5.3.2. Plugins, Microsoft Agents, and Security Store Agents
💡 First Principle: Security Copilot's reach into any specific data source or capability is opt-in at the plugin level, not assumed — enabling Copilot itself doesn't automatically connect it to every security tool in your environment.
Plugins extend Copilot's ability to query specific data sources (Defender for Cloud, Sentinel, Entra ID, and others) — each must be individually enabled, and some require additional permission configuration before they'll return data. Microsoft agents are pre-built, task-specific Copilot capabilities from Microsoft (for example, an agent focused on phishing triage or vulnerability prioritization). Security Store agents extend this further with third-party and partner-built agents available through a marketplace-style store, each with its own enablement and permission scope.
⚠️ Exam Trap: Assuming a newly-enabled Microsoft or Security Store agent has the same access as Copilot's core capabilities is incorrect — each agent has its own scope and permissions, and an agent built for one specific task (like phishing triage) won't necessarily have access to unrelated data sources unless separately configured.
Reflection Question: Why would a phishing-triage-focused Microsoft agent need its own separate permission scope rather than simply inheriting whatever access the Security Copilot workspace already has?