Microsoft Security Copilot | Microsoft Security (original) (raw)
Security Copilot delivers agentic automation and AI-driven insights across Security and IT, empowering organizations to protect, detect, and respond at the speed and scale of AI.
Security Copilot combines a specialized language model with security-specific capabilities from Microsoft. These capabilities incorporate a growing set of security-specific skills informed by our unique global threat intelligence and more than 100 trillion daily signals.
Yes, Security Copilot is generally available for use by security and IT teams.
Get started by flexibly provisioning compute capacity to run Security Copilot workloads. Scale confidently to meet your evolving needs even during periods of unexpected demand. Learn about pricing and read more about how to get started with Security Copilot. Security Copilot will also be included in Microsoft 365 E5. See below for details.
Yes. Copilot integrates with other Microsoft Security products, including but not limited to Microsoft Defender XDR, Microsoft Sentinel, Microsoft Intune, Microsoft Entra, Microsoft Purview, Microsoft Defender for Cloud, and Microsoft Defender External Attack Surface Management. It also integrates with Azure security tools including Azure Web Application Firewall (WAF) and Azure Firewall. Copilot uses the data and signals from these products to generate customized guidance.
Yes. Security Copilot integrates with partner products to provide plugins and promptbooks that extend customer insights. Copilot capabilities are also expanding to include agents built by partners. Learn more about partners that integrate with Security Copilot.
Security Copilot agents enhance security and IT operations with autonomous and adaptive automation. Integrated seamlessly with Microsoft Security solutions and partner ecosystems, agents handle high-volume security tasks, reduce workloads, and accelerate responses. They learn from feedback and adapt to workflows, boosting efficiency while teams stay in control.
Users interact with agents from within Microsoft Defender, Entra, Intune, Microsoft Purview, and Security Copilot. Get started with Security Copilot agents using security compute units (SCUs) or access as part of your Microsoft 365 E5 subscription.
At Ignite 2025, Microsoft announced that Security Copilot agents will be directly built into the flow of work for security teams, available in Microsoft Defender, Entra, Intune and Purview. To make the agents easily accessible and help security teams get started faster, Security Copilot will be available to all Microsoft 365 E5 customers. Microsoft 365 E5 customers already using Security Copilot as of November 18, 2025, can access this benefit now. All other Microsoft 365 E5 customers will be activated through a phased roll-out in the upcoming months. Customers will receive advanced notice.
Eligible Microsoft 365 E5 customers will have 400 Security Compute Units (SCUs) per month for every 1000 user licenses, up to 10,000 SCUs per month. This included capacity is expected to support typical scenarios.
Example 1: An organization with 400 seats gets 160 SCUs/month.
Example 2: An organization with 4,000 seats gets 1,600 SCUs/month.
Microsoft 365 E5 customers already using Security Copilot as of November 18, 2025, can access this benefit now. All other Microsoft 365 E5 customers will be activated through a phased roll-out in the upcoming months. Customers will receive advanced notice.