This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
--> Implement Microsoft Security Copilot
--> Enable and configure Microsoft agents and Security Store agents
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Microsoft Security Copilot extends beyond interactive prompting through security agents.
Agents are specialized AI-driven components designed to perform particular security or operational tasks. They can gather information, analyze security data, provide recommendations, and in some scenarios perform actions based on configured triggers, permissions, identities, plugins, and other parameters.
For the SC-500 exam, you should understand two important categories of agents:
- Microsoft-built agents
- Partner-built agents obtained through Microsoft Security Store
Microsoft Security Copilot provides an agent library where Microsoft and partner-built agents can be discovered and configured. Security Store provides an integrated storefront for discovering and acquiring Microsoft and partner security agents and solutions.
The current Microsoft training module specifically identifies the following objectives for this topic:
- Discover and set up Microsoft-built agents using the Security Copilot agent library.
- Acquire and configure partner-built agents through Security Store.
- Understand the Global Administrator approval workflow.
- Manage agent run state.
- Edit agent configuration.
- Manage agent memory.
1. What Is a Security Copilot Agent?
A Security Copilot agent is a specialized AI component designed to perform a particular security task or workflow.
An agent can combine:
- An identity
- Permissions
- Plugins
- Microsoft security products
- Triggers
- Input parameters
- Security Copilot capabilities
- Specialized instructions or logic
A useful mental model is:
Security Copilot Agent
|
+-----------------+-----------------+
| | |
v v v
Identity Permissions Plugins
| | |
v v v
Who is the What can the What can the
agent? agent access? agent use?
| | |
+-----------------+-----------------+
|
v
Trigger
|
v
Agent execution
|
v
Security result/action
Microsoft describes an agent’s identity as the credentials it uses when it runs, while permissions determine what information or tasks the agent is authorized to access or perform. Plugins extend what the agent can do by connecting it to capabilities in Microsoft and non-Microsoft services and public websites.
2. Microsoft-Built Agents
Microsoft-built agents are agents created and published by Microsoft.
They are designed for particular security scenarios and can be discovered through the Security Copilot agent library.
Microsoft provides agents across areas such as:
- Microsoft Entra
- Microsoft Defender
- Microsoft Intune
- Microsoft Purview
- Microsoft Sentinel
- Security Copilot
Agents may also be available through embedded experiences within Microsoft security products.
Example
Microsoft provides a Threat Intelligence Briefing Agent that can generate threat-intelligence reports using Microsoft threat data and related security information.
The agent has defined requirements for:
- Identity
- Licensing
- Permissions
- Products
- Plugins
- Role-based access
- Triggering
This illustrates an important exam concept:
An agent is more than an AI prompt. It is a configured security workload with an identity, permissions, dependencies, and execution behavior.
3. Discovering Microsoft-Built Agents
To discover Microsoft-built agents in the standalone Security Copilot experience:
- Sign in to Microsoft Security Copilot.
- Select Agents from the navigation pane.
- The agent library appears.
- Browse or select the agent you want to use.
- Select Set up.
Microsoft indicates that the agent must be set up before it can be used.
Conceptually:
Security Copilot | v Agents | v Agent Library | v Select Agent | v Set up | v Configure Agent | v Run
4. Agent Setup
When setting up a Microsoft-built agent, you may need to configure several components.
Microsoft identifies the following concepts as possible agent parameters:
| Component | Purpose |
|---|---|
| Trigger | Determines what event or condition initiates the agent |
| Permissions | Determines what information or actions the agent is authorized to access |
| Identity | Provides credentials used when the agent runs |
| Plugins | Extend the agent’s capabilities |
| Products | Microsoft products required by the agent |
| Role-based access | Roles or permissions required to turn on or run the agent |
Not every agent necessarily requires configuration of every parameter. The exact setup requirements vary by agent.
5. Agent Identity
Agent identity is one of the most important security concepts in the exam.
An agent needs an identity so that it can authenticate and securely access resources when it runs.
During setup, Microsoft-built agents can provide two identity options:
- Create an agent identity
- Use an existing user account
Microsoft recommends creating an agent identity where that option is available.
6. Dedicated Agent Identity
A dedicated agent identity gives the agent its own identity rather than making the agent dependent on an individual user’s account.
