring in your third-party vendor
11. Custom Plugin in Action
- 73 - Learning objectives
- 74 - 11.1 Use case - Defanging websites
- 75 - 11.2 UrlScan plugin
- 76 - 11.3 Use case - Shodan plugin
- 77 - 11.4 Use case - Virus Total plugin
- 78 - 11.5 Logic App extended
- 79 - 11.6 Use case - Loading a KB file
12. Next Steps
- 80 - Learning objectives
- 81 - 12.1 Growth spaces - Training, plugins, and promptbooks
- 82 - 12.2 Tuning to reduce costs
- 83 - 12.3 Future technology impact
- 84 - 12.4 Reference material and resources
Conclusion
- 85 - Complete guide to Microsoft Copilot for Security - Summary