You landed here because SC-5006v2 is recommended for the following:
SC-5006: Enhance Security Operations by Using Microsoft Security Copilot
SC-5006v2: Enhance Security Operations by Using Microsoft Security Copilot (v2)
Is it right for your organization?
Explore the transformative power of AI in security with Microsoft Security Copilot. This course starts by introducing you to the fundamental concepts of generative AI. The course then delves into the cutting-edge AI functionality of Microsoft Security Copilot that empowers analysts to respond to threats quickly, process signals at machine speed, and assess risk exposure more quickly than may otherwise be possible. Lastly, the course guides the learner through a series of simulation-based exercises that mimic real-world situations.
At the end of this course, you will be able to evaluate whether Microsoft Security Copilot is the right product for your Security Organization. Our instructors, Mike Danseglio and Rick Trader, will walk you through the capabilities and implementation costs of Microsoft Security Copilot. Their unique insights into Cybersecurity best practices and Microsoft security products will help you understand how Microsoft Security Copilot fits into the Microsoft security product family. Bring your questions to class; Mike and Rick are ready to answer them.
What you will learn
- With a focus on practical applications, the course covers:
- Learn how generative AI creates agents
- Learn the basic terminology of Microsoft Security Copilot
- Learn the elements of an effective prompt
- Learn how to enable Microsoft Security Copilot
- Learn what plugins and promptbooks are available for Microsoft Security Copilot
- Learn how to share information with Copilot
- Learn how some Microsoft security products can directly access Microsoft Security Copilot
- Learn how to automate threat detection and response with Microsoft Security Copilot agents
- Learn the use cases for using Microsoft Security Copilot in standalone experience versus embedded experience
What products and services will you use and learn about in this course
- Microsoft Security Copilot
- Microsoft Defender
- Microsoft Purview
- Microsoft Intune
- Microsoft Defender for Cloud
- Microsoft Security Copilot
- Security Compute Units
Prepare for the Microsoft Certified: Azure Virtual Desktop Specialty Certification
No certification
- $0 MSRP
$695(AI Promo) - 1 Day, Live Q&A
- MOC: SC-5006
- Live Instructor-Led Training
- Microsoft Official Curriculum
- Included in “all-you-can-eat” Microsoft Live Training Subscription
4:00 AM - 12:00 PM (HI)
7:00 AM - 3:00 PM (PT)
7:00 AM - 3:00 PM (AZ)
8:00 AM - 4:00 PM (MT)
9:00 AM - 5:00 PM (CT)
10:00 AM - 6:00 PM (ET)
4:00 AM - 12:00 PM (HI)
7:00 AM - 3:00 PM (PT)
7:00 AM - 3:00 PM (AZ)
8:00 AM - 4:00 PM (MT)
9:00 AM - 5:00 PM (CT)
10:00 AM - 6:00 PM (ET)
Course Outline
Module 1: Introduction to generative AI concepts
Generative AI powers applications that can create content, answer questions, and assist with tasks. In this module, you'll explore the fundamentals of generative AI, including large language models (LLMs), prompts, and AI agents.
Lessons:
- Large language models (LLMs)
- Prompts
- AI agents
Exercise:
- Explore generative AI agent scenario
Module 2: Describe Microsoft Security Copilot
Get acquainted with Microsoft Security Copilot. You are introduced to some basic terminology, how Microsoft Security Copilot processes prompts, the elements of an effective prompt, and how to enable the solution.
Lessons:
- Get acquainted with Microsoft Security Copilot
- Describe Microsoft Security Copilot terminology
- Describe how Microsoft Security Copilot processes prompt requests
- Describe the elements of an effective prompt
- Describe how to enable Microsoft Security Copilot
Exercise:
- None
Module 3: Describe the core features of Microsoft Security Copilot
Microsoft Security Copilot has a rich set of features. Learn about available plugins, promptbooks, the ways you can export and share information from Copilot, and much more.
Lessons:
- Describe the features available in the standalone experience of Microsoft Security Copilot
- Describe the features available in a session of the standalone experience
- Describe workspaces
- Describe Security Copilot plug-ins
- Describe custom promptbooks
- Describe knowledge base connections
Exercise:
- None
Module 4: Describe the embedded experiences of Microsoft Security Copilot
Microsoft Security Copilot is accessible directly from some Microsoft security products. This is referred to as the embedded experience. Learn about the scenarios supported by the Copilot embedded experience in Microsoft’s security solutions.
Lessons:
- Describe Copilot in Microsoft Defender XDR
- Copilot in Microsoft Purview
- Copilot in Microsoft Entra
- Copilot in Microsoft Intune
- Copilot in Microsoft Defender for Cloud
Exercise:
- None
Module 5: Describe Microsoft Security Copilot agents
Automate threat detection and response with Microsoft Security Copilot agents—AI-powered tools that streamline cybersecurity operations, reduce manual workloads, and scale protection across your digital environment.
Lessons:
- Describe Microsoft Copilot Security agents
- Understand agent identities and permissions
- Describe the Security Copilot agents in Microsoft Entra
- Describe the Security Copilot agents in Microsoft Defender
- Explore the Describe the Security Copilot agents in Microsoft Purview
- Describe the Security Copilot agents in Microsoft Intune
- Describe the agents in the Security Copilot standalone experience
- Build your own agents
Exercise:
- None
Module 6: Experience Security Copilot through guided simulations
Explore use cases of Microsoft Security Copilot in the standalone and embedded experiences, through lab-like exercises.
Lessons:
- Introduction
Simulations:
- Explore owner settings in Security Copilot
- Explore Use prompts and promptbooks in Security Copilot
- Create a custom promptbook in Security Copilot
- Investigate data protection activity in Microsoft Purview
- Investigate insider risks and compliance in Microsoft Purview
- Investigate security incidents in Microsoft Defender XDR
- Explore and create an agent in Security Copilot
- Explore the Conditional Access Optimization Agent
Audience
This course is targeted to security professionals interested in getting started with Microsoft Security Copilot, including security analysts, security admins, and SOC managers.
The person taking this course is looking to familiarize themselves with the functionality of Microsoft Security Copilot in both the standalone and embedded experiences. They should have working knowledge of security operations and incident response, experience with Microsoft security products and services, and is interested in learning how Microsoft Security Copilot, an AI-powered security analysis tool, can help them process security signals and respond to threats more quickly.
Prerequisites
They should have working knowledge of:
- Security operations and incident response.
- Experience with Microsoft security products and services.
- And is interested in learning how Microsoft Security Copilot, an AI-powered security analysis tool, can help them process security signals and respond to threats more quickly.