Microsoft Security Copilot Entra Update and Conditional Access Agent

THE SUMMARYAI-generated

Key Concepts

  • Microsoft Security Copilot: An AI assistant for security roles, aiding in understanding security posture, threat detection, and mitigation.
  • Entra Skill: A new, comprehensive skill within Security Copilot that replaces eight separate, limited skills.
  • Microsoft Graph: The foundation for the Entra skill, enabling complex queries and access to data across Microsoft services.
  • Conditional Access Agent (CA Agent): An automated agent that identifies users and applications not covered by conditional access policies and suggests remediation.
  • Natural Language to Graph Query Conversion: The process of translating natural language requests into Microsoft Graph queries for more comprehensive data retrieval.
  • Sidecar/Embedded Experience: Accessing Security Copilot directly within Microsoft portals like Entra.microsoft.com.
  • Few-Shot Learning: Using examples to improve the quality of generative AI responses.

Microsoft Security Copilot Overview

The video discusses significant updates to Microsoft Security Copilot, focusing on its integration with Microsoft Entra and the introduction of a Conditional Access Agent. Security Copilot acts as an AI assistant, helping security professionals understand their security posture, detect threats, and mitigate risks.

Security Copilot Experiences

There are two primary ways to access Security Copilot:

  1. Security Copilot Site: A standalone experience accessible via securitycopilot.microsoft.com. It offers guidance for prompts and connects to various skills from Microsoft and third parties. Users can adjust the skills used for queries.
  2. Sidecar/Embedded Experience: Integrated directly into Microsoft portals like entra.microsoft.com. A co-pilot button activates a sidecar, providing suggested prompts and utilizing source-specific skills (e.g., Entra skills within the Entra portal).

Enhanced Entra Integration

Replacement of Separate Skills

Previously, Security Copilot had eight separate, limited skills related to Entra (e.g., users, risky users, audit logs). These have been replaced by a single, comprehensive "Entra skill."

Microsoft Graph Foundation

The new Entra skill is based on the Microsoft Graph, allowing it to access data from Entra, Office, Intune, and other services.

Natural Language to Graph Query Conversion

The core improvement is the ability to convert natural language requests into Microsoft Graph queries. This enables more complex reasoning and broader scope.

  • The system uses a special module and a knowledge base (similar to retrieval augmented generation) to formulate the correct graph queries.
  • Specific Entra teams contribute "few-shot" examples to improve query quality.
  • The system can perform multiple iterations to get the desired answer.

Security and Permissions

Security Copilot operates "on behalf of" the user, respecting their existing permissions. It cannot perform actions the user is not authorized to do. It currently only supports read operations for investigation purposes.

Examples

  • In the Entra portal, a user can ask "list the global admins." Security Copilot formulates the necessary graph calls and displays the results.
  • A follow-up question like "do they have pass keys enabled?" leverages the context of the previous query.
  • In the Security Copilot site, a user can ask "what risky users in my Entra tenant are also group owners?" The system shows the steps it takes, such as finding risky users, checking if they are group owners, and identifying the groups they own.

Conditional Access Agent (CA Agent)

Purpose

The CA Agent addresses the issue of new users and applications "falling between the cracks" of conditional access policies. It automates the process of identifying these gaps and suggesting remediation.

Functionality

  • The agent runs every 24 hours (or can be triggered manually).
  • It looks for:
    • App drift: New applications not covered by CA policies.
    • User drift: New users not covered by CA policies.
    • Policy merge opportunities: Redundant policies that can be combined.
  • It suggests adding users to groups (best practice) rather than directly to policies. If a suitable group already exists, it recommends adding the user to that group.

Operation

The agent ties into the Microsoft Graph and runs on a 24-hour interval. It identifies new users or applications not in a CA scope. It also looks for conditional access policies that could be merged.

Suggestions and Remediation

The agent provides suggestions for remediation, such as adding a user to a group that is already in scope of a policy. Users can review and apply these suggestions.

Custom Instructions

Users can configure custom instructions to exclude specific users or groups from the agent's scope (e.g., break-glass accounts).

Example

The video shows an example where the agent identified an unprotected user and suggested adding them to an existing policy. The user can review and apply the suggestion.

Conclusion

The updates to Microsoft Security Copilot, particularly the enhanced Entra integration and the Conditional Access Agent, represent significant advancements in security management. The natural language to graph query conversion enables more comprehensive data retrieval and analysis, while the CA Agent automates the identification and remediation of policy gaps. These features aim to reduce the burden on security professionals and improve overall security posture.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.