Nearly 200 hours a month, recovered from phishing triage. When St. Luke's University Health Network needed real-time visibility across a fragmented security stack, it adopted Security Copilot in Microsoft Defender as the connective tissue linking alerts, access controls, and vulnerabilities. Agentic capabilities now speed threat response and turn incident reporting from hours into minutes. As a Microsoft Security solutions provider, Contoso Acme can help you apply this approach. Read the story to learn from St. Luke's experience.
How did St. Luke’s use AI to save nearly 200 hours a month on security tasks?
St. Luke’s University Health Network is using Microsoft Security Copilot as an AI layer across its existing security stack to streamline high-volume, repetitive work—especially phishing triage and incident reporting.
The biggest time savings come from the Phishing Triage Agent in Microsoft Defender:
- It autonomously handles and closes thousands of false positive phishing alerts.
- This shift is saving the team nearly 200 hours every month that used to be spent manually reviewing user-reported suspicious emails.
- The agent uses advanced language models to understand the content and intent of emails and classify them as malicious or benign.
- It also provides plain-text explanations of its decisions, so analysts can quickly validate and build trust in the results.
Beyond phishing, Security Copilot also speeds up incident reporting for a large workforce and data footprint:
- St. Luke’s has more than 23,000 employees and manages over 2.5 petabytes of data and patient records in motion.
- Incident reports that previously took hours to compile are now generated in minutes within Defender.
- Teams can copy the AI-generated report, add context, and escalate to leadership or forensics quickly and confidently.
By offloading routine triage and reporting to Security Copilot agents, St. Luke’s SOC has moved from a largely reactive posture to more proactive threat hunting, while also reducing analyst burnout and improving overall efficiency.
What security challenges was St. Luke’s trying to solve with Security Copilot?
St. Luke’s University Health Network operates at significant scale—15 campuses, 300 outpatient sites, and more than 2.5 petabytes of data and patient records in motion. Before adopting Security Copilot, the security team faced several key challenges:
- Fragmented visibility across tools
They were already using Microsoft Defender, Microsoft Sentinel, Microsoft Entra, Microsoft Purview, and other solutions, but these tools were largely disconnected. The team lacked a unified, real-time view across endpoints, email, identities, applications, and cloud workloads.
- High volume of alerts and manual triage
Analysts had to sift through hundreds of alerts a day, often jumping between multiple portals and tabs. Phishing was the biggest threat vector, and user-reported suspicious emails demanded careful, manual investigation. This slowed response and increased the risk of missing real threats.
- Difficulty spotting subtle or emerging threats
With millions of signals daily, it was hard to perform behavioral analytics at scale. Even with dashboards like Power BI, the team struggled to pinpoint threats that weren’t immediately obvious.
- Time-consuming incident reporting and compliance needs
Given more than 23,000 employees and millions of patient records, compliance and clear documentation are critical. Manually creating incident reports took hours and consumed valuable analyst time.
Security Copilot addresses these issues by:
- Acting as an AI-powered connective layer across Defender, Sentinel, Entra, Purview, and Intune.
- Providing a consolidated, real-time view of alerts, access controls, and vulnerabilities.
- Embedding AI-guided insights and recommendations directly into existing workflows.
- Using specialized agents (such as the Phishing Triage Agent, Conditional Access Optimization Agent, and Vulnerability Remediation Agent) to automate repetitive tasks and highlight true threats.
This reimagines how the SOC operates: analysts spend less time on manual triage and more time on proactive threat hunting, strategic improvements, and closing visibility gaps across the environment.
Which Security Copilot agents is St. Luke’s using, and what impact are they seeing?
St. Luke’s is an early adopter of several Microsoft Security Copilot agents, each focused on a different part of their security posture. Together, these agents help the team reimagine how they manage risk at scale.
Key agents in use and their impact:
- Phishing Triage Agent (Microsoft Defender)
- Autonomously handles and closes thousands of false positive phishing alerts.
- Saves the SOC team nearly 200 hours every month in phishing alert triage.
- Uses language models to understand email content and intent, classifying submissions as genuine phishing or false alarms.
- Provides detailed, plain-text explanations of its decisions, which has built analyst confidence to the point where they no longer double-check every incident.
- Allows analysts to shift from reactive triage to proactive threat hunting.
- Conditional Access Optimization Agent (Microsoft Entra)
- Helps optimize conditional access policies across a large identity footprint.
- Supports the team in balancing security with clinician and staff access needs, so care delivery is not disrupted.
- Contributes to identifying gaps in access controls and informing roadmap decisions.
- Vulnerability Remediation Agent (Microsoft Intune)
- Assists in prioritizing and remediating vulnerabilities across thousands of endpoints.
- Surfaces where the organization is “not seeing things” and where weaknesses exist, helping shape remediation strategies.
- Alert Triage Agents (Microsoft Purview DLP and IRM)
- Help manage and triage alerts related to data loss prevention and information rights management.
- Reduce noise so analysts can focus on higher-risk data protection incidents.
Across these agents, St. Luke’s reports that:
- Triage that once took hours now takes minutes, with all relevant information in one place.
- Routine, repetitive tasks are automated, which supports analyst satisfaction and reduces burnout.
- The security team is maturing toward an AI-first, end-to-end security approach, with Security Copilot acting almost like an additional team member or mentor guiding decisions.
Overall, these agents help St. Luke’s reshape fragmented tools into a more unified, resilient security posture that better protects patient care and operations.