Understanding the Cost Model
Microsoft Security Copilot consumes Security Compute Units based on usage. As of November 2025, E5 customers receive an allocation of 400 SCUs per 1,000 licences, up to a maximum of 10,000 SCUs per month. This is a significant entitlement, but it is not unlimited.
The cost question becomes important when working with an MDR provider. If your provider uses Microsoft Security Copilot on your behalf to conduct investigations, you pay for that consumption. Heavy usage by a provider running automated queries could consume your SCU allocation quickly, creating unexpected costs or requiring additional licensing.
This is why the integration model matters. You need clarity on who uses Microsoft Security Copilot, for what purposes, and how consumption is managed. The goal should be maximising your existing investment, not creating cost increases through provider usage for their benefit.
A Vendor-Agnostic Approach
At Bridewell, we have deliberately designed our approach to avoid consuming customer Microsoft Security Copilot resources for our core investigation work. Our orchestration platform and AI capabilities are built on Azure infrastructure for control and privacy, but they do not depend on Microsoft Security Copilot. This means our investigations do not consume your SCU allocation.
This vendor-agnostic approach serves multiple purposes. It ensures our customers are not liable for our AI usage. It maintains our ability to work consistently across customers with different licensing positions. And it preserves the glass-box transparency that co-managed models require, with our own AI infrastructure where we control the architecture and can explain exactly how it works.
Microsoft Security Copilot becomes an enrichment layer rather than a core dependency. This positioning ensures you get value from both investments without conflict or cost overlap.
Where Microsoft Security Copilot Adds Value
In a co-managed model, Microsoft Security Copilot is most valuable as a tool for your analysts rather than your provider's analysts. Your team can use it for ad-hoc investigation queries, extending analysis beyond what the managed service covers. Promptbooks enable repeatable investigation workflows tuned to your environment. Natural language threat hunting lets analysts explore hypotheses without writing complex queries.
The November 2025 updates introduced twelve new Microsoft Security Copilot agents across Defender, Entra, Intune, and Purview. These include alert triage agents, threat intelligence prioritisation, and missed threat detection. For organisations with internal security teams working alongside an MDR provider, these agents can extend your capability without requiring your provider to operate them on your behalf. Find out more from the Microsoft announcement.
Customers using our Cybiquity platform will be able to integrate Microsoft Security Copilot as an enrichment source. When your analysts investigate through Cybiquity, they can pull Copilot insights to enhance and extend the investigation, which can be also integrated into a Customer ITSM or workflow. The platform workflows connect to Copilot without requiring Bridewell analysts to use your SCU allocation. This model ensures you control your Microsoft Security Copilot usage while still benefiting from integration with managed services.
Integration Considerations
When evaluating how to integrate Microsoft Security Copilot with managed security services, several questions help clarify the right model for your organisation.
First, who will be the primary users? If your internal team will use Microsoft Security Copilot extensively, optimising for their workflows makes sense. If you rely primarily on your MDR provider, you need a provider whose approach does not depend on consuming your allocation. When using agents and workflows with a service provider, be conscious of impacts on workflows that may cause issues in ownership and create unseen risks.
Second, how will consumption be tracked? Visibility into SCU usage helps you understand value and avoid surprises. Microsoft provides usage dashboards, but understanding what is driving consumption requires operational insight.
Third, what is the boundary between Microsoft Security Copilot and other AI capabilities? If your MDR provider has their own AI tools, clarity on which capabilities come from which source helps you evaluate value and avoid duplication.
Maximising Your Investment
The goal with Microsoft Security Copilot integration is simple: maximise the value of your existing licensing investment without creating cost conflicts with your managed service arrangement. This requires a provider whose model is designed to complement rather than consume your Microsoft entitlements.
Microsoft Security Copilot is a powerful tool, and the recent updates have significantly expanded its capabilities. For organisations with E5 licensing and a co-managed security model, the question is not whether to use it but how to integrate it effectively. With the right approach, it becomes an extension of your security capability that delivers value to your team while your managed service provider brings their own AI capabilities to the partnership.