Knowledge for better technology decisions
Knowledge BaseAI FinOps & Token Economics

AI FinOps · Microsoft Security Copilot

What are Security Compute Units—
and how many tasks can one SCU really handle?

Microsoft Security Copilot is not metered by prompts, users, or tokens. It uses compute capacity measured in Security Compute Units. That is why there is no credible universal answer such as ‘one SCU equals ten tasks’. This guide explains when SCUs are consumed, which capacity models apply, and how to estimate real demand with evidence.

An SCU is compute capacity—not a fixed number of tasks.

Security Copilot consumes SCUs when a Security Copilot workload actually runs. The amount depends on scope, complexity, plugins, data, and automation.

  1. 01SCUs apply to Microsoft Security Copilot—not Microsoft 365 Copilot or Copilot Studio Credits.
  2. 02Prompts, embedded features, promptbooks, agents, and automated calls can consume SCUs.
  3. 03Microsoft 365 E5/E7 may include a monthly SCU pool; other customers provision hourly capacity.
  4. 04Tasks per SCU must be calculated from the measured average of a specific workload.

From licence to compute capacity

Security Copilot supports security work.
SCUs power its execution.

Security Copilot is Microsoft’s generative and agentic AI solution for security and IT teams. It is available in its own portal and embedded in Microsoft Defender, Entra, Intune, Purview, and other security experiences. Entitlement opens access; SCU capacity enables the actual processing.

01

Four concepts that should not be confused

Licence, access, task, and compute describe different layers. Separating them is essential for understanding cost and capacity.

PRODUCT

Microsoft Security Copilot

An AI-powered security solution for analysis, summaries, investigations, queries, and agentic automation—standalone and embedded.

CAPACITY

Security Compute Unit

A unit of compute power used to run Security Copilot workloads reliably. An SCU measures compute, not the business value of a task.

EXECUTION

Prompt, promptbook, agent, primitive

Microsoft distinguishes single prompts, multi-step promptbooks, agents, and service-side AI calls that may run without direct user interaction.

NOT THE SAME

Not tokens and not Copilot Credits

SCUs are a separate capacity and billing model for Security Copilot. They should not be equated with LLM tokens or Copilot Studio Credits.

Rule of thumb:

The licence determines who—or which tenant—may use Security Copilot. The SCU determines how much Security Copilot compute is available for execution.

02

SCUs are consumed when a Security Copilot workload runs

The key question is not only where a feature appears, but whether it invokes Security Copilot. Microsoft specifically identifies these consumption paths:

STANDALONE

Prompts in the Security Copilot portal

An analyst starts an investigation, asks for a script explanation, or requests relevant threat intelligence.

Manual or automated invocation
EMBEDDED

Embedded security features

Security Copilot is invoked directly from Defender, Entra, Intune, Purview, or another supported Microsoft experience.

For example, an incident summary
AGENT

Microsoft and partner agents

An agent performs repeatable or autonomous security steps. Running agent work uses SCUs like other Security Copilot capabilities.

Interactive, scheduled, or event-driven
AUTOMATION

Promptbooks, Logic Apps, and connectors

Multi-step or API-oriented calls can run automatically. The invoking service may generate separate charges as well.

Every actual Security Copilot call counts

For custom security agents, the lifecycle matters

According to current Microsoft developer documentation, not every builder action uses compute. Some of the documented agent capabilities are still preview information.

Create an agent in the builderNo

Creating or generating the agent does not yet start an SCU workload.

Test the agentYes

Testing executes the workload and therefore consumes SCUs.

Publish the agentNo

The publication action itself does not consume SCUs.

Run the published agentYes

Each real agent execution requires Security Copilot compute.

Remember adjacent costs:

SCUs cover Security Copilot compute. Prerequisites and connected products—such as Microsoft Sentinel, Azure Logic Apps, or a paid partner-agent licence—may be charged separately.

03

Included, provisioned, or overage—which model applies?

Whether SCUs must be purchased manually depends mainly on the Microsoft 365 licence and tenant activation.

M365 E5 / E7

Included monthly pool

For eligible and enabled Microsoft 365 E5/E7 tenants, Microsoft provides 400 SCUs per month for every 1,000 paid user licences—scaled proportionally and capped at 10,000 SCUs per month.

  • Shared tenant-wide across users and experiences
  • No hourly billing for the included pool
  • Monthly reset with no rollover
  • Phased tenant activation must have completed
PROVISIONED

Hourly baseline capacity

Customers without included E5/E7 capacity provision at least one SCU. For an introductory exploration, Microsoft recommends three provisioned SCUs with unlimited overage, then adjusting from actual usage.

  • Allocated in advance
  • Refreshes each full billing hour
  • Unused units expire at the end of the hour
  • Best suited to predictable baseline demand
OVERAGE

Usage-based peak capacity

In the provisioned model, overage is used once baseline capacity is exhausted. It can be capped per hour or left unlimited and is billed to one decimal place from actual usage.

  • Consumed only when used
  • Absorbs unexpected peaks
  • A limit protects budget but can stop work
  • Cannot be shared across workspaces
What happens when no capacity remains?

