[D 7.5] The Metered and the Negotiated: Security Copilot and Defender Experts

Everything else in this series is machinery you own outright. Two things are not: an artificial intelligence capacity that is metered and currently uncapped by any bill, and five human services that carry no public price at all.


Everything else in this block is machinery that arrives with a licence you already hold. Two things do not work that way, and they fail differently enough that treating them as one category is how procurement conversations go wrong. One is metered, generously, with a bill that has been announced and has not started. The other is negotiated, entirely, with no price list anywhere and a scope bounded by decisions you made about your own deployment years before you signed the contract.


The boundary moved from a licence to a meter

Until late 2025, Security Copilot was a separate purchase and the answer to whether E5 included it was no. That answer is dead and I still hear it repeated. Rollout began on 18 November 2025 for existing Security Copilot customers on E5 and has been phasing out to everyone else since, so Microsoft 365 E5 and E7 now include a capacity allocation: four hundred security compute units per month for every thousand paid user licences, capped at ten thousand a month, scaling proportionally below a thousand seats so that four hundred licences yields a hundred and sixty units. It provisions itself, with no capacity to configure and no Azure work to do, and the allocation resets monthly and does not roll over.

A capability that used to be a procurement decision is now a capacity planning discipline, and the constraint is how much of it a security operations team can actually consume in a month. Unused allocation evaporates at month end, so an organisation that provisioned nothing is discarding real capability every month without noticing.

The tense on what happens past the allocation matters more than the numbers, and it is the reason this article says what it says. Microsoft’s wording is that usage beyond the allocation will be throttled at a future date, that pay as you go will be available at that time, and that customers will receive thirty days of notice before it is. That is all future. As of today the allocation is a ceiling on capability rather than a bill you can accidentally run up, which is an unusually forgiving arrangement and is also a temporary one. The right posture is to use it deliberately now and to have a view on what you would do when the meter starts, because the notice period is thirty days and thirty days is not long enough to have the conversation from scratch.

An entitlement nobody consumes is not a saving. It is capability discarded monthly, on terms the vendor is under no obligation to keep offering.

What the allocation covers is broad: chat, promptbooks and agent scenarios across the identity, device management, data governance and security portals, the standalone experience, workspace scenarios for those who have one, and the developer surfaces for building your own agents. The exclusions are worth reading as a list of places the meter still bites. Data lake compute and storage, the non-agentic data security investigation experience, orchestration app charges, and licence fees for agents bought from partners rather than the compute they consume. There is a fifth exclusion that is the most architectural and the easiest to miss: some agents have prerequisites involving products outside the suite, and those prerequisites are not covered. So the meter does not stop at the boundary of Security Copilot. It stops at the boundary of what you deployed to feed it, which is the same constraint this block has been describing under other names.

On prices, be careful about what is actually published. The four dollar provisioned and six dollar overage figures exist, and both appear inside a worked billing example on a pricing page that carries an estimates-only disclaimer. The six dollar figure is corroborated in the documentation. I would use them for a rough model and I would not put them in a contract position without asking, and I would note that the pricing page has moved, so a link you saved last year now redirects.

One structural change that affects how you read all of this: there is now a tier above E5. The Frontier suite, E7, became generally available on 1 May 2026, and it is a strict superset of E5, adding the productivity Copilot, Microsoft Entra Suite and Agent 365 in one licence. Microsoft publishes it at ninety nine dollars per user per month against sixty for E5, on the plans and pricing page rather than in the documentation. Every capacity statement in this article applies to both tiers. For a series whose anchor is titled around what you actually own with E5, that is the first time in three years the ceiling has moved.

Agents are consumers, not products

The agents are the part of this that will change how a security operations centre is staffed, and the licensing model is the least interesting thing about them, which is itself the point: they carry no separate purchase and they consume the same capacity as everything else. The Phishing Triage Agent is generally available for mail and collaboration and is the one with a track record; the Security Alert Triage Agent, which is the same agent extended past mail into other alert types, is in preview. The conditional access optimisation agent went generally available a year ago. The vulnerability remediation agent opened to all customers in preview in June. There is a hunting agent and an always-on detection agent in preview, and a threat intelligence briefing agent that went generally available at the end of last year.

There is one collision in that set worth knowing before you deploy, because it is now a conflict between two generally available features rather than a preview quirk. The Phishing Triage Agent does not classify alerts that alert tuning has already resolved, and the built-in tuning rules that went generally available in April include one that auto-resolves exactly the user-reported phishing alerts the agent exists to triage. Microsoft now disables the built-in rule during agent setup, which closes the obvious version of this. What is not handled for you is any custom tuning rule that resolves the same alert, and an organisation that wrote one of those has bought an agent that silently skips the work it was bought for.

