Microsoft Security Copilot Deployment and SOC Automation
IT Partner turns a Microsoft Security Copilot entitlement — the capacity Microsoft now includes with Microsoft 365 E5 and E7, or standalone provisioned Security Compute Units (SCUs) — into working SOC automation in a fixed-price, three-week engagement. We size the capacity against the agents and promptbooks you actually intend to run, confirm the auto-provisioned workspace or create one in the right data-storage geography, replace the default owner and contributor access with named security groups, set Purview audit logging and the data-sharing choices you make, connect the Defender XDR, Sentinel, Entra, Intune, Purview and Microsoft Threat Intelligence plugins, then set up and tune up to six Security Copilot agents and promptbooks that fit your team — Phishing Triage in Defender, Conditional Access Optimization in Entra, Vulnerability Remediation in Intune, the Data Security Triage agent for Purview DLP and Insider Risk alerts, the Threat Intelligence Briefing agent, and promptbooks for incident summary, investigation, KQL-assisted hunting and executive reporting. Two automations are wired into Sentinel playbooks or Azure Logic Apps, usage monitoring and cost alerts are set, and your security team gets a short enablement session and a handover pack. Fixed at $5,950 per project. The SCUs the platform consumes are yours — drawn from your E5 allocation, or billed by Microsoft for provisioned and overage capacity — and are not part of this fee. Sentinel deployment, 24×7 monitoring and incident-response retainers are separate, named services linked below.
What this engagement is
Microsoft folded Security Copilot into Microsoft 365 E5 and E7 in 2026. Per Microsoft's Message Center notice MC1261596 and its 'Security Copilot for Microsoft 365 E5 and E7 customers' guidance, eligible tenants were auto-provisioned in a phased rollout between 20 April and 30 June 2026 and receive 400 Security Compute Units (SCUs) a month for every 1,000 paid E5 or E7 user licenses, scaled proportionally for smaller counts, capped at 10,000 SCUs a month, reset monthly with no rollover. Activation was 'zero click': Microsoft created a default capacity and a default workspace in your tenant, set the data-storage location to your Microsoft Entra geography, and let several administrator roles inherit Security Copilot owner or contributor access. That is the situation most E5 security teams are in today — a working Security Copilot they did not switch on, holding a monthly pool of capacity that either sits unused or gets drawn down by an agent nobody tuned. Organizations outside E5 buy the same platform as standalone provisioned SCUs on an Azure subscription (minimum one SCU, billed by the hour, with optional overage) — Microsoft's published example at the time of writing prices a provisioned SCU at $4 an hour and an overage SCU at $6. Security Copilot in 2026 is three things at once. It is a standalone portal (securitycopilot.microsoft.com) where analysts prompt across plugins — Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra, Microsoft Intune, Microsoft Purview, Microsoft Threat Intelligence, Defender External Attack Surface Management and third-party sources — and save repeatable sequences as promptbooks. It is an embedded experience inside the Defender, Entra, Intune and Purview portals: incident summaries and guided response, natural-language KQL in advanced hunting, script and policy explanations. And, since 2025, it is a set of agents that run on a schedule or a trigger and consume SCUs on their own: the Phishing Triage Agent in Microsoft Defender (generally available for user-reported email; its extension to identity and cloud alerts as the Security Alert Triage Agent is in preview), the Threat Intelligence Briefing Agent, the Conditional Access Optimization Agent in Entra, the Vulnerability Remediation Agent in Intune, and the Data Security Triage Agent for Purview DLP and Insider Risk alerts, alongside newer Defender agents and partner-built agents in the Microsoft Security Store. Each agent needs the product license behind it, an identity with a least-privilege role, a human who reviews its verdicts and teaches it through feedback, and a share of the capacity — which is why turning them all on at once is the fastest way to exhaust an allocation. For SOC automation, the Security Copilot connector for Azure Logic Apps can submit a prompt or a whole promptbook from a Sentinel playbook, so an incident can arrive in the queue with its summary and next steps already attached. This engagement is the operationalization step, not a platform rollout. Over three weeks we work out how much capacity you actually have and what it will bear, put the workspace, roles, audit and data-sharing settings in order, connect the plugins, enable and tune the agents and promptbooks that match your team and your licenses (up to six), build two automations into Sentinel playbooks or Logic Apps, set usage monitoring and cost alerts, and hand over to your security team with a runbook and an enablement session. The price is fixed at $5,950 per project. The SCUs that Security Copilot consumes — your E5 allocation, or provisioned and overage capacity billed by Microsoft to your Azure subscription — are Microsoft's meter and the customer's own; nothing on this page changes Microsoft's rates. Sentinel itself, around-the-clock monitoring, incident-response retainers and Defender product rollouts are separate, named services.
