Home / Security Copilot / Microsoft Entra
🔑

Microsoft Entra

Identity security - Conditional Access policies, sign-in logs, identity risk detections, and privileged access insights

What is Microsoft Entra?

Microsoft Entra provides Security Copilot with deep identity security context including Conditional Access policies and sign-in logs, identity risk detections and authentication events, and privileged access and identity posture insights. Security Copilot uses Entra to explain access decisions, summarize risky sign-ins, and recommend identity improvements - enabling analysts to investigate identity-related incidents faster and strengthen their organization's identity posture.

Core Capabilities

Conditional Access Analysis

Copilot explains why access was granted or denied based on CA policies, helping analysts understand access decisions.

Risky Sign-in Investigation

Investigate and summarize risky sign-in events with AI assistance to accelerate identity incident response.

Identity Risk Assessment

Assess user risk levels with leaked credentials, anomalous activity detection, and threat intelligence signals.

Privileged Access Review

Review and manage privileged identity assignments and access to enforce least-privilege principles.

Authentication Insights

Analyze MFA enrollment, authentication methods, and sign-in patterns to identify security gaps.

Lifecycle Workflows

Automate identity governance with joiner, mover, leaver workflows for consistent access management.

Learning Resources

Back to Security Copilot