Commvault has announced a significant enhancement to its partnership with Microsoft Security, focusing on seamlessly connecting threat detection processes to trusted recovery solutions.
This development involves the integration of Microsoft's Sentinel, Security Copilot, and Commvault's Cloud platform.
By improving resilience operations (ResOps) and enabling real-time data insights, the collaboration aims to help organisations rapidly shift from threat identification to data validation and recovery with increased confidence.
Integration benefits
The new integration fosters greater coordination between security and recovery teams. Security alerts from Commvault Cloud are ingested into the Microsoft Sentinel data lake, enabling Security Operations Center (SOC) analysts to leverage partner intelligence to assess the impact and validate the scope of incidents.
In upcoming quarters, these insights are expected to drive automated, policy-based recovery workflows, facilitating efficient and orchestrated recovery.
Integrated capabilities
The integration offers advanced capabilities to bridge threat detection and trusted recovery:
- Modernised Microsoft Sentinel Connector: This feature streams alerts and signals from Commvault Cloud Threat Scan and Risk Analysis—covering malware detections, backup anomalies, and sensitive data exposure—into Microsoft Sentinel in real time. This integration enhances security team's visibility into backup-related risks and aids in recognising ransomware patterns, integrating backup telemetry into existing SOC workflows.
- Commvault’s Investigation Agent in Security Copilot: Specially crafted for cyber recovery investigations, this tool autonomously analyses suspicious activities and uses Commvault's intelligence to determine the scope, such as impacted hosts and anomalous encryption patterns. It helps to synchronise insights with broader Microsoft security signals, reducing the need for manual coordination and decreasing the mean time to clean recovery (MTCR).
Expert insights
"This isn't just an integration – it's a blueprint for the future of agentic ResOps," stated Michelle Graff, SVP, Global Channels and Partnerships at Commvault. "As attacks continue to evolve, siloed approaches don't work. Seconds matter. By uniting and automating critical workflows, Commvault and Microsoft are ushering in a modern approach that can diminish the time between detection and recovery, advance collaboration between IT and security teams, and keep enterprises running in a state of continuous resiliency."
Krishna Kumar Parthasarathy, CVP Sentinel Platform, Microsoft Security, emphasised, "In today’s threat landscape, the need to connect AI-enabled intelligence with automated recovery has never been greater. The combination of Microsoft’s Security Copilot, Microsoft Sentinel, and Commvault’s Threat Scan and Risk Analysis gives enterprises access to a unified approach that can transform ResOps."
Commvault, a pioneer in unified resilience at enterprise scale, announced an expanded integration with Microsoft Security to better connect threat detection with trusted recovery.
The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud platform to streamline resilience operations (ResOps) and enable real-time data insights, helping organisations move quickly from identifying a threat to validating and restoring clean data faster with greater confidence.
Integration benefits
This new integration enables coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center (SOC) analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery.
Integrated capabilities
As part of this announcement, Commvault is delivering integrated capabilities that bridge the gap between threat detection and trusted recovery.
- Modernised Microsoft Sentinel Connector: Streams alerts and signals generated by Commvault Cloud Threat Scan and Risk Analysis, including malware detections, backup anomalies, and sensitive data exposure, into Microsoft Sentinel in real time. This provides security teams with visibility into backup-related risks alongside broader threat intelligence and helps organisations identify ransomware patterns earlier while incorporating backup telemetry into existing SOC workflows.
- Commvault’s Investigation Agent in Security Copilot: Specifically designed for cyber recovery investigations, Commvault’s Investigation Agent in Microsoft Security Copilot autonomously analyses suspicious activity and uses Commvault’s recovery-layer intelligence to determine scope including impacted hosts, anomalous encryption patterns, and validated restore points. By correlating these insights with broader Microsoft security signals, it can help eliminate manual coordination between security and backup teams while reducing mean time to clean recovery (MTCR).
Expert insights
“This isn't just an integration – it's a blueprint for the future of agentic ResOps,” said Michelle Graff, SVP, Global Channels and Partnerships at Commvault. “As attacks continue to evolve, siloed approaches don’t work. Seconds matter. By uniting and automating critical workflows, Commvault and Microsoft are ushering in a modern approach that can diminish the time between detection and recovery, advance the collaboration between IT and security teams, and keep enterprises running in a state of continuous resiliency.”
“In today’s threat landscape, the need to connect AI-enabled intelligence with automated recovery has never been greater,” said Krishna Kumar Parthasarathy, CVP Sentinel Platform, Microsoft Security. “The combination of Microsoft’s Security Copilot, Microsoft Sentinel, and Commvault’s Threat Scan and Risk Analysis gives enterprises access to a unified approach that can transform ResOps.”