Back to library
Advanced & governed: Cowork, enterprise automation and agent governanceMedium - IT/security-only use case, not a general staff Copilot feature riskUpdated 3 SeptAI requiredCredits may apply

Use Security Copilot for IT/security investigations

An IT/security team uses Security Copilot agents to support investigations across Defender, Entra, Intune or Purview, while monitoring included compute usage.

Where the action happens

Defender / Entra / Intune / Purview / Security Copilot

Product or feature needed

Security Copilot for eligible Microsoft 365 E5/E7 customers

AI required

Yes

Extra credits

Depends - Microsoft describes included Security Compute Units for eligible E5/E7 customers, with usage/capacity limits

Technical skill

High

Risk level

Medium - IT/security-only use case, not a general staff Copilot feature

Watch-outs for Advanced & governed

  • Cowork has been generally available worldwide since 16 June 2026 for Microsoft 365 Copilot customers, but admins still control discoverability and must enable usage-based billing before users can run tasks.
  • Cowork consumption is measured in Copilot Credits; organisations can set user or group limits and users can check approximate task cost with /cost.
  • UK Cowork does not require Anthropic/Claude. Microsoft separates Cowork access from model availability; if Anthropic is disabled, Cowork users can continue with allowed non-Anthropic models such as GPT models.
  • For UK organisations, model-provider choice should be recorded as a governance/configuration decision because Anthropic availability has separate admin and data-processing considerations.
  • For Work IQ or other connected agent tools, start read-only where possible and enable write operations only for a justified use case with appropriate identity and approval controls.
  • Treat Cowork access like any other temporary or role-based capability: record owner, purpose, limit and review date, and remove access when the user or project no longer needs it.
  • Agent governance becomes more important as shared, action-taking and connected Agents accumulate; maintain an inventory before the estate becomes hard to understand.
  • Use human approval or an equivalent controlled handoff before high-impact actions where the technology supports it, and keep human accountability for regulated AO decisions.
Disclaimer: Always follow your organisation's internal guidance and policies regarding AI usage. The suggestions in this guide have been created to the best of accuracy, but Microsoft licensing, pricing and feature availability change frequently — treat them as a planning baseline, not a procurement quote.

Community feedback

Has your organisation tried this? Confirm whether it's possible, whether it's useful, and share any tips.

0

Confirmed possible

0

Reported not possible

0

Found it useful

0

Not useful

Add your feedback

Used to verify feedback comes from a real organisation. Never displayed publicly.

Is this possible in practice?

Is it useful?

Loading feedback…