Skip to main content

Responses are generated using AI and may contain mistakes.

CollectorsCloud Collectors Administration Guide

Microsoft Copilot Integration

To monitor the behavior of your AI agents and secure digital workforces against threats, New-Scale Security Operations Platform offers Agent Behavior Analytics (ABA). By centralizing logs and automating incident timelines, it identifies access abuse in real time without relying on static rules. Dedicated dashboards and risk scoring help you track AI agent activity and continuously improve your security posture.

Integration with Microsoft Copilot expands the reach of ABA to cover Microsoft agents that are active in your environment. It includes coverage for:

  • Microsoft 365 Copilot – an AI-powered productivity assistant integrated into Microsoft 365 applications, such as Word, Excel, Outlook, Teams, and PowerPoint.

  • Microsoft Copilot – a generative artificial intelligence chatbot developed by Microsoft AI

  • Copilot Studio – a platform for building and managing agents.

ABA includes the following the key benefits.

  • AI Monitoring: Track AI agent behavior to detect and respond to threats.

  • Automated Timelines: View sequenced activity logs for faster incident investigation.

  • Risk Management: Measure your AI security against peer standards to identify and close security gaps and scale AI automation.

  • Centralized Dashboards: Gain a unified view of all non-human entity activity.

Options for Onboarding Microsoft Copilot Logs

The Microsoft Copilot integration makes it possible to ingest Microsoft Copilot logs via existing Exabeam cloud collectors. These logs can be collected via the following options:

Supported Data Types

The table below lists the types of events each of the onboarding options can ingest. For each data type, information is included about the service that holds the data, its purpose, and its usability.

  • Data type – Describes the type of data generated by the AI product

  • Where data lives – Shows a service that holds or stores data

  • Purpose – Explains why the data exists and its usage

  • Externally collectable and useful – Indicates if data is retrievable via logs, APIs, or integrations

  • Collector that can ingest the data – Indicates which collector the data can be ingested through.

Based on the following table you can check feasibility of using associated existing cloud collectors for collecting Microsoft Copilot logs via Microsoft Copilot integration.

Data type

Where data lives

Purpose

Externally collectable and useful

Collector that can ingest the data

Prompts and Responses

Microsoft 365 workloads that include Exchange mailboxes, Teams chats, SharePoint, and OneDrive

User productivity content

No

Activity Metadata

Microsoft Purview Unified Audit Log (UAL)

Investigation and compliance

Yes

Microsoft 365 Management Activity (or Microsoft Sentinel)

Prompts, Responses, and Metadata (risk views)

Microsoft Purview DSPM for AI

Data exposure and governance

No

Alerts and detections

Microsoft Defender (Defender for Cloud Apps / XDR)

Security operations

Yes

Microsoft Security Alerts (or Microsoft Sentinel)

Agent lifecycle audit events

Microsoft Purview Unified Audit Log. Workload typically appears as Power Platform Analytics for Copilot Studio agents.

Security operations and data governance

Yes

Microsoft Security Alerts (or Microsoft Sentinel)

Security Use Cases and Detections/Coverage

Integrating with Microsoft Copilot provides access to all of the Agent Behavior Analytics (ABA) functionality that New-Scale Analytics provides in its downstream applications. This functionality includes the following capabilities:

  • Establish a baseline for AI activity in your environment so that abnormal behavior can be detected, such as an abnormal volume of AI requests, new agent creation, or unauthorized outbound activity.

  • Detect early signs of prompt injection, model manipulation, or tool exploitation.

  • Monitor for privilege escalation and misuse in the AI platform, such as new users or role assignments.

  • Provide visibility into the lifecycle of AI agents, including creation, modification, and usage of agents.

To support ABA functionality, New-Scale Analytics includes behavioral models and security content dedicated to monitoring AI agent-related activity in your environment. For detailed information about the security content Exabeam provides, see the latest New-Scale Content Package Release Notes.