What limits most security teams is never the tooling. It is that two people physically cannot read everything.
It summarizes an incident, writes the query language nobody on your team ever learned, explains what a suspicious script actually does, and drafts the report going to the board. There is included capacity for E5 and E7 customers, which means for some businesses the first question is simply what they already hold rather than what to buy.

- Eight use casesNamed by Microsoft, not by us
- Standalone and embeddedIn Defender, Sentinel, Intune and Entra
- Natural language to KQLWithout learning the query language
- Included capacityStated for E5 and E7 customers
You may already have capacity, it does not run in the Azure portal, and government clouds are excluded.
All three are documented by Microsoft and all three change the shape of the conversation before any purchase is discussed.
- There is capacity included for E5 and E7 customers. Businesses on those subscriptions routinely arrive at this conversation assuming the whole thing is an additional purchase. Establishing what is already covered takes a few minutes and is the first thing worth doing.
- Where Sentinel is concerned specifically, this does not exist in the Azure portal at all and does exist in the Defender one. If your security operations still live in the Azure portal, that is one of several reasons the transition matters, alongside the rather larger fact that support for Sentinel there ends on 31 March 2027.
- The documentation is written for customers in the commercial clouds, and this is not currently designed for use by anybody in the US government clouds, whether the standard community cloud, the higher one, the defense environment or Azure Government. For a defense contractor or a public sector supplier operating in any of those, that boundary settles the question well before licensing enters into it.
- All three get verified against your own tenant before anybody recommends anything, because entitlement, capacity and availability are precisely the details that shift between one documentation update and the next.
Eight use cases, and Microsoft named all of them.
Investigate and remediate, with the triage step compressed
The stated purpose is gathering context around an incident so that a complicated alert becomes an actionable summary quickly, then remediating faster with guidance offered step by step. For a team of two or three, summarizing is exactly where the hours disappear, and compressing that step is the whole difference between working the queue and drowning in it.
Query language and script analysis, without the specialist
The idea is removing the need to write query scripts by hand or to reverse engineer a malicious one, translating plain language so that anybody on the team can carry out a technical task. In practice this is the capability that genuinely changes what a small team is capable of, because query language proficiency is nearly always the bottleneck sitting between holding the data and getting an answer out of it.
Posture, explained rather than listed
Producing a broad picture of the environment with the risks already ordered, so that opportunities to improve are easier to find. Every security product on earth generates a list of recommendations. What is missing is nearly always somebody with the time to work out which of them matter for this particular business and in what sequence, and that is precisely the gap this fills.
Reports written for the audience that will read them
It produces a clear and concise report covering the context, the environment, whatever remains open and what is protecting you, pitched at the tone and language of whoever will read it. Writing the board version of a technical incident is a task most security people actively dislike and very few do well, and it consumes a genuinely surprising share of a senior person week.
Policy work, including conflict checking
Drafting a new policy, cross-referencing it against the existing ones looking for contradictions, and summarizing what already exists so somebody can hold the whole context. The conflict check is the genuinely useful half, because policy sets accumulate across years and the contradictions are normally discovered when two of them collide during an incident.
Plugins, which are how it knows anything about you
Plugins extend it outward and pull other services in, bringing context from event logs, alerts, incidents and policies across the Microsoft products and from supported outside products including ServiceNow and Jamf. They also open access to the threat intelligence articles and profiles, the threat analytics reports out of Defender XDR, and the vulnerability disclosure publications.
Embedded where the work happens, as well as standalone
There is a full standalone experience and there are embedded ones living inside the other security products, reaching Defender XDR, Sentinel, device management and identity alike. The embedded versions are where adoption genuinely happens, because the help appears inside whatever somebody already has open rather than requiring them to switch to a different window.
Agents, including in Sentinel
Building and adding agents is listed as one of the primary use cases, and inside the Defender portal three autonomous agents are named specifically: one triaging alerts, one briefing on threat intelligence, and one hunting. That is a materially different proposition from an assistant answering questions, and it is plainly the direction the product is traveling.
Four things that separate adoption from an expensive novelty.
What you already hold gets established before anybody discusses a purchase
There is capacity included for E5 and E7 customers. Businesses on those subscriptions arrive assuming this is entirely new spending with considerable regularity, and the first genuinely useful thing anybody can do is check. Where the capacity is already there, the conversation stops being about procurement and becomes about adoption, which is a much shorter route to anything valuable.
