Microsoft Security Copilot
Microsoft / microsoft.com
AI security analyst combining GPT-4 with Microsoft's 65 trillion daily security signals for natural language threat investigation, incident summarisation, and security reporting within Microsoft security products.
Pricing
Free
Free plan
No
Category
Developer Tools
Platforms
2
Free plan
No
API access
No
Open source
No
Platforms
2
What is Microsoft Security Copilot?
Microsoft Security Copilot allows analysts to investigate threats, summarise incidents, and generate security reports in natural language, grounded in Microsoft's 65 trillion daily security signals and nation-state threat intelligence. Embedded in Defender XDR, Sentinel, Purview, and Entra, analysts ask Copilot to investigate alerts, explain suspicious scripts, or generate phishing reports within existing tools. Consumption-based pricing at $4/SCU per hour scales with workload.
How Microsoft Security Copilot works
Microsoft Security Copilot runs as llm assistant software built around text and code workflows. Users typically start with a prompt, upload, or connected data source, and the underlying model handles the heavy lifting before returning a result you can refine or export. It's available on web and microsoft security products.
Watch Microsoft Security Copilot in action
Recent YouTube videos cached from the backend so this page stays fast and fresh.
What makes it worth shortlisting
The capabilities that matter most for teams evaluating Microsoft Security Copilot.
Natural language investigation
Investigates threats, summarises incidents, and analyses suspicious code using plain English across Microsoft security data.
Threat intelligence grounding
Responses grounded in Microsoft's 65 trillion daily signals and nation-state threat tracking.
Prompt books
Codified investigation procedures as reusable prompts for consistent response workflows.
Best use cases
Who should use it
Pros
- Grounded in Microsoft's 65 trillion daily signals for real-world threat intelligence
- Embedded in existing Microsoft security tools without new platform adoption
- Consumption-based pricing scales with actual workload
- Natural language investigation reduces analyst time on routine triage
Cons
- Requires existing Microsoft security product ecosystem for full value
- $4/SCU pricing can accumulate quickly under heavy investigation workloads
- Less useful for non-Microsoft security stacks
Is it worth the price?
$4/Security Compute Unit (SCU) per hour. Scales with workload. Requires Microsoft Entra account and Microsoft security product subscriptions.
Model
Subscription
Starting price
Free
Free trial
No
Tools like Microsoft Security Copilot
Darktrace provides autonomous AI security across non-Microsoft environments. CrowdStrike Charlotte AI is embedded in the Falcon platform.
Microsoft Security Copilot vs CrowdStrike Charlotte AI
A side-by-side look at the closest alternative in this category.
Technical & deployment info
Key facts about model providers, platforms, and team support.
Model Provider
OpenAI
Models
GPT-4
Platforms
Web, Microsoft security products
Deployment
SaaS
Integrations
Microsoft Defender XDR, Microsoft Sentinel, Microsoft Purview, Microsoft Entra, Microsoft Intune
Team Collaboration
Yes
Launch Year
2023
Security & privacy
Compliance signals and data-handling notes as reported by the vendor.
Microsoft enterprise security. SOC 2 Type II. ISO 27001. FedRAMP authorised. Customer security data processed within Microsoft's compliance boundary.
Security investigation data processed within Microsoft's enterprise security boundary. Customer data not used to train Microsoft AI models.
What users are saying
Verified reviews from signed-in users, stored in the backend and averaged into this tool's rating.
Sign in to rate Microsoft Security Copilot and leave a review.
No other reviews yet — be the first to share how this tool performs in practice.
Common questions about Microsoft Security Copilot
Editorial Verdict
Should you use Microsoft Security Copilot?
Microsoft Security Copilot is the right AI security tool for organisations already using Microsoft Defender, Sentinel, and Purview.
Last verified July 24, 2026.



