Skip to content
M365 E7 & Agent 365

Security Copilot in Microsoft 365 E5 and E7: Access, Capacity and Readiness

2 min read

Microsoft Security Copilot is included for eligible Microsoft 365 E5 and E7 customers, with tenant rollout and capacity conditions. Confirm your tenant’s enablement and included capacity before buying additional capacity or planning a pilot.

Reviewed September 6, 2026 against Microsoft’s inclusion guidance.

What does inclusion mean?

Microsoft describes a phased rollout and automatic provisioning for eligible tenants. Its current guidance provides 400 Security Compute Units per month for every 1,000 paid qualifying user licenses, proportional to license count and capped at 10,000 units per month. The allocation is shared across the tenant and resets monthly.

Eligibility and usable access are different checkpoints. Verify the Microsoft 365 Message center notice or the relevant in-product experience, then review the tenant’s usage dashboard. Check current billing guidance before changing any existing provisioned capacity.

What costs can remain?

The included allocation does not cover every connected service. Microsoft identifies examples such as Microsoft Sentinel data lake compute or storage, Azure Logic Apps usage and partner-agent licensing. Additional capacity and feature terms can change, so use the current product documentation and your agreement.

What should a useful pilot prove?

Choose an investigation task your team already performs, such as reviewing phishing alerts or summarizing an incident. Establish the current time, quality standard and escalation process. Compare the pilot output with the underlying evidence and measure the analyst’s review effort.

Confirm that the relevant data sources and permissions are configured. The exact prerequisites depend on the experience being used; a particular Microsoft Sentinel deployment is not a universal prerequisite for every Security Copilot feature.

Review access and data settings

Microsoft documents that Security Copilot may copy, process and store relevant customer data. Review storage geography, processing location, sharing preferences and assigned roles with your security and privacy owners. Do not assume that using the service means data never leaves a source system or is never retained.

Keep a named person responsible for reviewing consequential recommendations. Test the selected workflow with representative, authorized data and document when it should stop or escalate.

Improve the security workflow first

Our Security Operations Optimization assessment examines detection and response workflows in an agreed scope. Use the free security and governance checklist to prepare, or book a free 15-minute strategy call.

Microsoft sources

Security Copilot inclusion, capacity and data handling; onboarding requirements. Confirm current availability for your cloud environment.

Put this guidance to work

Security Operations Optimization assessment

Prepare with a free guide: M365 AI Security and Governance Checklist.

Discuss your priorities in a free 15-minute strategy call. A detailed assessment or implementation is scoped separately.

Book a consultation
Share this article: LinkedIn