Study guide
Technical reference and lesson notes
Purpose of This Lesson
Security Copilot requires provisioned Security Compute Unit (SCU) capacity before you can create and use a workspace. This lesson focuses on the operational and cost implications of allocating that capacity, especially in a lab or training subscription.
The key decision is not only how to configure Security Copilot, but also when to provision capacity and when to remove it so that hands-on experimentation does not create avoidable costs.
Key Concepts
Security Compute Units and capacity
SCUs provide the compute capacity used by Security Copilot. A workspace cannot be created until the required capacity has been allocated.
Capacity can be added from:
securitycopilot.microsoft.com- Azure
The provisioning path does not change the important operational consideration: allocating capacity begins the billing period.
Hour-based billing behavior
The lecture demonstrates billing using an example rate of $4 per SCU per hour. The important behavior is the billing interval, not the specific price, because rates can change.
If one unit is allocated and used for any part of an hour, the example charges for that hour:
- Five minutes of use: one hour is billed
- Fifty-five minutes of use: one hour is billed
- Usage that continues into the next hour: the next hourly unit is billed
Deleting the capacity resource stops additional billing after deletion, but it does not reverse the hourly charge already incurred.
> Always verify current pricing and billing details in the Azure portal or Microsoft documentation. The dollar amount shown in a training demonstration should not be treated as a permanent rate.
Microsoft Security Operations Context
Security Copilot may be used alongside Microsoft security operations tooling, but capacity management is a separate administrative and financial concern. A SOC analyst or lab user should distinguish between:
- Using the security capability: investigating or analyzing security information
- Provisioning the capacity: allocating the SCUs required for a workspace
- Controlling cost exposure: deleting capacity when testing is complete
In a production environment, capacity allocation should follow organizational approval, subscription ownership, and change-control procedures. In a personal lab, the same principle applies at a smaller scale: provision only when ready to work, monitor elapsed time, and remove unused capacity promptly.
Exam-Relevant Takeaways
- Security Copilot requires allocated SCU capacity before a workspace can be created.
- Capacity can be added through the Security Copilot portal or Azure.
- Allocating capacity starts the billing exposure.
- The example billing model charges by hourly unit rather than exact minutes used.
- Deleting capacity prevents further charges but does not eliminate the charge for the current billing interval.
- A practical lab strategy is to observe a demonstration first, then provision capacity only when ready to perform the exercise.
Tool / Feature Decision Guide
| Situation | Recommended action | Reason |
|---|---|---|
| You are only reviewing how Security Copilot works | Do not allocate capacity yet | Provisioning starts billing exposure |
| You are ready to create a workspace and perform the lab | Allocate the required SCU capacity | Capacity is required before workspace creation |
| You finished testing and do not need the workspace capacity | Delete the capacity resource | This limits charges in later billing intervals |
| You have used part of an hourly interval | Do not expect deletion to prorate that interval | The demonstrated model bills the used hourly unit |
| You are using a paid production subscription | Obtain approval and confirm pricing first | Capacity has tenant and subscription cost implications |
Common Exam Traps
- Assuming minute-by-minute billing: The demonstrated model bills an hourly unit even when capacity is used for only part of the hour.
- Assuming deletion refunds the current hour: Removing the resource stops future billing exposure; it does not undo the charge already incurred.
- Assuming a workspace can be created first: SCU capacity must be allocated before creating the workspace.
- Treating the demonstration price as universal: The price is an example and may vary by region, agreement, or current Microsoft pricing.
- Provisioning before planning the exercise: In a lab, watching the workflow first can prevent paying for unused capacity.
Real-World SOC Analyst Notes
- Coordinate capacity allocation with the subscription owner or cloud-finance team.
- Use change control for production provisioning, especially where capacity affects shared budgets.
- Schedule or document start and stop times for lab exercises.
- Delete unused capacity as part of the test-completion checklist, but retain the relevant billing evidence and activity records according to organizational policy.
- Do not assume that deleting capacity immediately removes every cost. Confirm the billing interval and current resource state in Azure.
