Try our new research platform with insights from 80,000+ expert users
Solutions Principal at a educational organization with 11-50 employees
Real User
Top 20
Nov 21, 2025
AI prompts have significantly shortened incident discovery and improved response efficiency
Pros and Cons
  • "Customers can write a prompt and receive all incidents that have happened in the organization, consolidated by the AI engine to help discover findings in approximately ten minutes instead of five hours."
  • "Regarding pricing, it is a bit high, as each time it is discussed with customers, pricing becomes a challenging topic."

What is our primary use case?

Microsoft Security Copilot has been in use for almost a year, integrated with the complete stack that includes M365 and agentic AI plus security. As Microsoft CSP partners, we deploy Microsoft Security Copilot for customers, allowing them to integrate their data with Microsoft Sentinel and other technologies to discover any issues that have occurred in the organization. Customers can write a prompt and receive all incidents that have happened in the organization, consolidated by the AI engine to help discover findings in approximately ten minutes instead of five hours.

Every engagement with customers starts with a conversation about secure score, where we assist in assessing anything related to identity or data. If there is a lack on the data side, we help them with Microsoft Purview, and for identity issues, we have Defender for Identity, enabling the necessary tools. When discussing Purview, it now has all the AI infusion that enhances its collaboration with the overall suite, effectively benefiting the customer.

The Security Copilot standalone portal is not used on a day-to-day basis by me, as the team manages it, but it is understood to be working well. I am more hands-on with M365 and Copilot Studio at a day-to-day productivity level, while the team is actively enabling Microsoft Security Copilot for customers.

The options for scalability with Microsoft Security Copilot are endless, and the goal is to encourage all employees to use this engine. By employing agents with agentic AI, tasks that typically take hours are reduced to minutes.

What is most valuable?

The way Microsoft Security Copilot integrates with the whole ecosystem is valuable, as it works seamlessly with Microsoft Sentinel and other frameworks. The data is obviously important, and AI itself will not have any value without the specific data lying in the underlying systems, making its integration with all the incoming information valuable.

The experience of the team using Microsoft Security Copilot has been amazing, as there are many customization options available. It integrates into the whole system, becoming the first layer of interaction for customers to figure out what is happening. Previously, customers needed to run queries to find specifics like event ID 1903, but now it is just a single prompt to check how many machines are affected. The way it helps customers discover issues within their organization is truly valuable.

Microsoft Security Copilot has helped us and our clients reduce the mean time to resolution significantly.

Microsoft Security Copilot really helps the overall NLP picture.

Microsoft Security Copilot can search both the internet and the data inside your organization using the Microsoft 365 Graph. This grants users access to powerful insights that would normally take hours to find, from a single prompt.

What needs improvement?

The flexibility to have more integrations with other available security tools would improve Microsoft Security Copilot, particularly with third-party integrations to enhance ease.

Regarding pricing, it is a bit high, as each time it is discussed with customers, pricing becomes a challenging topic. This is an area worth investigating for potential improvement.

For how long have I used the solution?

I have been an MCT for more than seven or eight years.

Buyer's Guide
Microsoft Security Copilot
January 2026
Learn what your peers think about Microsoft Security Copilot. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.

What do I think about the stability of the solution?

Although there was a recent CrowdStrike outage, things have been smooth, and there have not been any significant issues with Microsoft Security Copilot.

What do I think about the scalability of the solution?

The options for scalability with Microsoft Security Copilot are endless, and the goal is to encourage all employees to use this engine.

How are customer service and support?

The option to open support tickets with Microsoft's customer service and technical support is available, and that process is utilized.

The experience with Microsoft support varies depending on the level of the ticket. Unified support makes more sense, but normal support has been rough for some customers.

How would you rate customer service and support?

Neutral

What was our ROI?

Being a Microsoft partner allows for Microsoft Security Copilot licenses to be received for free, which makes stating an ROI challenging. However, from the customer's perspective, this would likely make more sense as a question.