We start with the task your team actually dislikes
Nearly always one of three things: writing a query nobody on the team is confident about, working out what a suspicious script actually does, or producing the report leadership is waiting for. Attaching this to one specific painful task produces genuine adoption. Introducing it as a general capability produces a demonstration everybody praises and nobody has opened a fortnight later.
We connect the plugins that supply your context
Plugins are the only way it knows anything at all about your environment, pulling context from event logs, alerts, incidents and policies across the Microsoft products and from supported outside ones including ServiceNow and Jamf. A deployment with nothing connected answers general security questions perfectly competently while telling you nothing whatsoever about your own company, which is not what anybody bought it for.
We put verification and governance in place first
Treat a generated summary as somewhere to start rather than as a conclusion, and give any autonomous agent making triage decisions oversight that a person has genuinely signed up to. Most businesses have an AI policy written with productivity tools in mind, which turns out to say nothing at all about security data. Settling that beforehand takes ten minutes. Settling it after somebody has acted on an unverified summary takes considerably longer.
Six situations where this genuinely changes what an American security team is capable of.
A two or three person security team
Easily the most common shape in the mid-market, with three people covering endpoints, identity, email, cloud and compliance between them. The constraint is never the tooling. It is that nobody can physically read everything. Summarizing incidents and guiding the response are aimed squarely at that, and this is the group where the difference shows up within weeks rather than quarters.
A team with no Kusto Query Language specialist
Sentinel and advanced hunting are worth exactly as much as the queries somebody can write against them, and that proficiency is both scarce and expensive to hire. Translating plain language into the query syntax means the person who understands the business question can get their own answer without queuing behind the one colleague who knows how to write it.
A regulated firm producing regular security reporting
Banks, insurers, health systems and anybody covered by NYDFS report to boards, to committees, to examiners and to their insurance carrier on a fixed cycle. Generating a report already pitched at the audience removes work that currently eats senior time and gets done inconsistently, because whoever writes it is simultaneously handling live incidents.
A combined IT and security function
Which describes almost every American business under a few hundred people. Troubleshooting ordinary IT problems faster appears on the named use case list alongside the security ones, and for a team doing both jobs simultaneously the ability to pull information across the two is worth considerably more than a tool understanding only one.
A business using ServiceNow or Jamf
Both appear as supported outside integrations. For a business running service management in ServiceNow or its Apple hardware through Jamf, the plugins bring that context into the same conversation as the Microsoft security data, which produces a materially better picture than either system offers on its own. Being an Apple Jamf Partner, we wire the Jamf side properly rather than approximately.
A team ready to move from assistance to automation
Autonomous agents triaging alerts, briefing on intelligence and hunting are a genuinely different proposition from an assistant answering questions. This suits a team that has already used the assistive side, understands where the output can be trusted and where it cannot, and has agreed how an agent action gets overseen. It belongs in the second phase rather than the first.
How US security teams are actually approaching this.
| Feature | Adopted deliberately | Entitled, unused | Not considered |
|---|---|---|---|
Knows what capacity is already included | Yes | No | No |
Incident summaries produced automatically | Yes | No | No |
Query language no longer a bottleneck | Yes | No | No |
Suspicious scripts explained without a specialist | Yes | No | No |
Board reporting drafted rather than written | Yes | No | No |
Third-party context through plugins | Yes | No | No |
Governance decision recorded for AI on security data | Yes | No | Not applicable |
Output verified before it is acted on | Yes | Not applicable | Not applicable |
Time saved actually measured | Yes | No | Not applicable |
Renewal decision backed by data | Yes | No | Not applicable |
What it is officially for, and who actually gets the most out of it.
Use case
Investigate and remediate security threats
- Who it helps most
- Small teams where triage time is the real constraint
Use case
Build KQL queries or analyze suspicious scripts
- Who it helps most
- Teams with no dedicated query language specialist
Use case
Understand risks and manage posture
- Who it helps most
- Anybody facing a long recommendation list with no ordering
Use case
Troubleshoot IT issues faster
- Who it helps most
- Combined IT and security functions, which is most SMBs
Use case
Define and manage security policies
- Who it helps most
- Businesses whose policy set has accumulated contradictions
Use case
Configure secure lifecycle workflows
- Who it helps most
- Teams building joiner, mover and leaver automation
Use case
Develop reports for stakeholders
- Who it helps most
- Whoever currently writes the board pack, usually reluctantly
Use case
Build and add agents
- Who it helps most
- Businesses ready to automate triage rather than assist it
Five steps, and the first one can close the whole question inside an afternoon.
