Analysts monitor a futuristic cybersecurity dashboard with biometric access, user data, and performance charts.
Avanade reports that it reduced average identity-incident resolution time by approximately 70–80% after embedding Microsoft Security Copilot and Microsoft Entra into daily investigations. For enterprise identity teams, the useful finding is how it achieved those gains: engineers combined AI-assisted investigation with reusable prompts and documented workflows, rather than deploying a standalone chatbot. The figures come from Avanade’s account in Microsoft’s September 18 customer story, subsequently covered by Technology Record on September 21; they are customer-reported results, not an independently validated benchmark.

What changed in the investigation workflow​

According to Microsoft’s account, Avanade’s previous process required engineers to gather and analyze information across multiple tools and screens. Manual investigations took between 10 and 77 minutes, depending on the scenario, and complex cases frequently needed senior specialists. That combination created both a processing bottleneck and a dependency on a relatively small pool of expertise.

Avanade started with a five-week pilot using Security Copilot during live identity investigations. Working with Microsoft Entra, Microsoft’s identity and access-management platform, Copilot brought together identity signals, investigation guidance and recommended next steps. Engineers documented recurring investigative patterns and converted them into prompt-based workflows.

The practical change was therefore broader than faster information retrieval. By recording how experienced investigators approached common problems, Avanade made those approaches reusable across the team. Engineers reportedly resolved complex cases without escalating every one, allowing the team to take on more work without increasing headcount. The described process retained engineers as decision-makers; it does not establish autonomous remediation.

For another IT department evaluating the results, this is an important implementation boundary: the measured intervention combined software with workflow standardization. The account does not isolate how much of the improvement came from Copilot itself versus the captured expertise and redesigned investigation process.

What the timing figures actually measure​

Microsoft’s customer story gives three useful before-and-after comparisons from Avanade’s identity work.

Investigation measurePrevious timeAI-assisted time
Guest-account investigation10 minutes1 minute
Passwordless phone sign-in issue27 minutes2 minutes
Average incident resolution10–12 minutes2–3 minutes

The two named scenarios show larger proportional reductions than the headline average: 90% for guest-account investigations and approximately 93% for passwordless phone sign-in issues, calculated from the published times. They are individual examples, whereas the 70–80% figure describes Avanade’s reported overall reduction. They should not be treated as interchangeable measurements.

Likewise, the earlier 10–77-minute range describes variation between manual scenarios. It does not mean the average incident previously took 77 minutes. Using that upper endpoint as the baseline would exaggerate the documented improvement.

The scope also matters. Guest-account issues, passwordless sign-in problems and passkey errors are identity-operations work, but they do not necessarily represent malicious activity. These timings support a claim about faster investigation and resolution of identity cases—not a claim that Avanade contained cyberattacks 80% faster.

A passkey rollout put the process under load​

Avanade used the AI-assisted workflow during a passkey rollout to approximately 17,000 users. Microsoft reports that identity teams used Security Copilot to help manage more than 180 passkey-adoption support tickets per day, focusing investigations and accelerating resolution.

This supplies a concrete operational setting for the pilot’s approach. A large authentication change can generate repeated support scenarios, making reusable investigation patterns especially relevant. Avanade’s experience suggests a useful evaluation strategy for other identity teams: assess assistance against a defined workload, such as a passwordless rollout, rather than judging it solely through occasional demonstrations.

The ticket count is a workload measure, however, not a failure rate. The published account does not give the duration of that ticket volume or the number of distinct affected users, so it cannot establish what proportion of the rollout encountered problems.

Custom agents and a separate investigation study​

Avanade subsequently built custom agents on the Security Copilot platform for broader security operations. Microsoft describes these agents as consolidating security signals, recommendations and playbook-based next steps for analysts, extending the same effort to make documented expertise reusable.

In a separate study covering more than 4,100 security operations investigations, Avanade reported:

  • Speed and efficiency improved by 70%.
  • Investigation and documentation quality improved by 7%.
  • Human error declined by 7%.
  • Analysts reported 31% lower work intensity and 24% less frequent distraction.

These findings should remain separate from the five-week identity pilot. The published account does not define the scoring methods, comparison groups or how “speed and efficiency” was calculated. Consequently, the 70% study result cannot safely be translated into a specific number of minutes saved or additional cases handled.

There is also a discrepancy in Microsoft’s presentation of analyst exhaustion. Its narrative reports a 38% reduction, which Technology Record repeats, while a separate callout on the same Microsoft page says 8%. The primary account therefore does not provide a consistent figure for that measure.

What enterprise teams can take from the case​

The strongest transferable lesson is the design of the work: identify repeated investigation patterns, preserve expert reasoning in reusable workflows, and measure both resolution time and investigation quality. That is a more defensible basis for a local evaluation than assuming Avanade’s percentage improvement will carry over to another organization.

Avanade already had an established Microsoft security foundation, including Entra, Sentinel and Defender XDR. Its results therefore describe assistance layered onto existing tools and operational knowledge, rather than a replacement for those capabilities. The customer story does not provide licensing costs or a quantified financial return, so faster handling alone is insufficient to calculate another organization’s business case.

Avanade plans to expand Security Copilot to broader identity and access-management and support teams, develop its prompt library, and continue measuring operational impact and return on investment. Microsoft also identifies potential application across parent company Accenture, with nearly 800,000 employees, but describes that as an opportunity—not a completed deployment at that scale.