Success criteria
What you receive
How the work unfolds
We confirm what you hold: the E5/E7 allocation in your tenant (or a standalone capacity), the workspace Microsoft created, who inherited owner and contributor access, and which plugins and agents are already switched on and drawing capacity. With your security lead we pick the two or three pains an agent should own first, check the product licenses behind each candidate agent, compute the allocation from your paid license count, and write the capacity model — including the overage decision — that you approve before we enable anything.
The default workspace is validated or a new one created in the agreed data-storage geography and linked to capacity. Owner and contributor access moves to named security groups and inherited access is trimmed. Owner settings are set as you decided — Purview audit logging, data sharing, plugin management, uploads and preview features — and the Defender XDR, Sentinel, Entra, Intune, Purview and Threat Intelligence plugins are connected and verified with recorded test prompts. Where the Phishing Triage Agent is in scope, unified RBAC, user-reported message settings and the alert policy are activated under your change control.
Each approved agent is set up with a dedicated agent identity, a least-privilege role and scope, a schedule and a human reviewer, and the four house promptbooks are adapted to your tenant and saved in the workspace. The pilot week begins on real alerts: reviewers read verdicts, give feedback that the agent applies, and we watch each agent's SCU draw on the usage dashboard against the model.
The two automations are built and tested — Sentinel automation rules with Logic Apps playbooks calling the Security Copilot connector, or Logic Apps alone where Sentinel is absent — with the actions you approved (summaries, enrichment, comments, notifications, scheduled reports; never containment unless you asked for it in writing). Usage thresholds, the monthly review checklist and, for Azure-billed capacity, a Cost Management budget with alert recipients go in.
We review the pilot-week measurements with you, adjust scopes and schedules, and re-baseline the capacity model against what the agents actually consumed. The enablement session runs for your lead and analysts, and the handover pack — configuration record, agent register, promptbook library, runbooks, capacity model, review cadence and next-agent backlog — is delivered for your approval.
Prerequisites
Who does what
IT Partner
- Verify the entitlement, compute the allocation from your licensed count, build the capacity model and present the recommendation for your approval before enabling anything.
- Configure the workspace, geography, capacity link, owner and contributor groups, owner settings, audit logging and plugin connections, and record every setting in the configuration record.
- Set up the approved agents with least-privilege agent identities, scopes, schedules and reviewers; adapt the four house promptbooks to your tenant; run the pilot week with your reviewers and tune on their feedback.
- Build and test the two automations with the actions you approved, and set usage monitoring, thresholds and — for Azure-billed capacity — Cost Management budgets and alerts.
- Deliver the enablement session and the handover pack, including the re-baselined capacity model, the agent register, runbooks and the next-agent backlog.
- Work only within the time-bound GDAP access you approve, flag risks and decisions as they arise, and report SCU draw honestly — including when an agent is not worth its capacity in your environment.
- Cite Microsoft's inclusion rules, agent statuses and prices as they stand at the time of writing, and say so where a feature is in preview.
Your team
- Confirm the entitlement (E5/E7 allocation or standalone capacity), the Azure subscription for any Azure-billed capacity and Logic Apps, and acceptance of Microsoft's SCU charges.
- Provide administrative access and approve the GDAP request in time for week 1; provide the Security Administrator, Entra, Intune, Purview and Sentinel owners for their parts.
- Make the kickoff decisions: geography, data sharing, audit logging, the agents to enable and their reviewers, and the automation actions you approve.
- Review agent verdicts and give feedback during the pilot week; attend the tuning review and the enablement session.
- Approve change requests for unified RBAC, alert policies, agent identities and playbook deployment within your change process.
- Own the licenses behind each agent, and the capacity decisions after handover — raising, lowering or pausing capacity and agents as usage shows.
- Operate Security Copilot after handover, or engage a separate ongoing service for monitoring and tuning.
What's not included
Limitations & technical notes
Frequently asked questions
What does this service actually deliver?
A working Security Copilot for your SOC, in three weeks, for a fixed $5,950: a capacity model you approve, a workspace with the right geography and roles, owner settings and audit logging set deliberately, the Microsoft plugins connected and verified, up to six agents and promptbooks enabled and tuned on a pilot week of your real alerts, two automations into Sentinel playbooks or Logic Apps, usage monitoring with cost alerts, an enablement session and a handover pack. It is the operationalization of an entitlement you already hold — not a Sentinel or Defender rollout, and not ongoing monitoring.
Do we already have Security Copilot? We are on Microsoft 365 E5.
Very likely yes. Microsoft's Message Center notice MC1261596 announced that Security Copilot is included with Microsoft 365 E5 and E7, with a phased, zero-click rollout between 20 April and 30 June 2026: Microsoft created a default capacity and workspace in eligible tenants, set the data-storage location to your Entra geography and let several administrator roles inherit owner or contributor access. Open the Security Copilot portal with a Global or Security Administrator account and you will see it. The first thing we do is check what is already switched on and drawing capacity.
How much capacity do we have, and is it enough?
Microsoft's rule at the time of writing is 400 Security Compute Units a month for every 1,000 paid E5 or E7 user licenses, scaled proportionally for smaller counts — so a 500-seat tenant gets about 200 a month and a 2,500-seat tenant about 1,000 — capped at 10,000, reset monthly, with nothing carried over. The pool is a consumption budget: prompts, promptbooks and agents draw it down, and the usage dashboard shows the draw per hour. Whether it is enough depends entirely on which agents you run and how much alert volume they see, which is why the first deliverable is a capacity model and the pilot week measures real draw before we hand over.
What happens when the included allocation runs out?
By Microsoft's current description, an exhausted E5 allocation throttles Security Copilot until the next monthly reset — prompts and agents pause rather than generating a bill — unless you have attached paid provisioned or overage capacity to the workspace. Microsoft has been adjusting how included and paid capacity combine, so we confirm the behavior in your tenant during sizing, put the overage decision in writing, and design agent schedules so the pool lasts the month. Any paid capacity is Microsoft's charge on your Azure subscription, not part of this fee.
We are not on E5. Can we still buy this?
Yes. Security Copilot is sold standalone as provisioned Security Compute Units on an Azure subscription in your tenant — a minimum of one SCU, billed by the hour, with optional overage. Microsoft's published example at the time of writing is $4 per provisioned SCU and $6 per overage SCU. The engagement is the same; the sizing step just starts from a purchase decision rather than an allocation, and we set an Azure Cost Management budget on the capacity resource so nobody discovers the meter on the invoice.
Which agents do you set up?
Up to six from Microsoft's catalog that match your licenses and your pains. In Microsoft Defender: the Phishing Triage Agent (generally available for user-reported email; needs Defender for Office 365 Plan 2 and unified RBAC) and its preview extension, the Security Alert Triage Agent, for identity and cloud alerts; the Threat Intelligence Briefing Agent, which schedules briefings built from Microsoft Threat Intelligence and your exposure data. In Microsoft Entra: the Conditional Access Optimization Agent. In Intune: the Vulnerability Remediation Agent. In Purview: the Data Security Triage Agent for DLP and Insider Risk alerts. Each gets a dedicated agent identity with a least-privilege role, a scope, a schedule, a human reviewer and a week of tuning. Partner-built agents from the Security Store are outside the fixed price.
