{"id":29924,"date":"2025-06-10T16:09:36","date_gmt":"2025-06-10T14:09:36","guid":{"rendered":"https:\/\/my-iam.com\/?p=29924"},"modified":"2025-06-26T12:18:30","modified_gmt":"2025-06-26T10:18:30","slug":"security-copilot-in-entra-id-best-practices-for-administrators","status":"publish","type":"post","link":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/","title":{"rendered":"Security Copilot in Entra ID: Best Practices for Administrators"},"content":{"rendered":"<p><strong>What if your security department could think ahead 24\/7?<\/strong><br \/>\n<a class=\"\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/ai-machine-learning\/microsoft-security-copilot\" target=\"_new\" rel=\"noopener\">Microsoft Security Copilot<\/a> brings exactly that to Entra ID\u2014with AI-powered analysis and risk evaluation. Intelligent security solutions are transforming the role of identity and security administrators. Unlike other Copilot experiences in Microsoft 365 or Azure, <strong>Security Copilot<\/strong> is designed to accelerate security decisions and back them with contextual intelligence.<\/p>\n<p>Instead of generating text or simplifying administrative workflows, Security Copilot focuses on incident response, risk analysis, threat intelligence, and real-time protection\u2014powered by generative AI based on GPT-4 and Microsoft\u2019s own security model. This article gives you a comprehensive overview of how to use Microsoft Security Copilot in Entra ID to strengthen your security operations and make fast, informed decisions.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter ez-toc-white ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Index<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Efficient_Risk_Detection_and_Damage_Control_with_Security_Copilot\" >Efficient Risk Detection and Damage Control with Security Copilot<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Understanding_Capacity_Model_and_SCU_Logic\" >Understanding Capacity Model and SCU Logic<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Securing_Entra_ID_in_Azure_with_Copilot_Features\" >Securing Entra ID in Azure with Copilot Features<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Prompts_in_the_Entra_Admin_Center\" >Prompts in the Entra Admin Center<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Two-Step_Security_Copilot_Onboarding\" >Two-Step Security Copilot Onboarding<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Best_practices_for_working_with_Copilot_in_Microsoft_Entra_ID\" >Best practices for working with Copilot in Microsoft Entra ID<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#%E2%9C%85_Top_5_best_practices_for_Copilot_in_Entra_ID\" >\u2705 Top 5 best practices for Copilot in Entra ID<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Insight_into_sign-in_behavior_and_audit_logs\" >Insight into sign-in behavior and audit logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Group_Analysis_and_Access_Rights_Management\" >Group Analysis and Access Rights Management<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#Analysis_of_Application_Risks_and_Service_Principals\" >Analysis of Application Risks and Service Principals<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#More_about_the_my-IAM_platform\" >More about the my-IAM platform<\/a><\/li><\/ul><\/nav><\/div>\n<h3><span class=\"ez-toc-section\" id=\"Efficient_Risk_Detection_and_Damage_Control_with_Security_Copilot\"><\/span>Efficient Risk Detection and Damage Control with Security Copilot<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In Microsoft Entra ID, Security Copilot shows its strength particularly in:<\/p>\n<ul>\n<li>\n<p><strong>Analyzing sign-in events<\/strong>,<\/p>\n<\/li>\n<li>\n<p><strong>Identifying compromised accounts<\/strong>, and<\/p>\n<\/li>\n<li>\n<p><strong>Evaluating risks associated with user identities and applications<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<p>Admins can use natural language queries to request information\u2014for example, about risky users, major policy changes, or permission modifications. Copilot then provides actionable recommendations, highlights unusual activity, and offers contextual guidance for damage control.<\/p>\n<p>The Entra integration also enables access to audit logs, sign-in logs, and role-based access data, which are automatically scanned for suspicious patterns. This turns Copilot in Entra ID into a tactical tool that not only speeds up identity-related security operations, but also improves them strategically.