Session

Unlocking Microsoft Security Copilot Agents: Practical Use Cases for Modern SOC Automation

In this session, I explore the power of Microsoft Security Copilot’s agentic AI model and demonstrate how Security Copilot agents transform modern SOC operations through automation, context‑aware reasoning, and workflow optimization. I explain what Security Copilot agents are, their core features, and the key terminology behind Microsoft’s agentic ecosystem—including skills, adapters, memory, grounding, and orchestrators—so attendees understand how they interact with platforms like Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Entra. I then walk through practical examples such as the Conditional Access Optimization Agent, which analyzes and improves Conditional Access policies; the Phishing Triage Agent, which automates the investigation of suspicious emails and accelerates analyst decision‑making; and the Threat Intelligence Briefing Agent, which synthesizes threat intelligence feeds and organizational exposure into actionable reporting. I conclude by clarifying how Security Copilot capabilities are included within the Microsoft 365 E5 subscription and what organizations gain by leveraging these agents in real-world SOC workflows. Attendees will leave with practical knowledge of how I use Security Copilot agents to reduce operational overhead, build Al agent and improve detection quality, and enhance overall security posture.

Uros Babic

Global Product Engineer - Microsoft Security DevOps at SoftwareOne, Microsoft Security MVP, MCT

Belgrade, Serbia

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top