Security Copilot Governance Review
TL;DR: This skill reviews how Microsoft Security Copilot is governed: who has access, how SCU capacity is consumed, and which promptbooks, agents, Sentinel data lake and MCP connections and Security Store purchases exist. It is read-only and separate from Microsoft 365 Copilot.
How is Microsoft Security Copilot governance different from Microsoft 365 Copilot?
Microsoft Security Copilot is a separate security product with its own portal (securitycopilot.microsoft.com), its own roles and its own compute capacity, measured in Security Compute Units (SCUs). Microsoft 365 Copilot governance is covered by Copilot Interaction Compliance Audit and DSPM for AI Remediation. This skill covers the SOC-side product and extends the Defender and Sentinel cluster: Defender Advanced Hunting Pack, Sentinel Analytics Rule Coverage and MITRE ATT&CK Coverage Gap. Those skills audit detections. This one audits the AI layer that reads, summarises and acts on that telemetry.
All status labels below (preview, general availability) are stated as of 2026-09-30, per Microsoft Learn. Learn’s what’s-new page updates monthly, so re-check before relying on a status.
| Area | Microsoft Security Copilot |
|---|---|
| Capacity model | SCUs: provisioned, overage, or Microsoft 365 E5 and E7 inclusion |
| Access control | Security Copilot owner and contributor roles, plus each plugin’s own Microsoft Entra, Azure or service RBAC |
When should you run this skill?
- “Who can use Security Copilot, and who is an owner?”
- “Is the Everyone group still a Copilot contributor?”
- “How many SCUs are we consuming, and by which agents or promptbooks?”
- “Which promptbooks are shared across the whole organisation?”
- “Which agents are running, under which identity, and who approved them?”
- “Did anyone buy a partner agent from the Microsoft Security Store?”
- “Are Security Copilot admin actions and prompts reaching Microsoft Purview audit and DSPM for AI?”
What is the preview or GA status of each Security Copilot capability?
Per Microsoft Learn’s what’s-new page and linked articles, as of 2026-09-30, this is the status each item is labelled with. Where Learn does not state a current status, the table says so rather than inferring one.
| Capability | Status per Microsoft Learn | Where stated |
|---|---|---|
| Security Analyst Agent | Public preview (April 2026 entry) | What’s new |
| Build your own agent (standalone agent builder, developer tools) | Public preview (September 2025 entry) | What’s new |
| Natural-language agent creation (NL2Agent) through MCP tools | Private Preview, but globally available | MCP overview |
| Microsoft Sentinel data lake | Generally available (September 2025 entry) | What’s new |
| Microsoft Sentinel graph and MCP server | Public preview (September 2025 entry). The Sentinel MCP overview page does not state a current status | What’s new |
| Microsoft Security Store | Public preview (September 2025 entry). The Security Store overview page does not state a current status | What’s new |
| Workspaces | Public preview (June 2025 entry) | What’s new |
| Workspace-level plugin management | Generally available (June 2025 entry) | What’s new |
| Agent administration auditing in Purview Unified Audit Log | Generally available (July 2025 entry) | What’s new |
| Promptbook “Continue on failure” | Generally available (March 2025 entry) | What’s new |
| Calling system capabilities directly in a promptbook prompt | Public preview (March 2025 entry) | What’s new |
| Security Alert Triage Agent | Preview. Email and collaboration alerts are labelled generally available; cloud and identity alerts are labelled preview | Defender agents article |
Who should have access to Security Copilot?
Security Copilot has its own two roles, Copilot owner and Copilot contributor, and they are not Microsoft Entra roles. They grant access to the platform only, not to security data, which stays governed by each plugin’s own Entra, Azure or service RBAC. Review these points:
| Check | What Microsoft Learn says | Finding to raise |
|---|---|---|
| Owner count | Security Copilot enforces retention of two owners at all times | Confirm two named, accountable owners |
| Inherited owner access | Billing Administrator, Entra Compliance Administrator, Global Administrator, Intune Administrator, Security Administrator, Purview Compliance Administrator, Purview Data Governance Administrator and Purview Organization Management inherit Copilot owner access | Confirm these roles are held through PIM or role-assignable groups |
| Contributor default | New instances default to the Recommended Microsoft Security roles group; some existing tenants still have Everyone as contributor | Replace Everyone with role-assignable security groups |
| Privileged role guidance | Learn advises against assigning Security Administrator purely for Copilot access and recommends a security group instead | Flag direct Security Administrator assignments made for Copilot access |
| Shared sessions | Shared sessions are read-only, and the recipient does not need access to the plugin data used to produce the response | Treat a session link as a data-sharing event |
| Multi-tenant and MSSP access | Supported through B2B tenant switching, GDAP and Azure Lighthouse | Inventory external identities and partner access |
Related identity skills: PIM Privileged Role and Activation Audit and Conditional Access Coverage Gap Analysis. Learn also points to a Conditional Access policy for protecting Security Copilot access.
What should you audit for promptbooks?
Promptbooks are ordered sets of prompts that run one after another, each building on earlier responses. Per Learn, prebuilt promptbooks include Incident investigation (Microsoft Sentinel and Microsoft Defender XDR variants), Microsoft User analysis, Suspicious script analysis, Threat actor profile, Vulnerability impact assessment, Check impact of an external threat article and Threat Intelligence 360 report based on MDTI article.
- Both Copilot owners and contributors can run promptbooks, manage personal promptbooks and share promptbooks with the tenant. Learn states that promptbook creation is available to all roles, including publishing for the tenant.
- The promptbook library lists each promptbook by name, owner, description, number of prompts, required plugins and visibility (Just me or Anyone in my organization).
- Learn warns that results vary with the permissions and data available to whoever runs a promptbook, and that reordering prompts can affect output and SCU usage.
- The Microsoft User analysis promptbook needs at least the Security Reader role for Microsoft Entra ID, Intune and Defender, and an Insider Risk Management Investigator or Analyst role for Microsoft Purview, to give a comprehensive response.
What should you govern for Security Copilot agents?
Per Learn, Security Copilot agents must be set up by your organisation; they are not enabled automatically. At setup you choose an agent identity: create a new agent identity (Microsoft’s recommendation) or assign an existing user account.
| Agent type | What to check | Source detail |
|---|---|---|
| Security Analyst Agent (public preview) | Data sources chosen (Defender XDR, Sentinel Log Analytics or Sentinel data lake); the identity is tied to the user, and each user configures it independently | Runs on read access to the selected data source |
| Security Alert Triage Agent (preview) | Identity, permissions (including Alerts manage) and licence prerequisites per alert type | Setup and management needs the Microsoft Entra Security Administrator role |
| No-code agent builder and NL2Agent | Who can build agents, what tools and instructions they carry, and where they are published | Build agents from natural language, an agent builder form, or an uploaded YAML manifest |
| Custom agents through MCP | Deployment scope (user or workspace) and the MCP client used | MCP tools generate an agent YAML file and deploy it to Security Copilot at user scope or workspace scope |
| Partner-built agents | Global Administrator approval where the agent reads Microsoft product data; who granted consent | Agents that need no Microsoft product permissions do not need approval |
Owners and contributors can pause an agent, run it on its trigger or one time, edit its identity and parameters, and reject stored feedback under Manage memory. Agent feedback is stored in the agent’s memory, so review it as configuration.
What should you check for the Sentinel data lake and MCP server?
Per Learn, the Microsoft Sentinel data lake is a fully managed, open-format (Parquet) store with an analytics tier and a data lake tier that can retain data for up to 12 years, with auditing enabled by default. Learn describes the Sentinel MCP server as fully hosted, using Microsoft Entra for identity, and offering collections for data exploration (including entity analysis), agent creation and incident triage.
- Confirm which agents point at the data lake or a Log Analytics workspace, and that their identities hold read access only.
- Confirm who can connect an MCP client, since MCP tools can query the data lake in natural language and deploy agents.
- Review the data lake audit log, which captures KQL queries against the lake, notebook runs, and job create, edit, run and delete events.
