Study guide
Technical reference and lesson notes
Purpose of This Lesson
Security Compute Units (SCUs) are the capacity and billing unit used by Microsoft Security Copilot. For SC-200 scenario questions and real-world administration, analysts should understand how Security Copilot is provisioned, how capacity is billed, and why SCUs assigned to other Microsoft security solutions cannot be reused by Security Copilot.
Key Concepts
Azure subscription requirement
Security Copilot requires an active Azure subscription. The Azure subscription is used for:
- Billing
- SCU provisioning
- Capacity management
- Resource administration through the Azure portal
An organization must therefore have an appropriate Azure subscription before it can provision Security Copilot capacity.
Security Compute Units
SCUs are the resource units that provide processing capacity for Security Copilot workloads. Capacity planning affects both performance and cost: too little capacity can limit the ability to handle workload demand, while excessive capacity can increase charges unnecessarily.
Two capacity models
Security Copilot uses two capacity models:
| Capacity model | Billing approach | Best fit |
|---|---|---|
| Provisioned capacity | Billed hourly | Regular, ongoing workloads with predictable demand |
| Overage capacity | Billed based on actual usage | Unexpected demand spikes or workloads that exceed normal provisioned capacity |
Overage capacity can be configured with no limit or with a maximum cap. This gives an organization a choice between maximum flexibility and tighter cost control.
Capacity is solution-specific
SCUs used by other Microsoft security products are not shared with Security Copilot. Security Copilot capacity is also separate from the SCUs used for data security investigations in Microsoft Purview.
Each solution must have its own provisioned and overage capacity. Having available SCUs elsewhere in the Microsoft security portfolio does not automatically make those units available to Security Copilot.
Capacity changes and monitoring
Administrators can increase or decrease Security Copilot SCUs through the Azure portal or the Security Copilot portal. Security Copilot also provides a usage monitoring dashboard to help administrators review consumption and make capacity-planning decisions.
Microsoft Security Operations Context
Security Copilot capacity is an administrative and financial consideration within the wider SOC toolset. It is not the same as Microsoft Sentinel data ingestion capacity, Defender licensing, or the investigation data available in Microsoft Purview.
A SOC may use Security Copilot during alert triage, investigation, or response support, but the organization still needs to plan its own Security Copilot capacity independently. This separation matters when multiple Microsoft security services are deployed under the same Azure tenant or subscription.
For operational planning, administrators should coordinate with security operations, cloud administrators, and finance teams. Capacity decisions should reflect normal analyst demand, anticipated investigation spikes, and the organization’s tolerance for variable usage charges.
Exam-Relevant Takeaways
- Security Copilot requires an active Azure subscription.
- Billing, provisioning, and management of Security Copilot SCUs flow through the Azure subscription.
- Provisioned capacity is billed hourly and is intended for regular workloads.
- Overage capacity is usage-based and helps handle demand above normal provisioned capacity.
- Overage can be unlimited or capped at a maximum amount.
- Provisioned capacity is charged in hourly blocks, not by the exact number of minutes used.
- Multiple provisioning changes in the same hour can still result in charges for the relevant capacity for the full hour.
- Security Copilot SCUs cannot be shared with SCUs assigned to other Microsoft security products.
- Security Copilot SCUs are separate from SCUs used for Microsoft Purview data security investigations.
- Capacity can be adjusted from the Azure portal or the Security Copilot portal.
- The usage monitor dashboard supports consumption tracking and capacity planning.
