VOOZH about

URL: https://www.microsoft.com/en-us/security/business/ai-machine-learning/microsoft-security-copilot

⇱ Microsoft Security Copilot | Microsoft Security


This is the Trace Id: 84092e2191d7dacafc25632cb23bd4ff
Microsoft Security Copilot

AI built into your daily workflows

Use Security Copilot agents across Microsoft Defender, Entra, Intune, and Purview to help you detect, investigate, and respond faster.
Overview

Protect at the speed and scale of AI

  • Summarize vast data signals into key insights to cut through the noise, and make use of AI-driven guidance and analysis across identities, devices, data, clouds, and apps.
  • Provide critical guidance and context for your security team. Use agents to automate processes and help your team respond to incidents in minutes, instead of hours or days.
  • Empower your staff with step-by-step guidance and automate tasks with agents so your security team can focus on strategic priorities.
DEMOS

Embedded AI in Action

Discover how Security Copilot brings AI-powered defense into your workflow with embedded skills, promptbooks, and dozens of agents that help you protect, detect, and respond across security and IT.
  • Leverage ready-to-use Security Copilot agents from Microsoft, seamlessly embedded in your Microsoft Security products, to streamline tasks such as phishing triage, vulnerability remediation, and alert triage.
  • Deploy agents built by our trusted partner ecosystem to extend agentic use cases—automating workflows and strengthening security postures.
  • Build your own Security Copilot agents for tailored workflows—ready to use in minutes, no coding required.
  • Gain context for incidents to quickly triage complex alerts into actionable summaries and remediate quicker with step-by-step response guidance.
  • Eliminate the need to manually write query-language scripts or reverse-engineer malware scripts with natural language translation to enable every team member to execute technical tasks.
  • Get a clear and concise report that summarizes the context and environment, open issues, and protective measures prepared for the tone and language of the report’s audience.
Security Copilot

Delivering a Unified, AI-First Defense

Explore how AI agents work side-by-side with security teams to scale defense and transform security operations.
INSIGHTS

Automate security and IT tasks with agents

Learn more about how Security Copilot can benefit your team with productivity and economic impact in these studies.
550%
SOC analysts using the Phishing Triage Agent in Defender found malicious emails up to 550% faster.1
204%
Admins using the Conditional Access Optimization Agent found 204% more missing zero trust policies.2
Integrations

Products integrated with Security Copilot

Microsoft Sentinel

Unify security data and context to power agentic defense with SIEM & AI-ready platform.

Microsoft Defender

Help prevent and detect cross-domain cyberattacks at the speed of AI—available with Copilot embedded.

Microsoft Intune

Mitigate cyberthreats to devices, protect data, and improve compliance across clouds—available with Copilot embedded.

Microsoft Entra

Help protect any identity and secure access to any resource with one family of solutions—available with Copilot embedded.

Microsoft Purview

Secure and govern your data at the machine speed and scale of AI—available with Copilot embedded.

Microsoft Defender for Cloud

Understand multicloud risk and get remediation recommendations—available with Copilot embedded.
In Microsoft 365 E5

Get AI agents built into your everyday workflows

Announcement

Get ahead of what could go wrong, so more things go right

Move forward confidently with autonomous Security Copilot agents built right into the Microsoft 365 E5 tools you use every day.
Documentation

See what’s included with Security Copilot in Microsoft 365 E5 and E7

Learn what’s included and find answers to frequently asked questions.
Product

Get Started

Get started with Security Copilot agents in the daily tools your teams already use:
Pricing

Security Copilot pricing

Start using Security Copilot today with options that fit your unique security requirements.
Customer stories

What customers are saying

RESOURCES

AI for security and beyond

Frequently asked questions

  • Security Copilot delivers agentic automation and AI-driven insights across Security and IT, empowering organizations to protect, detect, and respond at the speed and scale of AI.
  • Security Copilot combines a specialized language model with security-specific capabilities from Microsoft. These capabilities incorporate a growing set of security-specific skills informed by our unique global threat intelligence and more than 100 trillion daily signals.
  • Yes, Security Copilot is generally available for use by security and IT teams.
  • Get started by flexibly provisioning compute capacity to run Security Copilot workloads. Scale confidently to meet your evolving needs even during periods of unexpected demand. Learn about pricing and read more about how to get started with Security Copilot.

    Security Copilot will also be included in Microsoft 365 E5. See below for details.
  • Yes. Copilot integrates with other Microsoft Security products, including but not limited to Microsoft Defender XDR, Microsoft Sentinel, Microsoft Intune, Microsoft Entra, Microsoft Purview, Microsoft Defender for Cloud, and Microsoft Defender External Attack Surface Management. It also integrates with Azure security tools including Azure Web Application Firewall (WAF) and Azure Firewall. Copilot uses the data and signals from these products to generate customized guidance.
  • Yes. Security Copilot integrates with partner products to provide plugins and promptbooks that extend customer insights. Copilot capabilities include agents built by partners. Learn more about partners that integrate with Security Copilot.
  • Security Copilot agents enhance security and IT operations with autonomous and adaptive automation. Integrated seamlessly with Microsoft Security solutions and partner ecosystems, agents handle high-volume security tasks, reduce workloads, and accelerate responses. They learn from feedback and adapt to workflows, boosting efficiency while teams stay in control.
  • Users interact with agents from within Microsoft Defender, Entra, Intune, Microsoft Purview, and Security Copilot. Get started with Security Copilot agents using security compute units (SCUs) or access as part of your Microsoft 365 E5 subscription.
  • At Ignite 2025, Microsoft announced that Security Copilot agents will be directly built into the flow of work for security teams, available in Microsoft Defender, Entra, Intune and Purview.

    To make the agents easily accessible and help security teams get started faster, Security Copilot will be available to all Microsoft 365 E5 customers.

    Microsoft 365 E5 customers already using Security Copilot as of November 18, 2025, can access this benefit now. All other Microsoft 365 E5 customers and Microsoft 365 E7 customers will be activated through a phased roll-out in the upcoming months. Customers will receive advanced notice.
  • Eligible Microsoft 365 E5  and E7 customers will have 400 Security Compute Units (SCUs) per month for every 1000 user licenses, up to 10,000 SCUs per month. This included capacity is expected to support typical scenarios.
     
    • Example 1: An organization with 400 seats gets 160 SCUs/month.
    • Example 2: An organization with 4,000 seats gets 1,600 SCUs/month.
  • Microsoft 365 E5 customers already using Security Copilot as of November 18, 2025, can access this benefit now. All other Microsoft 365 E5 and E7 customers will be activated through a phased roll-out in the upcoming months. Customers will receive advanced notice.
Get started

Empower your security and IT teams

Get started with Security Copilot and turbocharge security in the flow of work.
  1. [1]
    Results based on randomized control trials involving professional security analysts participating in a Microsoft internal study; 167 professional security analysts triaging a 25-email queue ; October 2025
  2. [2]
    Results based on randomized control trials involving IT administrators participating in a Microsoft internal study; 162 identity administrators with varying degrees of self-reported experience completing 4 conditional access policy management tasks; October 2025

Follow Microsoft Security