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-05-1024x856.jpg\" alt=\"Copilot for Security\" \/><\/p>\n<h3><span class=\"ez-toc-section\" id=\"Understanding_Capacity_Model_and_SCU_Logic\"><\/span>Understanding Capacity Model and SCU Logic<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>Using Security Copilot requires strategic resource planning.<\/strong><br \/>\nMicrosoft charges usage based on Security Compute Units (SCUs). These are billed hourly and can be scheduled or consumed flexibly through so-called overage units.<\/p>\n<p>Billing is done in blocks: any started hour counts as a full unit\u2014whether you use it for 5 or 55 minutes. Overage usage, however, is billed by the minute. For example, if you activate an SCU at 9:05 AM, end it at 9:35 AM, and start a new one at 9:45 AM, you\u2019ll be billed for two full SCUs for the 9:00\u201310:00 AM window.<\/p>\n<p>Accessing Security Copilot requires at least one provisioned SCU.<\/p>\n<p>\ud83d\udc49 For a smooth start, <a class=\"\" href=\"https:\/\/learn.microsoft.com\/en-us\/copilot\/security\/get-started-security-copilot#note\" target=\"_new\" rel=\"noopener\">Microsoft recommends<\/a> a configuration with three SCUs and unlimited overage capacity.<br \/>\nThis setup ensures stable response times even during traffic spikes. Important: SCUs for Security Copilot are <strong>not compatible<\/strong> with those used for Microsoft Purview\u2014each must be licensed separately.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Securing_Entra_ID_in_Azure_with_Copilot_Features\"><\/span>Securing Entra ID in Azure with Copilot Features<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>In Microsoft Azure, Entra ID can also be secured using AI features provided by the general <strong>Azure Copilot<\/strong>. This version differs significantly from the specialized Security Copilot\u2014it primarily supports the configuration and management of Azure resources through explanations, automated suggestions, and code generation.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/azure-copilot-01-1024x728.png\" alt=\"Azure Copilot\" \/><\/p>\n<p>In the Entra ID context, Azure Copilot can help with <strong>setting up Conditional Access Policies<\/strong>, <strong>role concepts<\/strong>, or <strong>building hybrid identity models<\/strong>.<\/p>\n<p>While Security Copilot focuses on <strong>threat analysis, incident response, and risk-based decision-making<\/strong>, Azure Copilot assists with structural tasks and helps optimize security policies during the design phase.<\/p>\n<p>\ud83d\udc49 The two tools complement each other: one works strategically in security operations, the other supports secure configuration and implementation.<\/p>\n<p>Even without full Security Copilot access, Azure Copilot can still provide contextual, real-time analysis of security-related data. Particularly in identity and access management, it can uncover potential vulnerabilities, evaluate policies, and analyze user activity efficiently. It draws on the same Entra identity data as Security Copilot, but remains within the Entra portal interface and <strong>targets administrators focused on identity governance<\/strong>.<\/p>\n<p>The key <strong>advantage<\/strong> is its <strong>low barrier to entry<\/strong>: it can be launched directly from the ribbon and <strong>does not require separate SCU provisioning<\/strong>.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Prompts_in_the_Entra_Admin_Center\"><\/span>Prompts in the Entra Admin Center<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Security Copilot uses <strong>simple natural language prompts<\/strong> that are instantly processed and visualized.<\/p>\n<ul>\n<li>\n<p>Prompt: <em>\u201cWhich users did not use multi-factor authentication in the past 24 hours?\u201d<\/em> \u2192 Identifies potentially vulnerable accounts.<\/p>\n<\/li>\n<li>\n<p>Prompt: <em>\u201cWhat changes were made to the \u2018User Administrator\u2019 role?\u201d<\/em> \u2192 Lists all role assignments and removals with timestamps and the initiating account.<\/p>\n<\/li>\n<li>\n<p>Prompt: <em>\u201cShow me all groups with more than 50 members and external access.\u201d<\/em> \u2192 Filters potentially over-privileged groups.<\/p>\n<\/li>\n<\/ul>\n<p>Copilot responds with structured answers, clear tables, and direct links to relevant admin areas. This helps even less experienced admins make informed security decisions.