Tool / Feature Decision Guide
| Situation | Appropriate capacity or action | Reason |
|---|---|---|
| Security Copilot has predictable, ongoing demand | Provision capacity | Hourly provisioned capacity fits regular workloads. |
| Demand occasionally exceeds the normal baseline | Overage capacity | Usage-based capacity can absorb temporary spikes. |
| Variable overage costs must be controlled | Set an overage cap | A maximum prevents unlimited usage-based expansion. |
| Demand is highly variable and interruptions must be avoided | Consider unlimited overage, subject to financial controls | It provides flexibility, but requires close monitoring of costs. |
| Capacity is needed for another Microsoft security product | Provision capacity for that product separately | SCUs are not shared across these solutions. |
| Capacity needs to be reviewed or adjusted | Use the Azure portal or Security Copilot portal | Both provide administrative access to capacity management. |
| Consumption needs to be evaluated before changing capacity | Review the usage monitor dashboard | Usage data supports informed capacity planning. |
Common Exam Traps
- Confusing Azure subscription requirements with licensing alone: Security Copilot requires an active Azure subscription for billing and capacity management.
- Assuming all SCUs are pooled: SCUs assigned to other Microsoft security products, and those used for Purview data security investigations, are separate from Security Copilot capacity.
- Treating provisioned capacity as minute-by-minute billing: Provisioned capacity is billed in hourly blocks.
- Assuming repeated changes avoid charges: Adding and removing capacity several times within one hour can still produce a full-hour charge for the applicable capacity.
- Confusing provisioned and overage capacity: Provisioned capacity is for normal demand; overage is usage-based capacity for demand beyond the normal baseline.
- Ignoring the overage limit setting: Overage can be unlimited or capped, which directly affects cost-control decisions.
Real-World SOC Analyst Notes
- Make provisioning changes near the beginning of an hour where practical. Changes made partway through an hour may not reduce the hourly charge for that block.
- Review the usage monitor before increasing capacity. A sustained trend may justify additional provisioned capacity, while a short-lived spike may be better handled with overage.
- Treat unlimited overage as a financial-risk decision, not simply a performance setting. Establish monitoring, ownership, and approval expectations before enabling it.
- Use a cap when cost predictability is more important than automatically supporting every possible workload spike.
- Document capacity changes and the operational reason for them, especially when a major incident or investigation causes unusual demand.
- Coordinate capacity planning with Azure administrators and finance teams. Security operations may identify the need, but the subscription and billing owners may control the change.
- Remember that changing Security Copilot capacity does not increase capacity for unrelated Microsoft security solutions.
Quick Reference Summary
- Prerequisite: Active Azure subscription.
- Core unit: Security Compute Unit, or SCU.
- Provisioned capacity: Hourly billing; designed for regular workloads.
- Overage capacity: Usage-based billing; designed for demand spikes.
- Overage control: Unlimited or capped maximum.
- Billing granularity: Hourly blocks for provisioned capacity.
- Sharing: Security Copilot SCUs are separate from other product capacity and Purview data security investigation capacity.
- Management: Azure portal or Security Copilot portal.
- Monitoring: Security Copilot usage monitor dashboard.
- Best practice: Review usage and make planned provisioning changes at the start of an hour when possible.
Flashcards
Q: What Azure prerequisite is required before an organization can use Microsoft Security Copilot?
A: The organization needs an active Azure subscription. Billing, provisioning, and management of Security Copilot SCUs are handled through that subscription.
Q: Which capacity model is intended for regular, ongoing Security Copilot workloads?
A: Provisioned capacity. It is billed hourly and is appropriate when demand is relatively consistent.
Q: When should overage capacity be considered instead of relying only on provisioned capacity?
A: Use overage capacity when workload demand may temporarily exceed the normal provisioned baseline. It is billed according to usage.
Q: How can an organization control the financial risk of overage capacity?
A: Overage can be capped at a maximum amount rather than configured as unlimited. A cap improves cost predictability but may limit support for unusually large spikes.
Q: An administrator provisions capacity at 9:05, removes it at 9:35, and adds it again at 9:45. What billing issue should the administrator expect?
A: Provisioned capacity is billed in hourly blocks, so changes within the same hour can still result in a full-hour charge for the applicable capacity. Repeated changes do not necessarily avoid the hourly charge.
Q: Why is changing provisioned capacity near the beginning of an hour a recommended practice?
A: Provisioned capacity has a minimum hourly charge. Scheduling changes near the start of the hour can help avoid paying for capacity that is only needed briefly during a partially elapsed hour.
