{
  "Name": "Microsoft Copilot",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/Copilot_logo.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Microsoft Copilot](https://www.microsoft.com/en-us/microsoft-365/copilot) solution allows you to stream your Microsoft Copilot audit logs from M365 Copilot and Security Copilot into Microsoft Sentinel in order to track Copilot activities across your organization.\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\n- [Office Management API](https://docs.microsoft.com/office/office-365-management-api/office-365-management-apis-overview)",
  "Data Connectors": [
    "Data Connectors/MicrosoftCopilot_ConnectorDefinition.json"
  ],
  "Analytic Rules": [
    "Microsoft Copilot/Analytic Rules/CopilotFileUploadsDisabled.yaml",
    "Microsoft Copilot/Analytic Rules/CopilotJailbreakAttempt.yaml",
    "Microsoft Copilot/Analytic Rules/CopilotPluginCreatedByNonAdmin.yaml",
    "Microsoft Copilot/Analytic Rules/CopilotPluginTampering.yaml"
  ],
  "Hunting Queries": [
    "Microsoft Copilot/Hunting Queries/CopilotExternalIPAccess.yaml",
    "Microsoft Copilot/Hunting Queries/CopilotPluginReEnabled.yaml"
  ],
  "Workbooks": [
    "Workbooks/MicrosoftCopilotActivityMonitoring.json"
  ],
  "BasePath": "Solutions/Microsoft Copilot",
  "Version": "3.0.2",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": false
}