First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Security Copilot Deployment and SOC Automation
ImplementationSecurity and Protection

Microsoft Security Copilot Deployment and SOC Automation

IT Partner turns a Microsoft Security Copilot entitlement — the capacity Microsoft now includes with Microsoft 365 E5 and E7, or standalone provisioned Security Compute Units (SCUs) — into working SOC automation in a fixed-price, three-week engagement. We size the capacity against the agents and promptbooks you actually intend to run, confirm the auto-provisioned workspace or create one in the right data-storage geography, replace the default owner and contributor access with named security groups, set Purview audit logging and the data-sharing choices you make, connect the Defender XDR, Sentinel, Entra, Intune, Purview and Microsoft Threat Intelligence plugins, then set up and tune up to six Security Copilot agents and promptbooks that fit your team — Phishing Triage in Defender, Conditional Access Optimization in Entra, Vulnerability Remediation in Intune, the Data Security Triage agent for Purview DLP and Insider Risk alerts, the Threat Intelligence Briefing agent, and promptbooks for incident summary, investigation, KQL-assisted hunting and executive reporting. Two automations are wired into Sentinel playbooks or Azure Logic Apps, usage monitoring and cost alerts are set, and your security team gets a short enablement session and a handover pack. Fixed at $5,950 per project. The SCUs the platform consumes are yours — drawn from your E5 allocation, or billed by Microsoft for provisioned and overage capacity — and are not part of this fee. Sentinel deployment, 24×7 monitoring and incident-response retainers are separate, named services linked below.

Timeline 3 weeksService owner Roman SotnikMicrosoft Security CopilotMicrosoft Defender XDRMicrosoft Sentinel

What this engagement is

Microsoft folded Security Copilot into Microsoft 365 E5 and E7 in 2026. Per Microsoft's Message Center notice MC1261596 and its 'Security Copilot for Microsoft 365 E5 and E7 customers' guidance, eligible tenants were auto-provisioned in a phased rollout between 20 April and 30 June 2026 and receive 400 Security Compute Units (SCUs) a month for every 1,000 paid E5 or E7 user licenses, scaled proportionally for smaller counts, capped at 10,000 SCUs a month, reset monthly with no rollover. Activation was 'zero click': Microsoft created a default capacity and a default workspace in your tenant, set the data-storage location to your Microsoft Entra geography, and let several administrator roles inherit Security Copilot owner or contributor access. That is the situation most E5 security teams are in today — a working Security Copilot they did not switch on, holding a monthly pool of capacity that either sits unused or gets drawn down by an agent nobody tuned. Organizations outside E5 buy the same platform as standalone provisioned SCUs on an Azure subscription (minimum one SCU, billed by the hour, with optional overage) — Microsoft's published example at the time of writing prices a provisioned SCU at $4 an hour and an overage SCU at $6. Security Copilot in 2026 is three things at once. It is a standalone portal (securitycopilot.microsoft.com) where analysts prompt across plugins — Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra, Microsoft Intune, Microsoft Purview, Microsoft Threat Intelligence, Defender External Attack Surface Management and third-party sources — and save repeatable sequences as promptbooks. It is an embedded experience inside the Defender, Entra, Intune and Purview portals: incident summaries and guided response, natural-language KQL in advanced hunting, script and policy explanations. And, since 2025, it is a set of agents that run on a schedule or a trigger and consume SCUs on their own: the Phishing Triage Agent in Microsoft Defender (generally available for user-reported email; its extension to identity and cloud alerts as the Security Alert Triage Agent is in preview), the Threat Intelligence Briefing Agent, the Conditional Access Optimization Agent in Entra, the Vulnerability Remediation Agent in Intune, and the Data Security Triage Agent for Purview DLP and Insider Risk alerts, alongside newer Defender agents and partner-built agents in the Microsoft Security Store. Each agent needs the product license behind it, an identity with a least-privilege role, a human who reviews its verdicts and teaches it through feedback, and a share of the capacity — which is why turning them all on at once is the fastest way to exhaust an allocation. For SOC automation, the Security Copilot connector for Azure Logic Apps can submit a prompt or a whole promptbook from a Sentinel playbook, so an incident can arrive in the queue with its summary and next steps already attached. This engagement is the operationalization step, not a platform rollout. Over three weeks we work out how much capacity you actually have and what it will bear, put the workspace, roles, audit and data-sharing settings in order, connect the plugins, enable and tune the agents and promptbooks that match your team and your licenses (up to six), build two automations into Sentinel playbooks or Logic Apps, set usage monitoring and cost alerts, and hand over to your security team with a runbook and an enablement session. The price is fixed at $5,950 per project. The SCUs that Security Copilot consumes — your E5 allocation, or provisioned and overage capacity billed by Microsoft to your Azure subscription — are Microsoft's meter and the customer's own; nothing on this page changes Microsoft's rates. Sentinel itself, around-the-clock monitoring, incident-response retainers and Defender product rollouts are separate, named services.

