Microsoft Copilot in Microsoft Purview Overview

Microsoft Copilot for Security is a cloud-based AI platform that can assist security and compliance professionals in protecting their organization's data. Security and compoliance professionals can use Copilot for Security to identify, summarize, triage, and remediate issues within the following Microsoft Purview solutions:

  • Microsoft Purview Data Loss Prevention (DLP)
  • Microsoft Purview Insider Risk Management
  • Microsoft Purview Communication Compliance
  • Microsoft Purview eDiscovery

For more information about what Copilot for Security can do and the different scenarios it supports, read What is Microsoft Security Copilot?.

Know before you begin

If you're new to Copilot for Security, you should familiarize yourself with it by reading these articles:

Microsoft Copilot in Microsoft Purview

Copilot in Microsoft Purview capabilities like summarizing DLP or insider risk management alerts are embedded into Microsoft Purview features.

Copilot in Microsoft Purview embedded experiences is a set of capabilities that are embedded in Microsoft Purview features. For more information, see standalone and embedded experiences.

Copilot in Microsoft Purview standalone experience is a chat-like experience that you can use to ask questions and get answers about your data. For more information, see standalone and embedded experiences.

Copilot in Microsoft Purview integration

When you sign up for Copilot for Security in the same tenant as Microsoft Purview, you can use both the Copilot in Microsoft Purview embedded and standalone experiences.

Features in the embedded experience

The embedded experience in Purview can help you:

Features in the standalone experience

The Copilot in Microsoft Purview standalone experience has many capabilities built in. You can use these capabilities to get insights from your Purview data and make connections between datapoints. This information can help you understand your information security and compliance posture and triage alerts.

System capabilities of Copilot in Microsoft Purview

In the standalone experience, there are built-in capabilities (prompts) that are available once the Microsoft Purview plugin is enabled.

Copilot in Purview brings three types of capabilities:

  • Summarize Microsoft Purview alerts.
  • Triage Microsoft Purview alerts.
  • Drill down into your Microsoft Purview data.

Enable the Microsoft Purview source in Microsoft Copilot for Security

Important

Copilot in Purview must be enabled for both the standalone and embedded experiences to work.

Copilot in Purview is enabled by default. To enable or disable the Microsoft Purview source in Microsoft Copilot for Security, follow these steps:

  1. Ensure that you have permissions.

  2. Open https://securitycopilot.microsoft.com/.

  3. Open Sources in the prompt bar.

    Screenshot that shows the plugins that are available, enabled, and disabled in Microsoft Security Copilot.

  4. On the Manage plugins page, set the Purview toggle to On to enable or Off to disable.

Review the Microsoft Purview system capabilities

  1. Select the capabilities control in the prompt bar.

    Screenshot that shows the system capabilities and promptbooks icon.

  2. Select See all system capabilities to see all the system capabilities that are available for Microsoft Purview. Here are a few:

    • Get Data Risk Summary
    • Get User Risk Summary
    • Summarize Purview Alert
    • Triage Purview Alerts
    • Zoom into Purview Data and User Risk

Sample prompts

For guidance on writing effective prompts, see Prompting in Microsoft Copilot for Security. Here are some examples:

  • Show me the top five DLP alerts from the past 24 hours.
  • Summarize the DLP alert with ID <12345>.
  • What's the risk profile of the user that's associated with the DLP alert <12345>.
  • Show me the top five Insider Risk Management alerts from the past 24 hours.
  • What items did user <user> exfiltrate in the past 30 days.

Privacy and data security in Microsoft Copilot for Security

To understand how Microsoft Copilot for Security in Purview handles your prompts and the data that's retrieved from the service (prompt output), see the Privacy and data security in Microsoft Copilot for Security.