Tag: Security Store Agents

Enable and configure Microsoft agents and Security Store agents (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Implement Microsoft Security Copilot
      --> Enable and configure Microsoft agents and Security Store agents


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Microsoft Security Copilot extends beyond interactive prompting through security agents.

Agents are specialized AI-driven components designed to perform particular security or operational tasks. They can gather information, analyze security data, provide recommendations, and in some scenarios perform actions based on configured triggers, permissions, identities, plugins, and other parameters.

For the SC-500 exam, you should understand two important categories of agents:

  1. Microsoft-built agents
  2. Partner-built agents obtained through Microsoft Security Store

Microsoft Security Copilot provides an agent library where Microsoft and partner-built agents can be discovered and configured. Security Store provides an integrated storefront for discovering and acquiring Microsoft and partner security agents and solutions.

The current Microsoft training module specifically identifies the following objectives for this topic:

  • Discover and set up Microsoft-built agents using the Security Copilot agent library.
  • Acquire and configure partner-built agents through Security Store.
  • Understand the Global Administrator approval workflow.
  • Manage agent run state.
  • Edit agent configuration.
  • Manage agent memory.

1. What Is a Security Copilot Agent?

A Security Copilot agent is a specialized AI component designed to perform a particular security task or workflow.

An agent can combine:

  • An identity
  • Permissions
  • Plugins
  • Microsoft security products
  • Triggers
  • Input parameters
  • Security Copilot capabilities
  • Specialized instructions or logic

A useful mental model is:

                    Security Copilot Agent
                            |
          +-----------------+-----------------+
          |                 |                 |
          v                 v                 v
       Identity         Permissions        Plugins
          |                 |                 |
          v                 v                 v
     Who is the        What can the       What can the
       agent?            agent access?       agent use?
          |                 |                 |
          +-----------------+-----------------+
                            |
                            v
                         Trigger
                            |
                            v
                     Agent execution
                            |
                            v
                    Security result/action

Microsoft describes an agent’s identity as the credentials it uses when it runs, while permissions determine what information or tasks the agent is authorized to access or perform. Plugins extend what the agent can do by connecting it to capabilities in Microsoft and non-Microsoft services and public websites.


2. Microsoft-Built Agents

Microsoft-built agents are agents created and published by Microsoft.

They are designed for particular security scenarios and can be discovered through the Security Copilot agent library.

Microsoft provides agents across areas such as:

  • Microsoft Entra
  • Microsoft Defender
  • Microsoft Intune
  • Microsoft Purview
  • Microsoft Sentinel
  • Security Copilot

Agents may also be available through embedded experiences within Microsoft security products.

Example

Microsoft provides a Threat Intelligence Briefing Agent that can generate threat-intelligence reports using Microsoft threat data and related security information.

The agent has defined requirements for:

  • Identity
  • Licensing
  • Permissions
  • Products
  • Plugins
  • Role-based access
  • Triggering

This illustrates an important exam concept:

An agent is more than an AI prompt. It is a configured security workload with an identity, permissions, dependencies, and execution behavior.


3. Discovering Microsoft-Built Agents

To discover Microsoft-built agents in the standalone Security Copilot experience:

  1. Sign in to Microsoft Security Copilot.
  2. Select Agents from the navigation pane.
  3. The agent library appears.
  4. Browse or select the agent you want to use.
  5. Select Set up.

Microsoft indicates that the agent must be set up before it can be used.

Conceptually:

Security Copilot
|
v
Agents
|
v
Agent Library
|
v
Select Agent
|
v
Set up
|
v
Configure Agent
|
v
Run

4. Agent Setup

When setting up a Microsoft-built agent, you may need to configure several components.

Microsoft identifies the following concepts as possible agent parameters:

ComponentPurpose
TriggerDetermines what event or condition initiates the agent
PermissionsDetermines what information or actions the agent is authorized to access
IdentityProvides credentials used when the agent runs
PluginsExtend the agent’s capabilities
ProductsMicrosoft products required by the agent
Role-based accessRoles or permissions required to turn on or run the agent

Not every agent necessarily requires configuration of every parameter. The exact setup requirements vary by agent.


5. Agent Identity

Agent identity is one of the most important security concepts in the exam.

An agent needs an identity so that it can authenticate and securely access resources when it runs.

