Security Copilot + Entra

Review suggestions from the Conditional Access Optimization Agent

In brief

Learn how to review and apply suggestions provided by the Security Copilot for Microsoft Entra optimization agent.

What Entra admins need to know

Review the documentation change to determine whether it affects tenant configuration, security posture, or rollout plans.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

Open on Microsoft Learn ↗

The comparison below is an extract of the Microsoft Learn article showing only the changed content. Open the full article for complete context.

When you open a Defender-linked suggestion in the Conditional Access Optimization Agent, the details include a Defender insight section that explains the Defender context that contributed to the suggestion. Administrators with the Security Administrator role can navigate directly to the related alerts and incidents in Microsoft Defender. Without those permissions, you can still review and act on the Conditional Access suggestion.

For more information about how Microsoft Defender threat insights are used by the agent, see Microsoft Defender integrationMicrosoft Defender integration.

Microsoft Teams agent suggestion notifications