What other advice do I have?

The deployment experience of Microsoft Security Copilot would need to be confirmed with the team, but overall, it has really improved daily productivity as the team leverages the RAG engine for emails and improved operations.

Many organizations encountered are using ChatGPT and the paid version, and the strongest pitch lies in the seamless transition between work and web profiles. The review rating for this product is eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Csp partnership
Last updated: Nov 21, 2025
Flag as inappropriate
PeerSpot user
reviewer2700648 - PeerSpot reviewer
Security engineer at a university with 10,001+ employees
Real User
Top 10
May 3, 2025
Facilitates quick document creation but requires independent decision-making improvements
Pros and Cons
  • "What I appreciate most about Microsoft Security Copilot is that it fixes all grammar issues, as I'm not particularly strong in grammar."
  • "The issue with all AIs, not just Microsoft Security Copilot, is that when I do something and feel it's wrong, I need a tech lead to verify."

What is our primary use case?

My use cases involve writing rough emails and general documents using Microsoft Security Copilot.

Microsoft Security Copilot benefits my company by making my work easier. I used to write documentation, and it made my work much easier while watching TV.

I don't enjoy writing documents, and given that Microsoft Security Copilot can write documents in a matter of seconds, that helped me significantly. I would say about 10% to 15% time was saved.

What is most valuable?

What I appreciate most about Microsoft Security Copilot is that it fixes all grammar issues, as I'm not particularly strong in grammar.

The AI-driven guidance and analysis of Microsoft Security Copilot has been great, but I need to do more use cases to provide a complete answer.

Microsoft Security Copilot for Security has impacted my team's ability to analyze security across different areas, such as identities, devices, and clouds effectively, but I will consult with my team's IAM and software departments for more details.

The task automation feature of Microsoft Security Copilot has been super useful for our team's workflow.

The integration of Microsoft Security Copilot with other Microsoft solutions has had a positive impact on my company's security posture because it's integrated into the operating system. Other LLM agents require downloading specific tools, but Microsoft shipped Copilot directly, which is the main reason I use it.

Microsoft Security Copilot has good integration with other Microsoft products.

Microsoft Security Copilot has helped reduce my company's mean time to resolution by allowing me to focus more on technical problems rather than writing documentation.

While I don't know the exact metrics, I estimate the reduction is around 20% to 25%.

What needs improvement?

To make it a perfect 10, Microsoft Security Copilot would need to take decisions independently and reduce hallucination.

The issue with all AIs, not just Microsoft Security Copilot, is that when I do something and feel it's wrong, I need a tech lead to verify.

For how long have I used the solution?

I have been using Microsoft Security Copilot for about a year.

What do I think about the stability of the solution?

Microsoft Security Copilot has demonstrated good stability and reliability in my experience.

What do I think about the scalability of the solution?

The scalability of Microsoft Security Copilot has been excellent since we have a good amount of people in our office and all of us use it.

How are customer service and support?

I haven't needed to contact customer service yet, which I consider a good sign as the tool performs very effectively.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I have used ChatGPT for a while to write documents, but Microsoft Security Copilot seems superior.

How was the initial setup?

We are deployed on-premises.

What about the implementation team?

My team experiences issues with any tool we implement, but the issues with Microsoft Security Copilot are manageable and the tool performs very well.

What was our ROI?

The biggest return on investment for me when using Microsoft Security Copilot is its ability to write my documents.

What's my experience with pricing, setup cost, and licensing?

I am not authorized or trained to know about the pricing, setup costs, and licensing. The tool was provided to me, and I have found it to be great.

Which other solutions did I evaluate?

As a Security Engineer, choosing other solutions before selecting Microsoft Security Copilot is not within my domain as it falls under leadership decisions.

I am not aware if my company considered using another product, though they probably evaluated other tools.

What other advice do I have?

The value of Microsoft Security Copilot is evident since I don't have to use Grammarly or other tools.