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Two-Step_Security_Copilot_Onboarding\"><\/span>Two-Step Security Copilot Onboarding<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Unlike Azure Copilot, <strong>Security Copilot must be set up first<\/strong>. Onboarding happens in two steps.<\/p>\n<p>First, you provision capacity via the Security Copilot portal or the Azure portal. Then, you assign this capacity to the default Entra ID environment. Roles with minimal necessary rights (e.g., Intune Admin or Entra Compliance Admin) should be used whenever possible. Global admin privileges should be reserved for emergencies.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-03-1024x530.png\" alt=\"Security Copilot Onboarding\" \/><\/p>\n<p>During capacity setup, you can choose a geographic location. If the selected region is overloaded, prompts may be processed in a globally available fallback region. Once everything is configured, the dashboard allows you to monitor usage minute-by-minute\u2014including SCUs in use and overage capacity. Data access always stays within the tenant\u2019s geographic region.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Best_practices_for_working_with_Copilot_in_Microsoft_Entra_ID\"><\/span>Best practices for working with Copilot in Microsoft Entra ID<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>With the integration of <strong>Security Copilot into Microsoft Entra<\/strong>, new opportunities arise in identity and access management. Copilot supports admins and security teams by intelligently linking data from Entra, Microsoft Sentinel, Defender, and other sources\u2014and generating actionable recommendations from it.<\/p>\n<p>Security Copilot analyzes login events, group memberships, and access policies in real time\u2014embedded in the context of current or past security incidents. The AI detects suspicious patterns, summarizes threat situations, and suggests concrete actions, such as quarantining compromised accounts or initiating an escalation.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"%E2%9C%85_Top_5_best_practices_for_Copilot_in_Entra_ID\"><\/span>\u2705 <strong>Top 5 best practices for Copilot in Entra ID<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ol>\n<li><strong>Use precise prompts<\/strong><br \/>\nThe more targeted the query, the better the results. Avoid general questions\u2014use context-specific prompts instead.<\/li>\n<li><strong>Trust, but validate<\/strong><br \/>\nCopilot provides well-founded insights\u2014however, they should always be validated manually or with complementary tools like Sentinel.<\/li>\n<li><strong>Integrate into daily workflows<\/strong><br \/>\nThe more Copilot is embedded into daily routines, the more effectively it supports tasks\u2014especially in early risk detection.<\/li>\n<li><strong>Enforce role-based access control<\/strong><br \/>\nOnly authorized users should be able to query security-critical information\u2014achieved through finely tuned Entra role assignments.<\/li>\n<li><strong>Combine Copilot with other security solutions<\/strong><br \/>\nCopilot delivers the most value when used alongside tools like Microsoft Sentinel, Defender for Identity, and Defender for Endpoint.<\/li>\n<\/ol>\n<p>By entering \u201cSummarize the risk details of the user Max.Mustermann@contoso.com\u201d, Security Copilot generates a compact overview of detected anomalies and risk detections, such as unusual login attempts, the use of insecure authentication methods or violations of access policies.<\/p>\n<p>The second prompt, \u201cWhich devices has <a class=\"cursor-pointer\" rel=\"noopener\" data-start=\"125\" data-end=\"151\">Max.Mustermann@contoso.com<\/a> registered?\u201d, provides a list of the end devices connected to this account. It also includes details such as the operating system, device status, and compliance status. <strong data-start=\"371\" data-end=\"386\">As a result<\/strong>, it creates a comprehensive overview of the user&#8217;s environment. <strong data-start=\"451\" data-end=\"469\">Taken together<\/strong>, this information forms a solid basis for decision-making, <strong data-start=\"529\" data-end=\"556\">allowing administrators<\/strong> to initiate actions such as enforcing MFA, cleaning up devices, <strong data-start=\"621\" data-end=\"627\">or<\/strong> temporarily blocking the account <strong data-start=\"661\" data-end=\"677\">if necessary<\/strong>.