When available provisioned capacity and configured overage are 100% consumed, Security Copilot may reject further requests. With hourly provisioned capacity, capacity becomes available again in the next full billing hour. For the E5/E7 inclusion pool, Microsoft describes a separate pay-as-you-go extension that is still being rolled out; verify availability in the tenant.

04

How many tasks can one SCU handle?

Microsoft deliberately provides no fixed task rate: every prompt and workflow can differ in complexity. A short summary, a multi-step investigation, and an autonomous agent are not equivalent units of work.

DIRECT ANSWER

One SCU has no fixed task count. Only after measuring the average SCU consumption of a specific, repeatable workload can you derive a defensible number of runs.

Planning formulaPossible similar runs = available SCUs ÷ measured SCUs per run

What Microsoft’s official numerical example demonstrates

Microsoft uses the following values to explain its capacity and billing models. They are an illustration—not a universal rate card for prompts or features.

Example workloadExample durationExample consumptionPure arithmetic per 1 SCU
Execute a prompt40 seconds3.0 SCUs0.33 such runs—one complete run requires 3 SCUs in this example
Summarise an incident10 seconds0.5 SCU2 such runs
Why 0.5 SCU does not mean ‘every summary costs 0.5’:

Scope, context, plugins, data volume, model steps, and workflow may vary. Use the example only to understand the arithmetic; planning and budgeting must rely on consumption in your own tenant.

05

How provisioned SCU billing works

With hourly provisioned capacity, the allocated amount is charged for each fixed clock hour—not only what was used. Overage, in contrast, follows measured extra consumption.

BASE

Provisioned SCUs

Charged for each billing hour. A change partway through an hour can trigger another full capacity block.

USED

Actual consumption

Shows how much compute workloads really used. Unused provisioned capacity does not carry into the next hour.

SPIKE

Overage SCUs

Used only after the baseline is exhausted and billed to one decimal place from consumption—up to the configured limit.

OFFICIAL MICROSOFT BILLING EXAMPLE

Four SCUs provisioned, 3.5 SCUs consumed

4

provisioned SCUs in the hour

3.5

SCUs actually consumed

$16

4 × $4 in Microsoft’s example

The unused difference of 0.5 SCU is not credited.

If consumption exceeded four SCUs, overage would be added—if configured. Microsoft’s current USD illustration uses $6 per consumed overage SCU.

Pricing shown on Microsoft’s US page on 13 August 2026. Microsoft labels these figures as estimates; agreement, region, currency, purchase date, and tax may change the actual price.
06

A monthly pool becomes a task plan only when measurements exist

An organisation with 1,000 paid Microsoft 365 E5/E7 user licences and enabled inclusion receives 400 SCUs per month under Microsoft’s model. The pool is shared across all eligible Security Copilot experiences in the tenant.

ASSUMPTION—MEASURED IN THE ORGANISATION’S OWN DASHBOARD

A recurring workflow averages 0.8 SCU per run

Other prompts, agents, and embedded features have already consumed 120 SCUs in the month. That leaves 280 SCUs for the workflow being planned.

400

included SCUs per month

−120

other consumption

280

remaining SCUs

350

possible similar runs at 0.8 SCU

280 SCUs ÷ 0.8 SCU per run = 350 comparable runsThis is a planning calculation, not a Microsoft consumption guarantee. Production automation must also allow for peaks, failed runs, quality checks, growth, and concurrent demand.
07

Plan SCU demand in six steps

Microsoft’s Capacity Calculator provides a starting point. Reliable sizing requires actual usage, an hourly demand profile, and the business outcome.

  1. 01

    Inventory workloads

    Record standalone use, embedded features, promptbooks, agents, Logic Apps, and partner solutions with an owner and purpose.

  2. 02

    Pilot narrowly

    Test representative tasks and peak periods instead of assuming a universal task rate.

  3. 03

    Export usage

    Use up to 90 days of dashboard data by prompt, promptbook, agent, primitive, user, plugin, and experience.

  4. 04

    Separate baseline and peak

    Align provisioned capacity to stable demand and size overage deliberately for volatility.

  5. 05

    Balance budget and service

    A low overage limit protects spend but can interrupt a critical investigation.

  6. 06

    Measure value and quality

    Track time saved, quality, risk reduction, failure rate, and outcome—not only SCUs per run.

A more useful metric:

SCU per successfully completed security outcome is more meaningful than SCU per prompt. A cheap prompt that produces no usable result is not efficient.

An SCU is not a bundle of tasks.

It is Security Copilot compute capacity. The number of tasks it supports comes from measured consumption for a clearly defined workload—within the right capacity model and with quality, risk, and business value in view.

Verified against current Microsoft documentation.

This article reflects publicly available Microsoft information on 13 August 2026. Security Copilot inclusion, preview capabilities, consumption, and pricing may change; verify the tenant, agreement, and current product documentation before purchasing capacity or automating workloads.

LizenzFrau is an independent knowledge platform. Microsoft, Microsoft 365, Security Copilot, Defender, Entra, Intune, Purview, and Sentinel are Microsoft trademarks. Calculations are explanatory interpretations of the linked official sources and are not individual pricing or licensing advice.

Related · AI Governance

AI Agent Governance: Who owns agents—and who controls the costs?

Govern agent risk, data access, lifecycle, monitoring, cost, and business value as one operating model.