On a scale of 1 to 10, I would rate Microsoft Security Copilot a 7.5.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 3, 2025
Flag as inappropriate
PeerSpot user
Buyer's Guide
Microsoft Security Copilot
January 2026
Learn what your peers think about Microsoft Security Copilot. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Bantu Kumar - PeerSpot reviewer
Senior Technical Director at a computer software company with 10,001+ employees
Real User
Top 5Leaderboard
May 7, 2025
Integration options and dataset compatibility have matured sufficiently
Pros and Cons
  • "I would rate Microsoft Security Copilot nine out of ten."
  • "Currently, Microsoft Security Copilot is not very intuitive. I still need to figure out how to operate some features, so more intuitive methods would be beneficial."

What is our primary use case?

I am using Microsoft Security Copilot primarily for generative AI security.

What is most valuable?

Initially, Microsoft Security Copilot did not meet my expectations, but it has now reached a good level of maturity. I am satisfied with the solution as it offers integration with other systems, data mapping options, and compatibility with any dataset in our databases.

What needs improvement?

Currently, Microsoft Security Copilot is not very intuitive. I still need to figure out how to operate some features, so more intuitive methods would be beneficial.

For how long have I used the solution?

I have been using Microsoft Security Copilot for about a year.

How are customer service and support?

I am generally satisfied with the technical support from Microsoft. However, they tend to be quite rigid with documentation and often redirect me to look at documents instead of directly assisting me, which can cause delays. Direct interaction with their professional services team could address this issue, but it is challenging to speak with that team.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

I was previously using UiPath products but am now mostly using Microsoft Power Platform.

What's my experience with pricing, setup cost, and licensing?

Pricing has not been a problem for me. Most of my customers are already within Microsoft stack, and the pricing is mostly well accepted.

Which other solutions did I evaluate?

I mostly use Microsoft Power Platform, which includes Power Apps and Power Automate.

What other advice do I have?

I would rate Microsoft Security Copilot nine out of ten. As a gold partner of Microsoft, I have noticed that professional services can improve their direct contact with developers to avoid delays.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: May 7, 2025
Flag as inappropriate
PeerSpot user
reviewer2778582 - PeerSpot reviewer
Manager at a comms service provider with 1,001-5,000 employees
Real User
Top 5Leaderboard
Nov 21, 2025
Triaging security incidents has become faster and helps prioritize critical fixes to boost product sales
Pros and Cons
  • "My thoughts on the integration of generative AI in it for incident response are that it saves us time and money; before it would take an hour to triage an incident to fix it, now it takes maybe ten to fifteen minutes."
  • "I think it can be improved by having more users feeding it information because the more things it pulls from, the more we teach it and it builds on it."

What is our primary use case?

My main use case is to design our activations to sell the products.

What is most valuable?

The feature I like the most about Microsoft Security Copilot is being able to triage and know what is the most important thing to fix for deficiencies or things that are just not effective.

I can provide an example of how it benefits the company: we sell more products. It helped me reduce the mean time to resolution very quickly. I would say it reduces the mean time to resolution by maybe fifteen minutes. Before, the time to resolution was approximately an hour.

What needs improvement?

I think it can be improved by having more users feeding it information because the more things it pulls from, the more we teach it and it builds on it. More users means more ways to fix and build upon it.

For how long have I used the solution?

I have been working in my current field for two to three years.

What do I think about the stability of the solution?

I did not face any challenges at some point; I did not have crashes or downtime. I would say it is very reliable and stable. It is very reliable and very easy to use.

Which solution did I use previously and why did I switch?

I did not think of other solutions before choosing this one.

How was the initial setup?

I would describe the experience deploying it as very easy. I think they give us all the tools, they give us the support, they give us the program managers, the product managers, and then it is easy to deploy.

What was our ROI?

I can say that I have seen a return on investment from having it.

What's my experience with pricing, setup cost, and licensing?

