St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents | Microsoft Customer Stories
Security teams often struggle with a lack of unified visibility across their tools, which delays the detection and neutralization of threats. St. Luke's addressed this challenge by implementing Microsoft Security Copilot to integrate its security stack. This integration drastically reduced the time spent on phishing triage, saving the organization nearly 200 hours every month. Read the full story to learn how they achieved these results.
How did St. Luke’s use AI to save nearly 200 hours a month on security tasks?
St. Luke’s University Health Network is using Microsoft Security Copilot as an AI layer across its existing security stack to streamline high-volume, repetitive work—especially phishing triage and incident reporting.
The biggest time savings come from the Phishing Triage Agent in Microsoft Defender:
- It autonomously handles and closes thousands of false positive phishing alerts.
- This shift is saving the team nearly 200 hours every month that used to be spent manually reviewing user-reported suspicious emails.
- The agent uses advanced language model–based analysis to understand the content and intent of reported emails and classify them as malicious or benign.
- It also provides plain-text explanations of its decisions, which helped the team build trust in its accuracy and reduce the need to double-check every incident.
Beyond phishing, Security Copilot also speeds up incident reporting inside Defender:
- Incident reports that previously took hours to compile manually are now generated in minutes.
- Analysts can quickly copy the AI-generated report, add context, and escalate to leadership or forensics.
By offloading routine triage and reporting to AI, St. Luke’s SOC team has moved from a largely reactive posture to more proactive threat hunting, while also reducing analyst burnout.
What security challenges was St. Luke’s trying to solve with Security Copilot?
St. Luke’s University Health Network operates 15 campuses, 300 outpatient sites, and manages more than 2.5 petabytes of data and patient records in motion. As a healthcare provider—one of the most targeted sectors for cyberattacks—it faced several key challenges:
- Fragmented visibility across tools: Although St. Luke’s already used Microsoft Defender, Sentinel, Entra, Purview, and other solutions, the tools were disconnected. The security team lacked a unified, real-time view across endpoints, email, identity, applications, and cloud workloads.
- High-volume phishing and DDoS risk: Phishing was the primary attack vector, with DDoS as another major concern. Both could disrupt clinical operations, delay patient care, and erode trust.
- Manual, time-consuming triage: Analysts were spending hours each day triaging hundreds of alerts, jumping between multiple portals and dashboards, which slowed response and increased the risk of missing real threats.
- Difficulty spotting subtle threats at scale: With millions of daily signals, behavioral analytics at scale was “almost impossible” to do manually, even with dashboards like Power BI.
Security Copilot helps St. Luke’s address these issues by:
- Acting as an AI-powered connective layer across Defender, Sentinel, Entra, Intune, and Purview, consolidating alerts, access controls, and vulnerabilities into a single, actionable view.
- Embedding AI-guided insights directly into existing workflows so analysts can correlate threats, eliminate silos, and respond faster.
- Using specialized agents—such as the Phishing Triage Agent, Conditional Access Optimization Agent, and Vulnerability Remediation Agent—to automate repetitive tasks and highlight the most important risks.
- Helping the team identify gaps and weaknesses in their environment and use that insight to shape security roadmaps and strategies.
The result is a more unified, AI-first security posture that helps St. Luke’s anticipate and disrupt attacks earlier, while keeping clinical operations running smoothly.
How do Security Copilot agents change day-to-day work for security analysts?
For St. Luke’s security analysts, Security Copilot agents have reshaped daily work from manual triage to higher-value analysis and response.
Key day-to-day changes include:
- Faster triage in one place: Instead of digging through multiple portals and tabs, analysts now see correlated alerts and context in a single, consolidated view. Triage that used to take hours now takes minutes.
- Autonomous handling of noise: The Phishing Triage Agent runs 24/7, automatically classifying and closing thousands of false positives. Analysts focus on the smaller set of alerts that truly matter.
- Clear explanations, not black-box decisions: For each email it reviews, the Phishing Triage Agent provides plain-text reasoning behind its verdict. This transparency has helped the team trust the classifications and reduce the need to re-check every case.
- Quicker, more consistent incident reports: Security Copilot generates sequential incident reports directly in Defender. Analysts can quickly refine and share them with leadership or forensics, which is especially important for a workforce of 23,000+ employees and strict compliance requirements.
- More time for proactive work: With routine tasks automated, the SOC team has shifted from reactive alert handling to proactive threat hunting and strategic improvements.
Analysts describe Security Copilot as being like an extra team member or mentor—guiding investigations, surfacing insights, and helping the team grow and mature without adding headcount. This not only improves operational efficiency but also supports analyst satisfaction by reducing repetitive, burnout-inducing work.

St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents | Microsoft Customer Stories
published by Cloud First Company
We are a highly driven team. Teamwork is our key strength. We have great technology partners. We develop computer systems and provide managed IT support services in Dublin.
For business convenience we offer Azure ‘Pay as you Go’ licensing in our IT Support managed services for Cloud, Microsoft Office 365, Mail 365, AWS and on premises computer systems to you today.
Human and AI learning means advances in how we deliver IT Services, IT systems & read data everyday. We embrace modern secure application, business email and data systems to deliver best cost and performance for your IT spend.