<\/p>\n<p>Copilot not only identifies patterns such as logins from unusual IP addresses, but also detects the use of new devices and repeated failed authentication attempts, which may indicate suspicious activity.This information serves as the basis for automated recommendations for action.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Insight_into_sign-in_behavior_and_audit_logs\"><\/span>Insight into sign-in behavior and audit logs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Security Copilot also demonstrates its strengths when analyzing user activities. Administrators can <strong>specifically search for activities of certain users<\/strong>, for example, related to role assignments, policy changes, or group modifications. For this purpose, Copilot accesses the <strong>audit logs of Entra ID and presents the results structured in natural language.<\/strong><\/p>\n<p>With targeted prompts, <strong>deep insights into user activities can be gained<\/strong> that are indispensable for forensic analyses or validating security-critical processes. The command \u201c<em>Show me all activities of Max.Mustermann@contoso.com in the audit logs of the last 72 hours<\/em>\u201d retrieves all logged changes and actions of this user within the specified period. These include, among others, role assignments, policy changes, app accesses, or administrative interventions, which can be traced precisely over time.<\/p>\n<p>Additionally, the prompt \u201c<em>List the last 20 sign-in attempts of Max.Mustermann@contoso.com with status and device<\/em>\u201d provides a <strong>chronological overview of successful and failed logins<\/strong>, including metadata such as IP address, browser used, and device. This combination of audit and sign-in information enables precise investigation of suspicious activities and supports quick risk assessment on the user level.<\/p>\n<p><img decoding=\"async\" class=\"imgshadow wp-image-29914 size-full aligncenter\" title=\"Investigation of suspicious activities with Copilot for Security\" src=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-01.png\" alt=\"Investigation of suspicious activities with Copilot for Security\" width=\"807\" height=\"428\" srcset=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-01.png 807w, https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-01-300x159.png 300w, https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-01-768x407.png 768w\" sizes=\"(max-width: 807px) 100vw, 807px\" \/><\/p>\n<p>If needed, the results can be formatted as tables and exported. Copilot provides information about the devices used, browsers employed, success or failure of the sign-in, and checks whether the devices are compliant and managed.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Group_Analysis_and_Access_Rights_Management\"><\/span>Group Analysis and Access Rights Management<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p data-start=\"90\" data-end=\"332\"><strong data-start=\"90\" data-end=\"108\">In addition to<\/strong> analyzing individual user data, Copilot <strong data-start=\"149\" data-end=\"190\">also allows administrators to examine<\/strong> the group structure. <strong data-start=\"212\" data-end=\"241\">This is especially useful<\/strong> when reviewing permission inheritance <strong data-start=\"280\" data-end=\"286\">or<\/strong> investigating potentially compromised groups.<\/p>\n<p><strong>Group-based analyses can also be efficiently performed with Security Copilot.<\/strong> The prompt \u201c<em>How many members does the group \u2018Finance-External\u2019 have?<\/em>\u201d delivers an exact number of active user accounts within the specified group, allowing for a quick assessment of its size and potential attack surface.<\/p>\n<p>More detailed is the command \u201c<em>Show me the email address, job title, and phone number of all members of the \u2018IT Project Management\u2019 group<\/em>.\u201d This query provides a complete overview of all assigned users, including their organizational roles and contact information. With this data, you can specifically evaluate which groups have which accesses and permissions, e.g., during audits or security checks. These functions are available both in the standalone Copilot portal and directly embedded in the Entra interface. The embedded version allows working without context switching and performing security analyses directly from the user interface.