AI FinOps · Microsoft Security Copilot
What are Security Compute Units—
and how many tasks can one SCU really handle?
Microsoft Security Copilot is not metered by prompts, users, or tokens. It uses compute capacity measured in Security Compute Units. That is why there is no credible universal answer such as ‘one SCU equals ten tasks’. This guide explains when SCUs are consumed, which capacity models apply, and how to estimate real demand with evidence.
The short answer
An SCU is compute capacity—not a fixed number of tasks.
Security Copilot consumes SCUs when a Security Copilot workload actually runs. The amount depends on scope, complexity, plugins, data, and automation.
- 01SCUs apply to Microsoft Security Copilot—not Microsoft 365 Copilot or Copilot Studio Credits.
- 02Prompts, embedded features, promptbooks, agents, and automated calls can consume SCUs.
- 03Microsoft 365 E5/E7 may include a monthly SCU pool; other customers provision hourly capacity.
- 04Tasks per SCU must be calculated from the measured average of a specific workload.
From licence to compute capacity
Security Copilot supports security work.
SCUs power its execution.
Security Copilot is Microsoft’s generative and agentic AI solution for security and IT teams. It is available in its own portal and embedded in Microsoft Defender, Entra, Intune, Purview, and other security experiences. Entitlement opens access; SCU capacity enables the actual processing.
Get the terms right
Four concepts that should not be confused
Licence, access, task, and compute describe different layers. Separating them is essential for understanding cost and capacity.
Microsoft Security Copilot
An AI-powered security solution for analysis, summaries, investigations, queries, and agentic automation—standalone and embedded.
Security Compute Unit
A unit of compute power used to run Security Copilot workloads reliably. An SCU measures compute, not the business value of a task.
Prompt, promptbook, agent, primitive
Microsoft distinguishes single prompts, multi-step promptbooks, agents, and service-side AI calls that may run without direct user interaction.
Not tokens and not Copilot Credits
SCUs are a separate capacity and billing model for Security Copilot. They should not be equated with LLM tokens or Copilot Studio Credits.
The licence determines who—or which tenant—may use Security Copilot. The SCU determines how much Security Copilot compute is available for execution.
When are SCUs needed?
SCUs are consumed when a Security Copilot workload runs
The key question is not only where a feature appears, but whether it invokes Security Copilot. Microsoft specifically identifies these consumption paths:
Prompts in the Security Copilot portal
An analyst starts an investigation, asks for a script explanation, or requests relevant threat intelligence.
Manual or automated invocationEmbedded security features
Security Copilot is invoked directly from Defender, Entra, Intune, Purview, or another supported Microsoft experience.
For example, an incident summaryMicrosoft and partner agents
An agent performs repeatable or autonomous security steps. Running agent work uses SCUs like other Security Copilot capabilities.
Interactive, scheduled, or event-drivenPromptbooks, Logic Apps, and connectors
Multi-step or API-oriented calls can run automatically. The invoking service may generate separate charges as well.
Every actual Security Copilot call countsFor custom security agents, the lifecycle matters
According to current Microsoft developer documentation, not every builder action uses compute. Some of the documented agent capabilities are still preview information.
Creating or generating the agent does not yet start an SCU workload.
Testing executes the workload and therefore consumes SCUs.
The publication action itself does not consume SCUs.
Each real agent execution requires Security Copilot compute.
SCUs cover Security Copilot compute. Prerequisites and connected products—such as Microsoft Sentinel, Azure Logic Apps, or a paid partner-agent licence—may be charged separately.
Three capacity paths
Included, provisioned, or overage—which model applies?
Whether SCUs must be purchased manually depends mainly on the Microsoft 365 licence and tenant activation.
Included monthly pool
For eligible and enabled Microsoft 365 E5/E7 tenants, Microsoft provides 400 SCUs per month for every 1,000 paid user licences—scaled proportionally and capped at 10,000 SCUs per month.
- Shared tenant-wide across users and experiences
- No hourly billing for the included pool
- Monthly reset with no rollover
- Phased tenant activation must have completed
Hourly baseline capacity
Customers without included E5/E7 capacity provision at least one SCU. For an introductory exploration, Microsoft recommends three provisioned SCUs with unlimited overage, then adjusting from actual usage.
- Allocated in advance
- Refreshes each full billing hour
- Unused units expire at the end of the hour
- Best suited to predictable baseline demand
Usage-based peak capacity
In the provisioned model, overage is used once baseline capacity is exhausted. It can be capped per hour or left unlimited and is billed to one decimal place from actual usage.
- Consumed only when used
- Absorbs unexpected peaks
- A limit protects budget but can stop work
- Cannot be shared across workspaces
When available provisioned capacity and configured overage are 100% consumed, Security Copilot may reject further requests. With hourly provisioned capacity, capacity becomes available again in the next full billing hour. For the E5/E7 inclusion pool, Microsoft describes a separate pay-as-you-go extension that is still being rolled out; verify availability in the tenant.
The key question
How many tasks can one SCU handle?
