Skip to content
TrustList
News

Security Copilot arrives in Microsoft 365 E5 and E7 tenants switched on, with Microsoft 365 data access enabled by default

Editorial

By TrustList Editorial

Microsoft told E5 and E7 tenants on 24 September that Security Copilot is now included and provisioned automatically, with 400 compute units a month per 1,000 licences. Access to Microsoft 365 data is on by default; opting out means calling support.

About Security Copilot arrives in Microsoft 365 E5 and E7 tenants switched on, with Microsoft 365 data access enabled by default

Security Copilot arrives in Microsoft 365 E5 and E7 tenants switched on, with Microsoft 365 data access enabled by default

24 September 2026 — Microsoft posted Message Center item MC1478465 on 24 September 2026 telling Microsoft 365 E5 and E7 customers that Security Copilot, its AI assistant for security teams, is now part of their existing licence: "beginning today, your organization has access". No purchase or action is needed, and Microsoft provisions the service automatically. The rollout began on 18 November 2025 for tenants that already had Security Copilot and has been reaching other eligible E5 and E7 tenants in phases since.

What is included

  • Capacity: 400 Security Compute Units (SCUs) a month for every 1,000 paid user licences, up to 10,000 SCUs a month. It scales down for smaller tenants: Microsoft's example gives 160 SCUs a month for 400 licences.
  • Where it works: agents and assistance inside Microsoft Defender, Entra, Intune and Purview, and the Security Copilot portal, plus developer tools and APIs for custom agents.
  • What still costs extra: Microsoft Sentinel data lake compute or storage, non-agentic Data Security Investigations in Purview, Azure Logic Apps used with Security Copilot, and third-party agents bought through the Microsoft Security Store.

The defaults Microsoft sets for you

Microsoft's provisioning documentation lists what is preselected:

  • Customer data, meaning prompts and responses, is stored in the tenant's Microsoft Entra geography, or its Microsoft 365 data-location override where one exists.
  • Prompts are processed in the EU if data is stored in the EU; otherwise they may be processed in the US, UK, EU or Australia and New Zealand depending on capacity.
  • Security Copilot's access to data from Microsoft 365 services such as Purview is on by default. Microsoft says relevant customer data "may be copied, processed, and stored" to produce answers.
  • Sharing data with Microsoft for human review is off by default.
  • Owner access is inherited by existing roles including Global Administrator, Security Administrator, Conditional Access Administrator, Intune Administrator and several compliance roles.

To opt out of the entitlement altogether, Microsoft says to contact support; the post names no admin switch for that.

Who is affected

Organisations on Microsoft 365 E5 or E7, their security and compliance teams, and data-protection officers who keep records of processing and data-location commitments.

What to do

  • Open the Owner settings in the Security Copilot portal and confirm the storage location, prompt-processing location and Microsoft 365 data access match your policies.
  • Review who has inherited owner and contributor access, and trim it to the people who need it.
  • Record the new processing in your data-protection documentation, and decide whether a data-protection impact assessment is needed.
  • Watch SCU use against the monthly allowance before enabling paid add-ons, and decide deliberately whether to keep the service or ask support to remove it.

Not yet independently verified. This rests on Microsoft’s own Message Center post, read through a public archive because the admin centre requires sign-in, and Microsoft’s Learn pages; no independent report was found, and the date a given tenant is switched on varies and was not checked. We will update this when it can be confirmed, and remove this note.

Sources