I do not have any experience with the pricing, setup cost, and the licensing.

What other advice do I have?

I have been using Microsoft Security Copilot for two to three years.

I am not using it as a standalone portal to build, test, deploy and deploy my own Microsoft Security Copilot agent.

My view on the effectiveness of Microsoft Security Copilot natural language interface is that each year it gets better. It is pretty effective, but I think each year it gets better in defending more and more threats because every year threats get larger and bigger. And so it only gets better. I know we are releasing new things at the conference this year that will even be better.

I have not used the agentic AI feature to automate security, but I know our agents work.

My thoughts on the integration of generative AI in it for incident response are that it saves us time and money. Before it would take an hour to triage an incident to fix it. Now it takes maybe ten to fifteen minutes.

I think I have used it to discover the autonomous Microsoft Security Copilot agent.

I give this product a rating of ten out of ten. I want to add: go buy Microsoft Security Copilot.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Nov 21, 2025
Flag as inappropriate
PeerSpot user
Surcel Stefan - PeerSpot reviewer
Head of Industrial Agency at a real estate/law firm with 51-200 employees
Real User
Top 10Leaderboard
Apr 6, 2025
Summarizing discussions and emails effectively saves significant processing time
Pros and Cons
  • "I would rate Microsoft Security Copilot ten points on a scale of one to ten because we are very satisfied with it."
  • "It would be beneficial if Microsoft Security Copilot could work across multiple systems."

What is our primary use case?

We are using Microsoft Security Copilot to summarize the discussions we have during calls. We also use it to rephrase different emails, and for PowerPoint presentations to reorder slides and manage information. We are exploring ways to extend its capabilities.

What is most valuable?

Microsoft Security Copilot's ability to understand and summarize information, particularly emails, is highly valuable. As I am managing a larger department, it allows me to receive summaries of emails, which significantly saves time when dealing with numerous unread emails. Additionally, the capability to generate input and generate information for use in presentations is very useful. Another valuable feature is its seamless integration with other Microsoft solutions, enhancing the efficiency of our operations.

What needs improvement?

It would be beneficial if Microsoft Security Copilot could work across multiple systems. For example, I would like it to automatically transfer information from Outlook to PowerPoint. At the moment, this feature is not available.

For how long have I used the solution?

We have been using Microsoft Security Copilot for approximately one month to one and a half months. It is a fairly new implementation for our company.

What do I think about the stability of the solution?

Microsoft Security Copilot is stable at the moment. We have not experienced any glitches, latency issues, or performance problems.

What do I think about the scalability of the solution?

We are an enterprise with around eighty people, and we have been able to offer Microsoft Security Copilot to all of them simultaneously. It seems to be quite easy to scale.

How are customer service and support?

I do not handle IT systems directly, but we have been using Microsoft products for some time without major issues. I assume the support is good as we have never encountered significant problems. When issues arise, our IT personnel manage the situation effectively.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We previously used Salesforce but found it challenging to input all necessary information into the platform. My team decided to switch to a simpler solution, a shared Excel file, which is more accessible for our sales team. We plan to explore a new solution called Drago.

How was the initial setup?

I presume the installation of Microsoft Security Copilot was very easy as my IT team handled it. It appears that one person managed the installation efficiently.

What about the implementation team?

Our IT team handled the installation of Microsoft Security Copilot. One person was sufficient for the task, and they managed it well.

What was our ROI?

While I haven't seen financial savings, the time saved for making summaries and understanding information through Microsoft Security Copilot is significant. For instance, the summary capability saves me fifty percent of the processing time on emails.

What's my experience with pricing, setup cost, and licensing?

I did not handle the acquisition or tender for Microsoft Security Copilot, so I cannot compare the pricing to other products. However, the assistance it provides us suggests that it is worth the price.

What other advice do I have?

I would rate Microsoft Security Copilot ten points on a scale of one to ten because we are very satisfied with it. It meets our needs without significant issues.

