Microsoft reports a randomized controlled trial of its own Security Copilot Phishing Triage Agent. In the trial, 167 external security analysts each triaged a 25-email queue drawn from a curated corpus of emails reported by Microsoft employees. In the scenario where the agent classified every corpus email correctly, analysts with the agent found 6.5 times as many true positives per minute as the control group and scored 77% higher on F1; with the agent's accuracy set to 80% and a 20% malicious rate, the productivity gain fell to 3.1 times. Analysts with the agent spent 53% more time on malicious emails and did not simply confirm its malicious verdicts, but they were more likely to accept its benign verdicts, including planted false negatives.
Microsoft Security Copilot
Microsoft's generative AI assistant and agents for security operations.
Records citing Microsoft Security Copilot
Microsoft announced Microsoft-built Security Copilot agents, including a Phishing Triage Agent in Defender, alert triage agents in Purview, a Conditional Access Optimization Agent, a Vulnerability Remediation Agent in Intune and a Threat Intelligence Briefing Agent, plus five partner agents. Preview was planned from April 2025; the announcement contains no evaluation of agent accuracy.
Microsoft economists ran randomized controlled trials in which novices and security professionals completed incident summarization, script analysis, incident report and guided response tasks in a Defender XDR test environment, with half given Security Copilot. The January 2024 revision reports that novices with Copilot answered 35% more questions correctly and professionals were 7% more accurate, with both groups completing tasks faster.