Lab Setup
Use an Azure subscription and Microsoft Entra tenant that you are authorized to administer. This lab requires the Security Administrator and Global Administrator roles, Security Compute Units (SCUs), and a Microsoft Security Copilot license. Use privileged roles only for the duration of the exercise and follow your organization's least-privilege practices.
===
Configure and Use Microsoft Security Copilot
You are preparing Security Copilot for operational use in a production security environment. The objective is not just to run prompts, but to set up capacity, permissions, data access, and plugin scope so Copilot can provide grounded, useful responses without unnecessary blast radius.
In this lab, you will:
- Provision Security Copilot SCU capacity.
- Configure workspace data-sharing settings.
- Assign contributor access for a delegated analyst user.
- Enable core Microsoft security plugins.
- Review and enable a built-in Copilot agent.
- Run structured prompts against connected security data.
This exercise should take approximately 45 minutes to complete.
Note: This lab assumes Security Copilot SCU provisioning is enabled in your environment and that relevant Microsoft security data sources are available.
Review the Preconfigured State
-
Sign in to the Azure portal and open Resource groups.
-
Select sc500-lab4f-rg and confirm sc500-lab4f-storage exists.
-
Confirm your tenant account includes access required to provision SCU capacity in Security Copilot.
Provision Security Copilot Capacity
-
Sign in to https://securitycopilot.microsoft.com using your User1 account.
-
Start the setup flow for capacity provisioning.
-
Provision 1 SCU in East US, unless your lab environment directs you to use another region.
-
Confirm provisioning completes and the workspace becomes available.
-
Record capacity settings in your notes:
Field Value Region East US, unless your lab environment directs otherwise SCU count 1
Configure Workspace and Role Assignments
-
Open Owner settings in Security Copilot.
-
Open Data sharing and configure least-privilege sharing choices for this lab environment.
-
Save settings.
-
Open Roles.
-
Confirm your account is listed as workspace owner.
-
Assign Security Copilot Contributor role to User3.
-
Confirm the role assignment is visible.
Enable Security Plugins
-
Open Sources or Plugins in Security Copilot.
-
Enable the following plugins:
- Microsoft Defender XDR
- Microsoft Defender for Cloud
- Microsoft Sentinel
- Microsoft Entra
-
Wait for plugin connection states to update.
-
Confirm each plugin shows connected.
-
Record plugin status in your notes:
Plugin Status Defender XDR Defender for Cloud Sentinel Entra
Review and Enable a Built-in Agent
-
Open Agents in Security Copilot.
-
Select Vulnerability Impact Assessment (or the equivalent built-in vulnerability-focused agent in your environment).
-
Review agent details:
- Purpose
- Required data sources
- Permission scope implications
-
Enable the agent.
-
In your notes, summarize in 2-3 lines how this agent's potential blast radius depends on plugin access scope.
Run Grounded Security Prompts
-
Return to the main Security Copilot prompt experience.
-
Run this prompt:
Summarize the current security posture of this environment based on Defender for Cloud findings. What are the top 3 recommendations? -
Review the response and citations.
-
Run this follow-up prompt:
Provide step-by-step remediation actions for the top recommendation you just identified. -
Record in your notes:
Field Value Top recommendation returned Referenced source/plugin Actionability of remediation steps
Summary
In this lab, you configured Security Copilot as an operational security platform component:
- Provisioned compute capacity.
- Applied workspace governance and delegated role access.
- Connected core Microsoft security data sources through plugins.
- Enabled a built-in autonomous security agent.
- Executed grounded prompts tied to Defender posture data.
This establishes the day-4 capstone pattern: configuration quality in your security stack directly improves Copilot output quality.