Bookkeeping Service Providers

  • Accounting
  • Bookkeeping
  • US Taxation
  • Financial Planning
  • Accounting Software
  • Small Business Finance
You are here: Home / CLOUD / Bringing generative AI to Azure network security with new Microsoft Copilot integrations

Bringing generative AI to Azure network security with new Microsoft Copilot integrations

May 7, 2024 by cbn Leave a Comment

Today we are excited to announce the Azure Web Application Firewall (WAF) and Azure Firewall integrations in the Microsoft Copilot for Security standalone experience. This is the first step we are taking toward bringing interactive, generative AI-powered capabilities to Azure network security.

Copilot empowers teams to protect at the speed and scale of AI by turning global threat intelligence (78 trillion or more security signals), industry best practices, and organizations’ security data into tailored insights. With the growing cost of security breaches, organizations need every advantage to protect against skilled and coordinated cyber threats. To see more and move faster, they need generative AI technology that complements human ingenuity and refocuses teams on what matters. A recent study shows that:

  • Experienced security analysts were 22% faster with Copilot.
  • They were 7% more accurate across all tasks when using Copilot.
  • And, most notably, 97% said they want to use Copilot the next time they do the same task.
Person talking to a group of people in conference room.

Azure network security

Protect your applications and cloud workloads with network security services

Explore solutions

Generative AI for Azure network security

Azure WAF and Azure Firewall are critical security services that many Microsoft Azure customers use to protect their network and applications from threats and attacks. These services offer advanced threat protection using default rule sets as well as detection and protection against sophisticated attacks using rich Microsoft threat intelligence and automatic patching against zero-day vulnerabilities. These systems process huge volumes of packets, analyze signals from numerous network resources, and generate vast amounts of logs. To reason over terabytes of data and cut through the noise to detect threats, analysts spend several hours if not days performing manual tasks. In addition to the scale of data there is a real shortage of security expertise. It is difficult to find and train cybersecurity talent and these staff shortages slow down responses to security incidents and limit proactive posture management. 

With our announcement of Azure WAF and Azure Firewall integrations in Copilot for Security, organizations can empower their analysts to triage and investigate hyperscale data sets seamlessly to find detailed, actionable insights and solutions at machine speeds using a natural language interface with no additional training. Copilot automates manual tasks and helps upskill Tier 1 and Tier 2 analysts to perform tasks that would otherwise be reserved for more experienced Tier 3 or Tier 4 professionals, redirecting expert staff to the hardest challenges, thus elevating the proficiency of the entire team. Copilot can also easily translate threat insights and investigations into natural language summaries to quickly inform colleagues or leadership. The organizational efficiency gained by Copilot summarizing vast data signals to generate key insights into the threat landscape enables analysts to outpace adversaries in a matter of minutes instead of hours or days.

graphical user interface
How Copilot for Security works with the Azure Firewall and Azure WAF plugins.

Azure Web Application Firewall integration in Copilot

Today, Azure WAF generates detections for a variety of web application and API security attacks. These detections generate terabytes of logs that are ingested into Log Analytics. While the logs give insights into the Azure WAF actions, it is a non-trivial and time-consuming activity for an analyst to understand the logs and gain actionable insights.

The Azure WAF integration in Copilot for Security helps analysts perform contextual analysis of the data in minutes. Specifically, it synthesizes data from Azure Diagnostics logs to generate summarization of Azure WAF detections tailored to each customer’s environment. The key capabilities include investigation of security threats—including analyzing WAF rules triggered, investigating malicious IP addresses, analyzing SQL Injection (SQLi) and Cross-site scripting (XSS) attacks blocked by WAF, and natural language explanations for each detection.

By asking a natural-language question about these attacks, the analyst receives a summarized response that includes details about why that attack occurred and equips the analyst with enough information to investigate the issue further. In addition, with the assistance of Copilot, analysts can retrieve information on the most frequently offending IP addresses, identify top malicious bot attacks, and pinpoint the managed and custom Azure WAF rules that have been triggered most frequently within their environment.

graphical user interface, text, application
A sneak peek at the Azure WAF integration in Copilot for Security.

