security
May 22, 2026
By Teun
Microsoft spotlights St. Luke’s, ManpowerGroup on AI security
Microsoft Security highlighted customer stories from St. Luke’s University Health Network and ManpowerGroup, saying both organizations are building security foundations for AI. The examples focus on unified visibility, governance, and automation across cloud, identity, data, and operations.
Microsoft Security has published two customer stories that it says show how organizations are adapting their security programs for AI. The examples come from St. Luke’s University Health Network and ManpowerGroup, and both focus on the same core problem: AI can speed up work, but it also expands risk across cloud, identity, data, and security operations.
The company said many organizations want AI-powered productivity, but their security foundations are not yet ready for it. In its view, protections for agentic AI, or AI systems that can take actions on a user’s behalf, cannot be added later. They need to be built into how those systems are developed, governed, and used.
Microsoft tied that approach to cloud security posture, data governance, and Zero Trust principles. Zero Trust is a security model that assumes breach and verifies access continuously rather than trusting users or devices by default.
The first example is St. Luke’s University Health Network. Microsoft said the health network wanted unified, real-time visibility across its security tools because its existing setup made it harder to detect and stop threats early.
To address that, St. Luke’s turned to Microsoft Security Copilot, which Microsoft describes as an AI tool that helps security analysts work faster. The organization also connected Microsoft Defender and Microsoft Sentinel to create a single view across endpoints, identity, email, and cloud workloads.
According to Microsoft, that setup helps analysts correlate threats faster, identify risks in real time, and move from reactive response to more proactive defense. Microsoft also said Security Copilot agents are automating tasks such as alert triage and vulnerability remediation.
The company said its Security Triage Agent is saving St. Luke’s up to 200 analyst hours each month. Microsoft also said advanced phishing triage is reducing false positives and improving decision confidence.
The second example is ManpowerGroup. Microsoft said the company was moving to a unified, cloud-based security platform to protect a distributed workforce and deal with identity-focused risk and compliance demands as AI becomes part of daily work.
According to Microsoft, ManpowerGroup had a mix of security tools that became harder to manage as the company grew globally. That led to more complexity, inconsistent controls, and slower response as threats and regulatory requirements increased.
To simplify that environment, ManpowerGroup deployed Microsoft 365 E5, Microsoft Defender, and Microsoft Sentinel. Microsoft said the move gave the company real-time prevention, detection, and response across identity, endpoint, email, and cloud, along with cloud-native SIEM and SOAR capabilities.
SIEM stands for security information and event management. SOAR stands for security orchestration, automation, and response. Both are used to collect security data, automate response steps, and coordinate incident handling.
Microsoft said the platform approach cut integration timelines from weeks or months to hours or days and helped ManpowerGroup unify global security operations. The company said that also helped build what it called an AI-ready security foundation.
Microsoft used the two customer stories to outline a repeatable playbook for securing AI at scale. The steps it listed were to lead with risk and business value, unify visibility across cloud, identity, data, and SecOps, make governance operational, harden posture continuously, and automate outcomes at scale.
The blog also framed these organizations as examples of what Microsoft calls “frontier firms,” or companies that pair speed with trust in the AI era. Microsoft said those firms treat security as a foundational capability rather than an afterthought.
The customer stories are presented as examples of how Microsoft Security says organizations can adopt AI without slowing business operations. The company said the goal is to connect visibility, governance, posture management, and automation so AI-powered work can scale with less risk.