Copilot for Security Feature Image

Monitoring Usage in Copilot for Security

In a previous post, I provided the steps for deploying Copilot for Security to your test environment. Now that it is deployed, administrators must be able to monitor the usage of Capacity to ensure they are not exceeding their allotted budget. In this post, we’ll get some insight into how you can monitor usage and review the cost to your organization.

Monitoring Usage in Copilot for Security

As discussed in the previous post, Copilot for Security is not a cheap platform. Even running it with a minimal deployment 24/7 will cost an organization upwards of $35,000 USD per year. That’s not insignificant for small or even some medium organizations, especially as Microsoft recommends at least three SCUs, which will bring the cost to over $100,000 USD per year.  So, how can we manage a test environment?

First, let’s understand what we have been using in our tenant.  This provides an overview of how much we’ll need to maintain based on the usage we’ve made of Copilot.  This is important because different requirements need different levels of SCU power.  Unfortunately, Copilot for Security doesn’t tell you how much a query is going to consume of an SCU.  You won’t know until it is done.  And the only way to determine that is to review the usage monitor immediately after the query is completed.  For example, I ran the query, “Can you scan my tenant configurations and provide a summary of common gaps in protective services?”  The query stopped when it discovered that I hadn’t yet enabled log diagnostics.

Monitor Usage and Control Copilot Provisioning - Gap Analysis Request

This query used up 0.5 of an SCU.  So you can see how quickly your SCUs are used and why Microsoft suggests more than one by default.  To view your usage, perform the following:

  1. Login to Copilot for Security (https://securitycopilot.microsoft.com/).
  2. Click on the Menu Toggle (pancake top left-hand corner).
  3. Click on Usage Monitoring.

Monitor Usage and Control Copilot Provisioning - Usage Monitoring

You can see I ran some more prompts after the one above.  You can also see that Microsoft allows you to exceed your SCU at times.  This is known as surging.  I do not know what the algorithm is that determines “I’ll let you continue” or “Nope, you need more resources to keep going”.  However, it does not appear that Microsoft forces you to pay for the surge pricing.  If we take a look at the cost usage for that time frame, Microsoft only charged my subscription for the amount of time I had the SCU in place.  Even though I exceeded the SCU with surging I don’t appear to have been charged for it.  The graph below outlines the amount charged while the SCU was active, and with conversion, it amounts to about $4 USD/hour.

Monitor Usage and Control Copilot Provisioning - SCU Cost Analysis

This is not to say I will always be able to pull this off or that this will always occur for every organization.  So, do not use what I experienced here as the expected outcome.  It’s likely going to depend on the situation.

In the next post, I’ll cover how to de-provision Copilot for Security when not actively using it.  This will assist in keeping costs down.

Thanks for reading!

 

Quick update (December 2024)

Microsoft has updated the usage page from when I originally wrote this post.  A lot more information is provided, including where the query was run now that Microsoft is supporting embedded Copilot environments.


I’d love to share regularly with you!

Subscribe to get the latest posts sent to your email.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *