Configure workspaces for Security Copilot (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Implement Microsoft Security Copilot
      --> Configure workspaces for Security Copilot


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Security Copilot is designed to help security teams investigate threats, analyze security information, and perform security-related tasks using generative AI. In an enterprise environment, however, simply enabling Security Copilot for the organization is not enough.

Organizations may need to separate users, workloads, data locations, compute capacity, and security responsibilities. Security Copilot workspaces provide an important administrative boundary for accomplishing this.

For the SC-500 exam, understanding workspaces means understanding how to plan and configure:

  • Security Copilot workspaces
  • Security Compute Units (SCUs)
  • Customer Data storage locations
  • Workspace access and roles
  • Workspace-level settings
  • Plugin access
  • Integrated Security Copilot agents
  • Capacity monitoring and management

The Microsoft SC-500 exam places this topic within Manage and monitor security posture (20–25%), under the learning path for implementing activity and security operations capabilities.


1. What Is a Security Copilot Workspace?

A Security Copilot workspace is a logical container used to organize and control Security Copilot usage within an organization.

A workspace establishes three particularly important boundaries:

Workspace characteristicWhat it controls
Customer Data storage locationWhere Security Copilot Customer Data associated with the workspace is stored
CapacityWhich Security Compute Unit capacity powers the workspace
AccessWhich Security Copilot owners and contributors can access the workspace

Microsoft describes the workspace as a logical container defining where data is stored, which capacity powers the experience, and who has access.

This makes the workspace useful for enterprise segmentation.

Example

Imagine a multinational company with:

  • A North American security operations team
  • A European security operations team
  • Separate compliance requirements
  • Different Security Copilot usage levels

Instead of placing every user and workload into one undifferentiated environment, the organization can design workspaces around its operational and compliance requirements.

For example:

WorkspacePrimary usersData locationCapacity
SOC-NorthAmericaNorth American SOCUnited StatesCapacity A
SOC-EuropeEuropean SOCEuropeCapacity B
Security-ResearchSecurity research teamOrganization-approved locationCapacity C

The exact workspace architecture should be based on the organization’s security, regulatory, operational, and capacity requirements.


2. Why Use Multiple Workspaces?

A single workspace may be sufficient for a smaller organization. Larger organizations may benefit from multiple workspaces.

Common reasons include:

Data residency

Different business units may have requirements governing where Customer Data is stored.

Administrative separation

Different security teams may need separate owners and contributors.

Capacity management

Different teams may require different amounts of Security Compute Unit capacity.

Enterprise segmentation

Organizations may want separate environments for different:

  • Geographic regions
  • Business units
  • Security operations teams
  • Regulatory environments
  • Security functions

Governance

Separate workspaces can help establish clearer boundaries around who can use and administer Security Copilot.

The important exam concept is:

A workspace is not simply a folder or user grouping. It establishes important boundaries for data location, capacity, and access.


3. Default Workspace

Security Copilot can have a default workspace.

For Microsoft 365 E5 and E7 customers whose Security Copilot inclusion has been enabled, Microsoft automatically provisions a default workspace and associated default capacity.

The default workspace is important because integrated Security Copilot experiences across Microsoft security products can use the default workspace.

Microsoft currently identifies experiences involving products such as:

  • Microsoft Defender
  • Microsoft Entra
  • Microsoft Purview
  • Microsoft Intune

as using the default workspace in the applicable automatic-provisioning scenario.

Important distinction

Default workspace does not mean every organization must use only one workspace.

Organizations can create additional workspaces when enterprise segmentation requires them.


4. Security Compute Units (SCUs)

One of the most important concepts when configuring Security Copilot is the Security Compute Unit, or SCU.

SCUs represent the compute capacity required to run Security Copilot workloads.

Security Copilot uses SCUs for activities such as:

  • Standalone Security Copilot prompts
  • Embedded Security Copilot experiences
  • Microsoft-developed agents
  • Partner-developed agents
  • Other Security Copilot capabilities

Think of SCUs as the compute capacity available to power Security Copilot.


Provisioned Capacity

For customers using the provisioned capacity model, SCUs are provisioned ahead of time.

Provisioned capacity provides a baseline amount of compute capacity.

For example:

An organization provisions 5 SCUs for its Security Copilot workload.

That establishes the organization’s baseline capacity for its workload.

Provisioned capacity is measured on hourly capacity periods, and unused provisioned capacity doesn’t roll over to a subsequent hour.


