Summary
Microsoft is including Security Copilot features and agents as part of existing Microsoft 365 E5 and E7 plans without requiring a separate purchase. Tenants receive a monthly allocation of Security Compute Units based on user counts. Administrators should review the newly available agentic capabilities across security portals and monitor usage against the included compute limits.
Administrator impact: No direct administrator action is required.
End user impact: Security teams gain access to integrated AI agents within Defender, Entra, Intune, and Purview.
Score rationale: This is a significant feature addition that introduces artificial intelligence capabilities and monthly compute allocations to existing licensing plans.
Security Copilot Adoption Hub | Microsoft Security Store | Customer support
Security Copilot is now included with Microsoft 365 E5/E7 plans, integrating agents across Defender, Entra, Intune, Purview, and its portal. No purchase or action is needed. Organizations get monthly Security Compute Units, developer tools, and can explore additional paid features or opt out by contacting support.
Message ID: MC1478465
Published: Sep 24, 2026
Expires: 23 Nov 2026
Last updated: 24 Sept 2026
Category: Stay informed
Service: Microsoft Entra, Microsoft Intune, Microsoft Defender XDR, Microsoft Purview
Tag: User impact, Admin impact
Microsoft Message
Microsoft Security Copilot agents are built into the flow of work of security teams using Microsoft Defender, Microsoft Entra, Microsoft Intune and Microsoft Purview. At Ignite 2025, Microsoft introduced a dozen new agents across these products, bringing agentic defense across workflows to enable autonomous and proactive protection.
Rollout schedule
To make it easier for teams to get started, beginning today, your organization has access to Security Copilot features and agents as part of your existing Microsoft 365 E5/E7 entitlement.
Impact on your organization
Who is affected
Organizations with Microsoft 365 E5 or E7
Platforms/Services
- Defender
- Entra
- Intune
- Purview
- Security Copilot portal
What will happen
- Security Copilot will be automatically included with Microsoft 365 E5/E7 (no separate purchase required).
- Your tenant will receive 400 Security Compute Units (SCUs) per month per 1,000 licensed users, up to 10,000 SCUs per month.
- Core agentic security experiences will be available across Defender, Entra, Intune, Purview, and the Security Copilot portal.
- Developer tools and APIs will be available to build custom agents and integrations.
- Existing security, compliance, and access policies continue to apply.
Additional capabilities outside the included entitlement may incur extra charges, including:
- Microsoft Sentinel data lake compute or storage.
- Non-agentic Data Security Investigations in Purview.
- Azure Logic Apps usage with Security Copilot.
- Third-party agents purchased via Microsoft Security Store.
Action required / Recommendations
No action is required to enable this feature.
We recommend:
- Reviewing new agentic scenarios and capabilities in the Security Copilot Adoption Hub.
- Reviewing the documentation for details on what’s included.
- Requesting assistance from a Microsoft 365 FastTrack specialist to unlock the full value of Security Copilot.
- Exploring Microsoft and partner-published agents in Microsoft Security Store, also accessible within Microsoft Defender and Entra.
If you would like to opt out of this entitlement, please contact support.