St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents | Microsoft Customer Stories
Security teams often struggle with a lack of unified visibility across their tools, which delays the detection and neutralization of threats. St. Luke's addressed this challenge by implementing Microsoft Security Copilot to integrate its security stack. This integration drastically reduced the time spent on phishing triage, saving the organization nearly 200 hours every month. Read the full story to learn how they achieved these results.
How did St. Luke’s use AI to save nearly 200 hours a month on security tasks?
St. Luke’s University Health Network is using Microsoft Security Copilot as an AI layer across its existing security stack to streamline high-volume, repetitive work—especially phishing triage and incident reporting.
The biggest time savings come from the Phishing Triage Agent in Microsoft Defender:
- It autonomously handles and closes thousands of false positive phishing alerts.
- This shift is saving the team nearly 200 hours every month that used to be spent manually reviewing user-reported suspicious emails.
- The agent uses advanced language model–based analysis to understand the content and intent of reported emails and classify them as malicious or benign.
- It also provides plain-text explanations of its decisions, which helped the team build trust in its accuracy and reduce the need to double-check every incident.
Beyond phishing, Security Copilot also speeds up incident reporting inside Defender:
- Incident reports that previously took hours to compile manually are now generated in minutes.
- Analysts can quickly copy the AI-generated report, add context, and escalate to leadership or forensics.
By offloading routine triage and reporting to AI, St. Luke’s SOC team has moved from a largely reactive posture to more proactive threat hunting, while also reducing analyst burnout.
What security challenges was St. Luke’s trying to solve with Security Copilot?
St. Luke’s University Health Network operates 15 campuses, 300 outpatient sites, and manages more than 2.5 petabytes of data and patient records in motion. As a healthcare provider—one of the most targeted sectors for cyberattacks—it faced several key challenges:
- Fragmented visibility across tools: Although St. Luke’s already used Microsoft Defender, Sentinel, Entra, Purview, and other solutions, the tools were disconnected. The security team lacked a unified, real-time view across endpoints, email, identity, applications, and cloud workloads.
- High-volume phishing and DDoS risk: Phishing was the primary attack vector, with DDoS as another major concern. Both could disrupt clinical operations, delay patient care, and erode trust.
- Manual, time-consuming triage: Analysts were spending hours each day triaging hundreds of alerts, jumping between multiple portals and dashboards, which slowed response and increased the risk of missing real threats.
- Difficulty spotting subtle threats at scale: With millions of daily signals, behavioral analytics at scale was “almost impossible” to do manually, even with dashboards like Power BI.
Security Copilot helps St. Luke’s address these issues by:
- Acting as an AI-powered connective layer across Defender, Sentinel, Entra, Intune, and Purview, consolidating alerts, access controls, and vulnerabilities into a single, actionable view.
- Embedding AI-guided insights directly into existing workflows so analysts can correlate threats, eliminate silos, and respond faster.
- Using specialized agents—such as the Phishing Triage Agent, Conditional Access Optimization Agent, and Vulnerability Remediation Agent—to automate repetitive tasks and highlight the most important risks.
- Helping the team identify gaps and weaknesses in their environment and use that insight to shape security roadmaps and strategies.
The result is a more unified, AI-first security posture that helps St. Luke’s anticipate and disrupt attacks earlier, while keeping clinical operations running smoothly.
How do Security Copilot agents change day-to-day work for security analysts?
For St. Luke’s security analysts, Security Copilot agents have reshaped daily work from manual triage to higher-value analysis and response.
Key day-to-day changes include:
- Faster triage in one place: Instead of digging through multiple portals and tabs, analysts now see correlated alerts and context in a single, consolidated view. Triage that used to take hours now takes minutes.
- Autonomous handling of noise: The Phishing Triage Agent runs 24/7, automatically classifying and closing thousands of false positives. Analysts focus on the smaller set of alerts that truly matter.
- Clear explanations, not black-box decisions: For each email it reviews, the Phishing Triage Agent provides plain-text reasoning behind its verdict. This transparency has helped the team trust the classifications and reduce the need to re-check every case.
- Quicker, more consistent incident reports: Security Copilot generates sequential incident reports directly in Defender. Analysts can quickly refine and share them with leadership or forensics, which is especially important for a workforce of 23,000+ employees and strict compliance requirements.
- More time for proactive work: With routine tasks automated, the SOC team has shifted from reactive alert handling to proactive threat hunting and strategic improvements.
Analysts describe Security Copilot as being like an extra team member or mentor—guiding investigations, surfacing insights, and helping the team grow and mature without adding headcount. This not only improves operational efficiency but also supports analyst satisfaction by reducing repetitive, burnout-inducing work.

St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents | Microsoft Customer Stories
published by BlueTeamAssess LLC
I founded BlueTeamAssess LLC to develop and offer actionable and cost effective security solutions to SMBs.
BlueTeamAssess LLC is a veteran-owned Cybersecurity Consulting business based in Onslow County, NC.
My company wants to be the trusted advisor to small businesses for cybersecurity and related information technology needs. We will help you meet compliance requirements for HIPAA, PCI, NC cybersecurity requirements for financial advisors, and NIST 800-171 and CMMC cybersecurity requirements for providing goods and services through DOD contracts.
We help small businesses understand cybersecurity threats and their vulnerability to those threats. We offer affordable products and services to protect their business and their livelihood from those threats.
We use the SAINT Security Suite and its family of assessment products to provide cybersecurity services that assess your exposure to the many threats that can impact your business. And we help you meet compliance requirements for NIST 800-171 cybersecurity requirements for providing goods and services through DOD contracts as well as for HIPAA, PCI, the NC data breach protection law and NC cybersecurity requirements for financial advisors.
We use the CyberSecurity Assessment Tool from QS Solutions to assess the security posture of your Microsoft 365 deployment and help bring your risk score to acceptable levels through our remediation services.
We will help you reduce SPAM, secure your email and defend against ransomware. To help do this, we offer a number of solutions scalable for small business budgets and environments. These include:
- Microsoft 365 email and office software and its extensive security features and advanced threat protection.
- Fortinet security solutions that provide a Security Fabric that knits together protection for your endpoints and servers, your firewalls, your wireless network, security analytics and many other services that protect your organization technology from today’s advanced threats whether the workers are working in the office or remotely from home.
- A backup and recovery solution from Acronis to protect your critical customer and business data when the next storm or other disaster impacts your business.
You can trust BlueTeamAssess LLC be the trusted advisor to small businesses for cybersecurity and related information technology needs.