What is Microsoft Security Copilot? Outlining E5/E7 Inclusion and SCUs in 2026
About This Article
This article was created using an automated generation flow leveraging generative AI. Based on official Microsoft information as of September 18, 2026, it outlines the role of Microsoft Security Copilot, its inclusion in Microsoft 365 E5/E7, Security Compute Units (SCUs), and differences from E3.Verification Status: 📘 Official Microsoft information verified / Not verified on actual devices
Microsoft Security Copilot is a product that assists security operations across Microsoft Defender, Entra, Intune, Purview, and more using generative AI. It is used to assist investigations—such as alert summarization, threat analysis, identity risk verification, and data security investigations—helping human analysts trace back to primary data.
Major Changes in 2026
Security Copilot is included in Microsoft 365 E5 and E7. According to Microsoft, the rollout to eligible customers began on November 18, 2025, and is being deployed in phases. E7 is a higher-tier SKU than E5 that became generally available (GA) on May 1, 2026.
| Item | Microsoft 365 E3 | Microsoft 365 E5 | Microsoft 365 E7 |
|---|---|---|---|
| Security Copilot Inclusion | None | Included | Included |
| Microsoft Copilot | Add-on | Add-on | Included |
| Included SCUs | None | 400 SCUs/month per 1,000 paid users | Same as above |
| Limit | — | Up to 10,000 SCUs/month | Up to 10,000 SCUs/month |
Quantities under 1,000 users are prorated; for example, Microsoft's official documentation states that 400 licenses yield 160 SCUs/month. Unused SCUs do not roll over to the next month.
flowchart LR L[E5 / E7 paid user licenses] --> C[Default Security Copilot Capacity] C --> S[月次SCU pool] S --> D[Defender] S --> E[Entra] S --> I[Intune] S --> P[Purview] S --> SC[Security Copilot portal]
"E5 means immediate availability" is not always true
Eligible E5/E7 tenants are automatically provisioned via zero-click activation, but Microsoft is conducting a phased rollout. You should verify not just eligibility, but whether it has actually been deployed to your tenant. The initial interface, such as agents-first versus chat-first, may also differ depending on the rollout phase.
First Steps: Review Capacity and Permissions
Sign in to Security Copilot and verify the following without making any changes:
Presence of Default Security Copilot Capacity
Whether it is inclusion capacity or traditional provisioned capacity
SCU usage
Owner / Contributor roles
Data sharing settings
Permissions on the Defender / Entra / Intune / Purview side
Success Criteriais being able to explain whether your organization is on the E5/E7 inclusion model or the traditional manual SCU model.
Change One Thing
Change only the display period for Usage monitoring and compare SCU consumption trends. Do not delete capacity or change billing settings during the initial verification.
Safe Practical Prompts
このインシデントについて、 1. 何が起きた可能性があるか 2. 影響を受けたユーザーとデバイス 3. 根拠となるシグナル 4. 次に人間が確認すべき一次データ を分けて説明してください。 確証がない内容は推測として明示してください。
What to look at: Instead of relying on the conclusion of the response, verify the alerts, timelines, users, and devices cited as evidence in the primary console.
Change One Thing: Change "primary data that a human should check next" to "primary data to check before containment" and compare how the focus of the response changes.
For Non-Inclusion Tiers Such as E3
Security Copilot can be used with tiers other than E5/E7, but you must use the traditional model where SCUs are provisioned manually. According to Microsoft, you set up capacity within Security Copilot or via Azure. Leaving provisioned capacity active after testing will affect billing, so verify your usage model beforehand.
Three Perspectives
General Users: Understand that Security Copilot is not a general-purpose business chat, but an AI designed for authorized security operations.
Business/Administrative Staff: Do not treat AI responses as definitive security decisions.
IT/SOC Teams: Manage primary signals, SCU consumption, roles, and data sharing as a cohesive set.
Checklist for Administrators
E5/E7 eligibility and actual rollout status to the tenant
Default Security Copilot Capacity
Monthly SCUs and usage
Do not hastily delete existing provisioned capacity
Least privilege for Owner / Contributor roles
Data storage and GPU processing regions
Original permissions in Defender / Entra / Intune / Purview
Prerequisites or additional fees for Preview/agent features
Official Microsoft Information and Primary Sources
In 2026, Security Copilot underwent a major shift from "a product requiring separately purchased SCUs" to a product that utilizes included capacity for E5/E7. The first step is to verify your tenant's licensing and actual rollout status.