Conceptually:
Agent
|
v
Dedicated identity
|
v
Assigned permissions
|
v
Required resources
This can make access easier to control because the agent’s access can be managed independently of a specific employee.
Microsoft describes Microsoft Entra Agent ID as providing identities specifically for AI agents. The setup process allows permissions to be granted to the agent identity so that the agent can perform its required functions.
7. Using an Existing User Account
An alternative is to connect an existing user account.
In this model:
User account | vAgent execution | vUser's permissions
The agent inherits the access and permissions associated with that account while it is active.
This can be appropriate in scenarios where the agent specifically needs to operate in the context of a user.
However, from a security-design perspective, you should understand the difference between:
Agent identity
and
User identity
because they produce different authorization and lifecycle considerations.
Exam clue
If a question asks:
“Which identity should be used to give the agent its own dedicated access?”
Think:
Agent identity.
If the question says:
“The agent should operate using the user’s existing permissions.”
Think:
Existing user account.
8. Agent Permissions
An agent’s identity determines who or what the agent is, while permissions determine what the agent can do.
For example:
Identity | +--> Authentication | v Permissions | +--> Read security data +--> Investigate alerts +--> Query threat intelligence +--> Perform authorized actions
An agent should receive only the permissions required for its intended workload.
This follows the principle of least privilege.
Microsoft specifically recommends using roles with the fewest permissions when configuring partner-built agents.
9. Plugins Used by Agents
Agents can use plugins to extend their capabilities.
A plugin can provide access to:
- Microsoft services
- Non-Microsoft services
- Public websites
- APIs
- Threat-intelligence systems
- Other security capabilities
Therefore:
Agent | +---- Plugin 1 --> Microsoft service | +---- Plugin 2 --> External API | +---- Plugin 3 --> Threat intelligence
An agent’s required plugins are part of its configuration.
Microsoft identifies plugins as components that extend an agent’s capabilities by providing access to Microsoft and non-Microsoft services and public websites through APIs.
10. Required Plugins
Some agents have dependent or required plugins.
When an agent requires a plugin, that plugin can be enabled for the agent.
However, there is an important distinction:
Enabled for the agent does not necessarily mean the plugin has been fully configured.
For an agent obtained through Security Store, Microsoft states that if the agent has a dependent plugin, the plugin is enabled for the agent but may still require configuration.
The administrator must go to:
Manage sources → Find the plugin → Configure the plugin
and complete the required configuration.
Exam scenario
An administrator obtains a Security Store agent.
The agent appears to be installed, but it does not run successfully.
The agent has a dependent plugin.
What should the administrator check?
The plugin’s configuration.
Do not assume that because the plugin is enabled for the agent, the plugin is completely configured.
11. Triggers
A trigger determines when an agent starts.
An agent may be configured to:
- Run automatically based on a trigger
- Run manually
- Run according to a schedule
- Be paused
Microsoft defines a trigger as an event or condition that tells an agentic system to initiate an action or series of actions.
Conceptually:
Event / Condition | v Trigger | v Agent | v Investigation | v Result / Action
12. Automatic Versus Manual Execution
Security Copilot allows an agent to operate automatically or manually.
Automatic
The agent runs when its configured trigger occurs.
Manual
An administrator or user can initiate a one-time execution.
Microsoft also allows an agent to be paused when it is not required to operate.
Example
An organization configures an agent to run every seven days.
If the organization wants to stop automatic executions temporarily, it can pause the agent.
The agent can later be resumed.
13. Pausing an Agent
Pausing an agent temporarily stops its operation.
This is useful when:
- The underlying service is undergoing maintenance.
- The agent is being investigated.
- A security issue has been identified.
- The agent is temporarily unnecessary.
- The organization wants to stop automated execution without deleting the agent.
Pausing is therefore different from removing or deleting an agent.
RUNNING | v PAUSED | v RESUMED
14. Editing an Agent
Owners and Contributors can edit agents.
Editing can include modifying:
- Identity
- Trigger configuration
- Other available parameters
- Agent settings
Microsoft states that Owners and Contributors can edit an agent to modify its configuration.
Important distinction
Being able to run an agent does not necessarily mean being able to perform every administrative operation associated with the agent.
