This is the Trace Id: a35c242eb9c5e007c72e7024b72171b3
Skip to main content Why Microsoft Security AI-powered cybersecurity Cloud security Data security & governance Identity & network access Privacy & risk management Security for AI Unified SecOps Zero Trust Microsoft Defender Microsoft Entra Microsoft Intune Microsoft Priva Microsoft Purview Microsoft Sentinel Microsoft Security Copilot Microsoft Entra ID (Azure Active Directory) Microsoft Entra Agent ID Microsoft Entra External ID Microsoft Entra ID Governance Microsoft Entra ID Protection Microsoft Entra Internet Access Microsoft Entra Private Access Microsoft Entra Permissions Management Microsoft Entra Verified ID Microsoft Entra Workload ID Microsoft Entra Domain Services Azure Key Vault Microsoft Sentinel Microsoft Defender for Cloud Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Office 365 Microsoft Defender for Identity Microsoft Defender for Cloud Apps Microsoft Security Exposure Management Microsoft Defender Vulnerability Management Microsoft Defender Threat Intelligence Microsoft Defender Suite for Business Premium Microsoft Defender for Cloud Microsoft Defender Cloud Security Posture Mgmt Microsoft Defender External Attack Surface Management Azure Firewall Azure Web App Firewall Azure DDoS Protection GitHub Advanced Security Microsoft Defender for Endpoint Microsoft Defender XDR Microsoft Defender for Business Microsoft Intune core capabilities Microsoft Defender for IoT Microsoft Defender Vulnerability Management Microsoft Intune Advanced Analytics Microsoft Intune Endpoint Privilege Management Microsoft Intune Enterprise Application Management Microsoft Intune Remote Help Microsoft Cloud PKI Microsoft Purview Communication Compliance Microsoft Purview Compliance Manager Microsoft Purview Data Lifecycle Management Microsoft Purview eDiscovery Microsoft Purview Audit Microsoft Priva Risk Management Microsoft Priva Subject Rights Requests Microsoft Purview Data Governance Microsoft Purview Suite for Business Premium Microsoft Purview data security capabilities Pricing Services Partners Cybersecurity awareness Customer stories Security 101 Product trials How we protect Microsoft Industry recognition Microsoft Security Insider Microsoft Digital Defense Report Security Response Center Microsoft Security Blog Microsoft Security Events Microsoft Tech Community Documentation Technical Content Library Training & certifications Compliance Program for Microsoft Cloud Microsoft Trust Center Security Engineering Portal Service Trust Portal Microsoft Secure Future Initiative Business Solutions Hub Contact Sales Start free trial Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Marketplace Rewards Software development companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap
Microsoft Security Copilot

AI built into your daily workflows

Use Security Copilot agents across Microsoft Defender, Entra, Intune, and Purview to help you detect, investigate, and respond faster.
Overview

Protect at the speed and scale of AI

  • Summarize vast data signals into key insights to cut through the noise, and make use of AI-driven guidance and analysis across identities, devices, data, clouds, and apps.
  • Provide critical guidance and context for your security team. Use agents to automate processes and help your team respond to incidents in minutes, instead of hours or days.
  • Empower your staff with step-by-step guidance and automate tasks with agents so your security team can focus on strategic priorities.
DEMOS

Embedded AI in Action

Discover how Security Copilot brings AI-powered defense into your workflow with embedded skills, promptbooks, and dozens of agents that help you protect, detect, and respond across security and IT.
Back to tabs
Microsoft Security report cover titled ‘Delivering a Unified, AI‑First Defense’ with a person working on a laptop.
Security Copilot

Delivering a Unified, AI-First Defense

Explore how AI agents work side-by-side with security teams to scale defense and transform security operations.
INSIGHTS

Automate security and IT tasks with agents

Learn more about how Security Copilot can benefit your team with productivity and economic impact in these studies.
A women holding mobile and looking into laptop.
550%
SOC analysts using the Phishing Triage Agent in Defender found malicious emails up to 550% faster.1
 
 
 
 
A person looking into a tab screen.
204%
Admins using the Conditional Access Optimization Agent found 204% more missing zero trust policies.2
 
 
 
 
Integrations

Products integrated with Security Copilot

Microsoft Sentinel

Unify security data and context to power agentic defense with SIEM & AI-ready platform.

Microsoft Defender

Help prevent and detect cross-domain cyberattacks at the speed of AI—available with Copilot embedded.