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Analysis_of_Application_Risks_and_Service_Principals\"><\/span>Analysis of Application Risks and Service Principals<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Another focus lies on the <strong>management and assessment of applications and service principals<\/strong>. Administrators have access to features that identify risky applications, detect excessive permissions, and uncover unused registrations.<\/p>\n<p><strong>Particularly critical:<\/strong> applications with high privileges that are registered outside the tenant itself, a common attack vector for lateral movements by attackers.<\/p>\n<p><img decoding=\"async\" class=\"imgshadow aligncenter wp-image-29917 size-full\" title=\"Managing plugins with Copilot for Security\" src=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-04.jpg\" alt=\"Managing plugins with Copilot for Security\" width=\"672\" height=\"904\" srcset=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-04.jpg 672w, https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-04-223x300.jpg 223w\" sizes=\"(max-width: 672px) 100vw, 672px\" \/><\/p>\n<p>The assessment of these risks is based on signals stored in Microsoft Entra ID Protection. Administrators can use Copilot to automatically receive recommended actions, such as restricting rights or disabling unnecessary applications.<\/p>\n<p>The prompt \u201c<em>Show me all risky applications in my tenant<\/em>\u201d delivers a <strong>curated list of applications<\/strong>. Copilot evaluates them based on identity protection signals, including risky permissions, suspicious usage patterns, or expired certificates.<\/p>\n<p>The query \u201cWhich applications were registered outside my tenant and are active?\u201d reveals external apps. These apps have active service principals in your tenant. This is a possible risk factor for uncontrolled third-party access.<\/p>\n<p>The prompt \u201cWhat delegated permissions does the app \u2018HR-SelfService\u2019 have?\u201d breaks down the <strong>app\u2019s delegated permissions<\/strong>. It shows which rights the app receives on behalf of the signed-in user and whether it accesses sensitive data excessively.<\/p>\n<p>The input \u201c<em>Show me all service principals with admin roles<\/em>\u201d provides a comprehensive <strong>overview of technical identities that hold privileged access rights<\/strong>. These identities often pose an increased risk of attack due to their elevated permissions. Additionally, the analysis triggered by the prompt \u201c<em>Which applications have not been used for 90 days?<\/em>\u201d helps identify outdated or orphaned applications. Such applications are frequently overlooked but can represent significant security vulnerabilities. Regularly reviewing these can reduce the attack surface and improve overall tenant security.<\/p>\n<p>\ud83d\udc49 We are happy to show you how Security Copilot and my-IAM together provide more overview, security, and automation.<\/p>\n<p><a href=\"https:\/\/my-iam.com\/en\/book-a-demo\/\" rel=\"noopener\"><button class=\"ButtonBeratung aligncenter\">Contact our team<\/button><\/a><\/p>\n<h2><span class=\"ez-toc-section\" id=\"More_about_the_my-IAM_platform\"><\/span>More about the my-IAM platform<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><img decoding=\"async\" class=\"alignleft wp-image-28423\" title=\"my-IAM platform\" src=\"https:\/\/my-iam.com\/wp-content\/uploads\/2024\/08\/my-IAM-platform-logo-210x300.png\" alt=\"my-IAM platform\" width=\"110\" height=\"157\" srcset=\"https:\/\/my-iam.com\/wp-content\/uploads\/2024\/08\/my-IAM-platform-logo-210x300.png 210w, https:\/\/my-iam.com\/wp-content\/uploads\/2024\/08\/my-IAM-platform-logo.png 491w\" sizes=\"(max-width: 110px) 100vw, 110px\" \/>The my-IAM platform unifies all identities from various source systems and makes them available for applications and apps of all kinds. Besides the Teams-integrated app <a href=\"https:\/\/my-iam.com\/en\/peopleconnect\/\">my-IAM PeopleConnect<\/a>, it includes the business services <a href=\"https:\/\/my-iam.com\/en\/realidentity\/\">my-IAM RealIdentity<\/a> and <a href=\"https:\/\/my-iam.com\/en\/realgroup\/\">my-IAM RealGroup<\/a>.