Always distinguish:
- Discover
- Set up
- Run
- Pause
- Edit
- Manage permissions
- Manage identity
when analyzing an exam scenario.
15. Agent Memory
Security Copilot agents can maintain memory associated with feedback and configuration.
Owners and Contributors can provide feedback to an agent.
That feedback can become part of the agent’s memory and influence subsequent operation.
An administrator can review the agent’s memory and reject feedback that should no longer be retained.
Process
Agent output | vProvide feedback | vFeedback stored in memory | vAgent considers memory | vFuture operation
To manage memory:
- Open the agent.
- Select the … menu.
- Select Manage memory.
- Review stored feedback.
- Select feedback.
- Use Reject feedback when appropriate.
16. Microsoft Security Store
Microsoft Security Store is a security-focused storefront for discovering, evaluating, acquiring, and deploying Microsoft and partner-built security solutions and agents.
It integrates with Microsoft security products including:
- Microsoft Defender
- Microsoft Sentinel
- Microsoft Entra
- Microsoft Purview
- Microsoft Intune
- Microsoft Security Copilot
Security Store is integrated into the standalone Security Copilot experience.
17. Microsoft Agents Versus Partner Agents
This distinction is important for SC-500.
| Characteristic | Microsoft-built agent | Partner-built agent |
|---|---|---|
| Publisher | Microsoft | Microsoft partner |
| Discovery | Security Copilot agent library / Security Store | Security Store |
| Setup | Security Copilot | Security Copilot after acquisition |
| May require Microsoft permissions | Yes | Yes |
| Global Administrator consent | Not necessarily the same partner-agent workflow | Required when the partner agent needs certain Microsoft product permissions |
| Identity configuration | Yes | Yes |
| Plugins | May be required | May be required |
| Commercial terms | Depend on agent/prerequisites | May require separate purchase/subscription |
Microsoft’s current documentation distinguishes Microsoft-built and partner-built agent setup, including a specific consent workflow for partner-built agents that require access to Microsoft tools and data.
18. Discovering Agents Through Security Store
From Security Copilot, users can navigate to:
Home → Security Store
They can then:
- Search for an agent.
- Filter by publisher, product, or pricing.
- Select the desired agent.
- Select Get agent.
Microsoft-built agents are routed to the Active agents experience.
Non-Microsoft agents are routed through Security Store for purchase or subscription where required.
19. Purchasing Versus Operating an Agent
This is an important exam distinction.
Security Store handles acquisition and billing.
Security Copilot handles agent configuration and operation.
Conceptually:
Security Store
|
v
Find / Purchase / Subscribe
|
v
Get Agent
|
v
Microsoft Security Copilot
|
v
Configure / Run / Pause
|
v
Manage Agent
Microsoft explicitly separates purchasing/subscription management from operational management in Security Copilot.
20. Removing an Agent Versus Ending a Subscription
A particularly important Security Store concept:
Removing an agent from Security Copilot and managing its commercial subscription are separate considerations.
Microsoft’s Security Store documentation states that purchases and subscriptions are handled separately from the Security Copilot platform.
For partner agents, billing and entitlement information may need to be managed through Security Store.
Exam clue
If the question says:
“Remove the agent from Security Copilot.”
Think:
Operational removal.
If the question says:
“Cancel the partner subscription.”
Think:
Security Store / subscription management.
Do not automatically treat the two as the same operation.
21. Security Compute Units
Using agents within Security Copilot consumes Security Compute Units (SCUs).
SCU consumption is distinct from any separate subscription or licensing fees associated with a partner agent.
This creates two potentially separate considerations:
Partner Agent | +---- Partner subscription / license | +---- Security Copilot usage | +---- SCUs
For exam purposes, remember:
Partner-agent acquisition costs and Security Copilot compute usage are not necessarily the same charge.
22. Partner Agent Global Administrator Consent
This is one of the most important exam scenarios.
Suppose an organization wants to deploy a partner-built Security Copilot agent.
The agent needs to access:
- Microsoft Entra
- Microsoft Intune
- Microsoft Sentinel
- Microsoft Defender
- Defender Threat Intelligence
and therefore requires permissions to Microsoft services.
A Global Administrator must approve the required permissions for the partner-built agent.