Azure Firewall integration in Copilot

Azure Firewall intercepts and blocks malicious traffic using the intrusion detection and prevention system (IDPS) feature today. However, when analysts need to perform a deeper investigation of the threats that Azure Firewall catches using this feature, they need to do this manually—which is a non-trivial and time-consuming task. The Azure Firewall integration in Copilot helps analysts perform these investigations with the speed and scale of AI.

The first step in an investigation is to pick a specific Azure Firewall and see the threats it has intercepted. Analysts today spend hours writing custom queries or navigating through several manual steps to retrieve threat information from Log Analytics workspaces. With Copilot, analysts just need to ask about the threats they’d like to see, and Copilot will present them with the requested information.

The next step is to better understand the nature and impact of these threats. Today, analysts must retrieve additional contextual information such as geographical location of IPs, threat rating of a fully qualified domain name (FQDN), details of common vulnerabilities and exposures (CVEs) associated with an IDPS signature, and more manually from various sources. This process is slow and involves a lot of effort. Copilot pulls information from the relevant sources to enrich your threat data in a fraction of the time.

Once a detailed investigation has been performed for a single Azure Firewall and single threat, analysts would like to determine if these threats were seen elsewhere in their environment. All the manual work they performed for an investigation for a single Azure Firewall is something they would have to repeat fleet wide. Copilot can do this at machine speed and help correlate this information with other security products integrated with Copilot to better understand how attackers are targeting their entire infrastructure.

graphical user interface, text, website
A sneak peek at the Azure Firewall integration in Copilot for Security.

Looking forward

The future of technology is here, and users will increasingly expect their network security products to be AI enabled; and Copilot positions organizations to fully leverage the opportunities presented by the emerging era of generative AI. The integrations announced today combine Microsoft’s expertise in security with state-of-the-art generative AI packaged together in a solution built with security, privacy, and compliance at its heart to help organizations better defend themselves from attackers while keeping their data completely private.

Getting access

We look forward to continuing to integrate Azure network security into Copilot to make it easier for our customers to be more productive and be able to quickly analyze threats and mitigate vulnerabilities ahead of their adversaries. These new capabilities in Copilot for Security are already being used internally by Microsoft and a small group of customers. Today, we’re excited to announce the upcoming public preview. We expect to launch the preview for all customers for Azure WAF and Azure Firewall at Microsoft Build on May 21, 2024. In the coming weeks, we’ll continuously add new capabilities and make improvements based on your feedback.

Please stop by the Copilot for Security booth at RSA 2024 to see a demo of these capabilities today, express interest for early access, and read about additional Microsoft announcements at RSA.

The post Bringing generative AI to Azure network security with new Microsoft Copilot integrations appeared first on Microsoft Azure Blog.

Share on FacebookShare on TwitterShare on Google+Share on LinkedinShare on Pinterest

Filed Under: CLOUD

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • May 2021
  • April 2021
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • March 2016

Recent Posts

  • How Azure Cobalt 100 VMs are powering real-world solutions, delivering performance and efficiency results
  • FabCon Vienna: Build data-rich agents on an enterprise-ready foundation
  • Agent Factory: Connecting agents, apps, and data with new open standards like MCP and A2A
  • Azure mandatory multifactor authentication: Phase 2 starting in October 2025
  • Microsoft Cost Management updates—July & August 2025

Recent Comments

    Categories

    • Accounting
    • Accounting Software
    • BlockChain
    • Bookkeeping
    • CLOUD
    • Data Center
    • Financial Planning
    • IOT
    • Machine Learning & AI
    • SECURITY
    • Uncategorized
    • US Taxation

    Categories

    • Accounting (145)
    • Accounting Software (27)
    • BlockChain (18)
    • Bookkeeping (205)
    • CLOUD (1,322)
    • Data Center (214)
    • Financial Planning (345)
    • IOT (260)
    • Machine Learning & AI (41)
    • SECURITY (620)
    • Uncategorized (1,284)
    • US Taxation (17)

    Subscribe Our Newsletter

     Subscribing I accept the privacy rules of this site

    Copyright © 2025 · News Pro Theme on Genesis Framework · WordPress · Log in