What it does
Embedded Security Copilot puts the assistant in-context inside the security products you already work in — Defender XDR, Sentinel, Purview, Entra, Intune, and the threat-intel surfaces — so analysts get AI summaries and guided response without switching to the standalone portal.
Key facts
- Defender XDR: incident summarisation, guided response, KQL-from-natural-language, script and file analysis, plus Copilot Chat in the Defender portal. This is the richest embedded surface.
- Microsoft Sentinel: now converged into the Defender portal experience; Copilot helps with hunting, incident context, and KQL. (Standalone Azure-portal Sentinel is being retired in favour of the unified Defender portal.)
- Purview: data-security investigations — summarising DLP alerts, insider-risk context, and eDiscovery/communication-compliance support.
- Entra: identity investigations and risk context, plus the identity agents (Conditional Access optimisation, risky-user remediation, access reviews).
- Intune: device and policy context, plus vulnerability-remediation guidance for endpoints.
- Threat Intelligence: Defender Threat Intelligence (MDTI) is wired in for threat-actor and indicator summaries directly in prompts.
- Same service, same SCU capacity pool as the standalone portal — embedded use draws down the same units.
- Availability varies by surface: some capabilities are GA, others are in preview, and the list changes most releases — check the "What's new" page per product.
When to use / skip
For day-to-day SOC work, embedded is where analysts should live — staying in Defender with Copilot at hand beats bouncing to a separate portal. Use the standalone portal for cross-product investigations, promptbook authoring, plugin management, and anything that spans data sources the embedded surface can't reach. Skip embedded expectations for a product the client doesn't own — Copilot in Purview does nothing if there's no Purview data behind it.
Configuration decisions
- Which embedded surfaces to switch on first — usually Defender XDR, because that's where incidents land.
- Whether to move Sentinel work into the unified Defender portal now or wait — this affects where analysts see Copilot.
- Per-product RBAC: embedded Copilot respects the user's existing product permissions, so get those right first.
- Whether to enable the identity/device agents (Entra, Intune) alongside the interactive embedded features, since they consume capacity differently.
Gotchas
- Embedded and standalone share one SCU pool — heavy embedded use in Defender quietly eats the same capacity your promptbooks need.
- Feature parity isn't uniform: Defender XDR is deep, other surfaces are thinner. Don't promise identical Copilot depth in Purview or Intune.
- Sentinel's move into the Defender portal trips people up — if a client still runs Sentinel in the Azure portal, the Copilot experience differs and is on the way out.
- Preview vs GA matters for regulated clients; some embedded features you'll demo are still preview.
- Embedded Copilot only sees what the product sees — poor connector/coverage in a product means weak answers there.
Consultant notes
- Sell the embedded story as "Copilot where the analyst already is" — it's a stronger adoption argument than the standalone portal.
- Defender XDR is your anchor demo surface; it's the most mature and the fastest credibility win.
- Flag the Sentinel-into-Defender convergence early in any Sentinel engagement — it changes the target architecture and the Copilot experience.
- Because embedded and standalone share capacity, model total usage across both when sizing SCUs; teams underestimate embedded draw.
Verify GA vs preview per embedded surface on each product's "What's new" page before committing capabilities to a client — parity is uneven and shifting.