Microsoft Intune

Mitigate cyberthreats to devices, protect data, and improve compliance across clouds—available with Copilot embedded.
Microsoft Entra

Microsoft Entra

Help protect any identity and secure access to any resource with one family of solutions—available with Copilot embedded.
Microsoft Purview

Microsoft Purview

Secure and govern your data at the machine speed and scale of AI—available with Copilot embedded.

Microsoft Defender for Cloud

Understand multicloud risk and get remediation recommendations—available with Copilot embedded.
In Microsoft 365 E5

Get AI agents built into your everyday workflows

Person with a backpack walking through a modern office lobby.
Announcement

Get ahead of what could go wrong, so more things go right

Move forward confidently with autonomous Security Copilot agents built right into the Microsoft 365 E5 tools you use every day.
Diagram showing Microsoft Security Copilot connected to multiple security agents.
Documentation

See what’s included with Security Copilot in Microsoft 365 E5

Learn what’s included and find answers to frequently asked questions.
Person using a tablet with a stylus in a home workspace.
Product

Get Started

Get started with Security Copilot agents in the daily tools your teams already use:
Pricing

Security Copilot pricing

Start using Security Copilot today with options that fit your unique security requirements.
Customer stories

What customers are saying

RESOURCES

AI for security and beyond

Frequently asked questions

  • Security Copilot delivers agentic automation and AI-driven insights across Security and IT, empowering organizations to protect, detect, and respond at the speed and scale of AI.
  • Security Copilot combines a specialized language model with security-specific capabilities from Microsoft. These capabilities incorporate a growing set of security-specific skills informed by our unique global threat intelligence and more than 100 trillion daily signals.
  • Yes, Security Copilot is generally available for use by security and IT teams.
  • Get started by flexibly provisioning compute capacity to run Security Copilot workloads. Scale confidently to meet your evolving needs even during periods of unexpected demand. Learn about pricing and read more about how to get started with Security Copilot.

    Security Copilot will also be included in Microsoft 365 E5. See below for details.
  • Yes. Copilot integrates with other Microsoft Security products, including but not limited to Microsoft Defender XDR, Microsoft Sentinel, Microsoft Intune, Microsoft Entra, Microsoft Purview, Microsoft Defender for Cloud, and Microsoft Defender External Attack Surface Management. It also integrates with Azure security tools including Azure Web Application Firewall (WAF) and Azure Firewall. Copilot uses the data and signals from these products to generate customized guidance.
  • Yes. Security Copilot integrates with partner products to provide plugins and promptbooks that extend customer insights. Copilot capabilities include agents built by partners. Learn more about partners that integrate with Security Copilot.
  • Security Copilot agents enhance security and IT operations with autonomous and adaptive automation. Integrated seamlessly with Microsoft Security solutions and partner ecosystems, agents handle high-volume security tasks, reduce workloads, and accelerate responses. They learn from feedback and adapt to workflows, boosting efficiency while teams stay in control.
  • Users interact with agents from within Microsoft Defender, Entra, Intune, Microsoft Purview, and Security Copilot. Get started with Security Copilot agents using security compute units (SCUs) or access as part of your Microsoft 365 E5 subscription.
  • At Ignite 2025, Microsoft announced that Security Copilot agents will be directly built into the flow of work for security teams, available in Microsoft Defender, Entra, Intune and Purview.

    To make the agents easily accessible and help security teams get started faster, Security Copilot will be available to all Microsoft 365 E5 customers.

    Microsoft 365 E5 customers already using Security Copilot as of November 18, 2025, can access this benefit now. All other Microsoft 365 E5 customers will be activated through a phased roll-out in the upcoming months. Customers will receive advanced notice.
  • Eligible Microsoft 365 E5 customers will have 400 Security Compute Units (SCUs) per month for every 1000 user licenses, up to 10,000 SCUs per month. This included capacity is expected to support typical scenarios.
     
    • Example 1: An organization with 400 seats gets 160 SCUs/month.
    • Example 2: An organization with 4,000 seats gets 1,600 SCUs/month.
  • Microsoft 365 E5 customers already using Security Copilot as of November 18, 2025, can access this benefit now. All other Microsoft 365 E5 customers will be activated through a phased roll-out in the upcoming months. Customers will receive advanced notice.
A man working on two desktops
Get started

Empower your security and IT teams

Get started with Security Copilot and turbocharge security in the flow of work.
  1. [1]
    Results based on randomized control trials involving professional security analysts participating in a Microsoft internal study; 167 professional security analysts triaging a 25-email queue ; October 2025
  2. [2]
    Results based on randomized control trials involving IT administrators participating in a Microsoft internal study; 162 identity administrators with varying degrees of self-reported experience completing 4 conditional access policy management tasks; October 2025

Follow Microsoft Security