Microsoft Security Copilot
Microsoft's AI-assisted security operations product — natural-language analysis over Defender / Sentinel / Entra signals.
Risk score
3/10Low
Assessment across data handling, compliance, security and transparency.
Overview
Microsoft Security Copilot is an enterprise-only product priced via Security Compute Units (SCUs). It runs on Azure infrastructure and inherits Microsoft's commercial cloud compliance posture — SOC 1/2/3, ISO 27001, FedRAMP High, HIPAA BAA, GDPR. Customer data ingested for prompt context is not used to train Microsoft's foundation models.
Risk factors
2- Reads from highly sensitive security signal sources (Defender, Sentinel, Entra) — privilege concentration
- Prompts may inadvertently expose IOCs, attacker TTPs, or insider-threat investigations to a broad operator audience
Recommendations
3- Restrict access to Security Copilot via Entra ID conditional access — high-privilege role only
- Audit prompt history for sensitive incident exposure before sharing across the SOC team
- Confirm BAA / FedRAMP coverage in the Microsoft Service Trust Portal before processing regulated data
Data handling
- Storage
- Customer-region Azure infrastructure; data residency configurable
- Retention
- Governed by tenant Microsoft 365 / Azure retention policies
- Training on inputs
- Off — customer data is not used to train Microsoft's foundation models
See the AI tools in use across your organisation.
Connect your tool research to the employee AI activity and data security questions that matter to your team.