Success criteria

01A written capacity decision exists before anything is enabled: which model applies (E5/E7-included allocation, standalone provisioned SCUs, or both), the allocation computed from your licensed count, whether overage is on or off, and the expected monthly draw of every agent and promptbook you approved.
02The workspace (default or newly created) carries the agreed data-storage geography and is linked to the right capacity; Security Copilot owner and contributor access is granted only through named security groups, and the roles that inherited access at auto-provisioning have been reviewed and reduced to what you approved.
03Owner settings match your decisions and are documented: Purview audit logging on, the data-sharing options recorded as you chose them, plugin availability limited to the agreed set, and file-upload and preview-feature toggles set deliberately.
04The agreed plugins — Microsoft Defender XDR, Microsoft Sentinel and Natural language to KQL for Sentinel (preview) where Sentinel is present, Microsoft Entra, Microsoft Intune, Microsoft Purview, Microsoft Threat Intelligence, and Defender EASM where you have it — are connected and each returns a correct answer to a recorded test prompt.
05Up to six agents and promptbooks are enabled, each with a dedicated agent identity holding a least-privilege role, a scope you approved, a named human reviewer with equal or higher permissions, and a schedule; at least one triage agent has processed real alerts during the pilot week and its verdicts have been reviewed.
06The four house promptbooks — incident summary, investigation, KQL-assisted hunting, executive report — run end to end in the standalone portal (and in the Defender portal where they apply) against your own incidents, and are saved and shared in the workspace.
07Two automations are live and tested: for example, a Sentinel automation rule and Logic Apps playbook that submits the incident-summary promptbook when an incident is created and writes the result back to the incident and a Teams channel, and a scheduled Logic App that distributes the Threat Intelligence Briefing.
08Usage monitoring is in place: your team has read the Security Copilot usage dashboard with us, thresholds and review cadence are agreed, and — for Azure-billed capacity — a Cost Management budget with named alert recipients exists on the capacity resource.
09Your security team has attended the enablement session and holds the handover pack: configuration record, agent register, promptbook library, automation runbooks, the capacity model, and the switches that pause an agent or change capacity.