Overage Capacity

Organizations can also configure overage capacity.

Overage capacity provides additional compute when workload demand exceeds provisioned capacity.

For example:

Provisioned capacity = 5 SCUs
Workload demand = 7 SCUs
5 SCUs → provisioned capacity
2 SCUs → overage capacity

Overage can help accommodate temporary workload spikes.

However, administrators should monitor usage because overage can have billing implications.


5. Security Copilot Capacity Is Associated With Workspaces

An important exam distinction is that capacity and workspaces are related.

A workspace needs capacity to power its Security Copilot workloads.

Current Microsoft documentation also states that SCUs cannot be shared between workspaces. For example, if Workspace A exhausts its available capacity, it cannot consume unused capacity associated with Workspace B.

This has important architectural consequences.

Example

Suppose:

Workspace A
Provisioned = 4 SCUs
Overage = 2 SCUs
Workspace B
Provisioned = 8 SCUs
Overage = 4 SCUs

If Workspace A exhausts its 6 available SCUs, it cannot automatically borrow the unused SCUs belonging to Workspace B.

Therefore, capacity planning needs to consider workspace-specific workloads.


6. Microsoft 365 E5/E7 Capacity Model

Security Copilot’s current licensing model has an important distinction for Microsoft 365 E5 and E7 customers.

Eligible Microsoft 365 E5 and E7 customers receive included Security Copilot capacity based on their licensed users.

Microsoft currently documents an inclusion amount of 400 SCUs per month for every 1,000 paid user licenses, subject to the documented limits and licensing conditions.

The included capacity is represented by a Default Security Copilot Capacity.

This differs from the traditional provisioned-capacity model.

Exam takeaway

Don’t assume that every Security Copilot deployment uses exactly the same capacity model.

Questions may distinguish between:

  • Provisioned capacity
  • Overage capacity
  • Microsoft 365 E5/E7 included capacity

7. Customer Data Storage Location

Another major workspace configuration is the Customer Data storage location.

Security Copilot Customer Data can include information such as:

  • User prompts
  • Information retrieved to generate responses
  • Security Copilot responses
  • Pinned content
  • Uploaded files

Microsoft states that Customer Data associated with a workspace is stored in the location selected during workspace creation.

This makes data location an important consideration for:

  • Data residency
  • Regulatory requirements
  • Organizational policies
  • Geographic segmentation

Storage Location Is Selected During Workspace Creation

When creating a workspace, administrators select its Customer Data storage location.

An important limitation is:

The Customer Data storage location cannot be changed after the workspace has been created.

If an organization needs a different data location, this needs to be considered during workspace planning and creation.

Exam scenario

An administrator creates a Security Copilot workspace in the United States.

Later, the organization determines that the workspace needs to store Customer Data in Europe.

The administrator cannot simply edit the existing workspace’s Customer Data storage location.

The data location decision must be made correctly during workspace creation.


8. Customer Data vs. Prompt Evaluation Location

These two concepts can easily be confused.

Customer Data storage location

This determines where Customer Data associated with the workspace is stored.

Prompt evaluation location

This determines where Security Copilot prompts are processed using GPU resources.

These are not necessarily the same thing.

Microsoft currently documents prompt evaluation locations including:

  • Australia
  • Europe
  • United Kingdom
  • United States

Organizations can also allow prompt evaluation to occur globally where appropriate.

Exam tip

If a question asks:

“Where is the organization’s Security Copilot Customer Data stored?”

Think:

Workspace → Customer Data storage location

If it asks:

“Where are prompts evaluated?”

Think:

Prompt evaluation location


9. Workspace Roles

Security Copilot has its own access model.

Two important Security Copilot roles are:

  • Security Copilot owner
  • Security Copilot contributor

These roles determine what users can do within Security Copilot.

Microsoft specifically distinguishes Security Copilot roles from Microsoft Entra roles and Azure RBAC roles.

Security Copilot Owner

The owner role provides administrative capabilities over Security Copilot.

Owners can perform tasks such as managing important Security Copilot settings and workspace configuration.

For example, owner-level capabilities can include management of:

  • Capacity associations
  • Data-sharing settings
  • Other owner settings
  • Workspace access
  • Security Copilot configuration

Security Copilot Contributor

The contributor role is intended for users who need to use Security Copilot but don’t require the full administrative capabilities of an owner.

This distinction supports least-privilege administration.


