---
title: "Microsoft Security Copilot, Security · SecOps Agent · Agent Fieldbook"
url: https://agentfieldbook.org/catalog/agents/sec-copilot/
description: "Investigates incidents and executes security workflows; Agent 365 is the enterprise control plane with shadow-AI discovery and network-level…"
section: "Catalogue · Agents · security"
source: Agent Fieldbook — generated from the published page
---

# Microsoft Security Copilot

**Security · SecOps Agent · Confirmed**

Investigates incidents and executes security workflows; Agent 365 is the enterprise control plane with shadow-AI discovery and network-level prompt-injection blocking.

Verified against [techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213)· 2026-06-16

- [techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213)

## Spec sheet

| Field | Value |
| --- | --- |
| Foundation | OpenAI (Azure) |
| Topology | sentinel |
| Type | agent |
| Deployment | cloud |
| Interface | api· soar |
| Scale | 15+ partner agents· Agent 365 control plane |
| Tools | SOAR· SIEM· EDR connectors |
| Orchestration | Agentic SOC |
| Safety | SOC 2· Microsoft governance |
| Country | US |
| Verified | 2026-06-16 |

## Sources

## Verified against

- [https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213](https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213)

The corpus does not rewrite vendor documentation. Where copy is quoted verbatim it is marked as such and attributed to its source.