What you receive

Capacity sizing and cost model — entitlement check (Microsoft 365 E5/E7 allocation computed from your paid license count under Microsoft's 400-per-1,000, 10,000-cap, monthly-reset rules; or standalone provisioned SCUs), the planned draw of each agent and promptbook, the overage decision, and a written recommendation you approve before anything is enabled.
Workspace configuration — the auto-provisioned default workspace validated, or one or two workspaces created with the agreed customer-data storage geography (fixed at creation), linked to the right capacity and named to your convention.
Role model — Security Copilot owner and contributor assigned through security groups; the administrator roles that inherit access by default reviewed and trimmed; the Microsoft Entra Security Administrator assignments needed for agent setup confirmed; our own access requested as a time-bound GDAP relationship you approve.
Owner settings — Purview audit logging enabled (Microsoft's default retention is 180 days; longer needs a Purview retention policy), data-sharing choices set and recorded, plugin management (who may add plugins, which plugins are on), file uploads and preview features set deliberately, and the whole configuration written down.
Plugin connections — Microsoft Defender XDR, Microsoft Sentinel (workspace selection) and Natural language to KQL for Sentinel (preview), Microsoft Entra, Microsoft Intune, Microsoft Purview, Microsoft Threat Intelligence and, where licensed, Defender External Attack Surface Management — each verified with a recorded test prompt.
Agent enablement — up to six from the current Microsoft catalog that match your licenses and pains: Phishing Triage Agent in Defender (Defender for Office 365 Plan 2, unified RBAC activated, user-reported message settings and the 'Email reported by user as malware or phish' alert policy on), Security Alert Triage Agent for identity and cloud alerts where you are in the preview, Threat Intelligence Briefing Agent, Conditional Access Optimization Agent in Entra, Vulnerability Remediation Agent in Intune, Data Security Triage Agent for Purview DLP and Insider Risk — each with an agent identity, a least-privilege role and data-source scope, a schedule and a named reviewer.
Agent tuning — a pilot week of real alerts: analyst feedback captured as lessons the agent applies, false-positive patterns and scope adjustments, and each agent's measured SCU draw compared with the capacity model.
Promptbooks — four house promptbooks adapted to your tenant and saved in the workspace: incident summary; investigation (entities, timeline, related alerts, recommended actions); KQL-assisted hunting for Sentinel and Defender advanced hunting; executive or weekly report.
Two automations — built as Sentinel automation rules with Azure Logic Apps playbooks using the Security Copilot connector (submit prompt / submit promptbook), for example incident-created → summary promptbook → incident comment and Teams post, and a scheduled Threat Intelligence Briefing distribution; where Sentinel is not present, both run as Logic Apps against the Defender and Security Copilot APIs.
Usage monitoring and cost alerts — the Security Copilot usage dashboard walked through with your team, per-agent consumption reviewed, thresholds and a monthly review checklist agreed; for Azure-billed capacity, an Azure Cost Management budget and alert recipients on the capacity resource; the procedure for raising, lowering or pausing capacity documented.
Enablement session — one remote working session for your security lead and analysts: prompting patterns that work, reading and teaching an agent, the promptbook library, the automations, capacity and cost controls, and the off-switches.
Handover pack — configuration record, agent register (identity, role, scope, schedule, owner), promptbook library, automation runbooks, the capacity model with the pilot-week measurements, a review cadence, and a backlog of the agents and automations we recommend next.

How the work unfolds

1. Kickoff, entitlement and capacity sizing (week 1, days 1–2)

We confirm what you hold: the E5/E7 allocation in your tenant (or a standalone capacity), the workspace Microsoft created, who inherited owner and contributor access, and which plugins and agents are already switched on and drawing capacity. With your security lead we pick the two or three pains an agent should own first, check the product licenses behind each candidate agent, compute the allocation from your paid license count, and write the capacity model — including the overage decision — that you approve before we enable anything.

2. Foundation: workspace, roles, owner settings, plugins (week 1, days 3–5)

The default workspace is validated or a new one created in the agreed data-storage geography and linked to capacity. Owner and contributor access moves to named security groups and inherited access is trimmed. Owner settings are set as you decided — Purview audit logging, data sharing, plugin management, uploads and preview features — and the Defender XDR, Sentinel, Entra, Intune, Purview and Threat Intelligence plugins are connected and verified with recorded test prompts. Where the Phishing Triage Agent is in scope, unified RBAC, user-reported message settings and the alert policy are activated under your change control.

3. Agents and promptbooks, pilot starts (week 2)

Each approved agent is set up with a dedicated agent identity, a least-privilege role and scope, a schedule and a human reviewer, and the four house promptbooks are adapted to your tenant and saved in the workspace. The pilot week begins on real alerts: reviewers read verdicts, give feedback that the agent applies, and we watch each agent's SCU draw on the usage dashboard against the model.

4. Automations, monitoring and cost alerts (week 3, first half)

The two automations are built and tested — Sentinel automation rules with Logic Apps playbooks calling the Security Copilot connector, or Logic Apps alone where Sentinel is absent — with the actions you approved (summaries, enrichment, comments, notifications, scheduled reports; never containment unless you asked for it in writing). Usage thresholds, the monthly review checklist and, for Azure-billed capacity, a Cost Management budget with alert recipients go in.

