Copilot for Security has the ability to search Microsoft Docs for supporting information for your queries and questions. I’ve talked about this before, but if you go into the System Capabilities area and choose Ask Microsoft documentation you can force Copilot for Security to search the Microsoft Docs to use in its response and in the response, you’ll get the Microsoft approved information along with a link to the original doc on Microsoft Learn so you can go deeper into the topic.
Great feature - but this currently does not scour ALL Microsoft Docs. This feature will obviously see improvements, but currently sources docs for only Purview, Intune, Defender, Entra, Azure Firewall, Azure Web Application Firewall, and other Microsoft 365 products.
Did you see anything missing from that list? One glaring gap for me is Sentinel.
So, here’s a tip.
You can use the “Use Microsoft Docs” phrase in your prompt and Copilot for Security is smart enough to use the Public Web plugin (make sure it is enabled!) to reach out to all Microsoft Docs on the Microsoft Learn website.
As you can see in the next screen capture, Copilot for Security automatically chose the Public Web option to source the response to my query about how to create a Sentinel Analytics Rule.
And this is not just for Sentinel or other security components. Using this method you can search Microsoft Docs for anything. As you can see in the next screen capture, I can query and get detailed results for how to spin up a new VM in Azure.
[Want to discuss this further? Hit me up on Twitter or LinkedIn]
[Subscribe to the RSS feed for this blog]
[ Subscribe to the Bi-weekly Copilot for Security Newsletter]
[Subscribe to the Weekly SIEM and XDR Newlsetter]
[Learn KQL with the Must Learn KQL series and book]
[Learn AI Security with the Must Learn AI Security series and book]
** Need a Tech break?? Sure, we all do! Check out my fiction novels: Sword of the Shattered Kingdoms: Ancient Crystal of Eldoria and WW2045: Alien Revenge