Agent Incident Investigation <> Governance Accountabilities
Identity provides traceability. Governance provides answers. An agent can have a valid security principal and still lack a complete governance record.
Aug 06, 2026
Library - Product reference
Microsoft Security Copilot, an AI-powered security solution designed to assist security operations teams by automating threat detection and response processes
Articles open in this browser tab. Some require sign-in.
Identity provides traceability. Governance provides answers. An agent can have a valid security principal and still lack a complete governance record.
Aug 06, 2026
AI is showing up everywhere - copilots, agents, custom apps, and third-party tools. This new dashboard gives security leaders a unified view to view and address AI risks.
Mar 04, 2026
Library Management in the Microsoft Defender portal is a new way to centrally manage the scripts and files your SOC uses in Live Response.
Feb 18, 2026
Most of what I share here is about security, governance, and control. But if we want those conversations to be useful (and not turn into vague fear or hype), we need a shared picture of what the AI platform for work actually is.
Feb 06, 2026
AI is no longer “nice to have” in security operations. It’s quickly becoming the only practical way to keep up with attacker speed, alert volume, and fragmented signals across the digital estate.
Jan 25, 2026
💡 Building a SOC-as-a-Service (SOCaaS) is not just about tools. It’s about designing a repeatable operating model that delivers consistent outcomes across customers, industries, and environments. Many SOCaaS discussions start too deep, too fast. Recently I’ve been asked for a simpler way to frame the Microsoft-aligned approach upfront. This infographic is a bird’s-eye view to…
Jan 20, 2026
Part 3 is addressing the inevitable next question: how do we govern AI itself so copilots and agents don’t become the newest - and quietest - exfiltration path? This is not a tooling problem. It’s a control problem.
Dec 12, 2025
Microsoft Security Copilot is now included in Microsoft 365 E5, what this means for customers? A simple scenario matrix is here to answer this question.
Nov 19, 2025
"Are we ready for the inevitable?". Part 2 is my practical answer: a human-in-control model where built-in intelligence across the Microsoft security stack and Security Copilot agents do the heavy lifting across identity, endpoints, data, cloud, and apps, all under clear guardrails.
Nov 14, 2025
CCS framework helps you protect, manage, and measure Microsoft 365 Copilot and agents - tying outcomes to controls, clarifying ownership, and sequencing a safe rollout.
Nov 07, 2025