The workflow is:
Security Copilot Owner/Contributor | v Begin agent setup | v Consent required banner | v Copy approval link | v Global Administrator | v Review permissions | v Approve access | v Owner/Contributor completes setup
23. What the Global Administrator Does
The Global Administrator should review the agent’s requested permissions before approving the agent.
The approval interface can provide information such as:
- Agent details
- Description
- Trigger
- Required permissions
- Other configuration information
The administrator starts the approval process and grants the necessary permissions.
Security principle
Microsoft explicitly recommends using the fewest permissions possible.
Global Administrator is a highly privileged role and should not be used unnecessarily.
24. What Happens After Consent?
Once Global Administrator approval is complete:
Security Copilot Owners and Contributors can finish the agent setup.
They can configure items such as:
- Identity
- Trigger
- Input parameters
- Other agent-specific settings
They do not necessarily need to remain Global Administrators simply because the initial consent required Global Administrator approval.
This distinction is highly relevant to least-privilege exam questions.
25. When Global Administrator Approval Isn’t Required
Global Administrator approval is required in the documented partner-agent scenario when the agent needs access to Microsoft tools and Microsoft product data.
However:
If the partner-built agent does not require Microsoft product permissions, the documented Global Administrator approval isn’t required.
Example
A partner-built agent only processes information through its own external service and does not request access to Microsoft product data.
The special Microsoft-product consent workflow does not apply.
26. Security Store Agent With a Dependent Plugin
This is an especially useful scenario to remember.
Suppose:
- You obtain a partner agent through Security Store.
- The agent has a dependent plugin.
- The agent appears in Security Copilot.
- The agent still doesn’t operate successfully.
The likely next step is to configure the dependent plugin.
Microsoft’s documented process is:
Manage sources → Find the plugin → Configure the plugin
The plugin may already be enabled for the agent but not configured.
27. Agent Lifecycle
For exam purposes, understand the lifecycle:
DISCOVER
|
v
ACQUIRE
|
v
SET UP
|
v
CONFIGURE
|
v
ENABLE
|
v
RUN
/ \
v v
Automatic Manual
|
v
PAUSE
|
v
EDIT
|
v
Manage Memory
|
v
REMOVE
Not every agent goes through exactly the same sequence, but this model is useful for scenario questions.
28. Agent States You Should Know
Microsoft’s Security Copilot agent experience distinguishes agents that are ready for configuration from agents that are already in use.
The custom-agent documentation describes:
Ready for setup
The agent has been made available but has not yet been configured.
Agents in use
The agent has been configured and is ready to run.
Conceptually:
Agent available
|
v
Ready for setup
|
v
Setup
|
v
Agents in use
|
v
Run / Pause
29. Security Copilot Owner and Contributor Roles
The Security Copilot Owner and Contributor roles are important when managing agents.
Microsoft states that Owners and Contributors can:
- Set up agents
- Edit agents
- Provide feedback
- Manage agent memory
- Run or pause agents
Specific capabilities can still depend on the agent and its required permissions.
Do not confuse these roles with Microsoft Entra roles.
For example:
Security Copilot Contributor ≠ Global Administrator
and
Security Copilot Owner ≠ Azure Owner
They are different authorization systems.
30. Agent Identity, Role-Based Access, and Permissions
When configuring an agent, three concepts can appear very similar but should be distinguished.
| Concept | Question it answers |
|---|---|
| Identity | Who/what is the agent when it runs? |
| Permissions | What information or actions can the agent access? |
| Role-based access | Which roles are required to turn on or run the agent? |
For example:
Agent | +--> Identity | "Who am I?" | +--> Permissions | "What can I access?" | +--> RBAC "Who is allowed to enable/run me?"
This distinction is valuable for scenario-based questions.
31. Embedded Versus Standalone Agents
Security Copilot agents can appear in both:
Standalone experience
The user accesses Security Copilot directly.
Embedded experience
Security Copilot capabilities and agents are integrated into other Microsoft security products.
Microsoft identifies integrated experiences across products including:
- Microsoft Defender
- Microsoft Sentinel
- Microsoft Intune
- Microsoft Entra
- Microsoft Purview
This matters because an agent’s availability can depend on how administrators configure access and which products and permissions are involved.