During setup, Microsoft-built agents can provide two identity options:

  • Create an agent identity
  • Use an existing user account

Microsoft recommends creating an agent identity where that option is available.


6. Dedicated Agent Identity

A dedicated agent identity gives the agent its own identity rather than making the agent dependent on an individual user’s account.

Conceptually:

              Agent
                |
                v
        Dedicated identity
                |
                v
        Assigned permissions
                |
                v
       Required resources

This can make access easier to control because the agent’s access can be managed independently of a specific employee.

Microsoft describes Microsoft Entra Agent ID as providing identities specifically for AI agents. The setup process allows permissions to be granted to the agent identity so that the agent can perform its required functions.


7. Using an Existing User Account

An alternative is to connect an existing user account.

In this model:

User account
|
v
Agent execution
|
v
User's permissions

The agent inherits the access and permissions associated with that account while it is active.

This can be appropriate in scenarios where the agent specifically needs to operate in the context of a user.

However, from a security-design perspective, you should understand the difference between:

Agent identity

and

User identity

because they produce different authorization and lifecycle considerations.

Exam clue

If a question asks:

“Which identity should be used to give the agent its own dedicated access?”

Think:

Agent identity.

If the question says:

“The agent should operate using the user’s existing permissions.”

Think:

Existing user account.


8. Agent Permissions

An agent’s identity determines who or what the agent is, while permissions determine what the agent can do.

For example:

Identity
|
+--> Authentication
|
v
Permissions
|
+--> Read security data
+--> Investigate alerts
+--> Query threat intelligence
+--> Perform authorized actions

An agent should receive only the permissions required for its intended workload.

This follows the principle of least privilege.

Microsoft specifically recommends using roles with the fewest permissions when configuring partner-built agents.


9. Plugins Used by Agents

Agents can use plugins to extend their capabilities.

A plugin can provide access to:

  • Microsoft services
  • Non-Microsoft services
  • Public websites
  • APIs
  • Threat-intelligence systems
  • Other security capabilities

Therefore:

Agent
|
+---- Plugin 1 --> Microsoft service
|
+---- Plugin 2 --> External API
|
+---- Plugin 3 --> Threat intelligence

An agent’s required plugins are part of its configuration.

Microsoft identifies plugins as components that extend an agent’s capabilities by providing access to Microsoft and non-Microsoft services and public websites through APIs.


10. Required Plugins

Some agents have dependent or required plugins.

When an agent requires a plugin, that plugin can be enabled for the agent.

However, there is an important distinction:

Enabled for the agent does not necessarily mean the plugin has been fully configured.

For an agent obtained through Security Store, Microsoft states that if the agent has a dependent plugin, the plugin is enabled for the agent but may still require configuration.

The administrator must go to:

Manage sources → Find the plugin → Configure the plugin

and complete the required configuration.

Exam scenario

An administrator obtains a Security Store agent.

The agent appears to be installed, but it does not run successfully.

The agent has a dependent plugin.

What should the administrator check?

The plugin’s configuration.

Do not assume that because the plugin is enabled for the agent, the plugin is completely configured.


11. Triggers

A trigger determines when an agent starts.

An agent may be configured to:

  • Run automatically based on a trigger
  • Run manually
  • Run according to a schedule
  • Be paused

Microsoft defines a trigger as an event or condition that tells an agentic system to initiate an action or series of actions.

Conceptually:

Event / Condition
|
v
Trigger
|
v
Agent
|
v
Investigation
|
v
Result / Action

12. Automatic Versus Manual Execution

Security Copilot allows an agent to operate automatically or manually.

Automatic

The agent runs when its configured trigger occurs.

Manual

An administrator or user can initiate a one-time execution.

Microsoft also allows an agent to be paused when it is not required to operate.

Example

An organization configures an agent to run every seven days.

If the organization wants to stop automatic executions temporarily, it can pause the agent.

The agent can later be resumed.


13. Pausing an Agent

Pausing an agent temporarily stops its operation.

This is useful when:

  • The underlying service is undergoing maintenance.
  • The agent is being investigated.
  • A security issue has been identified.
  • The agent is temporarily unnecessary.
  • The organization wants to stop automated execution without deleting the agent.

Pausing is therefore different from removing or deleting an agent.

RUNNING
|
v
PAUSED
|
v
RESUMED

14. Editing an Agent

Owners and Contributors can edit agents.

