Maintained with ☕️ by
IcePanel logo

Generally Available: Azure Firewall integration in Security Copilot

Share

Services

The [Azure Firewall integration in Security Copilot](https://aka.ms/AzFWCfSLearnDocs) helps analysts perform detailed investigations of the malicious traffic intercepted by the IDPS feature of their firewalls across their entire fleet using natural language questions. The following capabilities can be accessed either via the [Security Copilot portal](https://securitycopilot.microsoft.com/) or the [Copilot in Azure](https://review.learn.microsoft.com/en-us/azure/copilot/capabilities) experience directly on the [Azure portal](https://portal.azure.com/): * Retrieve the top IDPS signature hits for an Azure Firewall: Get log information about the traffic intercepted by the IDPS feature instead of constructing KQL queries manually. * Enrich the threat profile of an IDPS signature beyond log information: Get additional details to enrich the threat information/profile of an IDPS signature instead of compiling it yourself manually. * Look for a given IDPS signature across your tenant, subscription, or resource group: Perform a fleet-wide search (over any scope) for a threat across all your Firewalls instead of searching for the threat manually. * Generate recommendations to secure your environment using Azure Firewall's IDPS feature: Get information from documentation about using Azure Firewall's IDPS feature to secure your environment instead of having to look up this information manually. To learn more about the user journey and value that Copilot can deliver, see the [Azure blog](https://aka.ms/AzFWCfSRSABlog). To see these capabilities in action, take a look at this [Tech Community blog](https://aka.ms/AzFWCfSRSAGABlog), and to get started, see the [documentation](https://aka.ms/AzFWCfSLearnDocs).