32. Common SC-500 Exam Traps
Trap 1: Assuming every agent is immediately usable
An agent generally needs to be set up and configured before it can be used.
Trap 2: Confusing an agent with a plugin
A plugin extends an agent’s capabilities.
An agent is the higher-level component that can use plugins, permissions, identities, triggers, and other configuration.
Think:
Agent → uses Plugin
not necessarily:
Plugin → is the Agent
Trap 3: Assuming the agent’s identity is the same as the administrator’s identity
An agent can have its own dedicated identity.
Microsoft recommends creating an agent identity where supported.
Trap 4: Assuming every partner agent requires Global Administrator approval
The special approval workflow applies when the partner-built agent needs access to Microsoft tools and Microsoft product data.
Partner agents that don’t require Microsoft product permissions don’t require that documented approval workflow.
Trap 5: Assuming Global Administrator must configure everything
Global Administrator approval may be required for the partner agent’s requested Microsoft permissions.
After approval, Security Copilot Owners and Contributors can complete the agent setup.
Trap 6: Assuming enabled dependent plugins are fully configured
A dependent plugin can be enabled for an agent but still require configuration.
Use:
Manage sources → Plugin → Configure
when required.
Trap 7: Confusing Security Store with Security Copilot
Security Store is used for discovering and acquiring partner agents and solutions.
Security Copilot is where agents are configured and operated.
Trap 8: Assuming removing an agent automatically cancels the subscription
Operational removal and subscription/billing management are separate considerations.
Trap 9: Giving the agent more permissions than necessary
Use least privilege.
Microsoft explicitly recommends using roles with the fewest permissions when setting up partner-built agents.
Trap 10: Confusing Run, Pause, and Remove
These are different lifecycle operations:
- Run → execute the agent
- Pause → temporarily stop operation
- Remove → remove the agent from the Security Copilot environment
33. Practical Configuration Example
Imagine an organization wants an agent that automatically generates a weekly threat-intelligence briefing.
The process might look like this:
Step 1 — Discover the agent
The security administrator opens:
Security Copilot → Agents
Step 2 — Select the agent
The administrator selects the Threat Intelligence Briefing Agent.
Step 3 — Review requirements
The administrator reviews:
- Identity
- Permissions
- Required products
- Plugins
- Trigger
- RBAC requirements
Step 4 — Configure identity
Where supported, create a dedicated agent identity.
Step 5 — Configure permissions
Grant only the permissions required by the agent.
Step 6 — Configure required plugins
Make sure required plugins are enabled and properly configured.
Step 7 — Configure the trigger
The agent can run according to its configured trigger.
Step 8 — Run/test
Run the agent and review the output.
Step 9 — Monitor
Allow the agent to operate according to the configured schedule.
This illustrates the broader pattern:
Discover → Review → Identity → Permissions → Plugins → Trigger → Run → Monitor
34. Practical Security Store Example
Suppose a company wants to deploy a partner-developed incident investigation agent.
The process could look like:
Security Copilot | vSecurity Store | vFind partner agent | vGet / Purchase / Subscribe | vAgent available in Security Copilot | vDoes it require Microsoft permissions? | +---+---+ | | Yes No | | v vGA consent Setup | | +---+---+ | v Configure identity | v Configure parameters/plugins | v Run
The exact commercial and consent requirements depend on the agent.
35. Exam-Focused Decision Tree
When you see an agent question, use this decision process:
Question 1: Who published it?
Microsoft → Microsoft-built agent
Partner → Partner-built agent
Question 2: Where did you find it?
Agents library → Security Copilot
Security Store → Security Store acquisition/discovery
Question 3: Does it require Microsoft product permissions?
Yes → Check the Global Administrator consent requirement for partner-built agents
No → That specific consent workflow isn’t required
Question 4: Does it have a dependent plugin?
Yes → Make sure the plugin is configured
No → Continue with normal setup
Question 5: What identity should it use?
Prefer a dedicated agent identity where supported and appropriate.
Question 6: How should it execute?
Choose the appropriate:
- Triggered execution
- Manual execution
- Pause/resume
Question 7: What permissions should it receive?
Apply least privilege.
36. High-Value Exam Comparison
| Scenario | Think |
|---|---|
| Find Microsoft-built agents | Security Copilot Agents library |
| Acquire partner-built agents | Security Store |
| Configure an agent | Security Copilot |
| Agent needs Microsoft product permissions | Global Administrator consent may be required for partner-built agents |
| Agent does not need Microsoft product permissions | No special Global Administrator approval workflow |
| Give agent its own identity | Create agent identity |
| Agent should use a user’s permissions | Existing user account |
| Agent requires additional capability | Plugin |
| Agent has dependent plugin but fails setup | Configure the plugin |
| Stop an agent temporarily | Pause |
| Change agent settings | Edit |
| Review stored agent feedback | Manage memory |
| Cancel partner subscription | Security Store |
| Control agent execution | Trigger / Run / Pause |
| Reduce security exposure | Least privilege |
37. Key Takeaways
For the SC-500 exam, remember these points:
- Security Copilot agents automate specialized security tasks and workflows.
- Microsoft-built agents can be discovered in the Security Copilot agent library.
- Partner-built agents can be discovered and acquired through Microsoft Security Store.
- An agent must generally be set up before it can be used.
- Agent setup can involve identity, permissions, plugins, products, triggers, and RBAC requirements.
- Where supported, Microsoft recommends using a dedicated agent identity.
- An existing user account can also be used, in which case the agent operates with that account’s permissions.
- Identity and permissions are different concepts.
- Plugins extend an agent’s capabilities.
- A dependent plugin can be enabled for an agent without being fully configured.
- Security Store handles acquisition and billing for partner offerings; Security Copilot handles agent configuration and operation.
- A partner-built agent that requires access to Microsoft tools and Microsoft product data requires the documented Global Administrator consent workflow.
- After consent, Security Copilot Owners and Contributors can complete the agent setup.
- Partner agents that don’t require Microsoft product permissions don’t require that specific Global Administrator approval workflow.
- Microsoft recommends using the fewest permissions necessary.
- Agents can be configured to run automatically or manually.
- Agents can be paused when they shouldn’t operate.
- Owners and Contributors can edit agents and manage agent memory.
- Removing an agent and managing a partner subscription are separate considerations.
- Always distinguish Microsoft-built agents, partner-built agents, plugins, Security Store, identities, permissions, triggers, and agent lifecycle states.
Practice Exam Questions
Question 1
A security administrator wants to use a Microsoft-built Security Copilot agent for the first time. The agent appears in the Security Copilot Agents library but has not been configured.
What should the administrator do first?
A. Select the agent and choose Set up.
B. Purchase the agent through Microsoft Security Store.
C. Assign the Global Administrator role to the agent.
D. Create a custom plugin for the agent.
Answer: A
Explanation: Microsoft-built agents must be set up before they can be used. The administrator can select the agent from the Security Copilot Agents library and select Set up. Microsoft agents do not require the partner-agent acquisition workflow simply because they are Microsoft-built.
Question 2
An organization wants a Security Copilot agent to have its own identity and permissions rather than using an employee’s account.
Which option should the administrator select when configuring the agent?
A. Create an agent identity
B. Security Copilot Contributor
C. Microsoft Entra Global Administrator
D. Security Store subscription identity
Answer: A
Explanation: Microsoft-built agents can be configured with a dedicated agent identity. Microsoft recommends creating an agent identity where that option is available.
Question 3
A company acquires a partner-built Security Copilot agent. During setup, the agent requests access to Microsoft Sentinel and Microsoft Defender data.
What is required before the Security Copilot Owner can complete the setup?
A. The agent must first be converted into a Microsoft-built agent.
B. A Security Copilot Contributor must approve the permissions.
C. The agent must be published to Security Store again.
D. A Global Administrator must approve the required Microsoft permissions.
Answer: D
Explanation: When a partner-built agent requires access to Microsoft tools and Microsoft product data, a Global Administrator in the tenant must approve the required permissions. After approval, the Security Copilot Owner or Contributor can complete setup.
Question 4
A partner-built agent does not access Microsoft product data or require Microsoft product permissions.
Is the documented Global Administrator approval workflow required?