- Related: Sentinel Data Connector Coverage.
- Microsoft states that Sentinel data lake compute and storage costs are not covered by the Microsoft 365 E5 and E7 inclusion.
What should you review in the Microsoft Security Store?
Per Learn, the Microsoft Security Store is a storefront for finding, buying and deploying Microsoft and partner security solutions, agents, connectors and content, and services, billed through existing Microsoft billing options such as the Microsoft Azure Consumption Commitment, via public or private offers.
- Purchasing partner agents needs the Azure subscription Contributor or Owner role; setup needs a Security Copilot owner or contributor role, and possibly a Microsoft Entra Global Administrator to grant permissions.
- Review My solutions for what has been purchased and deployed.
- Partner agent licensing paid through Security Store is not covered by the Microsoft 365 E5 and E7 inclusion.
How is Security Copilot licensed and how is SCU capacity controlled?
Security Copilot runs on SCUs. Learn describes three models: provisioned, overage, and Microsoft 365 E5 and E7 inclusion. Learn states that SCUs are charged for generally available and public preview capabilities, and not for private preview.
| Capacity model | What Learn says | Governance check |
|---|---|---|
| Provisioned | Set in advance (minimum one SCU), billed hourly, refreshed each clock hour, unused SCUs do not roll over | Compare provisioned SCUs with actual use |
| Overage | Billed on use to one decimal place; can be capped at a maximum or set to unlimited | Confirm whether overage is a set maximum or unlimited, and that this is deliberate |
| Microsoft 365 E5 and E7 inclusion | 400 SCUs a month per 1,000 paid user licences, up to 10,000 SCUs a month, at no additional cost; allocation resets monthly with no rollover | Confirm the Default Security Copilot Capacity exists and note that it cannot be modified |
| Beyond the inclusion | Usage beyond the allocation will be throttled at a future date; a pay-as-you-go option at USD 6 per SCU is described, with 30 days’ notice | Track the advance notice Microsoft has said it will give |
Learn describes rollout of the inclusion starting on 18 November 2025 for existing Security Copilot customers with Microsoft 365 E5, continuing for other eligible E5 and E7 customers. Microsoft Sentinel customers without Microsoft 365 E5 or E7 are not eligible for the inclusion. The included auto-provisioning preselects the data storage geography, GPU processing location, data sharing preferences (off by default) and access to Microsoft 365 service data (on by default). Review each of those settings.
The usage monitoring dashboard (Owner settings, then Usage monitoring) holds up to 90 days of data, and shows units used by category (Prompt, Promptbook, Agent, Primitive), type (Manual or Automated), Copilot experience, plugin and initiator. It can be exported.
How do you audit Security Copilot activity?
Per Learn, Security Copilot audit data flows to Microsoft Purview Unified Audit Log (admin events and activity metadata) and Microsoft Purview DSPM for AI (prompt and response pairs). Learn states that prompt and response content is currently only included through DSPM for AI.
- Check the Logging audit data in Microsoft Purview toggle in Owner settings; it is set by a Security Administrator at first run or later in Owner settings.
- Admin events include changes to data sharing, agents, agent triggers, plugins and promptbook configurations. Agent administration auditing (create, update, delete of agents and triggers) is labelled generally available.
- Learn gives 180 days as the default audit log retention, extendable with audit log retention policies. Compare with Audit Log Retention Validator.
- Purview permissions to read the audit log can differ from Security Copilot roles.
- Related: Purview AI Activity Explorer and Admin Action and Audit Trail Review.
How this skill works, step by step
- Sign in to the Security Copilot portal with a read-capable account and record the tenant’s capacity model (provisioned, overage or Microsoft 365 E5 and E7 inclusion).
- List Copilot owners and contributors and compare them with the inherited owner roles and the Everyone or Recommended Microsoft Security roles assignment.
- Open the promptbook library and record each promptbook’s owner, visibility and required plugins.
- Open the Agents page and record each agent’s status, identity, trigger, plugins and who set it up.
- Record which agents use Sentinel data lake, Log Analytics or Defender XDR as data sources, and any MCP-built agents and their deployment scope.
- Review Security Store purchases (My solutions) and any Global Administrator approvals granted to partner agents.
- Export the usage dashboard and summarise SCU use by category, type and initiator.
- Confirm the Purview audit toggle and search Unified Audit Log for Security Copilot admin events.
- Score each finding High, Medium or Low and compile the report.
Output format
| Area | Item | Finding | Risk |
|---|---|---|---|
| Access | Everyone group assigned as contributor | Broad contributor access | High |
| Agents | Custom agent running on a personal account | Identity not a dedicated agent identity | Medium |
| Promptbooks | Tenant-visible promptbook needing an unusual plugin | Results vary by runner’s permissions | Low |
| Capacity | Overage set to unlimited | Uncapped spend exposure | Medium |
| Audit | Purview logging toggle off | Admin events and prompts not captured | High |
The summary lists owner and contributor counts, agents by identity type, promptbooks by visibility, SCU use by category, partner agents purchased, and audit status, with prioritised remediation.
Licensing and permissions
Licences and add-ons
| Capability used | Minimum licence |
|---|---|
| Security Copilot capacity | Provisioned SCUs (Azure), or Microsoft 365 E5 or E7 inclusion |
| Security Analyst Agent | Learn lists licence as Not Applicable; requires Security Copilot and read access to the chosen data source |
| Security Alert Triage Agent | Depends on alert type: Defender for Office 365 Plan 2, Defender for Cloud and Defender for Containers, or Microsoft Entra ID P2 with Defender for Identity and Defender for Cloud Apps |
| Sentinel data lake | Billed separately from the Microsoft 365 E5 and E7 inclusion |
| Partner agents | Partner licence purchased through Security Store |
Least-privilege roles
- Security Copilot contributor for platform access, sessions and running promptbooks
- Security Copilot owner to view the usage dashboard and Owner settings
- Microsoft Sentinel Reader for Sentinel incident access from Copilot
- Purview audit read permissions to search Unified Audit Log
Microsoft Graph permissions (read-only)
The pages cited here do not document a Microsoft Graph permission set for this review. The review uses the Security Copilot portal, the usage dashboard export, the Microsoft Purview portal and Azure role-based access control.
Scope and safety
This skill is read-only by default. It reports on roles, capacity, promptbooks, agents, connections and audit settings without changing them.
This skill does NOT:
- Assign, remove or change Security Copilot roles.
- Create, edit, pause, run or delete agents, promptbooks or plugins.
- Change SCU provisioned or overage capacity, or delete capacity.
- Buy, deploy or approve anything in the Microsoft Security Store.
- Change the Purview audit toggle, data sharing settings or any Sentinel configuration.
Related skills
- Admin Action and Audit Trail Review: before: reads privileged admin events from the Purview audit log
- Sentinel Data Connector Coverage: after: confirms which Microsoft Sentinel log sources are ingesting
- Sentinel Analytics Rule Coverage: after: confirms which Sentinel analytics rules are enabled and where coverage has gaps
- Governing AI Agents in Microsoft 365: pillar: govern agents by finding them first, then check tools, data policies and access
- Governing Microsoft 365 Copilot with Microsoft Purview: pillar: the Microsoft Purview controls documented for Microsoft 365 Copilot
Sources and compliance
- What’s new in Microsoft Security Copilot?
- Prompting in Microsoft Security Copilot
- Use promptbooks in Microsoft Security Copilot
- Build your own promptbooks
- Understand authentication in Microsoft Security Copilot
- Setup and manage Security Copilot agents
- Build Security Copilot agents in standalone
- Model Context Protocol overview (Preview)
- Deploy AI agents in Microsoft Defender
- What is Microsoft Sentinel’s support for Model Context Protocol (MCP)?
- What is Microsoft Sentinel data lake?
- What is Microsoft Security Store?
- Security Copilot Security Compute Units and capacity
- Manage security compute unit usage in Security Copilot
- Security Copilot for Microsoft 365 E5 and E7 included customers
- Access the Security Copilot audit log
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30