10. Don’t Confuse Security Copilot RBAC With Azure RBAC

This is an important exam concept.

There are multiple permission systems involved in Security Copilot.

Permission modelPurpose
Security Copilot rolesControl access to Security Copilot capabilities
Microsoft Entra rolesControl access to Microsoft Entra and related Microsoft services
Azure RBACControls access to Azure resources such as capacity resources
Microsoft Defender/Purview/Intune rolesControl access to their respective security services

Security Copilot roles are defined within Security Copilot and are not the same as Microsoft Entra roles.

Example

A user may have an appropriate Security Copilot role but still lack the Azure permissions necessary to change an Azure capacity resource.

Conversely, having Azure Contributor permissions doesn’t automatically make a user a Security Copilot owner.


11. Microsoft Entra Roles Can Inherit Security Copilot Access

Some Microsoft Entra, Microsoft Defender, Microsoft Purview, and Microsoft Intune roles can automatically receive Security Copilot access in applicable configurations.

For example, current Microsoft 365 E5/E7 automatic provisioning documentation identifies roles such as:

  • Global Administrator
  • Security Administrator
  • Conditional Access Administrator
  • Intune Administrator

among roles that can inherit Security Copilot owner access.

Various Defender, Purview, and Intune roles can inherit contributor access.

The exact role mappings are subject to Microsoft’s current role model, so exam candidates should understand the concept rather than assuming that every administrator role automatically grants every Security Copilot capability.


12. Least Privilege Still Applies

Security Copilot is a powerful security tool, so administrators should follow least-privilege principles.

A user who only needs to investigate incidents and use Security Copilot generally shouldn’t receive administrative permissions simply because those permissions are convenient.

A good design is:

Security Copilot administrators
↓
Owner permissions
Security analysts
↓
Contributor permissions
Azure capacity administrators
↓
Azure capacity permissions

This separates Security Copilot administration from Azure resource administration.

Microsoft explicitly recommends using the fewest permissions necessary.


13. Workspace-Level Settings

Workspace configuration goes beyond users and capacity.

Administrators may need to configure settings affecting how the workspace operates, including:

  • Customer Data storage location
  • Capacity association
  • Access
  • Data-sharing preferences
  • Prompt evaluation location
  • Access to Microsoft 365 service data
  • Workspace-level plugin behavior

The current Security Copilot training module specifically identifies workspace-level plugins and owner settings as part of workspace configuration.


14. Microsoft 365 Data Access

Security Copilot can integrate with Microsoft 365 services.

Current documentation identifies Microsoft Purview data as an important example of Microsoft 365 data that Security Copilot can access when the appropriate configuration is enabled.

The organization can control whether Security Copilot is allowed to access Microsoft 365 service data through its owner settings.

Turning off this capability does not mean that previously retrieved data is immediately erased.

Previously accessed data remains subject to Security Copilot’s data-retention and deletion policies.


15. Data Sharing Settings

Security Copilot includes settings that control whether Microsoft can capture certain Customer Data for purposes such as product-performance validation and security AI model development.

These settings are distinct from the basic ability to use Security Copilot.

Owners can manage these settings through the Security Copilot owner settings.

For Microsoft 365 E5/E7 automatic provisioning, current documentation indicates that the default data-sharing settings differ from the non-E5/E7 onboarding experience, so exam questions should be read carefully for the licensing scenario.

Important distinction

Do not confuse:

Customer Data storage location

with:

Customer Data sharing preferences

The first concerns where data is stored.

The second concerns whether specified data can be shared with Microsoft for documented purposes.


16. Workspace-Level Plugin Governance

Plugins allow Security Copilot to obtain information from connected services and extend its capabilities.

Workspace configuration can therefore become part of plugin governance.

A good enterprise approach is to consider:

  • Which users need a plugin
  • Which workspaces should have access
  • Whether a plugin introduces additional data access
  • Whether the plugin is appropriate for a particular security team
  • Whether users should be able to configure or publish custom plugins

Owner-level settings provide organization-wide governance capabilities, while workspace configuration can be used as part of segmentation.

The separate Manage plugins and agents in Microsoft Security Copilot module goes deeper into plugin governance, so for this topic the key exam objective is understanding that plugin configuration can be part of the workspace design.


17. Assigning Workspaces to Integrated Security Copilot Agents

Security Copilot can also work through integrated agents.

The workspace configuration module includes assigning workspaces for integrated Microsoft Security Copilot agents.