Which deployment model are you using for this solution?

Other

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Darwin Lopez - PeerSpot reviewer
System Administrator at a performing arts with 1,001-5,000 employees
Real User
Top 10Leaderboard
Dec 17, 2024
Helps us understand and manage security warnings, but I often need to reword prompts several times
Pros and Cons
  • "Microsoft Copilot for Security helps us understand security warnings. It allows me to understand global user and device activity, and this feature keeps all critical information in one place."
  • "The solution does exactly what I need, but sometimes the prompts required to get the needed information need to be rephrased several times. This might improve as I become more accustomed to using the system."

What is our primary use case?

I use Microsoft Copilot for Security to understand and manage security warnings and scores. It helps me make sense of these scores and allows me to take action to improve them.

How has it helped my organization?

Microsoft Copilot for Security gives us flexibility. We're a small organization, so everyone wears many hats, and security is everyone's job. It allows anyone to engage with the system without extensive prior knowledge and ask questions, making the process actionable and understandable.

What is most valuable?

Microsoft Copilot for Security helps us understand security warnings. It allows me to understand global user and device activity, and this feature keeps all critical information in one place. 

It helps us process security information by taking complex data from different areas of Defender and spitting it out in an easy-to-understand format. The solution's AI-driven guidance and analysis point us to exactly what we need to do. It asks us to enable or disable policies, so we create internal conversations about what we want to do in our security.

What needs improvement?

The solution does exactly what I need, but sometimes the prompts required to get the needed information need to be rephrased several times. This might improve as I become more accustomed to using the system.

For how long have I used the solution?

I have been using Microsoft Copilot for Security for about three months.

What do I think about the stability of the solution?

The stability is generally good, though there can be minor delays.

What do I think about the scalability of the solution?

The system is highly scalable, and it provides many possibilities for handling diverse tasks.

How are customer service and support?

Sometimes it takes some time to get responses, but overall it's satisfactory.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was simple, involving assigning licenses to users.

What about the implementation team?

I used a reseller. Our experience with CDW was very smooth, allowing us to obtain licenses as needed.

What was our ROI?

Microsoft offers good incentives for nonprofits. While we pay the full price for some licenses, the benefits have been clear in reducing resolution times and increasing efficiency.

What's my experience with pricing, setup cost, and licensing?

Our nonprofit organization benefits from Microsoft's incentives, though we pay full price for certain licenses like the Copilot license.

What other advice do I have?

I rate Microsoft Copilot for Security seven out of 10. We've had it for three months, so maybe it has some features I'm unaware of. Sometimes, you have to reword the prompts three or four times before getting exactly what you need. It might improve with me getting better at asking and Copilot understanding what I'm asking for.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2595939 - PeerSpot reviewer
Senior Application Engineer at a computer software company with 1,001-5,000 employees
Real User
Top 20
Nov 27, 2024
Has made our security analysis easier because all the data is ingested into one place
Pros and Cons
  • "The most valuable feature of Microsoft Copilot is the interactive chat, which allows me to interact with Copilot directly and get responses quickly. This consolidates our efforts into one place without the need to access multiple resources."
  • "It would be beneficial if Copilot's security features were available to roles other than just the top security personnel. Other roles could use some of the functions, perhaps with limited access, allowing for greater flexibility within an organization."

What is our primary use case?

I use Microsoft Copilot for tracking down security incidents and making the process less complex. It allows me to figure out where each incident originates and consolidates everything into one place when an incident occurs.

How has it helped my organization?

The solution reduces the time needed to get what you want, as well as the time needed to investigate and resolve issues. Copilot has made our security analysis easier because all the data is ingested into one place. The data could be all over the place. If you have a data dump, you can get all the logs and make sense of them. 

Sometimes, the data logs come in sporadically and aren't easily understood by the naked eye. Copilot organizes it all and spits out something comprehensible. It's especially helpful for a smaller team, so it can handle more tickets.

What is most valuable?

