Microsoft / microsoft.com
AI security analyst combining GPT-4 with Microsoft's 65 trillion daily security signals for natural language threat investigation, incident summarisation, and security reporting within Microsoft security products.
Free plan
No
API access
No
Open source
No
Platforms
2
Microsoft Security Copilot allows analysts to investigate threats, summarise incidents, and generate security reports in natural language, grounded in Microsoft's 65 trillion daily security signals and nation-state threat intelligence. Embedded in Defender XDR, Sentinel, Purview, and Entra, analysts ask Copilot to investigate alerts, explain suspicious scripts, or generate phishing reports within existing tools. Consumption-based pricing at $4/SCU per hour scales with workload.
Microsoft Security Copilot runs as llm assistant software built around text and code workflows. Users typically start with a prompt, upload, or connected data source, and the underlying model handles the heavy lifting before returning a result you can refine or export. It's available on web and microsoft security products.
Recent YouTube videos cached from the backend so this page stays fast and fresh.
The capabilities that matter most for teams evaluating Microsoft Security Copilot.
Investigates threats, summarises incidents, and analyses suspicious code using plain English across Microsoft security data.
Responses grounded in Microsoft's 65 trillion daily signals and nation-state threat tracking.
Codified investigation procedures as reusable prompts for consistent response workflows.
$4/Security Compute Unit (SCU) per hour. Scales with workload. Requires Microsoft Entra account and Microsoft security product subscriptions.
Model
Subscription
Starting price
Free
Free trial
No
Darktrace provides autonomous AI security across non-Microsoft environments. CrowdStrike Charlotte AI is embedded in the Falcon platform.
A side-by-side look at the closest alternative in this category.
Key facts about model providers, platforms, and team support.
Model Provider
OpenAI
Models
GPT-4
Platforms
Web, Microsoft security products
Deployment
SaaS
Integrations
Microsoft Defender XDR, Microsoft Sentinel, Microsoft Purview, Microsoft Entra, Microsoft Intune
Team Collaboration
Yes
Launch Year
2023
Compliance signals and data-handling notes as reported by the vendor.
Microsoft enterprise security. SOC 2 Type II. ISO 27001. FedRAMP authorised. Customer security data processed within Microsoft's compliance boundary.
Editorial Verdict
Microsoft Security Copilot is the right AI security tool for organisations already using Microsoft Defender, Sentinel, and Purview.
Last verified July 24, 2026.
Raghu Boddu, Sami Lamppu
Raghu Boddu, Sami Lamppu
Bi Yue Xu, Rod Trent
PATRICK. JONES
$4/Security Compute Unit (SCU) per hour. Scales with workload. Requires Microsoft Entra account and Microsoft security product subscriptions.
Enterprise pricing bundled with CrowdStrike Falcon platform. Included in Falcon Flex subscription.
CrowdStrike Falcon platform (all modules)
Microsoft enterprise security. SOC 2 Type II. ISO 27001. FedRAMP authorised. Customer security data processed within Microsoft's compliance boundary.
CrowdStrike enterprise security. SOC 2 Type II. ISO 27001. FedRAMP authorised. Customer security data processed within Falcon's secure environment.
Security investigation data processed within Microsoft's enterprise security boundary. Customer data not used to train Microsoft AI models.
Security telemetry processed within CrowdStrike's Falcon platform boundary.
Security investigation data processed within Microsoft's enterprise security boundary. Customer data not used to train Microsoft AI models.
Verified reviews from signed-in users, stored in the backend and averaged into this tool's rating.
Sign in to rate Microsoft Security Copilot and leave a review.
No other reviews yet — be the first to share how this tool performs in practice.