This is important because an enterprise may want agent activity to operate within an appropriately configured workspace rather than treating every agent as completely independent of workspace architecture.

When designing an agent deployment, consider:

  1. Which users will use the agent?
  2. Which workspace should support the workload?
  3. Which capacity is associated with that workspace?
  4. What data location applies?
  5. What permissions are required?
  6. What plugins or services does the agent need?

18. Monitoring Workspace Capacity

Workspace configuration isn’t a one-time activity.

Administrators should monitor Security Copilot capacity to determine whether the organization has sufficient resources.

The Security Copilot usage monitoring dashboard provides visibility into usage, including provisioned and overage consumption and the workspace associated with usage.

Administrators can use the dashboard to identify:

  • Capacity consumption
  • Which workspace is consuming capacity
  • Provisioned usage
  • Overage usage
  • Usage trends
  • Users or workloads contributing to consumption

The current dashboard provides up to 90 days of usage data.


19. What Happens When Capacity Is Exhausted?

Capacity planning matters because insufficient capacity can affect users.

When usage approaches the available capacity, Security Copilot can display notifications indicating that capacity is being approached.

When the available provisioned and overage capacity is exhausted, users can encounter an error and may be unable to submit additional prompts until capacity becomes available or administrators increase capacity.

This makes capacity monitoring an operational security responsibility.


20. Example Enterprise Workspace Design

Consider a company with three security teams:

  • Corporate SOC
  • European SOC
  • Security Engineering

The organization could design:

                    Security Copilot
                           |
          +----------------+----------------+
          |                |                |
      SOC-US          SOC-Europe       Security-Engineering
          |                |                |
      Capacity A        Capacity B       Capacity C
          |                |                |
      US Data           EU Data        Approved Region
          |                |                |
      US Analysts      EU Analysts      Engineers

Each workspace can be designed around:

  • Data residency
  • User access
  • Security responsibilities
  • Capacity requirements
  • Operational separation

This is the fundamental value of workspace-based enterprise segmentation.


21. Workspace Configuration Process

A practical implementation process is:

Step 1 — Determine the segmentation requirements

Identify whether separate workspaces are needed based on:

  • Geography
  • Regulatory requirements
  • Business units
  • Security teams
  • Data residency
  • Capacity requirements

Step 2 — Determine the data location

Select the appropriate Customer Data storage location.

Remember that this decision is made during workspace creation and cannot subsequently be changed for that workspace.

Step 3 — Determine capacity

Determine the appropriate SCU capacity for the workload.

Consider:

  • Expected number of users
  • Prompt volume
  • Agents
  • Embedded experiences
  • Peak usage
  • Provisioned capacity
  • Overage requirements

Step 4 — Create the workspace

Create the workspace using the planned configuration.

Step 5 — Configure access

Assign appropriate Security Copilot owners and contributors.

Use least privilege.

Step 6 — Configure workspace settings

Review:

  • Data-sharing configuration
  • Microsoft 365 data access
  • Prompt evaluation location
  • Plugin configuration
  • Owner settings

Step 7 — Configure integrated agents

Assign applicable workspaces to integrated Security Copilot agents.

Step 8 — Monitor usage

Review SCU consumption and adjust capacity as operational requirements change.


22. Common Exam Traps

Trap 1: Assuming a workspace is only a user container

A workspace also establishes important boundaries around data location and capacity.


Trap 2: Confusing data storage with prompt evaluation

They are different settings.

Storage location = where Customer Data is stored.

Prompt evaluation location = where prompts are processed.


Trap 3: Assuming workspace data location can be changed later

The Customer Data storage location is selected during workspace creation and cannot be changed afterward.


Trap 4: Assuming SCUs can move between workspaces

SCUs aren’t shared between workspaces.


Trap 5: Confusing Security Copilot roles with Azure RBAC

Security Copilot roles and Azure RBAC solve different authorization problems.


Trap 6: Giving everyone the Owner role

Security Copilot should follow least-privilege principles.

Most analysts don’t need the same administrative privileges as Security Copilot owners.


Trap 7: Assuming E5/E7 and standalone deployments behave identically

Microsoft 365 E5/E7 customers can receive Security Copilot through an included capacity model, while other customers can use provisioned and overage capacity.


