Agentshield

Microsoft 365 Copilot vs Security Copilot: Pricing, Licensing and Which One to Buy

Marcus Feld, Security·Aug 24, 2026·8 min read

Try it live

Watch Agentshield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
12,408 injections blocked this week

Run a request

Inspection lane

INSPECTING
untrusted input

Policy trace

High-risk action held for approval

Audit trail

Microsoft 365 Copilot and Microsoft Security Copilot are unrelated products that share a brand, and buying one does nothing to secure the other. Microsoft 365 Copilot, renamed simply Microsoft Copilot during 2026, is a productivity assistant licensed per user that reads your mail, files and chats to draft and summarize. Microsoft Security Copilot is an assistant for your security operations team, billed by Security Compute Unit, that helps analysts investigate incidents. If you are trying to reduce the risk created by rolling out the first one, the second one is not the answer, and several teams have approved capacity spend believing otherwise.

The confusion is understandable and it is getting worse rather than better. Microsoft now runs at least four products with Copilot in the name: Microsoft Copilot for productivity, Microsoft Security Copilot for the SOC, GitHub Copilot for developers, and Copilot Studio for building agents. They have different licenses, different admin centers and different threat models.

What is the difference between Microsoft 365 Copilot and Microsoft Security Copilot?

Microsoft 365 Copilot is AI applied to your business data. Microsoft Security Copilot is AI applied to your security work. The first one creates a governance problem because it reads everything a user can read. The second one is a productivity tool for the people who have to clean that problem up. One is a workload to be secured, the other is staffing leverage for the team doing the securing.

 Microsoft 365 Copilot (Microsoft Copilot)Microsoft Security Copilot
BuyerIT and productivity leadership, usually funded from a digital workplace budgetSecurity operations, funded from the security budget
UsersEvery information worker you licenseAnalysts, incident responders, security admins
Data it touchesMail, files, chats, meetings and calendar through Microsoft Graph, scoped to each user permissionsSecurity signals, incidents and threat intelligence from your security stack
Pricing modelPer user per month, annual commitment, on top of a required base suite licenseCapacity based, billed by Security Compute Unit, minimum one provisioned SCU billed hourly
Admin surfaceMicrosoft 365 admin center and Microsoft PurviewSecurity Copilot portal and Microsoft Defender

Microsoft 365 Copilot vs Security Copilot pricing

The two products are priced on completely different models, which is the practical reason they should never be compared line for line on a spreadsheet.

Microsoft 365 Copilot carries a list price of 30 USD per user per month on an annual commitment, verified August 2026. The number that catches finance teams out is that you cannot buy it standalone: it sits on top of a base suite license, and Microsoft raised base suite prices on July 1, 2026, so the all-in cost per seat is considerably higher than the add-on line implies. Model the fully loaded seat, not the 30 USD.

Security Copilot is capacity based. Microsoft describes provisioned capacity as priced per hour and billed monthly with a minimum of one provisioned SCU, and its own billing example uses 4 USD per provisioned SCU and 6 USD per overage SCU. Run a single SCU continuously and you are into four figures a month before any analyst has been trained on it. Microsoft attaches an explicit caveat to those figures, which is worth repeating rather than smoothing over: "Prices are estimates only and are not intended as actual price quotes. Actual pricing may vary depending on the type of agreement entered with Microsoft, date of purchase, the currency exchange rate and taxes."

Is Microsoft Security Copilot included in Microsoft 365 E5?

Partly, and this is the detail most worth knowing before a renewal conversation. Microsoft states that "eligible Microsoft 365 E5 and E7 customers will have 400 Security Compute Units (SCUs) per month for every 1000 user licenses, up to 10,000 SCUs per month". That is an included allowance, not unlimited access, and consumption past it is billed separately.

So a 1,000 seat E5 tenant already has a meaningful Security Copilot allocation sitting unused. If your SOC has never switched it on, the cheapest experiment available to you costs nothing extra. Microsoft 365 Copilot has no equivalent inclusion at any suite level. It is always an add-on purchase.

Which one should you buy?

Answer the question the products actually address, not the one the shared name suggests.

