vendor
Microsoft publishes AI activity playbook for Copilot investigations
The useful part is boring by design: identity, time, resource access, and KQL beat another lecture about responsible AI.
Microsoft published an investigator playbook for Microsoft 365 Copilot and Azure AI services, aimed at reconstructing AI-related activity from telemetry in Microsoft Purview, Defender, and Sentinel. Security teams get a scope, context, signal workflow covering prompts, resource access, detection logic, KQL queries, and agent configurations. It is also a Microsoft answer to a Microsoft visibility problem, so the playbook’s value depends on how much of the stack you already run.