Summary is AI-generated, newsdesk-reviewed
  • Commvault integrates AI threat detection, recovery with Microsoft Security for faster data insights.
  • New integration enhances security with Microsoft Sentinel, Security Copilot, Commvault Cloud platform.
  • Innovations streamline threat detection, trusted recovery, reduces mean time to clean recovery.

Commvault has announced a significant enhancement to its partnership with Microsoft Security, focusing on seamlessly connecting threat detection processes to trusted recovery solutions.

This development involves the integration of Microsoft's Sentinel, Security Copilot, and Commvault's Cloud platform.

By improving resilience operations (ResOps) and enabling real-time data insights, the collaboration aims to help organisations rapidly shift from threat identification to data validation and recovery with increased confidence.

Integration benefits

The new integration fosters greater coordination between security and recovery teams. Security alerts from Commvault Cloud are ingested into the Microsoft Sentinel data lake, enabling Security Operations Center (SOC) analysts to leverage partner intelligence to assess the impact and validate the scope of incidents.

In upcoming quarters, these insights are expected to drive automated, policy-based recovery workflows, facilitating efficient and orchestrated recovery.

Integrated capabilities

The integration offers advanced capabilities to bridge threat detection and trusted recovery:

  • Modernised Microsoft Sentinel Connector: This feature streams alerts and signals from Commvault Cloud Threat Scan and Risk Analysis—covering malware detections, backup anomalies, and sensitive data exposure—into Microsoft Sentinel in real time. This integration enhances security team's visibility into backup-related risks and aids in recognising ransomware patterns, integrating backup telemetry into existing SOC workflows.
  • Commvault’s Investigation Agent in Security Copilot: Specially crafted for cyber recovery investigations, this tool autonomously analyses suspicious activities and uses Commvault's intelligence to determine the scope, such as impacted hosts and anomalous encryption patterns. It helps to synchronise insights with broader Microsoft security signals, reducing the need for manual coordination and decreasing the mean time to clean recovery (MTCR).

Expert insights

"This isn't just an integration – it's a blueprint for the future of agentic ResOps," stated Michelle Graff, SVP, Global Channels and Partnerships at Commvault. "As attacks continue to evolve, siloed approaches don't work. Seconds matter. By uniting and automating critical workflows, Commvault and Microsoft are ushering in a modern approach that can diminish the time between detection and recovery, advance collaboration between IT and security teams, and keep enterprises running in a state of continuous resiliency."

Krishna Kumar Parthasarathy, CVP Sentinel Platform, Microsoft Security, emphasised, "In today’s threat landscape, the need to connect AI-enabled intelligence with automated recovery has never been greater. The combination of Microsoft’s Security Copilot, Microsoft Sentinel, and Commvault’s Threat Scan and Risk Analysis gives enterprises access to a unified approach that can transform ResOps."

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...