5. Tuning review, enablement and handover (week 3, second half)

We review the pilot-week measurements with you, adjust scopes and schedules, and re-baseline the capacity model against what the agents actually consumed. The enablement session runs for your lead and analysts, and the handover pack — configuration record, agent register, promptbook library, runbooks, capacity model, review cadence and next-agent backlog — is delivered for your approval.

Prerequisites

A Security Copilot entitlement: Microsoft 365 E5 or E7 with the included allocation auto-provisioned in your tenant (Microsoft's phased rollout ran 20 April to 30 June 2026 — look for MC1261596 in your Message Center and the default capacity in the Security Copilot portal), or agreement to buy standalone provisioned SCUs on an Azure subscription in your own tenant before week 1 ends.
Microsoft Defender in production — Defender for Endpoint and/or Defender for Office 365 — and Microsoft Sentinel where you want the Sentinel plugin and playbooks. Deploying Sentinel is a separate service; if it is not in place, the two automations are built in Logic Apps against Defender.
The product licenses behind the agents you choose: Defender for Office 365 Plan 2 for the Phishing Triage Agent; the Microsoft Entra plan that licenses Conditional Access for the Conditional Access Optimization Agent; Intune for the Vulnerability Remediation Agent; Purview DLP and Insider Risk Management licensing for the Data Security Triage Agent; Microsoft Entra ID P2 with Defender for Identity and Defender for Cloud Apps for identity-alert triage, and Defender for Cloud with Defender for Containers for cloud-alert triage (both preview).
Administrative access for the engagement: a Global or Security Administrator to onboard and set owner roles, Security Administrator for agent setup in the Defender, Entra, Intune and Purview portals, Owner or Contributor on the Azure subscription for standalone capacity and Logic Apps, and approval of our time-bound GDAP request.
Decisions you own, made at kickoff: the customer-data storage geography for any new workspace (it cannot be changed afterwards), your data-sharing choices, audit logging, which agents to enable, who reviews their verdicts, and which automation actions are approved.
Availability of a security lead and one or two analysts through the three weeks — the pilot week in particular — plus the Sentinel or Logic Apps owner for the playbooks and the Entra, Intune and Purview administrators for their agents.
Change control for the settings the agents depend on: unified RBAC activation in the Defender portal, user-reported message settings and alert policies, agent identities and custom roles, and playbook deployment into your Azure subscription.
Acceptance that SCU consumption is Microsoft's meter and your charge: the E5 allocation is Microsoft's to reset monthly; provisioned and overage SCUs are billed by Microsoft to your Azure subscription.

Who does what

IT Partner

  • Verify the entitlement, compute the allocation from your licensed count, build the capacity model and present the recommendation for your approval before enabling anything.
  • Configure the workspace, geography, capacity link, owner and contributor groups, owner settings, audit logging and plugin connections, and record every setting in the configuration record.
  • Set up the approved agents with least-privilege agent identities, scopes, schedules and reviewers; adapt the four house promptbooks to your tenant; run the pilot week with your reviewers and tune on their feedback.
  • Build and test the two automations with the actions you approved, and set usage monitoring, thresholds and — for Azure-billed capacity — Cost Management budgets and alerts.
  • Deliver the enablement session and the handover pack, including the re-baselined capacity model, the agent register, runbooks and the next-agent backlog.
  • Work only within the time-bound GDAP access you approve, flag risks and decisions as they arise, and report SCU draw honestly — including when an agent is not worth its capacity in your environment.
  • Cite Microsoft's inclusion rules, agent statuses and prices as they stand at the time of writing, and say so where a feature is in preview.

