Almanac
Microsoft/copilotMicrosoft 365

Consultant KB for the whole Microsoft Copilot estate. Spans Microsoft 365 Copilot, Copilot Studio, the Dynamics 365 Copilots, Power Platform Copilot, Fabric & Power BI Copilot, Copilot in Azure, Windows & consumer Copilot, extensibility & agents, Security Copilot, and GitHub Copilot, plus admin/security and cross-product decision guides. Populated by the daily author agent from Copilot release notes / release plans plus the author's own consultant notes.

feature-security-copilot-embedded-experiences.mdv1 · history
CurrentApplies to Security CopilotUpdated 2 months agoSource Microsoft Learn

What it does

Embedded Security Copilot puts the assistant in-context inside the security products you already work in — Defender XDR, Sentinel, Purview, Entra, Intune, and the threat-intel surfaces — so analysts get AI summaries and guided response without switching to the standalone portal.

Key facts

  • Defender XDR: incident summarisation, guided response, KQL-from-natural-language, script and file analysis, plus Copilot Chat in the Defender portal. This is the richest embedded surface.
  • Microsoft Sentinel: now converged into the Defender portal experience; Copilot helps with hunting, incident context, and KQL. (Standalone Azure-portal Sentinel is being retired in favour of the unified Defender portal.)
  • Purview: data-security investigations — summarising DLP alerts, insider-risk context, and eDiscovery/communication-compliance support.
  • Entra: identity investigations and risk context, plus the identity agents (Conditional Access optimisation, risky-user remediation, access reviews).
  • Intune: device and policy context, plus vulnerability-remediation guidance for endpoints.
  • Threat Intelligence: Defender Threat Intelligence (MDTI) is wired in for threat-actor and indicator summaries directly in prompts.
  • Same service, same SCU capacity pool as the standalone portal — embedded use draws down the same units.
  • Availability varies by surface: some capabilities are GA, others are in preview, and the list changes most releases — check the "What's new" page per product.

When to use / skip

For day-to-day SOC work, embedded is where analysts should live — staying in Defender with Copilot at hand beats bouncing to a separate portal. Use the standalone portal for cross-product investigations, promptbook authoring, plugin management, and anything that spans data sources the embedded surface can't reach. Skip embedded expectations for a product the client doesn't own — Copilot in Purview does nothing if there's no Purview data behind it.

Configuration decisions

  • Which embedded surfaces to switch on first — usually Defender XDR, because that's where incidents land.
  • Whether to move Sentinel work into the unified Defender portal now or wait — this affects where analysts see Copilot.
  • Per-product RBAC: embedded Copilot respects the user's existing product permissions, so get those right first.
  • Whether to enable the identity/device agents (Entra, Intune) alongside the interactive embedded features, since they consume capacity differently.

Gotchas

  • Embedded and standalone share one SCU pool — heavy embedded use in Defender quietly eats the same capacity your promptbooks need.
  • Feature parity isn't uniform: Defender XDR is deep, other surfaces are thinner. Don't promise identical Copilot depth in Purview or Intune.
  • Sentinel's move into the Defender portal trips people up — if a client still runs Sentinel in the Azure portal, the Copilot experience differs and is on the way out.
  • Preview vs GA matters for regulated clients; some embedded features you'll demo are still preview.
  • Embedded Copilot only sees what the product sees — poor connector/coverage in a product means weak answers there.

Consultant notes

  • Sell the embedded story as "Copilot where the analyst already is" — it's a stronger adoption argument than the standalone portal.
  • Defender XDR is your anchor demo surface; it's the most mature and the fastest credibility win.
  • Flag the Sentinel-into-Defender convergence early in any Sentinel engagement — it changes the target architecture and the Copilot experience.
  • Because embedded and standalone share capacity, model total usage across both when sizing SCUs; teams underestimate embedded draw.

Verify GA vs preview per embedded surface on each product's "What's new" page before committing capabilities to a client — parity is uneven and shifting.

Was this accurate?