Microsoft continues its aggressive strategy to strengthen cybersecurity, introducing a major upgrade: the direct integration of Azure Firewall with Security Copilot, the AI-driven tool that aims to transform the way security teams work. This new partnership allows analysts to explore suspicious network activity simply by… talking to the machine, using natural language instead of complex queries and technical commands.

An AI tool that thinks like an analyst
Security Copilot is designed to act as a true “partner” for security professionals. It can assist in incident response, threat detection, intelligence gathering , and security posture management.
How it differs from traditional tools? It works at the speed and scale of a machine, but communicates like a human. The introduction of natural language as a way of interaction dramatically reduces investigation time, while allowing analysts to perform complex procedures.
See also: 5 ways attack surface management will evolve in 2026
Azure Firewall: The first line of defense in the cloud
Azure Firewall is Microsoft's cloud-native firewall solution for protecting workloads in Azure. Combined with Security Copilot, it creates a much more dynamic and intelligent shield for organizations that rely on Azure for critical infrastructure.
The newest integration focuses on enabling analysts to examine malicious traffic that has been blocked by the firewall's IDPS (Intrusion Detection and Prevention System), turning it into insightful information and actionable insights.
Two ways to access – one unified experience
Security teams can leverage integration through two different experiences:
- Security Copilot standalone gateway
- Azure Copilot built-in directly within the Azure portal
In both cases, the basic philosophy is common: the user simply formulates a question in English, and the system takes on the task of analyzing logs, IDPS signatures, patterns, and relevant context to display a comprehensive picture of the threat.
See also: Network Visibility: The Thread That Holds Cybersecurity Together

What analysts can do with the new integration
Microsoft has equipped the system with a number of features that until now required a lot of time or specialized technical knowledge:
- Display top IDPS signatures per firewall, for quick detection of recurring threats.
- Enriched threat profiles, which provide immediate information about the origin, motivations and behavior of a signature.
- Search across the entire environment — across tenants, subscriptions, resource groups — providing a single view across all firewall devices.
- Automatic hardening suggestions, based on the IDPS function, so teams know which best practices to implement to strengthen their defense.
Simply put, Security Copilot doesn't just answer questions — it guides.
What does an organization need to utilize it?
To enable the integration, enterprises must configure Azure Firewall to send resource-specific structured logs for IDPS to a Log Analytics Workspace.
In terms of access, appropriate Role-Based Access Control permissions, while the service is also based on Security Compute Units (SCU) , which each organization can customize according to its needs and workload.
See also: Attacks on AI Models – Model Inversion and Prompt Injection

The message behind Microsoft's new move
This addition is not just another feature. It reflects Microsoft’s long-term strategy to empower security teams with AI tools that reduce complexity and pave the way for more mature, automated defenses.
In an era where attacks are constantly evolving and security teams are pressured to respond quickly, being able to investigate an incident with a simple question… in English, is not a luxury; it is a necessity.