Editing can include modifying:

  • Identity
  • Trigger configuration
  • Other available parameters
  • Agent settings

Microsoft states that Owners and Contributors can edit an agent to modify its configuration.

Important distinction

Being able to run an agent does not necessarily mean being able to perform every administrative operation associated with the agent.

Always distinguish:

  • Discover
  • Set up
  • Run
  • Pause
  • Edit
  • Manage permissions
  • Manage identity

when analyzing an exam scenario.


15. Agent Memory

Security Copilot agents can maintain memory associated with feedback and configuration.

Owners and Contributors can provide feedback to an agent.

That feedback can become part of the agent’s memory and influence subsequent operation.

An administrator can review the agent’s memory and reject feedback that should no longer be retained.

Process

Agent output
|
v
Provide feedback
|
v
Feedback stored in memory
|
v
Agent considers memory
|
v
Future operation

To manage memory:

  1. Open the agent.
  2. Select the … menu.
  3. Select Manage memory.
  4. Review stored feedback.
  5. Select feedback.
  6. Use Reject feedback when appropriate.

16. Microsoft Security Store

Microsoft Security Store is a security-focused storefront for discovering, evaluating, acquiring, and deploying Microsoft and partner-built security solutions and agents.

It integrates with Microsoft security products including:

  • Microsoft Defender
  • Microsoft Sentinel
  • Microsoft Entra
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Security Copilot

Security Store is integrated into the standalone Security Copilot experience.


17. Microsoft Agents Versus Partner Agents

This distinction is important for SC-500.

CharacteristicMicrosoft-built agentPartner-built agent
PublisherMicrosoftMicrosoft partner
DiscoverySecurity Copilot agent library / Security StoreSecurity Store
SetupSecurity CopilotSecurity Copilot after acquisition
May require Microsoft permissionsYesYes
Global Administrator consentNot necessarily the same partner-agent workflowRequired when the partner agent needs certain Microsoft product permissions
Identity configurationYesYes
PluginsMay be requiredMay be required
Commercial termsDepend on agent/prerequisitesMay require separate purchase/subscription

Microsoft’s current documentation distinguishes Microsoft-built and partner-built agent setup, including a specific consent workflow for partner-built agents that require access to Microsoft tools and data.


18. Discovering Agents Through Security Store

From Security Copilot, users can navigate to:

Home → Security Store

They can then:

  1. Search for an agent.
  2. Filter by publisher, product, or pricing.
  3. Select the desired agent.
  4. Select Get agent.

Microsoft-built agents are routed to the Active agents experience.

Non-Microsoft agents are routed through Security Store for purchase or subscription where required.


19. Purchasing Versus Operating an Agent

This is an important exam distinction.

Security Store handles acquisition and billing.

Security Copilot handles agent configuration and operation.

Conceptually:

             Security Store
                   |
                   v
          Find / Purchase / Subscribe
                   |
                   v
              Get Agent
                   |
                   v
          Microsoft Security Copilot
                   |
                   v
          Configure / Run / Pause
                   |
                   v
              Manage Agent

Microsoft explicitly separates purchasing/subscription management from operational management in Security Copilot.


20. Removing an Agent Versus Ending a Subscription

A particularly important Security Store concept:

Removing an agent from Security Copilot and managing its commercial subscription are separate considerations.

Microsoft’s Security Store documentation states that purchases and subscriptions are handled separately from the Security Copilot platform.

For partner agents, billing and entitlement information may need to be managed through Security Store.

Exam clue

If the question says:

“Remove the agent from Security Copilot.”

Think:

Operational removal.

If the question says:

“Cancel the partner subscription.”

Think:

Security Store / subscription management.

Do not automatically treat the two as the same operation.


21. Security Compute Units

Using agents within Security Copilot consumes Security Compute Units (SCUs).

SCU consumption is distinct from any separate subscription or licensing fees associated with a partner agent.

This creates two potentially separate considerations:

Partner Agent
|
+---- Partner subscription / license
|
+---- Security Copilot usage
|
+---- SCUs

For exam purposes, remember:

Partner-agent acquisition costs and Security Copilot compute usage are not necessarily the same charge.


22. Partner Agent Global Administrator Consent

This is one of the most important exam scenarios.

Suppose an organization wants to deploy a partner-built Security Copilot agent.

