What is Microsoft Security Copilot? E5 Inclusion and SCUs in 2026

セキュリティカテゴリを表すパンダのイラスト Generative AI

What is Microsoft Security Copilot? Outlining E5/E7 Inclusion and SCUs in 2026

About This Article
This article was created using an automated generation flow leveraging generative AI. Based on official Microsoft information as of September 18, 2026, it outlines the role of Microsoft Security Copilot, its inclusion in Microsoft 365 E5/E7, Security Compute Units (SCUs), and differences from E3.

Verification Status: 📘 Official Microsoft information verified / Not verified on actual devices

Microsoft Security Copilot is a product that assists security operations across Microsoft Defender, Entra, Intune, Purview, and more using generative AI. It is used to assist investigations—such as alert summarization, threat analysis, identity risk verification, and data security investigations—helping human analysts trace back to primary data.

Major Changes in 2026

Security Copilot is included in Microsoft 365 E5 and E7. According to Microsoft, the rollout to eligible customers began on November 18, 2025, and is being deployed in phases. E7 is a higher-tier SKU than E5 that became generally available (GA) on May 1, 2026.

ItemMicrosoft 365 E3Microsoft 365 E5Microsoft 365 E7
Security Copilot InclusionNoneIncludedIncluded
Microsoft CopilotAdd-onAdd-onIncluded
Included SCUsNone400 SCUs/month per 1,000 paid usersSame as above
LimitUp to 10,000 SCUs/monthUp to 10,000 SCUs/month

Quantities under 1,000 users are prorated; for example, Microsoft's official documentation states that 400 licenses yield 160 SCUs/month. Unused SCUs do not roll over to the next month.

flowchart LR
  L[E5 / E7 paid user licenses] --> C[Default Security Copilot Capacity]
  C --> S[月次SCU pool]
  S --> D[Defender]
  S --> E[Entra]
  S --> I[Intune]
  S --> P[Purview]
  S --> SC[Security Copilot portal]

"E5 means immediate availability" is not always true

Eligible E5/E7 tenants are automatically provisioned via zero-click activation, but Microsoft is conducting a phased rollout. You should verify not just eligibility, but whether it has actually been deployed to your tenant. The initial interface, such as agents-first versus chat-first, may also differ depending on the rollout phase.

First Steps: Review Capacity and Permissions

Sign in to Security Copilot and verify the following without making any changes:

  • Presence of Default Security Copilot Capacity

  • Whether it is inclusion capacity or traditional provisioned capacity

  • SCU usage

  • Owner / Contributor roles

  • Data sharing settings

  • Permissions on the Defender / Entra / Intune / Purview side

Success Criteriais being able to explain whether your organization is on the E5/E7 inclusion model or the traditional manual SCU model.

Change One Thing

Change only the display period for Usage monitoring and compare SCU consumption trends. Do not delete capacity or change billing settings during the initial verification.

Safe Practical Prompts

このインシデントについて、

1. 何が起きた可能性があるか

2. 影響を受けたユーザーとデバイス

3. 根拠となるシグナル

4. 次に人間が確認すべき一次データ
を分けて説明してください。
確証がない内容は推測として明示してください。

What to look at: Instead of relying on the conclusion of the response, verify the alerts, timelines, users, and devices cited as evidence in the primary console.

Change One Thing: Change "primary data that a human should check next" to "primary data to check before containment" and compare how the focus of the response changes.

For Non-Inclusion Tiers Such as E3

Security Copilot can be used with tiers other than E5/E7, but you must use the traditional model where SCUs are provisioned manually. According to Microsoft, you set up capacity within Security Copilot or via Azure. Leaving provisioned capacity active after testing will affect billing, so verify your usage model beforehand.

Three Perspectives

  • General Users: Understand that Security Copilot is not a general-purpose business chat, but an AI designed for authorized security operations.

  • Business/Administrative Staff: Do not treat AI responses as definitive security decisions.

  • IT/SOC Teams: Manage primary signals, SCU consumption, roles, and data sharing as a cohesive set.

Checklist for Administrators

  • E5/E7 eligibility and actual rollout status to the tenant

  • Default Security Copilot Capacity

  • Monthly SCUs and usage

  • Do not hastily delete existing provisioned capacity

  • Least privilege for Owner / Contributor roles

  • Data storage and GPU processing regions

  • Original permissions in Defender / Entra / Intune / Purview

  • Prerequisites or additional fees for Preview/agent features

Official Microsoft Information and Primary Sources

In 2026, Security Copilot underwent a major shift from "a product requiring separately purchased SCUs" to a product that utilizes included capacity for E5/E7. The first step is to verify your tenant's licensing and actual rollout status.

Document information

Article title
What is Microsoft Security Copilot? E5 Inclusion and SCUs in 2026
Published
Updated
Source
https://papanda925.com/?p=16304&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL