What's changed: Added per-section figures (cert-figure-retrofit). New SC-500 Chapter 4 (Domain 4 "Manage and monitor posture": Defender for Cloud = CSPM(recommendations/Secure Score/attack paths/regulatory compliance)-CWP plans-multicloud(AWS/GCP)-Defender Vulnerability Management-EASM; Microsoft Sentinel = workspaces/roles/content hub/data connectors/Syslog-CEF/Windows events(DCR-WEF)/custom tables/automation rules-playbooks/data retention/Purview Audit in Defender XDR; Microsoft Security Copilot = workspaces/permissions-roles/plugins/Microsoft-Security Store agents)
4.3Microsoft Security Copilot
Learn Microsoft Security Copilot, which applies generative AI to security operations: configuring workspaces, managing permissions and roles, enabling and configuring plugins, and enabling and configuring Microsoft agents and Security Store agents.
Microsoft Security Copilot brings generative AI to security operations (SecOps), enabling natural-language incident summarization, KQL generation assistance, threat explanation, and response guidance. SC-500 focuses less on feature minutiae and more on "how to configure and govern it safely" (workspaces, permissions, plugins, agents).
4.3.1Workspaces and permissions/roles
Configure a Security Copilot workspace and allocate capacity such as Security Compute Units (SCUs). Control access with permissions and roles, managing who can use Copilot and which data sources (via plugins) they can reach, with least privilege. By design, Copilot should operate within the user’s existing permissions in connected products (Defender, Sentinel, Intune, Entra, etc.).
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

