30 Days Gen AI Risk Trial -Start Now
Skip to main content
CybersecurityPay-as-you-go via Security Compute Units (SCU); minimum capacity reservation requiredmicrosoft.com

Microsoft Security Copilot

Microsoft's AI-assisted security operations product — natural-language analysis over Defender / Sentinel / Entra signals.

Risk score

3/10Low

Assessment across data handling, compliance, security and transparency.

Overview

Microsoft Security Copilot is an enterprise-only product priced via Security Compute Units (SCUs). It runs on Azure infrastructure and inherits Microsoft's commercial cloud compliance posture — SOC 1/2/3, ISO 27001, FedRAMP High, HIPAA BAA, GDPR. Customer data ingested for prompt context is not used to train Microsoft's foundation models.

Risk factors

2
  • Reads from highly sensitive security signal sources (Defender, Sentinel, Entra) — privilege concentration
  • Prompts may inadvertently expose IOCs, attacker TTPs, or insider-threat investigations to a broad operator audience

Recommendations

3
  • Restrict access to Security Copilot via Entra ID conditional access — high-privilege role only
  • Audit prompt history for sensitive incident exposure before sharing across the SOC team
  • Confirm BAA / FedRAMP coverage in the Microsoft Service Trust Portal before processing regulated data

Data handling

Storage
Customer-region Azure infrastructure; data residency configurable
Retention
Governed by tenant Microsoft 365 / Azure retention policies
Training on inputs
Off — customer data is not used to train Microsoft's foundation models

See the AI tools in use across your organisation.

Connect your tool research to the employee AI activity and data security questions that matter to your team.