What is a promptbook, and which ones do you build?
A promptbook is a saved sequence of prompts that runs as one unit against your connected plugins — the repeatable part of an analyst's day. We adapt four house promptbooks to your tenant: an incident summary (what happened, entities, timeline, severity, recommended next steps), an investigation (related alerts, user and device risk, sign-in and process context), KQL-assisted hunting that drafts and runs queries in Sentinel or Defender advanced hunting, and an executive or weekly report. They are saved and shared in the workspace, and two of them can be the ones the automations call.
What are the two automations? Do they need Sentinel?
Typical pairs are an incident-created automation rule in Sentinel that runs a Logic Apps playbook calling the Security Copilot connector — submit the incident-summary promptbook, write the result to the incident and post to Teams — and a scheduled Logic App that distributes the Threat Intelligence Briefing to your leads. Sentinel makes the first one elegant, but it is not required: both can run as Logic Apps against Defender and the Security Copilot connector. Actions are limited to summaries, enrichment, comments, notifications and reports unless you approve containment in writing.
Does this replace analysts or our SOC?
No. The agents triage and recommend; your analysts review verdicts, give feedback the agent learns from, and decide. Microsoft requires that the humans overseeing an agent hold permissions equal to or higher than the agent's, and we set every agent up that way. We make no claim about detection rates, accuracy or time saved — the pilot week and the usage dashboard give you your own numbers.
Where is our data stored, and what gets logged?
Prompts, responses and workspace data are stored in the customer-data storage geography chosen when the workspace is created — the default workspace follows your Entra geography, Microsoft offers a short list of geographies, and the choice is permanent for that workspace. Security Copilot activity can be logged to Microsoft Purview audit (we turn it on; Microsoft's default retention is 180 days, extendable with a Purview retention policy), and the data-sharing options — whether Microsoft may capture data to improve the product — are set as you decide at kickoff and written into the configuration record.
What does it cost, and what is not in the price?
The project is a fixed $5,950, quoted in writing before work begins and paid after you approve delivery. Not in the price: the Security Compute Units Security Copilot consumes — your E5 allocation, or provisioned and overage SCUs billed by Microsoft to your Azure subscription — Microsoft licensing, Sentinel deployment, ongoing monitoring, incident response, Defender product rollouts, custom agents and partner-built agents. The full exclusions list is on this page.
How long does it take, and what do you need from us?
Three weeks: sizing and foundation in week 1, agents and promptbooks with the pilot week in week 2, automations, monitoring, tuning review and handover in week 3. We need the entitlement in place (E5/E7 allocation provisioned or standalone capacity bought), a Global or Security Administrator to onboard and approve our time-bound GDAP access, the kickoff decisions on geography, data sharing, agents and reviewers, and a security lead plus one or two analysts who can review agent verdicts during the pilot week.
We turned it on ourselves and it is already burning capacity. Can you fix that?
Yes — that is a common starting point. Week 1 inventories what is enabled and what each item draws on the usage dashboard, then we pause what is not earning its capacity, trim inherited owner access, restrict plugins to the agreed set, put agents on schedules and scopes, and re-baseline the model. The rest of the engagement is the same.
What happens after handover?
Your team runs Security Copilot with the handover pack: agent register, promptbook library, runbooks, the capacity model and a review cadence. If you buy your Microsoft licensing through IT Partner, questions after handover go to the same support queue that already includes unlimited break-fix support during business hours; deeper changes — new agents, new automations — are quoted separately. Around-the-clock operation of the queue is Microsoft Sentinel SIEM/SOAR Ongoing Monitoring or Managed Detection and Response, both linked below. There is no minimum term and no lock-in on our side.
Is anything on this page in preview?
Yes, and we say so wherever it matters: the Security Alert Triage Agent's identity and cloud alerts, Natural language to KQL for Sentinel, and the newer Conditional Access Optimization Agent enhancements were in preview at the time of writing. Preview features can change or be withdrawn by Microsoft, so we enable them only when you accept that, and the handover pack marks each one.