What does unified security visibility change? St. Luke's University Health Network needed a real-time view across multiple platforms to disrupt attacks earlier in the chain. This customer story shows how Security Copilot in Microsoft Defender delivered an AI-powered, agentic view of alerts, access controls, and vulnerabilities, saving nearly 200 hours monthly in phishing triage. Read the story to learn from St. Luke's experience, then talk with Tier 2 Networks, Inc. about applying Security Copilot in your environment.
How did St. Luke’s use AI to save nearly 200 hours every month?
St. Luke’s University Health Network is using Microsoft Security Copilot as an AI layer across its existing security stack to streamline day-to-day work in the Security Operations Center (SOC).
The biggest time savings come from the Phishing Triage Agent in Microsoft Defender:
- It autonomously handles and closes thousands of false positive phishing alerts.
- This shift is saving the team nearly 200 hours every month that used to be spent manually triaging user-reported suspicious emails.
- The agent uses advanced language model–based analysis to understand the content and intent of reported emails and decide whether they are genuine phishing attempts or false alarms.
Beyond phishing triage, Security Copilot also:
- Summarizes large volumes of security data from tools like Microsoft Defender, Microsoft Sentinel, Microsoft Entra, and Microsoft Purview into actionable insights.
- Generates incident reports in minutes instead of hours, which is especially important for a network with more than 23,000 employees and over 2.5 petabytes of data and patient records in motion.
By automating repetitive triage and reporting tasks, St. Luke’s SOC team has been able to shift from reactive triage to proactive threat hunting, focusing their time on higher-value investigations rather than routine alert handling.
What security challenges was St. Luke’s trying to solve with Security Copilot?
St. Luke’s University Health Network operates 15 campuses and 300 outpatient sites, with more than 2.5 petabytes of data and patient records in motion. As a healthcare provider, it is in what its CISO calls the number one cyberattack target sector globally.
The team identified several key challenges:
- Fragmented tools and limited visibility: They were already using Microsoft Defender, Microsoft Sentinel, Microsoft Entra, Microsoft Purview, and other tools, but these were disconnected. Analysts had to jump between multiple portals and dashboards, which slowed investigations and made it harder to see the full picture.
- High volume of phishing and DDoS threats: Phishing was the primary attack vector, followed by DDoS. The volume of user-reported suspicious emails created a heavy manual triage workload and increased the risk of missing real threats.
- Manual, time-consuming triage and reporting: Before Security Copilot, it took hours to triage and understand hundreds of alerts a day, and incident reports were created by hand, also taking hours.
Security Copilot helped St. Luke’s address these issues by:
- Acting as an AI-powered connective layer across their security stack, consolidating alerts, access controls, and vulnerabilities into a single, unified view.
- Enabling real-time threat identification by correlating signals from endpoints, email, identity, applications, and cloud workloads.
- Using Security Copilot agents—such as the Phishing Triage Agent in Defender, Conditional Access Optimization Agent in Entra, and Vulnerability Remediation Agent in Intune—to automate repetitive tasks and optimize policies.
- Embedding AI guidance directly into workflows, so analysts receive context and recommendations that support faster, data-driven decisions.
As a result, St. Luke’s has been able to reimagine its security operations from a set of fragmented tools into a more unified, AI-first approach that improves visibility, speeds response, and supports both compliance and patient care continuity.
How does Security Copilot improve analyst effectiveness and reduce burnout?
For St. Luke’s security analysts, Microsoft Security Copilot is reshaping daily work by taking on the heavy lifting and surfacing what matters most.
Key changes in their day-to-day experience include:
- Faster triage: Before Security Copilot, analysts spent hours each day triaging and understanding hundreds of alerts, often switching between multiple portals and tabs. Now, with Security Copilot and its Phishing Triage Agent, triage is consolidated in one place and can take minutes instead of hours.
- Automated routine work: The Phishing Triage Agent runs 24/7, autonomously handling and closing thousands of false positive alerts and saving nearly 200 hours monthly. This frees analysts from repetitive tasks so they can focus on real threats.
- Clear explanations and context: The agent provides plain-text explanations for its decisions, giving analysts the context they need to quickly determine whether an email is malicious or benign. Over time, the team has gained confidence in the agent’s accuracy and no longer needs to double-check every incident.
- Quicker incident reporting: Incident reports that once took hours to create manually can now be generated in minutes within Defender. Analysts simply copy the AI-generated report, add any needed context, and escalate it to leadership or forensics.
These improvements have several impacts on the team:
- Higher productivity: Analysts can move from reactive triage to proactive threat hunting, spending more time on complex investigations and less on routine filtering.
- Reduced burnout: By automating repetitive, high-volume tasks and consolidating information into a single view, Security Copilot helps lower cognitive load and makes the work more sustainable.
- Skill development: Leaders at St. Luke’s describe Security Copilot as being “almost like having an extra person—a mentor,” guiding the team to grow and mature as a security function.
Overall, Security Copilot is helping St. Luke’s rethink how analysts work—from chasing alerts across disconnected tools to operating within a unified, AI-assisted environment that supports faster, more confident decision-making.