Almanac
Microsoft/copilotMicrosoft 365

Consultant KB for the whole Microsoft Copilot estate. Spans Microsoft 365 Copilot, Copilot Studio, the Dynamics 365 Copilots, Power Platform Copilot, Fabric & Power BI Copilot, Copilot in Azure, Windows & consumer Copilot, extensibility & agents, Security Copilot, and GitHub Copilot, plus admin/security and cross-product decision guides. Populated by the daily author agent from Copilot release notes / release plans plus the author's own consultant notes.

feature-security-copilot-overview.mdv1 · history
CurrentApplies to Security CopilotUpdated 2 months agoSource Microsoft Learn

What it does

Security Copilot is Microsoft's generative-AI assistant for security and IT teams. It reasons over signals from the Microsoft security stack (and third-party sources via plugins) to summarise incidents, hunt threats, guide response, and run autonomous agents.

Key facts

  • Two ways to use it: the standalone portal at securitycopilot.microsoft.com, and embedded surfaces inside Defender, Sentinel, Purview, Entra, and Intune.
  • The standalone portal is where you get the open prompt bar, promptbooks, sessions, plugin management, and agent configuration. Embedded experiences give you Copilot in-context (incident summary, guided response) without leaving the product.
  • Pulls data from Defender XDR, Sentinel, Entra, Intune, Purview, Defender for Cloud, Defender EASM, and Defender Threat Intelligence.
  • Aimed at SOC analysts, threat hunters, incident responders, identity/device admins, and data-security teams — not just tier-1.
  • Billed on Security Compute Units (SCUs), a provisioned-capacity model — not per-user seats.
  • As of 18 November 2025, Security Copilot is included for Microsoft 365 E5 and E7 customers (400 SCUs/month per 1,000 paid E5 licences, capped at 10,000 SCUs/month), rolling out in phases.
  • The autonomous agents (phishing triage, alert triage, and so on) are the headline of the 2025/2026 story — the assistant is now as much a set of agents as a chat surface.

When to use / skip

If you already run Defender XDR and/or Sentinel and your SOC is drowning in triage, this is the obvious add-on — the embedded incident summaries and the triage agents earn their keep fast. If your Microsoft security footprint is thin (say, Defender for Office 365 only, no XDR/Sentinel), you'll get far less out of it and the SCU meter still runs. And if you're not on E5/E7, you're paying real money for compute capacity, so pilot before you commit.

Configuration decisions

  • Portal-first or embedded-first: decide whether analysts live in the standalone portal or stay in Defender/Sentinel with Copilot in-context. Most SOCs settle on embedded for daily work, portal for deep investigations and promptbooks.
  • Owner/contributor roles: Copilot has its own RBAC on top of product permissions — work out who can provision SCUs, manage plugins, and publish promptbooks.
  • Which data sources to plug in on day one, and which to hold back for cost/noise reasons.
  • Geographic/data-residency choice at setup — this is set early and matters for regulated clients.

Gotchas

  • Copilot honours the underlying product permissions of the signed-in user, but the Copilot-specific roles are a separate layer people forget to configure. You'll hit "why can't I provision capacity" tickets.
  • The standalone portal and the embedded experiences are the same service but feel like different products — set expectations so users don't think features are missing.
  • E5/E7 inclusion is phased and capped; don't assume a client "has it for free" without checking their rollout state and licence count.
  • It reasons over the data it can reach — weak Defender/Sentinel coverage means weaker answers, not magic.

Consultant notes

  • Position it as a SOC force-multiplier, not a replacement for a SIEM or for analysts. The value is time-to-triage and time-to-context.
  • The E5/E7 inclusion changed the sales conversation in late 2025: for E5 shops it's now "you already have capacity, let's use it" rather than a net-new spend.
  • Lead demos with embedded incident summarisation in Defender — it's the fastest "oh, I get it" moment for a security lead.
  • Anchor every engagement to SCU cost from the first conversation; the compute model is where deals go sideways.

Check the E5/E7 inclusion rollout state for this specific tenant before quoting "it's included" — it's phased and capped.

Was this accurate?