Copilot Activity Investigation
Brings Microsoft 365 Copilot activity into Microsoft Sentinel through the CopilotActivity table, letting analysts scope interactions by user, host, IP, agent, model, and record type for audit and incident investigation. Detailed prompt and resource context lives in the table's LLMEventData column.