<\/p>\n<p><a href=\"https:\/\/my-iam.com\/en\/book-a-demo\/\" rel=\"noopener\"><button class=\"ButtonBeratung2 aligncenter\">Book an online demo now<\/button><\/a><\/p>\n<p style=\"text-align: center;\">You can also reach our team by phone at<br \/>\n<a href=\"tel:+4981969984330\"><strong>+49 8196 998 4330<\/strong><\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What if your security department could think ahead 24\/7? Microsoft Security Copilot brings exactly that to Entra ID\u2014with AI-powered analysis [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3213,150],"tags":[3456,3457,3458],"class_list":["post-29924","post","type-post","status-publish","format-standard","hentry","category-entra-id-en","category-news","tag-azure-copilot-en","tag-ki-en","tag-security-copilot-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Security Copilot in Entra ID: Best Practices for Administrators - my-IAM<\/title>\n<meta name=\"description\" content=\"Practical tips on Security Copilot in Entra ID: AI-supported analyses, risk assessment and incident response for identity security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Copilot in Entra ID: Best Practices for Administrators - my-IAM\" \/>\n<meta property=\"og:description\" content=\"Practical tips on Security Copilot in Entra ID: AI-supported analyses, risk assessment and incident response for identity security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/\" \/>\n<meta property=\"og:site_name\" content=\"my-IAM\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/firstattribute\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-10T14:09:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-26T10:18:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-05-1024x856.jpg\" \/>\n<meta name=\"author\" content=\"Elysabeth Yven\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Elysabeth Yven\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/\"},\"author\":{\"name\":\"Elysabeth Yven\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#\\\/schema\\\/person\\\/cb96a6c7bc8321c5a023ea9fccd6f359\"},\"headline\":\"Security Copilot in Entra ID: Best Practices for Administrators\",\"datePublished\":\"2025-06-10T14:09:36+00:00\",\"dateModified\":\"2025-06-26T10:18:30+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/\"},\"wordCount\":1936,\"publisher\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/my-iam.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/copilot-05-1024x856.jpg\",\"keywords\":[\"Azure Copilot\",\"KI\",\"Security Copilot\"],\"articleSection\":[\"Entra ID\",\"News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/\",\"url\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/\",\"name\":\"Security Copilot in Entra ID: Best Practices for Administrators - my-IAM\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/my-iam.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/copilot-05-1024x856.jpg\",\"datePublished\":\"2025-06-10T14:09:36+00:00\",\"dateModified\":\"2025-06-26T10:18:30+00:00\",\"description\":\"Practical tips on Security Copilot in Entra ID: AI-supported analyses, risk assessment and incident response for identity security.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/#primaryimage\",\"url\":\"https:\\\/\\\/my-iam.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/copilot-05-1024x856.jpg\",\"contentUrl\":\"https:\\\/\\\/my-iam.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/copilot-05-1024x856.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/en\\\/security-copilot-in-entra-id-best-practices-for-administrators\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\\\/\\\/my-iam.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Copilot in Entra ID: Best Practices for Administrators\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/my-iam.com\\\/de\\\/\",\"name\":\"my-IAM\",\"description\":\"Identity Access Management, Active Directory Spezialisten\",\"publisher\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/my-iam.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#organization\",\"name\":\"my-IAM\",\"url\":\"https:\\\/\\\/my-iam.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/my-iam.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/Logo-my-IAM-blau-512-150x150-2.png\",\"contentUrl\":\"https:\\\/\\\/my-iam.com\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/Logo-my-IAM-blau-512-150x150-2.png\",\"width\":200,\"height\":200,\"caption\":\"my-IAM\"},\"image\":{\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/firstattribute\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/my-iam.com\\\/de\\\/#\\\/schema\\\/person\\\/cb96a6c7bc8321c5a023ea9fccd6f359\",\"name\":\"Elysabeth Yven\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Copilot in Entra ID: Best Practices for Administrators - my-IAM","description":"Practical tips on Security Copilot in Entra ID: AI-supported analyses, risk assessment and incident response for identity security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/","og_locale":"en_US","og_type":"article","og_title":"Security