Your team

  • Confirm the entitlement (E5/E7 allocation or standalone capacity), the Azure subscription for any Azure-billed capacity and Logic Apps, and acceptance of Microsoft's SCU charges.
  • Provide administrative access and approve the GDAP request in time for week 1; provide the Security Administrator, Entra, Intune, Purview and Sentinel owners for their parts.
  • Make the kickoff decisions: geography, data sharing, audit logging, the agents to enable and their reviewers, and the automation actions you approve.
  • Review agent verdicts and give feedback during the pilot week; attend the tuning review and the enablement session.
  • Approve change requests for unified RBAC, alert policies, agent identities and playbook deployment within your change process.
  • Own the licenses behind each agent, and the capacity decisions after handover — raising, lowering or pausing capacity and agents as usage shows.
  • Operate Security Copilot after handover, or engage a separate ongoing service for monitoring and tuning.

What's not included

Microsoft's metered charges — Security Compute Units. Your Microsoft 365 E5/E7 allocation is Microsoft's to grant and reset; provisioned and overage SCUs are billed by Microsoft to your own Azure subscription at Microsoft's rates. This service does not resell, discount, cap or absorb them; if you need an Azure subscription for standalone capacity we can provision one through our CSP, and the meter stays Microsoft's.
Microsoft 365 E5 or E7, Defender, Entra, Intune or Purview licensing — we can transact it, and Microsoft 365 E5 is where the included Security Copilot allocation comes from, but it is not part of this fee.
Deploying Microsoft Sentinel, connecting data sources or migrating from another SIEM — that is Microsoft Sentinel SIEM/SOAR Monitoring Implementation or Splunk to Microsoft Sentinel SIEM Migration.
Ongoing monitoring, alert triage and response after handover — Microsoft Sentinel SIEM/SOAR Ongoing Monitoring and Managed Detection and Response are the 24×7 services; this project ends with handover.
Incident response, breach containment, forensics or a retainer — Security Managed Service: Incident Response.
Rolling out the Defender products the agents depend on — Defender for Endpoint, Defender for Office 365, Defender for Identity and Defender for Cloud Apps are their own implementations.
Designing Purview DLP or Insider Risk policies for the Data Security Triage Agent to work on — see Microsoft Purview Insider Risk Management Implementation; the agent triages the alerts your policies already raise.
Custom agents and plugins — agents built in the Security Copilot agent builder or with the developer tools, custom API or KQL plugins, and agents or automations beyond the agreed six-plus-two — quoted separately once the first set is running.
Partner-built agents from the Microsoft Security Store, their purchase and their own fees.
Fixing what the agents find — patching and configuration remediation is Managed Vulnerability Remediation, and redesigning Conditional Access around the optimization agent's recommendations is Microsoft Zero Trust Architecture Implementation; governing Microsoft 365 Copilot and business agents is AI Security for Microsoft 365 Copilot and Agents.

Limitations & technical notes

!The fixed price assumes one tenant, one or two workspaces, up to six agents and promptbooks from Microsoft's first-party catalog, two automations, and the standard Microsoft plugins; additional workspaces, agents, automations or third-party plugins are quoted separately.
!Microsoft's inclusion rules — 400 SCUs a month per 1,000 paid E5/E7 licenses, proportional scaling, a 10,000-SCU monthly cap, monthly reset with no rollover — and its standalone prices are stated as Microsoft published them at the time of writing (September 2026). Microsoft changes them; we restate them at kickoff.
!What happens when an included allocation runs out is Microsoft's behavior, not ours: by Microsoft's current description, Security Copilot is throttled until the next monthly reset unless paid capacity has been attached. We confirm the behavior in your tenant during sizing and design agent schedules so the pool lasts the month.
!Preview features — the Security Alert Triage Agent's identity and cloud alerts, Natural language to KQL for Sentinel, and the newer Conditional Access agent enhancements — can change or be withdrawn by Microsoft; we enable them only when you accept that, and say which ones are preview in the handover pack.
!Every agent is bounded by the license and telemetry behind it and by the scope you approve; its verdicts are recommendations reviewed by your analysts. We make no claim about detection rates, accuracy or time saved — those are your numbers to measure after handover.
!The customer-data storage geography of a workspace is chosen at creation and cannot be changed afterwards, and Microsoft offers a short list of geographies; the default workspace follows your Entra geography. Purview audit records live in your Microsoft 365 region.
!Agent identities are set up on least privilege, and Microsoft requires the people who oversee an agent to hold equal or higher permissions than the agent — which occasionally means widening a reviewer's role, a change you approve.
!Automations act within the scope you approve: summaries, enrichment, comments, notifications and scheduled reports by default; containment or configuration changes only where you approve them in writing, and only through the product's own automation and RBAC.
!Per-agent SCU draw depends on your alert volume, and the pilot-week measurement is a starting estimate rather than a guarantee; the handover pack tells your team how to re-measure and what to switch off first if consumption climbs.
!The three-week timeline starts once the entitlement is provisioned and access is granted; if Microsoft's auto-provisioning has not reached your tenant, or standalone capacity has not been purchased, the clock starts when it has.

