Share via

What license, subscription, and audit log details are required for Microsoft Security Copilot?

Louis 40 Reputation points
2026-01-27T11:53:55.5333333+00:00

I want to use Microsoft Security Copilot. What license is required and which subscription should we have? Does Security Copilot have audit logs? Is Security Copilot considered a separate workload? In the Security Copilot workload, what record types are available in the audit logs?

Microsoft Copilot | Microsoft Security Copilot
0 comments No comments

Answer accepted by question author

Marcin Policht 90,975 Reputation points MVP Volunteer Moderator
2026-01-27T12:10:23.56+00:00

Microsoft Security Copilot is licensed as a standalone, capacity-based add-on rather than being bundled into an existing Microsoft 365 or Azure security license. To use it, you must have an eligible Azure subscription where Security Copilot capacity is provisioned, and your tenant must already use supported Microsoft security services such as Microsoft Defender, Microsoft Sentinel, Entra ID, or Intune so Copilot has data to reason over. There is no per-user license; instead, you purchase Security Copilot capacity units through Azure, and access is then granted to users via role assignment in the tenant.

Security Copilot does generate audit logs. User interactions, prompts, responses, and administrative actions are audited through Microsoft Purview Audit (Standard or Premium, depending on your tenant licensing). These logs allow you to track who accessed Security Copilot, when it was used, and what type of actions were performed, which supports security investigations and compliance requirements.

Security Copilot is treated as a separate workload in Microsoft Purview auditing. It does not fall under existing workloads like Exchange, SharePoint, or Defender; instead, it has its own dedicated workload classification so that Copilot-specific activity can be filtered, searched, and retained independently.

Within the Security Copilot workload, the audit logs include record types that capture Copilot interaction and management activity. These include events for Copilot prompt submission, Copilot response generation, Copilot session start and end, plugin or data connector usage, and administrative configuration or access changes related to Security Copilot. The exact record type names may evolve, but they are exposed under the Security Copilot workload and are searchable through the unified audit log in Purview.

For more, refer to https://learn.microsoft.com/security-copilot/overview


If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

hth

Marcin

Was this answer helpful?


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.