↳ GitHub sourceConnector

Microsoft Copilot

Description

The Microsoft Copilot logs connector in Microsoft Sentinel enables seamless ingestion of Copilot-generated activity logs from M365 Copilot and Security Copilot into Microsoft Sentinel for advanced threat detection, investigation and response. It collects telemetry from Microsoft Copilot services such as usage data and system responses and ingests into Microsoft Sentinel, allowing security teams to monitor for misuse, detect anomalies, and maintain compliance with organizational policies.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions.
Workspace
Workspace
Tenant Permissions
'Security Administrator' or 'Global Administrator' on the workspace's tenant.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect Microsoft Copilot audit logs to Microsoft Sentinel
This connector uses the Office Management API to get your Microsoft Copilot audit logs. The logs will be stored and processed in your existing Microsoft Sentinel workspace. You can find the data in the **CopilotActivity** table.

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
MicrosoftCopilot
Additional source files 2Solutions/Microsoft Copilot/Data Connectors/MicrosoftCopilot_ConnectorDefinition.jsonsource ↗Solutions/Microsoft Copilot/Data/Solution_MicrosoftCopilot.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.