Copilot in Entra ID: Best Practices for Administrators - my-IAM","og_description":"Practical tips on Security Copilot in Entra ID: AI-supported analyses, risk assessment and incident response for identity security.","og_url":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/","og_site_name":"my-IAM","article_publisher":"https:\/\/www.facebook.com\/firstattribute","article_published_time":"2025-06-10T14:09:36+00:00","article_modified_time":"2025-06-26T10:18:30+00:00","og_image":[{"url":"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-05-1024x856.jpg","type":"","width":"","height":""}],"author":"Elysabeth Yven","twitter_misc":{"Written by":"Elysabeth Yven","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#article","isPartOf":{"@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/"},"author":{"name":"Elysabeth Yven","@id":"https:\/\/my-iam.com\/de\/#\/schema\/person\/cb96a6c7bc8321c5a023ea9fccd6f359"},"headline":"Security Copilot in Entra ID: Best Practices for Administrators","datePublished":"2025-06-10T14:09:36+00:00","dateModified":"2025-06-26T10:18:30+00:00","mainEntityOfPage":{"@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/"},"wordCount":1936,"publisher":{"@id":"https:\/\/my-iam.com\/de\/#organization"},"image":{"@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#primaryimage"},"thumbnailUrl":"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-05-1024x856.jpg","keywords":["Azure Copilot","KI","Security Copilot"],"articleSection":["Entra ID","News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/","url":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/","name":"Security Copilot in Entra ID: Best Practices for Administrators - my-IAM","isPartOf":{"@id":"https:\/\/my-iam.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#primaryimage"},"image":{"@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#primaryimage"},"thumbnailUrl":"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-05-1024x856.jpg","datePublished":"2025-06-10T14:09:36+00:00","dateModified":"2025-06-26T10:18:30+00:00","description":"Practical tips on Security Copilot in Entra ID: AI-supported analyses, risk assessment and incident response for identity security.","breadcrumb":{"@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#primaryimage","url":"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-05-1024x856.jpg","contentUrl":"https:\/\/my-iam.com\/wp-content\/uploads\/2025\/06\/copilot-05-1024x856.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/my-iam.com\/en\/security-copilot-in-entra-id-best-practices-for-administrators\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/my-iam.com\/en\/"},{"@type":"ListItem","position":2,"name":"Security Copilot in Entra ID: Best Practices for Administrators"}]},{"@type":"WebSite","@id":"https:\/\/my-iam.com\/de\/#website","url":"https:\/\/my-iam.com\/de\/","name":"my-IAM","description":"Identity Access Management, Active Directory Spezialisten","publisher":{"@id":"https:\/\/my-iam.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/my-iam.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/my-iam.com\/de\/#organization","name":"my-IAM","url":"https:\/\/my-iam.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/my-iam.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/my-iam.com\/wp-content\/uploads\/2021\/07\/Logo-my-IAM-blau-512-150x150-2.png","contentUrl":"https:\/\/my-iam.com\/wp-content\/uploads\/2021\/07\/Logo-my-IAM-blau-512-150x150-2.png","width":200,"height":200,"caption":"my-IAM"},"image":{"@id":"https:\/\/my-iam.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/firstattribute"]},{"@type":"Person","@id":"https:\/\/my-iam.com\/de\/#\/schema\/person\/cb96a6c7bc8321c5a023ea9fccd6f359","name":"Elysabeth Yven"}]}},"_links":{"self":[{"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/posts\/29924","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/comments?post=29924"}],"version-history":[{"count":7,"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/posts\/29924\/revisions"}],"predecessor-version":[{"id":29974,"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/posts\/29924\/revisions\/29974"}],"wp:attachment":[{"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/media?parent=29924"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/categories?post=29924"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/my-iam.com\/en\/wp-json\/wp\/v2\/tags?post=29924"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}