30 Days Gen AI Risk Trial -Start Now
Book a demo
Cybersecurity·Pay-as-you-go via Security Compute Units (SCU); minimum capacity reservation required·microsoft.com

Microsoft Security Copilot

Microsoft's AI-assisted security operations product — natural-language analysis over Defender / Sentinel / Entra signals.

Risk Score
Low
3/10

Independent assessment across data handling, compliance, security and transparency.

Overview

Microsoft Security Copilot is an enterprise-only product priced via Security Compute Units (SCUs). It runs on Azure infrastructure and inherits Microsoft's commercial cloud compliance posture — SOC 1/2/3, ISO 27001, FedRAMP High, HIPAA BAA, GDPR. Customer data ingested for prompt context is not used to train Microsoft's foundation models.

Risk factors

2
  • Reads from highly sensitive security signal sources (Defender, Sentinel, Entra) — privilege concentration
  • Prompts may inadvertently expose IOCs, attacker TTPs, or insider-threat investigations to a broad operator audience

Recommendations

3
  • Restrict access to Security Copilot via Entra ID conditional access — high-privilege role only
  • Audit prompt history for sensitive incident exposure before sharing across the SOC team
  • Confirm BAA / FedRAMP coverage in the Microsoft Service Trust Portal before processing regulated data

Data handling

Storage
Customer-region Azure infrastructure; data residency configurable
Retention
Governed by tenant Microsoft 365 / Azure retention policies
Training on inputs
Off — customer data is not used to train Microsoft's foundation models