Humans are negotiated, and the portfolio does not agree with itself

The other posture is Defender Experts, and the first honest thing to say is that the portfolio is in motion. As of this month there are five, and Microsoft’s documentation and Microsoft’s sales pages name different fives. Both lists contain managed detection and response, cybersecurity incident response, hunting and threat intelligence. The documentation’s fifth is Defender Experts for Servers, delivered through Defender for Cloud; the sales page’s fifth is Microsoft Enhanced Designated Engineering, which does not appear in the documentation at all. Neither list is wrong. They are two different views of a portfolio that has been in motion for a year. The flagship shed its old name across the documentation during 2025, the servers offerings moved from add-ons to standalone products in May 2026, and this month it gained a second plan for coverage beyond Microsoft’s own estate.

I mention the divergence rather than resolving it because it is diagnostic. A capability whose composition you can read off a product page is a product. A capability whose composition differs between the engineering documentation and the sales material, whose plan structure exists only in a blog post, and which has no published price is a services engagement, and it should be evaluated the way you evaluate a services engagement: scope in writing, in the contract, with the exclusions named.

Because the exclusions are substantial and they are documented. The managed service covers high and medium severity incidents on Windows, Linux and macOS devices. Outside its scope: internet of things devices, mobile devices on either platform, anything categorised as compliance or data loss prevention, and, notably, incidents raised by your own custom detections. That last one is a direct consequence of the previous articles in this block. The detection plane your team owns is the part a managed service will not operate for you, which is defensible and is also exactly the opposite of what most people assume they are buying.

Your deployment decides what you are allowed to buy

The service’s authority over your estate is bounded by two things you control, and both were decided long before the contract was signed.

The first is deployment mode. Microsoft’s wording is that products deployed in active mode are fully covered and that the experts investigate and respond on your behalf, and that products deployed in passive mode might be non-actionable, in which case guided response might still be provided but no remediation actions are taken for you. So an estate running Defender for Endpoint in passive mode alongside another vendor, which is a completely normal migration state and is discussed in the detection engine article, has bought a Defender Experts managed response service that may only be able to advise. Microsoft hedges the wording and I would too, but the shape is unambiguous: this is shared responsibility enforced technically rather than contractually.

The second is the role you grant them. The experts act within the permissions you assign in your own portal: granted a reader role they investigate and hand you managed response to act on, and granted an operator role they can take remediation actions agreed with your team. That is the authority model from earlier in this block deciding the value of a commercial contract. The permissions work argued in the authority article is the mechanism by which you decide what a service you are paying for is permitted to do, and an organisation that has not done it cannot express the difference between advice and action.

The hunting service sits at the other end of the same gradient and is honest about it. It does not remediate. It investigates what it finds and hands over contextual alert information along with remediation instructions so that your team can respond, which is the right service for an organisation that has a capable security operations function and wants depth rather than hands. Knowing which of those two you are buying, in a portfolio where both are sold by the same people under adjacent names, is most of the diligence.

No price list, and the last free humans

None of these services has a public price. Every route to them ends at a customer interest form or an instruction to work with your commercial representative to transact the arrangement, and the sales page says to contact sales for pricing. The bundle announced at the start of this year has a promotional discount running to the end of December 2026 with a fifteen hundred seat minimum, and it has no published availability date at all, only the date of the announcement. Do not let anyone tell you what these things cost by reference to a list, because there is not one.

One small ending is worth recording because it completes an argument this series opened. Endpoint attack notifications, the service that put Microsoft analysts in the loop for endpoint customers at no additional cost, has its intake paused, and the documented instruction to anyone interested is to sign up for the paid service request form. The operating documentation for enrolled tenants remains. What has stopped is new people joining. That is the last of the free humans being retired into the paid funnel, and it is the clearest single illustration of the boundary this article is about.

Owned, metered, negotiated

Three postures, and the discipline is knowing which one a capability sits in before you plan around it. What you own outright is the machinery: correlation, disruption, the schema, the permissions model, the detections your team writes. It arrives with the first qualifying licence and it costs nothing further, and the constraint on it is deployment breadth rather than budget. What you meter is the artificial intelligence, generously today and on announced terms tomorrow, where the constraint is how much your team can actually consume. What you negotiate is people, at a price nobody publishes, with a scope your own architecture decided.

That closes the block and it closes the series. Six blocks ago this began with a suite most organisations own and few operate, and thirty-odd articles later the gap between those two facts is still where the work is. What this block added is the boundary at the end of it. Almost everything is paid for, some of it is metered on terms that have been announced and not yet applied, and the last of it is priced by a salesperson who will ask what you have already deployed before answering. Those are three different conversations and only one of them is a purchase order.

If you arrived at this article first, the argument it completes starts at what you actually own with E5, and the platform layer this block describes begins at the fabric anchor.


Defender XDR
‹ Previous: [D 7.4] The Sentinel Decision: What E5 Buys and What the Workspace Adds