23. Key Concepts to Remember

ConceptRemember
WorkspaceLogical container for Security Copilot configuration
SCUSecurity Compute Unit; represents Security Copilot compute capacity
Provisioned capacityBaseline capacity configured for workloads
Overage capacityAdditional capacity available when configured limits are exceeded
Customer Data storage locationDetermines where workspace Customer Data is stored
Prompt evaluation locationDetermines where prompts are processed
OwnerAdministrative Security Copilot role
ContributorUser role for Security Copilot usage without full owner privileges
Workspace segmentationSeparates workloads/users/data/capacity according to organizational requirements
Capacity monitoringTracks SCU usage and helps prevent capacity-related disruption
Integrated agentsCan be assigned to appropriate Security Copilot workspaces
Least privilegeGive administrators and analysts only the permissions they require

24. Exam-Focused Summary

For the SC-500 exam, remember this mental model:

Workspace = Data + Capacity + Access

Then expand it:

                    SECURITY COPILOT WORKSPACE
                              |
          +-------------------+-------------------+
          |                   |                   |
       DATA               CAPACITY             ACCESS
          |                   |                   |
   Storage location          SCUs          Owners/Contributors
          |                   |                   |
   Data residency       Provisioned        Least privilege
   requirements          Overage
          |
   Selected at creation
   Cannot be changed

Around that core, administrators configure:

  • Prompt evaluation
  • Microsoft 365 data access
  • Data-sharing settings
  • Plugins
  • Integrated agents
  • Capacity monitoring

If a scenario asks why an organization should create multiple Security Copilot workspaces, think enterprise segmentation.

If it asks where Customer Data is stored, think workspace data-storage location.

If it asks how much compute is available, think SCUs and capacity.

If it asks who can administer Security Copilot, think Security Copilot owner.

If it asks who can use Security Copilot without full administrative rights, think Security Copilot contributor.

If it asks why an analyst cannot use another workspace’s unused capacity, remember that SCUs aren’t shared between workspaces.


Practice Exam Questions

Question 1

An organization is designing its Microsoft Security Copilot deployment. The security team wants to separate users based on geography and ensure that each group’s Customer Data is stored according to its regional requirements.

What Security Copilot capability should the organization primarily use?

A. Multiple workspaces
B. Multiple promptbooks
C. Multiple plugins
D. Multiple Microsoft Entra tenants

Answer: A

Explanation:
Security Copilot workspaces provide an important enterprise segmentation boundary. Different workspaces can have different Customer Data storage locations, capacity associations, and access assignments. Creating multiple promptbooks or plugins does not provide the same workspace-level separation.


Question 2

A Security Copilot administrator is creating a new workspace. The organization has a regulatory requirement that Customer Data associated with the workspace must be stored in a particular geography.

When should the administrator make this decision?

A. After the first user signs in
B. During workspace creation
C. After assigning Security Copilot contributors
D. After configuring the first plugin

Answer: B

Explanation:
The Customer Data storage location is selected during workspace creation. Microsoft currently states that the storage location cannot be changed after the workspace has been created. Therefore, the data residency requirement must be considered before creating the workspace.


Question 3

An organization has two Security Copilot workspaces:

  • Workspace A has exhausted its available SCUs.
  • Workspace B still has unused SCUs.

Users in Workspace A are unable to continue because its capacity has been exhausted.

What is the reason?

A. Security Copilot requires all users to be owners
B. Workspace B must first disable its plugins
C. SCUs aren’t shared between workspaces
D. Customer Data must be moved to Workspace B

Answer: C

Explanation:
Security Copilot capacity is associated with individual workspaces. Current Microsoft documentation states that SCUs cannot be shared between workspaces. Workspace A therefore cannot automatically consume Workspace B’s unused capacity.


Question 4

A security analyst needs to use Security Copilot for investigations but doesn’t need administrative control over Security Copilot configuration.

Which role is generally more appropriate?

A. Global Administrator
B. Azure Owner
C. Security Copilot Owner
D. Security Copilot Contributor

Answer: D

Explanation:
The Security Copilot Contributor role is intended for users who need to use Security Copilot without requiring the full administrative capabilities of an owner. Assigning an Owner or highly privileged Azure/Entra role would provide more permissions than necessary.


Question 5

An administrator is reviewing two Security Copilot settings:

  • Setting A determines where Customer Data associated with a workspace is stored.
  • Setting B determines where prompts are processed using GPU resources.

What are these settings?

A. Setting A = SCU capacity; Setting B = data sharing
B. Setting A = Customer Data storage location; Setting B = prompt evaluation location
C. Setting A = prompt evaluation location; Setting B = Customer Data storage location
D. Setting A = workspace role; Setting B = plugin scope

Answer: B

Explanation:
Customer Data storage location determines where workspace Customer Data is stored. Prompt evaluation location determines where prompts are processed. These are separate Security Copilot concepts and should not be confused.


Question 6

A company wants to give its security analysts access to Security Copilot while minimizing administrative privileges.

Which principle should guide the workspace access design?

A. Assign all analysts the Owner role
B. Assign Azure Owner to every analyst
C. Use least privilege and assign Contributor access when administrative permissions aren’t required
D. Assign Global Administrator and restrict access through plugins

Answer: C

Explanation:
Security Copilot should be administered according to least-privilege principles. Analysts who need to use Security Copilot generally don’t need the full administrative capabilities of an Owner.


Question 7

An organization is experiencing periodic spikes in Security Copilot usage. The administrators want additional capacity available when demand exceeds their normal provisioned capacity.

Which capability addresses this requirement?

A. Overage capacity
B. Additional workspaces
C. Customer Data sharing
D. Prompt evaluation geography

Answer: A

Explanation:
Overage capacity provides additional SCUs when workload demand exceeds the provisioned capacity, assuming it has been configured. It is particularly useful for accommodating workload spikes.


Question 8

A Security Copilot administrator wants to determine which workspace is consuming Security Compute Units and whether the organization is using provisioned or overage capacity.

Which capability should the administrator use?

A. Microsoft Entra audit logs
B. Security Copilot usage monitoring
C. Microsoft Purview eDiscovery
D. Azure Policy

Answer: B

Explanation:
The Security Copilot usage monitoring dashboard provides visibility into SCU consumption, including provisioned and overage usage and the workspace associated with capacity consumption.


Question 9

An organization is configuring Security Copilot for Microsoft 365 E5 users. The administrator notices that a default Security Copilot workspace and default capacity have already been created.

What is the most likely explanation?

A. Security Copilot automatically creates a workspace whenever a user installs a plugin
B. The Azure subscription automatically creates a workspace whenever an SCU is purchased
C. Microsoft 365 E5/E7 Security Copilot inclusion can automatically provision a default workspace and associated capacity
D. Microsoft Sentinel automatically creates the Security Copilot workspace

Answer: C

Explanation:
For eligible Microsoft 365 E5 and E7 customers whose Security Copilot inclusion is enabled, Microsoft can automatically provision a default workspace and associated default capacity. This provisioning is part of the current E5/E7 inclusion model.


Question 10

A company wants to deploy a Security Copilot agent for a specialized security team. The team has specific data residency requirements and its own Security Copilot capacity.

Which design consideration is most appropriate?

A. Assign the agent to a workspace whose configuration satisfies the team’s data, access, and capacity requirements
B. Place the agent in the default workspace regardless of requirements
C. Give every member of the team Global Administrator permissions
D. Disable SCU monitoring because agents manage their own capacity

Answer: A

Explanation:
Integrated Security Copilot agents can be associated with appropriate workspaces. The workspace should be selected based on the team’s requirements for data storage, access, capacity, and governance. Using the default workspace without considering those requirements defeats the purpose of enterprise workspace segmentation.


Final Exam Takeaways

For Configure workspaces for Microsoft Security Copilot, focus especially on these relationships:

  1. Workspace → data storage location
  2. Workspace → capacity
  3. Workspace → owners and contributors
  4. Storage location → selected during workspace creation
  5. SCUs → Security Copilot compute capacity
  6. SCUs → aren’t shared between workspaces
  7. Provisioned capacity → baseline capacity
  8. Overage capacity → additional configured capacity
  9. Owner → administrative control
  10. Contributor → Security Copilot usage with fewer privileges
  11. Prompt evaluation location ≠ Customer Data storage location
  12. Multiple workspaces → enterprise segmentation
  13. Workspace configuration → can include plugin and agent considerations
  14. Usage monitoring → helps identify capacity consumption and potential capacity problems
  15. E5/E7 → current included-capacity model differs from traditional provisioned capacity

The central exam concept is:

A Security Copilot workspace is an enterprise control boundary that brings together data residency, compute capacity, and user access, with additional configuration for governance, plugins, agents, and operational monitoring.


Go to the SC-500 Exam Prep Hub main page

Leave a Reply