Frequently asked questions

What does this service actually deliver?

A working Security Copilot for your SOC, in three weeks, for a fixed $5,950: a capacity model you approve, a workspace with the right geography and roles, owner settings and audit logging set deliberately, the Microsoft plugins connected and verified, up to six agents and promptbooks enabled and tuned on a pilot week of your real alerts, two automations into Sentinel playbooks or Logic Apps, usage monitoring with cost alerts, an enablement session and a handover pack. It is the operationalization of an entitlement you already hold — not a Sentinel or Defender rollout, and not ongoing monitoring.

Do we already have Security Copilot? We are on Microsoft 365 E5.

Very likely yes. Microsoft's Message Center notice MC1261596 announced that Security Copilot is included with Microsoft 365 E5 and E7, with a phased, zero-click rollout between 20 April and 30 June 2026: Microsoft created a default capacity and workspace in eligible tenants, set the data-storage location to your Entra geography and let several administrator roles inherit owner or contributor access. Open the Security Copilot portal with a Global or Security Administrator account and you will see it. The first thing we do is check what is already switched on and drawing capacity.

How much capacity do we have, and is it enough?

Microsoft's rule at the time of writing is 400 Security Compute Units a month for every 1,000 paid E5 or E7 user licenses, scaled proportionally for smaller counts — so a 500-seat tenant gets about 200 a month and a 2,500-seat tenant about 1,000 — capped at 10,000, reset monthly, with nothing carried over. The pool is a consumption budget: prompts, promptbooks and agents draw it down, and the usage dashboard shows the draw per hour. Whether it is enough depends entirely on which agents you run and how much alert volume they see, which is why the first deliverable is a capacity model and the pilot week measures real draw before we hand over.

What happens when the included allocation runs out?

By Microsoft's current description, an exhausted E5 allocation throttles Security Copilot until the next monthly reset — prompts and agents pause rather than generating a bill — unless you have attached paid provisioned or overage capacity to the workspace. Microsoft has been adjusting how included and paid capacity combine, so we confirm the behavior in your tenant during sizing, put the overage decision in writing, and design agent schedules so the pool lasts the month. Any paid capacity is Microsoft's charge on your Azure subscription, not part of this fee.

We are not on E5. Can we still buy this?

Yes. Security Copilot is sold standalone as provisioned Security Compute Units on an Azure subscription in your tenant — a minimum of one SCU, billed by the hour, with optional overage. Microsoft's published example at the time of writing is $4 per provisioned SCU and $6 per overage SCU. The engagement is the same; the sizing step just starts from a purchase decision rather than an allocation, and we set an Azure Cost Management budget on the capacity resource so nobody discovers the meter on the invoice.

Which agents do you set up?

Up to six from Microsoft's catalog that match your licenses and your pains. In Microsoft Defender: the Phishing Triage Agent (generally available for user-reported email; needs Defender for Office 365 Plan 2 and unified RBAC) and its preview extension, the Security Alert Triage Agent, for identity and cloud alerts; the Threat Intelligence Briefing Agent, which schedules briefings built from Microsoft Threat Intelligence and your exposure data. In Microsoft Entra: the Conditional Access Optimization Agent. In Intune: the Vulnerability Remediation Agent. In Purview: the Data Security Triage Agent for DLP and Insider Risk alerts. Each gets a dedicated agent identity with a least-privilege role, a scope, a schedule, a human reviewer and a week of tuning. Partner-built agents from the Security Store are outside the fixed price.