The agent needs to access:

  • Microsoft Entra
  • Microsoft Intune
  • Microsoft Sentinel
  • Microsoft Defender
  • Defender Threat Intelligence

and therefore requires permissions to Microsoft services.

A Global Administrator must approve the required permissions for the partner-built agent.

The workflow is:

Security Copilot Owner/Contributor
|
v
Begin agent setup
|
v
Consent required banner
|
v
Copy approval link
|
v
Global Administrator
|
v
Review permissions
|
v
Approve access
|
v
Owner/Contributor completes setup

23. What the Global Administrator Does

The Global Administrator should review the agent’s requested permissions before approving the agent.

The approval interface can provide information such as:

  • Agent details
  • Description
  • Trigger
  • Required permissions
  • Other configuration information

The administrator starts the approval process and grants the necessary permissions.

Security principle

Microsoft explicitly recommends using the fewest permissions possible.

Global Administrator is a highly privileged role and should not be used unnecessarily.


24. What Happens After Consent?

Once Global Administrator approval is complete:

Security Copilot Owners and Contributors can finish the agent setup.

They can configure items such as:

  • Identity
  • Trigger
  • Input parameters
  • Other agent-specific settings

They do not necessarily need to remain Global Administrators simply because the initial consent required Global Administrator approval.

This distinction is highly relevant to least-privilege exam questions.


25. When Global Administrator Approval Isn’t Required

Global Administrator approval is required in the documented partner-agent scenario when the agent needs access to Microsoft tools and Microsoft product data.

However:

If the partner-built agent does not require Microsoft product permissions, the documented Global Administrator approval isn’t required.

Example

A partner-built agent only processes information through its own external service and does not request access to Microsoft product data.

The special Microsoft-product consent workflow does not apply.


26. Security Store Agent With a Dependent Plugin

This is an especially useful scenario to remember.

Suppose:

  1. You obtain a partner agent through Security Store.
  2. The agent has a dependent plugin.
  3. The agent appears in Security Copilot.
  4. The agent still doesn’t operate successfully.

The likely next step is to configure the dependent plugin.

Microsoft’s documented process is:

Manage sources → Find the plugin → Configure the plugin

The plugin may already be enabled for the agent but not configured.


27. Agent Lifecycle

For exam purposes, understand the lifecycle:

             DISCOVER
                 |
                 v
              ACQUIRE
                 |
                 v
                SET UP
                 |
                 v
             CONFIGURE
                 |
                 v
               ENABLE
                 |
                 v
                RUN
              /     \
             v       v
        Automatic   Manual
             |
             v
            PAUSE
             |
             v
            EDIT
             |
             v
        Manage Memory
             |
             v
          REMOVE

Not every agent goes through exactly the same sequence, but this model is useful for scenario questions.


28. Agent States You Should Know

Microsoft’s Security Copilot agent experience distinguishes agents that are ready for configuration from agents that are already in use.

The custom-agent documentation describes:

Ready for setup

The agent has been made available but has not yet been configured.

Agents in use

The agent has been configured and is ready to run.

Conceptually:

             Agent available
                   |
                   v
             Ready for setup
                   |
                   v
                  Setup
                   |
                   v
             Agents in use
                   |
                   v
              Run / Pause

29. Security Copilot Owner and Contributor Roles

The Security Copilot Owner and Contributor roles are important when managing agents.

Microsoft states that Owners and Contributors can:

  • Set up agents
  • Edit agents
  • Provide feedback
  • Manage agent memory
  • Run or pause agents

Specific capabilities can still depend on the agent and its required permissions.

Do not confuse these roles with Microsoft Entra roles.

For example:

Security Copilot Contributor ≠ Global Administrator

and

Security Copilot Owner ≠ Azure Owner

They are different authorization systems.


30. Agent Identity, Role-Based Access, and Permissions

When configuring an agent, three concepts can appear very similar but should be distinguished.

ConceptQuestion it answers
IdentityWho/what is the agent when it runs?
PermissionsWhat information or actions can the agent access?
Role-based accessWhich roles are required to turn on or run the agent?

For example:

Agent
|
+--> Identity
| "Who am I?"
|
+--> Permissions
| "What can I access?"
|
+--> RBAC
"Who is allowed to enable/run me?"

This distinction is valuable for scenario-based questions.


