Security Copilot support for Azure Lighthouse in Microsoft Sentinel 🔥
Security Copilot support for Azure Lighthouse in Microsoft Sentinel use cases for Managed Security Service Providers (MSSPs) is now available in Public Preview—a significant step forward for MSSPs managing multiple customers.
🔐 What's included?
✅ Simplified Deployment – MSSPs can now purchase Security Compute Units (SCUs) once and attach them directly to their managing tenant in Azure Lighthouse. This enables MSSPs to invoke Sentinel-specific Security Copilot skills across their customer tenants—without customers needing their own Security Copilot licences.
✅ Expanded Sentinel Skillset – MSSPs can leverage natural language prompts, query Sentinel incidents, access incident details, fetch workspace queries, and create custom promptbooks to automate investigations and streamline security operations.
✅ Automation & Efficiency – Easily integrate Sentinel promptbooks with Logic Apps to trigger automated workflows, enabling MSSPs to respond swiftly and efficiently to threats across multiple customer environments.
🔑 Access Controls & GDAP Integration:
✅ GDAP (Granular Delegated Admin Privileges) – MSSPs managing Microsoft 365 services can use GDAP to securely access customer environments. With GDAP, MSSPs can leverage the complete Security Copilot skillset (including Entra, Defender, Intune, Purview, and XDR) directly in customer environments, using customer-owned SCUs.
📖 Want to learn more?
MS Tech Community: Azure Lighthouse support for MSSP use of Security Copilot Sentinel scenarios in Public Preview | Microsoft Community Hub
#CyberSecurity #AzureLighthouse #MSSP #SecurityCopilot #MicrosoftSentinel #ManagedSecurity #Automation #ThreatResponse #AIinSecurity #GDAP #Microsoft365 #ManagedServices #MSPartner #BusinessGrowth #MicrosoftSecurity