MS Microsoft Healthcare United States

St. Luke’s University Health Network

IT Operations Automation · Security and Compliance

St. Luke’s—with 15 campuses, 300 outpatient sites, 23,000+ employees, and 2.5+ petabytes of patient data—needed unified, real-time visibility across a previously disconnected security stack so its SOC could anticipate and disrupt phishing and DDoS attacks before they paralyzed life-saving care delivery.

15 campuses and 300 outpatient sites
2.5+ petabytes of patient data in motion
23,000+ employees
Incident reports created in minutes instead of hours

Solution

St. Luke's University Health Network implemented Microsoft Security Copilot as a unified AI layer across its security operations, connecting Microsoft Defender, Microsoft Sentinel, Microsoft Entra, Microsoft Intune, and Microsoft Purview. The system ingests millions of daily security signals from endpoints, email, identity, applications, and cloud workloads, correlating threats across fragmented platforms. Security Copilot agents including the Security Alert Triage Agent, Vulnerability Remediation Agent, and Conditional Access Optimization Agent autonomously handle routine tasks—triaging phishing emails, categorizing false positives, and remediating vulnerabilities—freeing SOC analysts for proactive threat hunting. All alerts, access controls, and vulnerabilities are consolidated in one interface, providing real-time visibility for faster incident response. Azure Monitor and Log Analytics provide comprehensive audit trails for compliance with healthcare regulations.

Data flow

Security signals flow from millions of daily events across endpoints, email, identity, cloud workloads, and data interactions into Azure Monitor and Log Analytics. Security Copilot ingests these signals, correlates threats across platforms using OpenTelemetry-compliant integration, and surfaces actionable insights. The Security Alert Triage Agent analyzes suspicious email submissions to determine if they are genuine phishing or false alarms, autonomously closing false positives. Incident reports are generated by Security Copilot in minutes, consolidating correlated data from all sources for escalation to leadership or forensic investigation.

Solution architecture

7 components · 2 layers
  1. Governance
    • Microsoft Security Copilot Unified AI layer providing centralized visibility and intelligent correlation of security signals across all platforms.
    • Microsoft Defender Spans endpoint, email, identity, application, and cloud workload protection providing security events across the attack surface.
    • Microsoft Sentinel Provides SIEM capabilities for security information and event management with correlation and analytics.
    • Microsoft Entra Manages identity and access controls with Conditional Access Optimization Agent for proactive policy refinement.
    • Microsoft Intune Manages endpoints across 15 campuses and 300+ sites with Vulnerability Remediation Agent for automated patch management.
    • Microsoft Purview Provides data loss prevention and information rights management with Alert Triage Agents for user behavior analysis.
  2. Uncategorized
    • Azure Monitor & Log Analytics Offers comprehensive observability, audit trail logging, and compliance reporting required by healthcare regulations.

Architecture clues

  • Agent explanations in plain text used by analysts to validate decisions
  • Alert Triage Agents in Purview DLP and IRM
  • Conditional Access Optimization Agent in Entra
  • Security Alert Triage Agent uses advanced language-model analysis to classify reported phishing emails
  • Security Copilot as connective tissue across Defender, Sentinel, Entra, Purview, and Intune
  • Vulnerability Remediation Agent in Intune

Evidence from the source

Creating an incident report by hand can take hours, but with Copilot, the process is reduced to minutes.
Healthcare is the number one cyberattack target in the world.
Our team shifted from reactive triage to proactive threat hunting, now that they’re not bogged down by routine triage.
The Security Alert Triage Agent is a game changer. It’s saving us nearly 200 hours monthly by autonomously handling and closing thousands of false positive alerts.