What it does
Security Copilot is Microsoft's generative-AI assistant for security and IT teams. It reasons over signals from the Microsoft security stack (and third-party sources via plugins) to summarise incidents, hunt threats, guide response, and run autonomous agents.
Key facts
- Two ways to use it: the standalone portal at securitycopilot.microsoft.com, and embedded surfaces inside Defender, Sentinel, Purview, Entra, and Intune.
- The standalone portal is where you get the open prompt bar, promptbooks, sessions, plugin management, and agent configuration. Embedded experiences give you Copilot in-context (incident summary, guided response) without leaving the product.
- Pulls data from Defender XDR, Sentinel, Entra, Intune, Purview, Defender for Cloud, Defender EASM, and Defender Threat Intelligence.
- Aimed at SOC analysts, threat hunters, incident responders, identity/device admins, and data-security teams — not just tier-1.
- Billed on Security Compute Units (SCUs), a provisioned-capacity model — not per-user seats.
- As of 18 November 2025, Security Copilot is included for Microsoft 365 E5 and E7 customers (400 SCUs/month per 1,000 paid E5 licences, capped at 10,000 SCUs/month), rolling out in phases.
- The autonomous agents (phishing triage, alert triage, and so on) are the headline of the 2025/2026 story — the assistant is now as much a set of agents as a chat surface.
When to use / skip
If you already run Defender XDR and/or Sentinel and your SOC is drowning in triage, this is the obvious add-on — the embedded incident summaries and the triage agents earn their keep fast. If your Microsoft security footprint is thin (say, Defender for Office 365 only, no XDR/Sentinel), you'll get far less out of it and the SCU meter still runs. And if you're not on E5/E7, you're paying real money for compute capacity, so pilot before you commit.
Configuration decisions
- Portal-first or embedded-first: decide whether analysts live in the standalone portal or stay in Defender/Sentinel with Copilot in-context. Most SOCs settle on embedded for daily work, portal for deep investigations and promptbooks.
- Owner/contributor roles: Copilot has its own RBAC on top of product permissions — work out who can provision SCUs, manage plugins, and publish promptbooks.
- Which data sources to plug in on day one, and which to hold back for cost/noise reasons.
- Geographic/data-residency choice at setup — this is set early and matters for regulated clients.
Gotchas
- Copilot honours the underlying product permissions of the signed-in user, but the Copilot-specific roles are a separate layer people forget to configure. You'll hit "why can't I provision capacity" tickets.
- The standalone portal and the embedded experiences are the same service but feel like different products — set expectations so users don't think features are missing.
- E5/E7 inclusion is phased and capped; don't assume a client "has it for free" without checking their rollout state and licence count.
- It reasons over the data it can reach — weak Defender/Sentinel coverage means weaker answers, not magic.
Consultant notes
- Position it as a SOC force-multiplier, not a replacement for a SIEM or for analysts. The value is time-to-triage and time-to-context.
- The E5/E7 inclusion changed the sales conversation in late 2025: for E5 shops it's now "you already have capacity, let's use it" rather than a net-new spend.
- Lead demos with embedded incident summarisation in Defender — it's the fastest "oh, I get it" moment for a security lead.
- Anchor every engagement to SCU cost from the first conversation; the compute model is where deals go sideways.
Check the E5/E7 inclusion rollout state for this specific tenant before quoting "it's included" — it's phased and capped.