Automate·Advanced·30 min·Updated Sep 30, 2026

Run a security script analysis before deployment

Use Security Copilot to evaluate a script for safety issues before it ships to production.

Download PDF

Microsoft 365

Prerequisites

The script under review and your organization's scripting security policy (approved commands, forbidden patterns)

Business Outcome

Fewer security incidents caused by scripts that weren't reviewed for risky behavior before deployment.

Handle with care

Scripts with credential/infrastructure handling

A script flagged for credential handling may contain a hardcoded secret or reveal internal infrastructure naming. Security Copilot keeps this inside your tenant, but still treat the script itself as sensitive when sharing the flagged findings in step 3's Teams post — don't paste the full script into a channel wider than the reviewing engineer.

Workflow Overview

Teams
Security Copilot

Step 1: Submit the script with its intended contextScSecurity Copilot

Give Security Copilot the script along with what it's meant to do and where it will run (a scheduled task, a login script, a deployment pipeline) — the same command can be benign or risky depending on context.

Step 2: Ask for a specific risk breakdownScSecurity Copilot

Have it evaluate the script for concrete risk categories — unrestricted network calls, credential handling, privilege escalation, destructive file operations — rather than a general "looks fine" verdict.

Prompt idea:

Review this PowerShell script intended to run as a scheduled maintenance task on domain-joined machines. Flag any command that makes an outbound network call, handles credentials, or could escalate privileges, and explain the specific risk for each.

Step 3: Have a security engineer review every flagTeams

Post the flagged behaviors and Security Copilot's stated reasoning to the reviewing engineer in Teams, with the script attached.

Have them confirm each flag against the script's actual intended use (a credential handling flag might be completely necessary for this specific maintenance task) rather than reflexively stripping out anything flagged.

Step 4: Re-run after every material changeScSecurity Copilot

Any time the script changes meaningfully, re-run the analysis — a script that passed review last month may have picked up new risky behavior since.

Check the work

  • Manually inspect every flagged line to confirm the described risk is accurate, not a false positive from pattern matching.
  • Confirm the analysis actually covered the full script, not just a truncated portion.
  • Don't treat a "clean" result as a substitute for a human security review on any script with elevated privileges.

Source: Microsoft Copilot Scenario Library — IT (2026)

Expected Outcome

A specific list of flagged risky behaviors in the script, or a clean result, before it's approved for deployment.

✓

AI is the right call here

The same command can be benign or risky depending on where and why it runs, as step 1 states directly — that contextual judgment is what a pattern-matching tool can't give you on its own.

Non-AI alternative: Static analysis tools (like PSScriptAnalyzer) already flag many risky patterns by rule, but can't judge whether a flagged behavior is actually safe for this script's specific intended use.

Related Workflows

WORK WITH LIMINALS

Ready to roll this out beyond one person?

Workflows like this tend to raise real governance and licensing questions once more than one person is using them — that's exactly what we help with.