Events
Take the Microsoft Learn Challenge
Nov 19, 11 PM - Jan 10, 11 PM
Ignite Edition - Build skills in Microsoft Security Copilot and earn a digital badge by January 10!
Register nowThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
As with any Microsoft Copilot, a prompt refers to the text-based, natural language input you provide in the prompt bar that instructs Security Copilot to generate a response. The quality of the response that Security Copilot returns depends in large part on the quality of the prompt used. In general, a well-crafted prompt with clear and specific inputs leads to more useful responses by Security Copilot.
Watch the following video to learn more about creating effective prompts:
To see the different ways you can create prompts in Security Copilot, read Prompting in Security Copilot.
Effective prompts give Security Copilot adequate and useful parameters to generate a valuable response. Security analysts or researchers should include the following elements when writing a prompt.
Every good prompt should have a goal. Whether it comes in the form of instructions or questions, it should indicate what you want out of your current session.
For Security Copilot, context can mean such information as the time frame, or that you plan to use the response for a report. Expectations can include whether you want the response to be in a table format, a list of action steps, a summary, or even a diagram. Source might be useful in specifying which Microsoft plugins you're referring to, if needed. Some plugins require more context to work effectively or supporting plugins to ensure a response when initial responses fail.
Some things to remember when coming up with your own prompts:
Be specific, clear, and concise as much as you can about what you want to achieve. You can always start simply with your first prompt, but as you get more familiar with Security Copilot, include more details following the elements of an effective prompt.
Iterate. Subsequent prompts are typically needed to either clarify what you need further, or try other versions of a prompt to get closer to what you're looking for. Like all LLM-based systems, Security Copilot can respond to the same prompt in slightly different ways.
Provide necessary context to narrow down where Security Copilot looks for data.
Give positive instructions instead of "what not to do". Security Copilot is geared toward action, so telling it what you want it to do for exceptions is more productive.
Directly address Security Copilot as "You", as in, "You should ..." or "You must ...", as this is more effective than referring to it as a model or assistant.
While these guidelines can help you get started in creating prompts, it’s important to note that you’re not limited to forming prompts following the structure of the previous examples. What’s great about Security Copilot is that it's designed to respond to questions or instructions made in your own words (that is, using natural language).
You have the flexibility to adapt these guidelines to your specific needs.
Watch the following video to learn more about creating better prompts:
Events
Take the Microsoft Learn Challenge
Nov 19, 11 PM - Jan 10, 11 PM
Ignite Edition - Build skills in Microsoft Security Copilot and earn a digital badge by January 10!
Register nowTraining
Learning path
Craft effective prompts for Microsoft 365 Copilot - Training
Discover ways to craft effective and contextual prompts for Microsoft 365 Copilot that create, simplify, transform, and compile content across Microsoft 365 applications. Learn the importance of providing a clear goal, context, source, and expectation in your prompt for the best results. This course covers real world scenarios and examples using Copilot in Microsoft 365 apps like Word, Excel, PowerPoint, Teams, Outlook, OneNote, and Chat.
Certification
Microsoft Certified: Security Operations Analyst Associate - Certifications
Investigate, search for, and mitigate threats using Microsoft Sentinel, Microsoft Defender for Cloud, and Microsoft 365 Defender.