If your goal isBuyWhy
Faster drafting, summarizing and meeting recap for staffMicrosoft 365 CopilotThis is the only product of the two that does it, and the value case is time saved per knowledge worker
Helping a small SOC triage more incidentsSecurity Copilot, starting with the E5 allowanceIf you hold E5 or E7 the allocation is already paid for. Prove value on included SCUs before provisioning more
Reducing the data exposure a Copilot rollout createsNeither. Buy nothingThe work is permission remediation and Purview labeling, both of which you already own. This is the mistake worth avoiding
Finding answers across company systems rather than draftingConsider a dedicated toolIf the real requirement is retrieval, a purpose-built system for searching across everything your team stores often costs less per seat than a full Copilot rollout
Governing what AI agents are allowed to doNeither, this is a separate control layerBoth Copilots assume the action is authorized. Nothing in either one decides whether an agent should be permitted to take it

The third row is the one we see most often and it is the reason this article exists. A team rolls out Microsoft 365 Copilot, security raises oversharing concerns, somebody notices Security Copilot in the price list, and capacity gets approved to answer a risk it has no relationship to. Security Copilot will help your analysts investigate an incident faster. It will not stop Copilot surfacing a payroll file to someone who should never have had read access to the site it lives on. That is a permissions problem, and the fix is Microsoft 365 Copilot security work in Purview: oversharing assessments, sensitivity labels with DLP, and Restricted SharePoint Search as a temporary circuit breaker while permissions get repaired.

Does Security Copilot protect Microsoft 365 Copilot?

No. Security Copilot is an analyst assistant. It reasons over signals your security tools already produce, and it has no enforcement role in the Copilot request path. It does not inspect Copilot prompts, does not decide whether Copilot may read a document, and does not sit between Copilot and Microsoft Graph.

The controls that do govern Microsoft 365 Copilot are ordinary Microsoft 365 controls: the permission model, sensitivity labels, Purview DLP policies scoped to the Copilot location, and Restricted SharePoint Search. Microsoft also runs jailbreak and cross-prompt injection classifiers inside its own service, with a caveat it publishes plainly, that those classifiers "may not be available in all Microsoft Copilot scenarios". None of that is affected by whether you own Security Copilot.

What about the other Copilots?

Two more products share the name and neither belongs in this comparison, though both come up in the same procurement conversation.

  • GitHub Copilot is a developer tool, licensed per seat through GitHub rather than Microsoft 365. Its security story is about agent mode, the coding agent and Copilot CLI acting on repositories, and GitHub documents its own control gaps unusually plainly. We cover that separately in GitHub Copilot security.
  • Copilot Studio is the platform for building custom agents, which is where a Copilot deployment stops answering questions and starts taking actions. That shift is the point at which agent authorization becomes a real requirement. See Copilot Studio security.

The reason to keep these straight is not pedantry about branding. Each product has a different threat model, and a control that covers one covers none of the others. Enterprise managed settings govern GitHub Copilot and have no bearing on Microsoft 365 Copilot. Purview DLP governs Microsoft 365 Copilot and does not reach a GitHub agent running in CI. Assessments that treat "Copilot" as one system routinely conclude that a control is in place when it applies to a different product entirely.

The question neither product answers

Both Copilots are built on an assumption that holds well for assistants and poorly for agents: that the human in front of the screen is accountable for what happens next. Microsoft 365 Copilot returns a draft and a person decides whether to send it. Security Copilot returns an investigation summary and an analyst decides whether to act. In both cases a human is the control.

That assumption stops holding the moment a Copilot Studio agent, a Graph connector or an MCP-connected tool starts taking actions unattended. At that point the meaningful question is not what the assistant may read, it is what it is permitted to do, and whether there is a record of it having done so. Microsoft is explicit that diligence on third-party agents attached to your tenant is yours to perform: check the privacy statement and terms of use of each agent to determine how it will handle your data. That is a fair position for a platform vendor and a thin control for a regulated business, which is why enterprise agent governance and a single audit record across agents tend to land on the roadmap shortly after the first Copilot Studio agent ships.

If you are still mapping the category, the AI security vendor landscape covers who does what, and AI agent hardening covers the controls that apply once agents act on their own.

See the firewall block an attack live.

Drive the Threat Console and watch a real prompt injection get stopped, then put Agentshield in front of your own agents.

Open the console