What and why:
Microsoft Security Copilot agents are built into the flow of work of security teams using Microsoft Defender, Microsoft Entra, Microsoft Intune and Microsoft Purview. At Ignite 2025, Microsoft introduced a dozen new agents across these products, bringing agentic defense across workflows to enable autonomous and proactive protection.
Rollout schedule:
To make it easier for teams to get started, beginning today, your organization has access to Security Copilot features and agents as part of your existing Microsoft 365 E5/E7 entitlement.
Impact on your organization:
Who is affected:
- Organizations with Microsoft 365 E5 or E7
Platforms/Services:
- Defender
- Entra
- Intune
- Purview
- Security Copilot portal
What will happen:
- Security Copilot will be automatically included with Microsoft 365 E5/E7 (no separate purchase required).
- Your tenant will receive 400 Security Compute Units (SCUs) per month per 1,000 licensed users, up to 10,000 SCUs per month.
- Core agentic security experiences will be available across Defender, Entra, Intune, Purview, and the Security Copilot portal.
- Developer tools and APIs will be available to build custom agents and integrations.
- Existing security, compliance, and access policies continue to apply.
Additional capabilities outside the included entitlement may incur extra charges, including:
- Microsoft Sentinel data lake compute or storage.
- Non-agentic Data Security Investigations in Purview.
- Azure Logic Apps usage with Security Copilot.
- Third-party agents purchased via Microsoft Security Store.
Action required / Recommendations:
No action is required to enable this feature.
We recommend:
If you would like to opt out of this entitlement, please contact support.