Microsoft deliberately provides no fixed task rate: every prompt and workflow can differ in complexity. A short summary, a multi-step investigation, and an autonomous agent are not equivalent units of work.
One SCU has no fixed task count. Only after measuring the average SCU consumption of a specific, repeatable workload can you derive a defensible number of runs.
What Microsoft’s official numerical example demonstrates
Microsoft uses the following values to explain its capacity and billing models. They are an illustration—not a universal rate card for prompts or features.
| Example workload | Example duration | Example consumption | Pure arithmetic per 1 SCU |
|---|---|---|---|
| Execute a prompt | 40 seconds | 3.0 SCUs | 0.33 such runs—one complete run requires 3 SCUs in this example |
| Summarise an incident | 10 seconds | 0.5 SCU | 2 such runs |
Scope, context, plugins, data volume, model steps, and workflow may vary. Use the example only to understand the arithmetic; planning and budgeting must rely on consumption in your own tenant.
Capacity is not the same as consumption
How provisioned SCU billing works
With hourly provisioned capacity, the allocated amount is charged for each fixed clock hour—not only what was used. Overage, in contrast, follows measured extra consumption.
Provisioned SCUs
Charged for each billing hour. A change partway through an hour can trigger another full capacity block.
Actual consumption
Shows how much compute workloads really used. Unused provisioned capacity does not carry into the next hour.
Overage SCUs
Used only after the baseline is exhausted and billed to one decimal place from consumption—up to the configured limit.
Four SCUs provisioned, 3.5 SCUs consumed
provisioned SCUs in the hour
SCUs actually consumed
4 × $4 in Microsoft’s example
The unused difference of 0.5 SCU is not credited.
If consumption exceeded four SCUs, overage would be added—if configured. Microsoft’s current USD illustration uses $6 per consumed overage SCU.
Pricing shown on Microsoft’s US page on 13 August 2026. Microsoft labels these figures as estimates; agreement, region, currency, purchase date, and tax may change the actual price.Practical case · Included pool
A monthly pool becomes a task plan only when measurements exist
An organisation with 1,000 paid Microsoft 365 E5/E7 user licences and enabled inclusion receives 400 SCUs per month under Microsoft’s model. The pool is shared across all eligible Security Copilot experiences in the tenant.
A recurring workflow averages 0.8 SCU per run
Other prompts, agents, and embedded features have already consumed 120 SCUs in the month. That leaves 280 SCUs for the workflow being planned.
included SCUs per month
other consumption
remaining SCUs
possible similar runs at 0.8 SCU
A defensible AI FinOps process
Plan SCU demand in six steps
Microsoft’s Capacity Calculator provides a starting point. Reliable sizing requires actual usage, an hourly demand profile, and the business outcome.
- 01
Inventory workloads
Record standalone use, embedded features, promptbooks, agents, Logic Apps, and partner solutions with an owner and purpose.
- 02
Pilot narrowly
Test representative tasks and peak periods instead of assuming a universal task rate.
- 03
Export usage
Use up to 90 days of dashboard data by prompt, promptbook, agent, primitive, user, plugin, and experience.
- 04
Separate baseline and peak
Align provisioned capacity to stable demand and size overage deliberately for volatility.
- 05
Balance budget and service
A low overage limit protects spend but can interrupt a critical investigation.
- 06
Measure value and quality
Track time saved, quality, risk reduction, failure rate, and outcome—not only SCUs per run.
SCU per successfully completed security outcome is more meaningful than SCU per prompt. A cheap prompt that produces no usable result is not efficient.
Remember
An SCU is not a bundle of tasks.
It is Security Copilot compute capacity. The number of tasks it supports comes from measured consumption for a clearly defined workload—within the right capacity model and with quality, risk, and business value in view.
Official sources
Verified against current Microsoft documentation.
This article reflects publicly available Microsoft information on 13 August 2026. Security Copilot inclusion, preview capabilities, consumption, and pricing may change; verify the tenant, agreement, and current product documentation before purchasing capacity or automating workloads.
- 01Microsoft Learn — Security Compute Units and capacity↗Open source
- 02Microsoft Learn — Security Copilot inclusion for Microsoft 365 E5 and E7↗Open source
- 03Microsoft Learn — Manage Security Compute Unit usage↗Open source
- 04Microsoft Learn — Security Copilot FAQ↗Open source
- 05Microsoft Learn — Get started with Security Copilot↗Open source
- 06Microsoft Learn — Manual onboarding for non-Microsoft 365 E5/E7 customers↗Open source
- 07Microsoft Learn — Cost considerations for Security Copilot agents↗Open source
- 08Microsoft — Security Copilot pricing↗Open source
LizenzFrau is an independent knowledge platform. Microsoft, Microsoft 365, Security Copilot, Defender, Entra, Intune, Purview, and Sentinel are Microsoft trademarks. Calculations are explanatory interpretations of the linked official sources and are not individual pricing or licensing advice.
Related · AI GovernanceAI Agent Governance: Who owns agents—and who controls the costs?
Govern agent risk, data access, lifecycle, monitoring, cost, and business value as one operating model.