At Ignite this week, Microsoft announced that Security Copilot will now be included in Microsoft 365 E5 (and E5 Security) at no additional cost. Security Copilot delivers “AI-powered, integrated, cost-effective, and extensible security capabilities” that elevate an organisations IT Security Operations or SOC’s efficiency and resilience.

So, what does it actually include and what are the catches?
1. Integrated AI-driven defense across the Microsoft stack
Security Copilot agents are natively embedded into Microsoft Defender, Entra, Intune, and Purview, which means that IT / Sec teams don’t need to juggle separate tools. This allows for a single, cohesive workflow where identity, endpoint, data, and threat protection are all reinforced by AI and can be reviewed, configured and monitored with just a prompt!
2. Autonomous and proactive protection
As part of this announcement, Microsoft has also introduced a dozen new AI agents that enable “agentic defense” — adaptive, autonomous responses to threats. Instead of just alerting, Copilot can recommend or even automate actions, helping teams stay ahead of evolving attacks or reasons for concern and to plan for action.
3. Included at no additional cost with E5
For Microsoft E5 customers, Security Copilot will now be included as part of the core entitlement.
Here’s the important part: Organisations receive 400 Security Compute Units (SCUs) per month per 1,000 users, scaling up to 10,000 SCUs/month — enough to cover (Microsoft say) most typical enterprise scenarios without extra spend.
4. Faster incident response and investigation
Copilot in Copilot Security is designed to accelerates triage, root cause analysis, and remediation by summarising complex signals into actionable insights. This can significantly reduce mean time to detect (MTTD) and mean time to respond (MTTR), freeing analysts to focus on strategic threats rather than repetitive tasks.
5. Customisation and extensibility
Beyond the built-in agents, Microsoft also provides extensive developer tools and APIs so organisations can create custom agents or connect other systems securely specifically tailored to their environment. This means it is possible and configure Security Copilot to unique workflows, integrate with third-party systems, and align it with your specific compliance or operational needs.
Enablement
Depending on your organisation, you might qualify for funded workshops for awareness and enablement of Security Copilot. Speak to your Microsoft Partner to find out more.
Read more at Microsoft Learn:

