Commvault has announced an enhanced integration with Microsoft Security, aiming to better align threat detection and trusted recovery.
This development leverages Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud platform to optimize resilience operations (ResOps) by enabling instant data insights.
The objective is to assist organizations in swiftly transitioning from threat identification to confirming and restoring clean data.
Integration Benefits
This expanded integration facilitates coordinated workflows between security and recovery teams. Security alerts from the Commvault Cloud are incorporated into the Microsoft Sentinel data lake, where security operations center (SOC) analysts can augment these incidents with partner intelligence.
By assessing impact and validating scope, these insights are expected to drive automated, policy-driven recovery workflows in the near future, thereby accelerating clean recovery.
Integrated Capabilities
A modern Microsoft Sentinel connector streams Commvault Cloud alerts to Sentinel in real timeThe announcement also includes new capabilities that bridge the gap between threat detection and trusted recovery. A modernized Microsoft Sentinel Connector streams alerts and signals from Commvault Cloud Threat Scan and Risk Analysis into Microsoft Sentinel in real time. This gives security teams enhanced visibility into backup-related risks while aiding organizations in detecting ransomware patterns sooner by integrating backup telemetry into existing SOC workflows.
Additionally, Commvault’s Investigation Agent in Security Copilot is tailored for cyber recovery investigations. It autonomously analyzes suspicious activity, using Commvault’s recovery-layer intelligence to determine scope, including assessing impacted hosts and anomalous encryption patterns. By linking these insights with broader Microsoft security signals, this capability helps reduce manual coordination between security and backup teams and minimizes mean time to clean recovery (MTCR).
Expert Insights
Michelle Graff, Senior Vice President of Global Channels and Partnerships at Commvault, remarked, “This isn't just an integration – it's a blueprint for the future of agentic ResOps. As attacks continue to evolve, siloed approaches don’t work. Seconds matter. By uniting and automating critical workflows, Commvault and Microsoft are ushering in a modern approach that can diminish the time between detection and recovery, advance the collaboration between IT and security teams, and keep enterprises running in a state of continuous resiliency.”
Krishna Kumar Parthasarathy, Corporate Vice President of the Sentinel Platform at Microsoft Security, emphasized the heightened necessity in today's threat landscape to connect AI-enabled intelligence with automated recovery, saying, “The combination of Microsoft’s Security Copilot, Microsoft Sentinel, and Commvault’s Threat Scan and Risk Analysis gives enterprises access to a unified approach that can transform ResOps.”
Commvault, a pioneer in unified resilience at enterprise scale, announced an expanded integration with Microsoft Security to better connect threat detection with trusted recovery.
The new integration uses Microsoft Sentinel, Microsoft Security Copilot, and the Commvault Cloud platform to streamline resilience operations (ResOps) and enable real-time data insights, helping organizations move quickly from identifying a threat to validating and restoring clean data faster with greater confidence.
Integration benefits
This new integration enables coordinated workflows between security and recovery teams. Security alerts from Commvault Cloud are ingested into Microsoft Sentinel data lake where security operations center (SOC) analysts can enrich these incidents with partner intelligence to access impact and validate scope. In the coming quarters, these insights can drive automated, policy-based recovery workflows to accelerate and orchestrate clean recovery.
Integrated capabilities
As part of this announcement, Commvault is delivering integrated capabilities that bridge the gap between threat detection and trusted recovery.
- Modernised Microsoft Sentinel Connector: Streams alerts and signals generated by Commvault Cloud Threat Scan and Risk Analysis, including malware detections, backup anomalies, and sensitive data exposure, into Microsoft Sentinel in real time. This provides security teams with visibility into backup-related risks alongside broader threat intelligence and helps organizations identify ransomware patterns earlier while incorporating backup telemetry into existing SOC workflows.
- Commvault’s Investigation Agent in Security Copilot: Specifically designed for cyber recovery investigations, Commvault’s Investigation Agent in Microsoft Security Copilot autonomously analyses suspicious activity and uses Commvault’s recovery-layer intelligence to determine scope including impacted hosts, anomalous encryption patterns, and validated restore points. By correlating these insights with broader Microsoft security signals, it can help eliminate manual coordination between security and backup teams while reducing mean time to clean recovery (MTCR).
Expert insights
“This isn't just an integration – it's a blueprint for the future of agentic ResOps,” said Michelle Graff, SVP, Global Channels and Partnerships at Commvault. “As attacks continue to evolve, siloed approaches don’t work. Seconds matter. By uniting and automating critical workflows, Commvault and Microsoft are ushering in a modern approach that can diminish the time between detection and recovery, advance the collaboration between IT and security teams, and keep enterprises running in a state of continuous resiliency.”
“In today’s threat landscape, the need to connect AI-enabled intelligence with automated recovery has never been greater,” said Krishna Kumar Parthasarathy, CVP Sentinel Platform, Microsoft Security. “The combination of Microsoft’s Security Copilot, Microsoft Sentinel, and Commvault’s Threat Scan and Risk Analysis gives enterprises access to a unified approach that can transform ResOps.”