← All posts

Operational Notes on Microsoft Security Copilot Agents in Defender XDR and Microsoft Entra ID

Practical SOC observations on Security Copilot agents — how they're deployed, how they consume Security Compute Units, the agentic identities and Unified RBAC roles they create, where to monitor usage, and KQL for reviewing agent activity.

I originally published this article on the Microsoft Tech Community.

Microsoft Security Copilot is now more visible inside day-to-day security operations, especially through embedded experiences and agent-based workflows across Microsoft Defender XDR, Microsoft Entra ID, Microsoft Intune, and Microsoft Purview.

Instead of looking at Security Copilot only as a standalone prompt interface, SOC and identity teams should understand how Security Copilot agents are deployed, how they consume Security Compute Units, how they appear in operational workflows, and where activity can be monitored. This post summarizes practical observations from a security operations perspective, focusing on Defender XDR, Entra ID, usage monitoring, and KQL-based activity review.

Security Copilot agents across Microsoft Defender XDR and Entra ID

Licensing & capacity units

Requirements: eligible Microsoft security licensing (typically Microsoft 365 E5).

Security Compute Units (SCUs):

Included capacity: organizations with 1,000 Microsoft 365 E5 licenses receive 400 included SCUs, shared across the tenant in a common capacity pool.

Scaling: SCU capacity can be scaled dynamically based on operational requirements and workload demand.

Data retention: Security Copilot session and interaction data without active SCU-backed retention is typically retained for 90 days.

Security Copilot agents — Microsoft Defender

Security Alert Triage Agent (Preview)

Threat Hunting Agent

Threat Intelligence Briefing Agent

Security Analyst Agent

Dynamic Threat Detection Agent (Preview)

Incidents handled by the Security Alert Triage Agent:

Incidents handled by the Security Alert Triage Agent

Incidents handled by the Security Alert Triage Agent (continued)

Alerts created by the Dynamic Threat Detection Agent:

Alerts created by the Dynamic Threat Detection Agent

Alerts created by the Dynamic Threat Detection Agent (continued)

Execution of the Threat Hunting Agent:

Threat Hunting Agent execution

Threat Hunting Agent execution (continued)

View agents in use (security.microsoft.com/security-copilot/agents):

Agents in use

Agents in use (continued)

View Unified RBAC custom roles (security.microsoft.com/mtp_roles):

Unified RBAC custom roles created by the agents

Unified RBAC custom roles created by the agents (continued)

View Security Copilot user identities in Microsoft Entra ID:

Security Copilot agentic identities in Microsoft Entra ID

Note: CloudAppEvents activity logs are produced only from the following agents:

Security Copilot agents — Microsoft Entra ID

Usage monitoring

Sign in to the Security Copilot portal with a Global Admin account and navigate to securitycopilot.microsoft.com/usage-monitoring. Reference: Microsoft Learn — Manage Security Copilot usage.

Logging activity

Copilot agents management:

CloudAppEvents
| where ActionType contains "CopilotAgent"
| extend AgentName = RawEventData.AgentName
| extend Workload = RawEventData.Workload
| extend ResultStatus = RawEventData.ResultStatus
| project TimeGenerated, ActionType, ResultStatus, AgentName, Application, Workload

All Copilot workload data:

CloudAppEvents
| extend Workload = RawEventData.Workload
| where Workload == "Copilot"
| summarize EventCount = count() by ActionType, AccountDisplayName