The most valuable feature of Microsoft Copilot is the interactive chat, which allows me to interact with Copilot directly and get responses quickly. This consolidates our efforts into one place without the need to access multiple resources. 

What needs improvement?

It would be beneficial if Copilot's security features were available to roles other than just the top security personnel. Other roles could use some of the functions, perhaps with limited access, allowing for greater flexibility within an organization.

For how long have I used the solution?

I have been using Microsoft Copilot since it became available, which is a little over a year ago.

What do I think about the stability of the solution?

I would rate the stability 10 out of 10. It has proven to be very stable.

What do I think about the scalability of the solution?

I am not sure about the scalability as we have not scaled it enough to assess properly.

How are customer service and support?

I rate Microsoft support seven out of 10. The customer service is hit or miss, depending on the person you get. Sometimes, the support is excellent, while it can be less satisfactory at other times.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was straightforward.

What was our ROI?

I'm unaware of what it costs, but I believe Copilot has shown its value because they haven't gotten rid of it. 

What other advice do I have?

I rate the Copilot for Security nine out of 10. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Manager II, Advanced Analytics at a healthcare company with 1,001-5,000 employees
Real User
Top 10
Dec 18, 2024
The auditing capabilities enable us to monitor and easily recognize unauthorized data access attempts
Pros and Cons
  • "One of the most valuable features of Microsoft Copilot for Security is its auditing capabilities, which allow us to monitor and easily recognize unauthorized data access attempts."
  • "One area for improvement is ensuring that personal information is not exposed through Copilot. For example, salary information of executives should remain confidential. Currently, I do not see this feature. Additionally, there should be better natural language processing to eliminate the need for prompt engineering."

What is our primary use case?

We are a healthcare organization building a platform for everyone that's secure. Microsoft Copilot for Security helps us ensure personally identifiable information (PII) and personal health information (PHI) aren't exposed. We use it in patient care in all our hospitals, clinics, and pharmacies. 

How has it helped my organization?

The use of Microsoft Copilot for Security has reduced costs by allowing many operations to be automated with minimal supervision. It has also improved our team's ability to analyze data security for PHI and PII, which is a critical area for us.

What is most valuable?

One of the most valuable features of Microsoft Copilot for Security is its auditing capabilities, which allow us to monitor and easily recognize unauthorized data access attempts.

Copilot enables us to implement self-service options for our data side. We do lots of analytics independently. We can enable our organization to do self-service mode and ask questions about our data using Copilot. It's improving our productivity. That's our main focus.

What needs improvement?

One area for improvement is ensuring that personal information is not exposed through Copilot. For example, salary information of executives should remain confidential. Currently, I do not see this feature. Additionally, there should be better natural language processing to eliminate the need for prompt engineering.

For how long have I used the solution?

We have been trying to use Microsoft Copilot with Power BI for the past year.

What do I think about the stability of the solution?

Microsoft Copilot for Security is excellent in terms of stability.

What do I think about the scalability of the solution?

The solution is scalable, which is a great attribute.

How are customer service and support?

The customer service and technical support are great and very knowledgeable. They consistently bring value to our organization.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We evaluated ThoughtSpot from an analytics perspective, which is a good tool, but we decided to go with Microsoft Copilot due to its wide variety of features in comparison to competitors.

How was the initial setup?

We have only conducted a proof of concept rather than a full implementation.

What about the implementation team?

We have Microsoft representatives who assist us by bringing subject matter experts to implement new solutions.

What was our ROI?

Copilot saves time. It reduces our development time by about 30 percent because auto-generated methods and text queries help us tremendously. We are looking forward to the return on investment with Microsoft Copilot in the future as we move forward with AI, developing our own model for patient care and customer support.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing are much better with Microsoft Copilot compared to competitors.

What other advice do I have?

I rate Microsoft Security Copilot nine out of 10. We have not explored all the features yet, and there might be some drawbacks or costs we are unaware of.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user