Cyber Intelligence
Security Posture Management and Microsoft Sentinel · 20-25% of exam

L18. Implementing Microsoft Security Copilot: Workspaces, Plugins & Agents

Video generating

Check back soon for the video lesson on Implementing Microsoft Security Copilot: Workspaces, Plugins & Agents

Course outlineLesson 18 of 18
SC-500 Exam Prep: course overview

Security Copilot is not a single tool bolted onto the SOC, it is a capacity you provision, a permission model you assign, and a growing set of plugins and agents you choose to turn on inside the consoles your analysts already live in.

Provisioning a Security Copilot Workspace

Security Copilot is provisioned as a workspace backed by Security Compute Units (SCUs), the capacity/billing unit that determines how much concurrent Copilot usage the organization can run. SCU capacity is purchased and can be scaled up or down based on usage patterns, similar in spirit to provisioning compute capacity for any other consumption-based Azure service, rather than a flat per-seat license.

Managing Permissions and Roles

Access to Security Copilot is governed through roles that integrate with existing Microsoft Entra ID role assignments rather than introducing an entirely parallel identity system:

  • Owner roles manage workspace settings, capacity, and plugin configuration
  • Standard contributor/analyst-level access lets a user run prompts and promptbooks against the data their existing product permissions (Defender, Sentinel, Entra) already allow them to see

This matters specifically because Copilot doesn't expand what a user can see, it answers using the same underlying data permissions the user already holds in the connected product, the identical principle covered for Microsoft 365 Copilot back in Lesson 11.

Promptbooks

A promptbook is a saved, reusable sequence of prompts designed for a repeatable investigation or response task (for example, "triage this phishing alert" or "summarize this incident for a report"), so an analyst doesn't need to construct the same multi-step prompt chain from scratch every time a similar situation comes up.

Enabling Plugins

Plugins connect Security Copilot to the data and actions of a specific product:
  • First-party Microsoft plugins: Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Intune, and others, each surfacing that product's data and allowing Copilot-driven actions within it
  • Third-party plugins: extend Copilot to non-Microsoft security tools an organization already has deployed, so an investigation doesn't stop at the boundary of Microsoft's own product suite

Each plugin needs to be explicitly enabled for the workspace, and a plugin's available actions are still bounded by the underlying product permissions of the user running the prompt.

Security Copilot Agents and Security Store Agents

Beyond conversational prompting, Security Copilot supports agents: semi-autonomous units that carry out a defined security task with defined guardrails, rather than requiring a human to drive every step interactively. Examples include an agent that triages routine phishing submissions or one that clusters and prioritizes alerts before an analyst ever looks at them. Security Store agents extend this further: agents built and published by Microsoft or third parties, distributed through a marketplace-style catalog, that an organization can adopt without building the automation from scratch, similar in spirit to installing a content hub solution in Sentinel rather than building analytics rules manually.

Embedded Experiences Across Consoles

Rather than requiring analysts to leave their existing tools, Security Copilot capabilities are embedded directly inside Defender, Sentinel, Purview, and Intune, so a Copilot-generated incident summary or recommended next step appears in context where the analyst is already working, rather than in a separate, disconnected chat application. Exam tip: The exam frames Security Copilot the same way it frames every other capability in this course: govern the capacity (SCUs), govern the access (roles tied to Entra ID and underlying product permissions), then layer on the specific capability (plugins for data/actions, promptbooks for repeatable workflows, agents for semi-autonomous tasks). Don't treat Copilot access as a separate permission model from the product it's plugged into.

Exam Focus Points
  • Security Copilot workspaces are provisioned against Security Compute Units (SCUs), a scalable capacity/billing unit rather than a flat per-seat license
  • Copilot permissions integrate with existing Microsoft Entra ID roles, and Copilot answers using the same underlying product permissions the user already holds, not expanded access
  • Promptbooks are saved, reusable prompt sequences for repeatable investigation or response tasks
  • Plugins (first-party like Defender XDR/Sentinel/Entra/Intune, or third-party) connect Copilot to a specific product's data and actions, and must be individually enabled
  • Security Copilot agents perform semi-autonomous security tasks with defined guardrails, and Security Store agents let organizations adopt prebuilt agents from a marketplace-style catalog instead of building automation from scratch
Knowledge Check

1. How is Security Copilot capacity provisioned and billed?

2. A user with only Sentinel Reader access runs a Security Copilot prompt asking to summarize a set of incidents. What data will Copilot use to answer?

3. An organization wants to adopt a prebuilt phishing-triage automation for Security Copilot without building it from scratch. Where would they find this?

Recommended: Pluralsight

This free course covers the theory. Pluralsight adds structured Cloud and AI Security Engineer learning paths, hands-on Azure and Defender for Cloud labs, and timed practice exams to make it stick before exam day.

Start SC-500 prep free10-day free trial · card required, cancel anytime before it renews