Q: Can SCUs assigned to another Microsoft security product be used by Security Copilot?
A: No. Capacity is solution-specific, so Security Copilot requires its own provisioned and overage capacity.
Q: Are Security Copilot SCUs shared with Microsoft Purview data security investigations?
A: No. Purview data security investigation capacity is separate and must be provisioned independently.
Q: Where can an administrator increase or decrease Security Copilot capacity?
A: Capacity can be managed through the Azure portal or the Security Copilot portal.
Q: Which feature helps an administrator decide whether Security Copilot capacity should be increased?
A: The Security Copilot usage monitor dashboard. It provides consumption information for capacity planning.
Q: What is the key difference between provisioned capacity and overage capacity from a billing perspective?
A: Provisioned capacity is billed hourly, while overage capacity is billed based on usage.
Q: A SOC expects predictable daily Security Copilot usage but occasional incident-driven spikes. What capacity approach fits this pattern?
A: Use provisioned capacity for the normal baseline and overage capacity to absorb demand above that baseline. The organization should decide whether to cap overage based on its cost-control requirements.
Q: What is the exam trap when an organization has unused SCUs assigned to another Microsoft security service?
A: Those units cannot automatically be reassigned or shared with Security Copilot. Security Copilot capacity is managed separately.
Practice Questions
Question 1
A SOC uses Security Copilot throughout every business day and expects relatively stable demand. During major incidents, usage may temporarily increase beyond the normal level. Which approach is most appropriate?
A. Use only unlimited overage capacity
B. Use provisioned capacity for the baseline and overage capacity for spikes
C. Use SCUs assigned to Microsoft Purview data security investigations
D. Avoid provisioning and rely on the Azure subscription alone
Correct answer: B
Provisioned capacity is designed for regular workloads, while usage-based overage capacity can handle demand above the normal baseline. Purview capacity cannot be shared with Security Copilot, and an Azure subscription by itself does not provide the required SCU capacity.
Question 2
An administrator provisions one SCU at 9:05 AM, removes it at 9:35 AM, and provisions it again at 9:45 AM. Which billing principle applies?
A. Billing is calculated only for the exact minutes used
B. The administrator pays only for the second provisioning event
C. Provisioned capacity is billed in hourly blocks, so changes in the same hour can still incur a full-hour charge
D. Provisioned capacity is free when removed before the end of the hour
Correct answer: C
Provisioned capacity has a minimum hourly billing block. Multiple changes within the same hour do not necessarily eliminate the charge for that hour.
Question 3
A finance team requires protection against uncontrolled usage-based charges, but the SOC still wants Security Copilot to handle occasional workload spikes. What should the administrator do?
A. Configure overage capacity with a maximum cap
B. Use only SCUs assigned to another Microsoft security product
C. Disable the Azure subscription
D. Configure provisioned capacity as unlimited
Correct answer: A
Overage capacity can be capped at a maximum amount. This supports temporary spikes while providing stronger cost control than unlimited overage.
Question 4
An administrator wants to review Security Copilot consumption before deciding whether to change capacity. Which option should be used first?
A. The Security Copilot usage monitor dashboard
B. Microsoft Purview data security investigations
C. A Defender for Endpoint device timeline
D. A Sentinel analytics rule
Correct answer: A
The usage monitor dashboard provides consumption information for Security Copilot capacity planning. The other options serve different security operations purposes.
Question 5
An organization already has SCUs provisioned for another Microsoft security product. The administrator wants to use those units for Security Copilot to avoid additional provisioning. What is the correct response?
A. Share the units automatically because all Microsoft security products use the same Azure subscription
B. Move the units to Purview first, then use them for Security Copilot
C. Provision separate SCUs for Security Copilot
D. Convert provisioned units to free overage capacity
Correct answer: C
SCUs are not shared between Security Copilot and other Microsoft security products. Security Copilot requires separate provisioned and overage capacity, regardless of unused capacity elsewhere.