Previously, I provided the steps for monitoring the usage of Copilot for Security within your tenant. This is important to ensure you are not over-deploying SCUs unnecessarily or under-deploying the SCUs based on the needs of your organization. Now that we have established how to review the cost let’s move on to controlling the cost. In this post I’ll demonstrate some methods for managing Copilot for Security costs with provisioning.
As always, please be aware of my blog disclaimer
Managing Copilot for Security Costs with Provisioning
Provisioning SCUs
Security Compute Unit controls the cost of Copilot for Security for your subscription. The cost is approx $4 USD/hour. Different queries will use different amounts of an SCU. If you have multiple investigations occurring or just heavy use in general your standard SCU deployment may not be enough. Users may receive messages that they are reaching or have exceeded the allotment of compute units. When this occurs administrators can increase the SCU for the Capacity to meet the current needs.
- Navigate to Copilot for Security console (https://securitycopilot.microsoft.com/).
- Click on the Menu Toggle (pancake top left-hand corner).
- Click on Usage Monitoring.
- Under Units per hour, click on Change
- Update the number of SCUs accordingly (can go down to if the SCUs are no longer required).
- Click Apply.
De-provisioning Copilot for Security
There is no way to provision Copilot with zero (0) SCUs. To save cost and remove SCUs, you will need to delete the capacity itself. This should not be done in a production environment without first considering that any data gathered by Copilot within that capacity will be removed. It will be maintained for 180 days from when the capacity is deleted (unless additional retention policies are in place), but it will eventually be removed. The de-provisioning can be done using the following steps:
- Navigate to Copilot for Security console (https://securitycopilot.microsoft.com/).
- Click on the Menu Toggle (pancake top left-hand corner).
- Click on Usage Monitoring.
- Under Units per hour, click on Change
- Click on the ellipsis (…) beside cancel and select Delete capacity.
- You will be prompted with an “Are you sure” screen. If you do not want to delete the capacity, click on the “X-out” as no cancel button is provided.
- Once the capacity is deleted, you will be prompted to create a new capacity.
Provisioning a New Copilot for Security Capacity
Once prepared to work with Copilot for Security again, you will need to create a new capacity and assign at least one (1) SCU.
- Navigate to Copilot for Security console (https://securitycopilot.microsoft.com/).
- You will see the Copilot landing page. Instead you will receive a pop-up requesting you to create a new capacity.
- The following are suggestions:
- Azure Subscription: Select the same subscription as the initial Copilot Capacity.
- Resource Group: Select the same resource group used previously.
- Capacity Name: Provide the same name as previously provided.
- Prompt evaluation location: This is where you wish to run your prompts to copilot. If available, select the region that your tenant exists within.
- “If this location has too much traffic, allow Copilot to evaluate prompts anywhere in the world.“: Check this box if your organization does not have any issues with data crossing national borders.
- Capacity region: Select the region within the selected evaluation location to run prompts. Note: At the time of this post, each location only had a single region to select from.
- Security compute units: Select 1 for the test environment (for now).
- Once filled in, click on Create.
If you cancel the prompt to create a new Capacity, the screen will go away. You will actually be able to type in the prompt box, but will receive an error:
Refreshing the page or going to Usage Monitoring will return the Capacity prompt.
In a future post, I will provide steps to automate this process as necessary.
Thanks for reading!







Leave a Reply