St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents | Microsoft Customer Stories
What does unified security visibility change? St. Luke's University Health Network needed a real-time view across multiple platforms to disrupt attacks earlier in the chain. This customer story shows how Security Copilot in Microsoft Defender delivered an AI-powered, agentic view of alerts, access controls, and vulnerabilities, saving nearly 200 hours monthly in phishing triage. Read the story to learn from St. Luke's experience, then talk with BlueTeamAssess LLC about applying Security Copilot in your environment.
How did St. Luke’s use AI to save nearly 200 hours a month on phishing triage?
St. Luke’s University Health Network uses the Phishing Triage Agent in Microsoft Defender, powered by Security Copilot, to handle the bulk of user-reported suspicious emails.
Previously, analysts spent hours each day manually reviewing hundreds of alerts across multiple portals. Now, the Phishing Triage Agent:
- Uses advanced language models to understand the content and intent of reported emails.
- Automatically classifies submissions as genuine phishing or false positives.
- Autonomously closes thousands of false positive alerts, with clear, plain-text explanations for each decision.
As a result, St. Luke’s is saving nearly 200 hours every month on phishing alert triage. Analysts no longer need to double-check every incident and can instead focus on proactive threat hunting and higher-value investigations. This shift has helped reduce burnout, improve response times, and ensure that real threats are surfaced more quickly.
How does Security Copilot unify St. Luke’s security tools and visibility?
St. Luke’s had a strong security stack—Microsoft Defender, Microsoft Sentinel, Microsoft Entra, Microsoft Purview, and other tools—but they were operating in silos. The team lacked a single, real-time view across endpoints, email, identities, applications, and cloud workloads.
Security Copilot acts as an AI layer across this entire stack, effectively becoming the “connective tissue” that:
- Consolidates alerts, access controls, and vulnerabilities into a single, unified view.
- Correlates signals from multiple platforms to identify threats in real time.
- Surfaces AI-driven insights and recommendations directly in analysts’ existing workflows.
This unified visibility helps St. Luke’s:
- Spot gaps and weaknesses in their environment.
- Move from reactive response to more predictive, proactive analytics.
- Make faster, data-driven decisions without jumping between multiple dashboards.
In practice, this reimagines their security operations from a set of disconnected tools into a cohesive, AI-first security posture that better supports both day-to-day operations and long-term strategy.
What other Security Copilot agents is St. Luke’s using beyond phishing triage?
St. Luke’s is an early adopter of several Security Copilot agents that help automate and streamline different parts of their security operations. In addition to the Phishing Triage Agent in Defender, they are using:
- Conditional Access Optimization Agent in Microsoft Entra – Helps refine and optimize conditional access policies so the team can balance security with clinician and staff productivity.
- Vulnerability Remediation Agent in Microsoft Intune – Assists with prioritizing and addressing vulnerabilities across thousands of endpoints.
- Alert Triage Agents in Microsoft Purview DLP and IRM – Support faster triage of data loss prevention and information protection alerts.
These agents work alongside Security Copilot’s core capabilities, such as:
- Automated incident reporting in Defender, which cuts report creation from hours to minutes for a workforce of more than 23,000 employees.
- Embedded guidance that helps analysts understand incidents step-by-step and collaborate more effectively.
Together, these agents help St. Luke’s reshape daily security work—moving repetitive, manual tasks to AI-driven agents and freeing the Security Operations Center to focus on complex threats, strategic improvements, and maintaining resilience across 15 campuses, 300 outpatient sites, and more than 2.5 petabytes of data.

St. Luke's saves nearly 200 hours monthly with AI-powered Security Copilot agents | Microsoft Customer Stories
published by BlueTeamAssess LLC
I founded BlueTeamAssess LLC to develop and offer actionable and cost effective security solutions to SMBs.
BlueTeamAssess LLC is a veteran-owned Cybersecurity Consulting business based in Onslow County, NC.
My company wants to be the trusted advisor to small businesses for cybersecurity and related information technology needs. We will help you meet compliance requirements for HIPAA, PCI, NC cybersecurity requirements for financial advisors, and NIST 800-171 and CMMC cybersecurity requirements for providing goods and services through DOD contracts.
We help small businesses understand cybersecurity threats and their vulnerability to those threats. We offer affordable products and services to protect their business and their livelihood from those threats.
We use the SAINT Security Suite and its family of assessment products to provide cybersecurity services that assess your exposure to the many threats that can impact your business. And we help you meet compliance requirements for NIST 800-171 cybersecurity requirements for providing goods and services through DOD contracts as well as for HIPAA, PCI, the NC data breach protection law and NC cybersecurity requirements for financial advisors.
We use the CyberSecurity Assessment Tool from QS Solutions to assess the security posture of your Microsoft 365 deployment and help bring your risk score to acceptable levels through our remediation services.
We will help you reduce SPAM, secure your email and defend against ransomware. To help do this, we offer a number of solutions scalable for small business budgets and environments. These include:
- Microsoft 365 email and office software and its extensive security features and advanced threat protection.
- Fortinet security solutions that provide a Security Fabric that knits together protection for your endpoints and servers, your firewalls, your wireless network, security analytics and many other services that protect your organization technology from today’s advanced threats whether the workers are working in the office or remotely from home.
- A backup and recovery solution from Acronis to protect your critical customer and business data when the next storm or other disaster impacts your business.
You can trust BlueTeamAssess LLC be the trusted advisor to small businesses for cybersecurity and related information technology needs.