Nearly 200 hours a month, recovered from phishing triage. When St. Luke's University Health Network needed real-time visibility across a fragmented security stack, it adopted Security Copilot in Microsoft Defender as the connective tissue linking alerts, access controls, and vulnerabilities. Agentic capabilities now speed threat response and turn incident reporting from hours into minutes. As a Microsoft Security solutions provider, Contoso Acme can help you apply this approach. Read the story to learn from St. Luke's experience.
How did St. Luke’s use AI to cut security workload by nearly 200 hours a month?
St. Luke’s University Health Network uses Microsoft Security Copilot as an AI layer across its existing security stack (including Microsoft Defender, Sentinel, Entra, Purview, and Intune) to streamline day-to-day security operations.
The biggest impact so far comes from the Phishing Triage Agent in Microsoft Defender. This agent:
- Autonomously analyzes user-reported suspicious emails using language model–based analysis.
- Understands the content and intent of emails to distinguish real phishing from false alarms.
- Automatically closes thousands of false positive alerts.
By offloading this repetitive triage work to the agent, St. Luke’s is saving nearly 200 hours every month that were previously spent manually reviewing phishing alerts.
Those hours are now redirected to higher-value work, such as proactive threat hunting and deeper investigations, instead of routine triage. Analysts also report that the agent’s plain-language explanations have built enough confidence that they no longer need to double-check every incident, further reducing workload.
What security challenges was St. Luke’s trying to solve with Security Copilot?
St. Luke’s operates a large and complex healthcare environment, with:
- 15 campuses and 300 outpatient sites
- More than 2.5 petabytes of data and patient records in motion
- Over 23,000 employees
As a healthcare provider, it is in what its CISO calls the number one cyberattack target sector, with phishing and DDoS attacks as primary concerns. Before Security Copilot, the team faced several challenges:
- Disconnected tools: They had strong products (Defender, Sentinel, Entra, Purview, and others), but lacked unified, real-time visibility across them.
- Manual triage: Analysts spent hours each day triaging hundreds of alerts across multiple portals and tabs.
- Alert overload: User-reported suspicious emails created a high volume of potential phishing incidents, many of which were false positives.
- Limited behavioral analytics at scale: With millions of daily signals, it was difficult to spot less obvious threats.
- Time-consuming reporting: Incident reports for compliance could take hours to compile manually.
Security Copilot helps St. Luke’s address these issues by:
- Acting as a unified AI layer across the security stack, correlating alerts, access controls, and vulnerabilities in one place.
- Embedding AI-guided insights directly into existing workflows, so analysts can make faster, data-driven decisions.
- Using specialized Security Copilot agents (for phishing triage, conditional access optimization, vulnerability remediation, and alert triage in DLP/IRM) to automate repetitive tasks.
- Providing clear, sequential incident reports in minutes instead of hours, supporting compliance and leadership reporting.
Overall, Security Copilot helps St. Luke’s move from reactive, manual work toward a more proactive, AI-first security posture.
How does Security Copilot change day-to-day work for St. Luke’s security team?
Security Copilot has reshaped how St. Luke’s security operations center (SOC) works day to day by consolidating information, automating routine tasks, and guiding analysts with AI-driven insights.
Key changes in daily work include:
- Faster triage: What used to take hours to triage and understand hundreds of alerts now takes minutes, because alerts and context are available in one place instead of multiple portals.
- Automated phishing handling: The Phishing Triage Agent runs 24/7, autonomously handling and closing large volumes of false positives and surfacing the real threats that need human attention.
- Proactive focus: With nearly 200 hours per month freed from manual phishing triage, analysts can shift from reactive work to proactive threat hunting and strategic improvements.
- Clear explanations: Agents provide plain-text reasoning for their decisions, giving analysts the context they need to trust classifications and act quickly.
- Faster incident reporting: Incident reports that once took hours to assemble are now generated in minutes within Defender, then refined and escalated as needed.
- Better collaboration: Having all incident information in a single location reduces back-and-forth across tools and helps the team align quickly on next steps.
Leaders at St. Luke’s describe Security Copilot as almost like having an additional team member or mentor embedded in their tools—one that continuously helps them identify gaps, refine their roadmap, and mature their overall security posture.