I have previously discussed that the wording of your query is very important in Security Copilot. But another key item to be aware of is also which Copilot to use when. You really want to use the correct Copilot for the task at hand. Or, as I like to call it… Don’t burn your SCUs (Security Compute Units) on wasteful queries.
As always, please be aware of my blog disclaimer
Save Your SCUs. Use M365 Copilot Instead
When accessing one of the Security Copilot’s embedded locations, such as Microsoft Purview, you’ll notice that the prompts focus very much on the documentation that supports the area of the console that you are in. For example, if you take a look at the following screenshot, you’ll see that I happen to be in the DLP solution of Purview.
You’ll also notice that Copilot is not prompting for alert-specific topics, but instead, it is providing prompts for documentation of the area of Purview that I am accessing. Moving to Insider Risk, I receive something similar:
Clicking on one of the prompts provides a very detailed answer:
This prompt used over 1/3 of a full SCU (0.341, to be exact).
Now, what if I was to run the same query in M365 Copilot?
I’ll admit the answer is not nearly as detailed as the results from Security Copilot, but it’s enough to get you started, and no SCUs were used. This means you spent about a dollar to get information you could have gotten yourself from a Microsoft Learn page. A dollar doesn’t seem like much, but consider if you are doing this all the time. Or even worse, you only have a limited number of SCUs deployed. If you are burning through SCUs for content searches in Security Copilot when M365 Copilot or even Bing\Google could help with, you are wasting resources (IMHO).
So, in conclusion. Avoid generalistic searches in Security Copilot. M365 Copilot will probably provide you with enough information to at least get started without burning through your SCUs.
Thank for reading!






Leave a Reply