- 1
Confirm entitlement, capacity and availability
What your subscription already covers, given the included capacity for E5 and E7 customers, and where the embedded experiences are actually available to you. If Sentinel still sits in the Azure portal that becomes a dependency, since none of this exists there. And if you operate inside a US government cloud, the documented exclusion settles the whole question before anything else.
- 2
Identify the task worth attaching it to
Not a general capability. One specific painful job: the queries nobody writes with any confidence, the scripts nobody can read, or the report somebody dreads producing every month. We pick a single one, measure how long it currently takes, and run the pilot against that.
- 3
Connect the plugins that supply your context
The Microsoft security products first, then whichever supported outside products you actually run, ServiceNow and Jamf among them, plus the intelligence sources covering the threat intelligence articles and profiles, the threat analytics reports, and the vulnerability disclosure publications.
- 4
Agree governance and verification
Who is permitted to use it and against which data, whether your existing AI usage policy says anything at all about security tooling, how output gets verified before anybody acts on it, and what oversight covers an autonomous agent. A short conversation now, and a considerably more uncomfortable one after somebody has already acted on an unverified summary.
- 5
Measure, then extend
Measured against the baseline captured in step two, so that renewal becomes a decision rather than a matter of opinion. Then extend to whichever other use cases genuinely fit, and consider agents only once the team knows precisely where the assistive output can be trusted and where it cannot.
What US businesses ask about Security Copilot.
Fifteen questions worth answering first.
Entitlement
- Are you on E5 or E7?Microsoft states there is included capacity.
- Does your Sentinel live in the Azure portal or the Defender one?Copilot is not available in the Azure portal.
- Are you on a commercial cloud?GCC, GCC High, DoD and Azure Government are excluded.
- Do you have Defender XDR deployed?It is one of the named integrations.
- Has anybody trialed it?Worth doing before scoping a purchase.
Will it help you
- What is your actual bottleneck?If the shortage is not analyst hours, this may not be your answer.
- Does anybody on the team write KQL confidently?If not, that is the strongest single case.
- How long does incident triage take today?Measure before, so you can measure after.
- Who writes the reports for leadership?And how much of their week it takes.
- Do you use ServiceNow or Jamf?Both are named third-party integrations.
Governance
- Who gets to use it, and against which data?Decide rather than default.
- Does your AI usage policy cover security tooling?Most policies were written for productivity tools.
- Will output be verified before it is acted on?A summary is a starting point, not a finding.
- Who reviews an agent action?Autonomous agents need an oversight decision.
- Is anybody tracking whether it saved time?Otherwise renewal is a matter of opinion.
The pages around this one.
Sentinel in the Defender portal
Where Security Copilot is available for Sentinel, and the March 31, 2027 deadline that makes the transition necessary anyway.
SOC as a service
The alternative for teams without the capacity to operate security themselves, assisted or otherwise.
Microsoft Copilot
The productivity side of the same family, and the data governance work that has to be in place before it is switched on.
Check the capacity you already have before you price anything.
Microsoft states there is included capacity for E5 and E7 customers, and businesses on those subscriptions regularly budget for something they partly own. That check takes minutes, and it changes whether this is a procurement conversation or an adoption one.
Related Services
Explore more solutions that work great with this service
Microsoft Sentinel Transition to the Defender Portal
Sentinel transition planning and delivery for US organizations ahead
Learn moreSOC-as-a-Service
24/7 security operations delivered as a service
Learn moreMicrosoft Sentinel
Cloud-native SIEM and threat intelligence
Learn moreMicrosoft Copilot
AI-powered productivity with Copilot
Learn moreMicrosoft Defender for Endpoint Services
EDR plan selection, onboarding and zero-gap AV migration
Learn moreMicrosoft Purview eDiscovery
Legal hold and eDiscovery readiness done properly
Learn more