A. Yes, all partner agents require Global Administrator approval.
B. Yes, but only when the agent uses a trigger.
C. Yes, but only when the agent uses a plugin.
D. No, that specific approval workflow isn’t required when Microsoft product permissions aren’t needed.
Answer: D
Explanation: Microsoft specifically states that partner-built agents that don’t require Microsoft product permissions do not require the documented Global Administrator approval workflow.
Question 5
A Security Copilot Owner has received Global Administrator approval for a partner-built agent. What can the Owner do next?
A. Nothing; the Global Administrator must perform the remainder of the configuration.
B. Delete the agent and reinstall it.
C. Complete the agent setup, including configuring identity, trigger, and other required values.
D. Convert the agent into a custom plugin.
Answer: C
Explanation: After Global Administrator approval, Security Copilot Owners and Contributors can finish setting up the partner-built agent, including identity, trigger, and other configuration values.
Question 6
An agent obtained through Security Store has a dependent plugin. The agent appears in Security Copilot, but it cannot operate successfully.
What should the administrator check?
A. Whether the dependent plugin has been configured.
B. Whether the agent has been converted to a Microsoft-built agent.
C. Whether the Security Copilot workspace has been deleted.
D. Whether the user has been assigned Global Administrator permanently.
Answer: A
Explanation: A dependent plugin can be enabled for an agent but still require configuration. Microsoft directs administrators to Manage sources, find the plugin, and configure it before using the agent successfully.
Question 7
A security team wants to temporarily stop an automated Security Copilot agent while investigating an issue with its behavior. They don’t want to remove the agent.
What should they do?
A. Delete the agent.
B. Pause the agent.
C. Remove its Security Copilot license.
D. Delete all of its plugins.
Answer: B
Explanation: Security Copilot allows an agent to be paused so that it temporarily stops operating. The agent can later be resumed. This is different from deleting or removing the agent.
Question 8
An organization wants to obtain a partner-built security agent and manage its acquisition and subscription.
Where should the organization perform the purchasing or subscription activity?
A. Azure Policy
B. Microsoft Entra admin center only
C. Security Copilot agent configuration
D. Microsoft Security Store
Answer: D
Explanation: Security Store is the security-focused storefront for discovering and acquiring Microsoft and partner-built security solutions and agents. Purchasing and subscription management are handled separately from the operational configuration of agents in Security Copilot.
Question 9
A Security Copilot administrator wants to give an agent only the access required to perform its assigned security task.
Which security principle should guide the configuration?
A. Least privilege
B. Full administrative access
C. Global Administrator inheritance
D. Shared credentials
Answer: A
Explanation: Microsoft recommends using roles with the fewest permissions when configuring partner-built agents. Least privilege reduces unnecessary access and limits the potential impact of a compromised or misconfigured agent.
Question 10
An administrator wants a Security Copilot agent to operate automatically when its configured condition occurs, rather than requiring a user to start it each time.
Which agent configuration should the administrator use?
A. User identity
B. Security Store subscription
C. Trigger
D. Agent memory
Answer: C
Explanation: A trigger is an event or condition that causes an agentic system to initiate an action or series of actions. Security Copilot supports automatic execution based on configured triggers as well as manual one-time execution.
Final Exam Mental Model
When an SC-500 question asks you to enable or configure a Microsoft or Security Store agent, use this sequence:
1. Identify the agent source
→ Microsoft-built
→ Partner-built
2. Find/acquire it
→ Security Copilot Agents library
→ Security Store
3. Determine whether consent is required
→ Does a partner agent need Microsoft product permissions?
4. Configure identity
→ Prefer a dedicated agent identity when supported
→ Or use an existing user account when appropriate
5. Configure permissions
→ Apply least privilege
6. Configure dependencies
→ Required products
→ Plugins
→ Input parameters
7. Configure execution
→ Trigger
→ Manual run
→ Pause/resume
8. Manage afterward
→ Edit
→ Review memory
→ Monitor
→ Remove when no longer required
The most important distinctions to remember are:
Microsoft agent vs. partner agent
Security Copilot vs. Security Store
Identity vs. permissions
Plugin enabled vs. plugin configured
Global Administrator consent vs. ongoing agent administration
Purchase/subscription vs. operational management
Run vs. pause vs. remove
Go to the SC-500 Exam Prep Hub main page
