Domain 4 of 4 · Chapter 3 of 3

Implement Microsoft Security Copilot

Unlock the complete study guide + 1,040 practice questions across 16 full exams.

Bundled into the existing SC-500 premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • Four layers behind a Security Copilot rollout
  • Workspaces, data location, and agent routing
  • Security Compute Units and capacity management
  • The two keys behind every Security Copilot answer
  • Provisioning access: bundles, groups, and owners
  • Owner settings: uploads, data sharing, audit logs
  • Plugin availability, scope, and per-user setup
  • Setting up Microsoft-built agents
  • Security Store: partner agents, consent, and billing
  • Exam patterns and the traps that fit them

Which grant unlocks which action in Security Copilot

ActionCopilot contributorCopilot ownerSource-service roleAzure capacity roleGlobal Administrator
Create sessions and run promptbooksYesYesNo effectNo effectNo effect
Read Microsoft Sentinel incidents in a sessionNot on its ownNot on its ownYes, Microsoft Sentinel Reader is the least-privileged built-in choiceNo effectNo effect
Assign roles and set preinstalled plugin availabilityNoYesNo effectNo effectNo effect
Publish a custom plugin for the organizationOnly if an owner allows contributors at both scopesYesNo effectNo effectNo effect
Buy, resize, or reassociate SCU capacityNoRequired to reach the setting in the Copilot portalNo effectOwner or Contributor on the capacity resourceNo effect
Approve a partner agent's Microsoft product permissionsNoNoNo effectNo effectRequired

Decision tree

Cannot open a sessionon the platform?Copilot contributorplatform access, no dataBlocked from settings,roles, or plugin controls?Copilot ownerthe administrative surfaceBlocked from buying orresizing capacity?Azure capacity roleOwner or Contributor on capacityPartner agent setupwaiting for consent?Global Administratorapproves Microsoft permissionsSource-service rolefor example Microsoft Sentinel ReaderYesYesYesYesNoNoNoNo

Cheat sheet

  • A Security Copilot workspace binds data location, capacity, and access
  • The default workspace powers embedded Security Copilot experiences
  • Security Compute Units measure the capacity consumed by Copilot workloads
  • Users need a Copilot role in the target workspace before a switch
  • Stop agent triggers before reassigning integrated-product traffic
  • Security Copilot roles grant platform capability, not source-data permission
  • Sentinel plugin access requires a Sentinel data role
  • Copilot Owner controls administrative settings unavailable to Contributor
  • Role-assignable groups simplify Copilot membership
  • Security Copilot retains two owners for administrative continuity
  • Use Copilot Owner settings to govern uploads and Purview audit logging
  • Choose the narrowest Security Copilot contributor-access bundle
  • Custom-plugin controls separate personal and organization scope
  • Preinstalled-plugin restrictions apply to standalone and embedded experiences
  • Certain preinstalled plugins require per-user configuration
  • Custom plugins are added from supported manifest definitions
  • Agent-required plugins are enabled only for that agent
  • A Microsoft-built agent can use a dedicated Agent ID
  • Agent setup must satisfy its declared dependencies
  • Agent triggers support automatic and one-time execution
  • Agent feedback can be retained and curated as memory
  • Microsoft agents can surface in standalone and embedded experiences
  • Security Store routes Microsoft and partner agents through different acquisition paths
  • Removing an agent does not cancel its Store subscription
  • Agent subscription fees and SCU consumption are billed independently
  • A Store agent's dependent plugin may still require configuration
  • Partner agents need tenant consent for Microsoft product permissions

Unlock with Premium — includes all practice exams and the complete study guide.

References

  1. What is Microsoft Security Copilot?
  2. Configure workspace access and settings (training module)
  3. Understand authentication in Security Copilot
  4. Create a Security Copilot workspace (training module)
  5. Assign workspaces for integrated agents (training module)
  6. Security Compute Units and capacity
  7. Monitor and manage workspace capacity (training module)
  8. Configure owner settings
  9. Manage SCU usage
  10. Microsoft Sentinel roles and permissions
  11. Manage plugins
  12. Security Copilot agents overview
  13. Setup and manage Security Copilot agents
  14. Microsoft Security Store in Security Copilot