What is a promptbook, and which ones do you build?

A promptbook is a saved sequence of prompts that runs as one unit against your connected plugins — the repeatable part of an analyst's day. We adapt four house promptbooks to your tenant: an incident summary (what happened, entities, timeline, severity, recommended next steps), an investigation (related alerts, user and device risk, sign-in and process context), KQL-assisted hunting that drafts and runs queries in Sentinel or Defender advanced hunting, and an executive or weekly report. They are saved and shared in the workspace, and two of them can be the ones the automations call.

What are the two automations? Do they need Sentinel?

Typical pairs are an incident-created automation rule in Sentinel that runs a Logic Apps playbook calling the Security Copilot connector — submit the incident-summary promptbook, write the result to the incident and post to Teams — and a scheduled Logic App that distributes the Threat Intelligence Briefing to your leads. Sentinel makes the first one elegant, but it is not required: both can run as Logic Apps against Defender and the Security Copilot connector. Actions are limited to summaries, enrichment, comments, notifications and reports unless you approve containment in writing.

Does this replace analysts or our SOC?

No. The agents triage and recommend; your analysts review verdicts, give feedback the agent learns from, and decide. Microsoft requires that the humans overseeing an agent hold permissions equal to or higher than the agent's, and we set every agent up that way. We make no claim about detection rates, accuracy or time saved — the pilot week and the usage dashboard give you your own numbers.

Where is our data stored, and what gets logged?

Prompts, responses and workspace data are stored in the customer-data storage geography chosen when the workspace is created — the default workspace follows your Entra geography, Microsoft offers a short list of geographies, and the choice is permanent for that workspace. Security Copilot activity can be logged to Microsoft Purview audit (we turn it on; Microsoft's default retention is 180 days, extendable with a Purview retention policy), and the data-sharing options — whether Microsoft may capture data to improve the product — are set as you decide at kickoff and written into the configuration record.

What does it cost, and what is not in the price?

The project is a fixed $5,950, quoted in writing before work begins and paid after you approve delivery. Not in the price: the Security Compute Units Security Copilot consumes — your E5 allocation, or provisioned and overage SCUs billed by Microsoft to your Azure subscription — Microsoft licensing, Sentinel deployment, ongoing monitoring, incident response, Defender product rollouts, custom agents and partner-built agents. The full exclusions list is on this page.

How long does it take, and what do you need from us?

Three weeks: sizing and foundation in week 1, agents and promptbooks with the pilot week in week 2, automations, monitoring, tuning review and handover in week 3. We need the entitlement in place (E5/E7 allocation provisioned or standalone capacity bought), a Global or Security Administrator to onboard and approve our time-bound GDAP access, the kickoff decisions on geography, data sharing, agents and reviewers, and a security lead plus one or two analysts who can review agent verdicts during the pilot week.

We turned it on ourselves and it is already burning capacity. Can you fix that?

Yes — that is a common starting point. Week 1 inventories what is enabled and what each item draws on the usage dashboard, then we pause what is not earning its capacity, trim inherited owner access, restrict plugins to the agreed set, put agents on schedules and scopes, and re-baseline the model. The rest of the engagement is the same.

What happens after handover?

Your team runs Security Copilot with the handover pack: agent register, promptbook library, runbooks, the capacity model and a review cadence. If you buy your Microsoft licensing through IT Partner, questions after handover go to the same support queue that already includes unlimited break-fix support during business hours; deeper changes — new agents, new automations — are quoted separately. Around-the-clock operation of the queue is Microsoft Sentinel SIEM/SOAR Ongoing Monitoring or Managed Detection and Response, both linked below. There is no minimum term and no lock-in on our side.

Is anything on this page in preview?

Yes, and we say so wherever it matters: the Security Alert Triage Agent's identity and cloud alerts, Natural language to KQL for Sentinel, and the newer Conditional Access Optimization Agent enhancements were in preview at the time of writing. Preview features can change or be withdrawn by Microsoft, so we enable them only when you accept that, and the handover pack marks each one.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$5,950 per project
3 weeks
Book a Security Copilot scoping call