- When multiple analysts share a subscription, document who owns the capacity and when it may be used to avoid accidental tenant-wide or subscription-wide cost exposure.
Quick Reference Summary
- Prerequisite: Allocate SCU capacity before creating a Security Copilot workspace.
- Provisioning locations: Security Copilot portal or Azure.
- Billing principle in the lesson: A partial hour is charged as an hourly unit.
- After deletion: Future usage is stopped, but the current hourly charge remains.
- Best lab practice: Watch or plan first, provision only when ready, and delete capacity after testing.
Flashcards
Q: What must be allocated before a Security Copilot workspace can be created?
A: Security Compute Unit capacity must be allocated first. Without that capacity, the workspace cannot be created.
Q: Where can Security Copilot capacity be added?
A: It can be added from securitycopilot.microsoft.com or through Azure.
Q: When does billing exposure begin for Security Copilot SCU capacity?
A: Billing exposure begins when the capacity is allocated, so provisioning should be timed carefully.
Q: A single SCU is used for five minutes and then deleted. What is the billing implication in the demonstrated model?
A: The used hourly unit is still charged. Deleting the resource does not make the five-minute use free or prorate the hour.
Q: What happens if SCU capacity remains allocated beyond the first hourly interval?
A: Usage that continues into the next hour can incur another hourly charge for the allocated unit.
Q: Does deleting SCU capacity refund the current hourly charge?
A: No. Deletion limits additional charges after removal but does not reverse the charge for the interval already used.
Q: You want to learn the workflow but are concerned about lab cost. What is the safest approach?
A: Review the demonstration or plan the steps first, then allocate capacity only when ready to perform the exercise.
Q: Why should the price shown in a training demonstration not be memorized as a permanent fact?
A: Pricing can change and may vary by context. Verify current rates and billing terms in Azure or Microsoft documentation.
Q: A learner says, “I will create the workspace now and allocate SCUs only if I need them.” What is the issue with this plan?
A: The prerequisite is reversed: capacity must be allocated before the workspace can be created.
Q: What should a production SOC consider before allocating Security Copilot capacity?
A: Confirm authorization, subscription ownership, current pricing, and change-control requirements before provisioning.
Practice Questions
Question 1
A lab user allocates one SCU, runs a five-minute test, and immediately deletes the capacity. Which statement best describes the billing result from the lesson?
A. No charge is incurred because the resource was deleted within the first hour.
B. The user is charged for five minutes only.
C. The user is charged for the hourly unit already used, but deletion limits later charges.
D. The user is charged for a full day automatically.
Correct answer: C
The demonstrated model bills the hourly unit when it is used, even for a partial hour. Deleting capacity prevents additional billing after deletion but does not remove the charge already incurred.
Question 2
An analyst attempts to create a Security Copilot workspace before allocating any SCU capacity. What should the analyst do?
A. Create the workspace and add capacity afterward.
B. Allocate the required capacity first, then create the workspace.
C. Create the workspace through Azure without capacity.
D. Use a Microsoft Sentinel data connector instead.
Correct answer: B
SCU capacity is a prerequisite for workspace creation. It can be added through the Security Copilot portal or Azure.
Question 3
A security team wants to run a paid lab exercise but has not yet reviewed the demonstration or planned the steps. What is the best cost-control decision?
A. Allocate capacity immediately so it is ready whenever someone starts.
B. Allocate the maximum capacity to reduce the number of provisioning operations.
C. Review the workflow first and provision capacity only when the team is ready to work.
D. Leave capacity allocated permanently so future charges are predictable.
Correct answer: C
The lesson recommends understanding the workflow before provisioning when cost is a concern. This reduces idle billed time and supports deliberate lab use.
Question 4
A team deletes Security Copilot capacity after using it for 55 minutes. Which assumption is incorrect?
A. The hourly usage already incurred may still be billed.
B. Deletion can prevent charges from continuing after the resource is removed.
C. The resource should be checked to confirm it was actually deleted.
D. Deletion automatically refunds the partial-hour charge.
Correct answer: D
Deleting capacity does not refund the hourly interval already used. It is a control for future charges, not a retroactive billing adjustment.