31. Embedded Versus Standalone Agents

Security Copilot agents can appear in both:

Standalone experience

The user accesses Security Copilot directly.

Embedded experience

Security Copilot capabilities and agents are integrated into other Microsoft security products.

Microsoft identifies integrated experiences across products including:

  • Microsoft Defender
  • Microsoft Sentinel
  • Microsoft Intune
  • Microsoft Entra
  • Microsoft Purview

This matters because an agent’s availability can depend on how administrators configure access and which products and permissions are involved.


32. Common SC-500 Exam Traps

Trap 1: Assuming every agent is immediately usable

An agent generally needs to be set up and configured before it can be used.


Trap 2: Confusing an agent with a plugin

A plugin extends an agent’s capabilities.

An agent is the higher-level component that can use plugins, permissions, identities, triggers, and other configuration.

Think:

Agent → uses Plugin

not necessarily:

Plugin → is the Agent


Trap 3: Assuming the agent’s identity is the same as the administrator’s identity

An agent can have its own dedicated identity.

Microsoft recommends creating an agent identity where supported.


Trap 4: Assuming every partner agent requires Global Administrator approval

The special approval workflow applies when the partner-built agent needs access to Microsoft tools and Microsoft product data.

Partner agents that don’t require Microsoft product permissions don’t require that documented approval workflow.


Trap 5: Assuming Global Administrator must configure everything

Global Administrator approval may be required for the partner agent’s requested Microsoft permissions.

After approval, Security Copilot Owners and Contributors can complete the agent setup.


Trap 6: Assuming enabled dependent plugins are fully configured

A dependent plugin can be enabled for an agent but still require configuration.

Use:

Manage sources → Plugin → Configure

when required.


Trap 7: Confusing Security Store with Security Copilot

Security Store is used for discovering and acquiring partner agents and solutions.

Security Copilot is where agents are configured and operated.


Trap 8: Assuming removing an agent automatically cancels the subscription

Operational removal and subscription/billing management are separate considerations.


Trap 9: Giving the agent more permissions than necessary

Use least privilege.

Microsoft explicitly recommends using roles with the fewest permissions when setting up partner-built agents.


Trap 10: Confusing Run, Pause, and Remove

These are different lifecycle operations:

  • Run → execute the agent
  • Pause → temporarily stop operation
  • Remove → remove the agent from the Security Copilot environment

33. Practical Configuration Example

Imagine an organization wants an agent that automatically generates a weekly threat-intelligence briefing.

The process might look like this:

Step 1 — Discover the agent

The security administrator opens:

Security Copilot → Agents

Step 2 — Select the agent

The administrator selects the Threat Intelligence Briefing Agent.

Step 3 — Review requirements

The administrator reviews:

  • Identity
  • Permissions
  • Required products
  • Plugins
  • Trigger
  • RBAC requirements

Step 4 — Configure identity

Where supported, create a dedicated agent identity.

Step 5 — Configure permissions

Grant only the permissions required by the agent.

Step 6 — Configure required plugins

Make sure required plugins are enabled and properly configured.

Step 7 — Configure the trigger

The agent can run according to its configured trigger.

Step 8 — Run/test

Run the agent and review the output.

Step 9 — Monitor

Allow the agent to operate according to the configured schedule.

This illustrates the broader pattern:

Discover → Review → Identity → Permissions → Plugins → Trigger → Run → Monitor


34. Practical Security Store Example

Suppose a company wants to deploy a partner-developed incident investigation agent.

The process could look like:

Security Copilot
|
v
Security Store
|
v
Find partner agent
|
v
Get / Purchase / Subscribe
|
v
Agent available in Security Copilot
|
v
Does it require Microsoft permissions?
|
+---+---+
| |
Yes No
| |
v v
GA consent Setup
| |
+---+---+
|
v
Configure identity
|
v
Configure parameters/plugins
|
v
Run

The exact commercial and consent requirements depend on the agent.


35. Exam-Focused Decision Tree

When you see an agent question, use this decision process:

Question 1: Who published it?

Microsoft → Microsoft-built agent

Partner → Partner-built agent

Question 2: Where did you find it?

Agents library → Security Copilot

Security Store → Security Store acquisition/discovery

Question 3: Does it require Microsoft product permissions?

Yes → Check the Global Administrator consent requirement for partner-built agents

No → That specific consent workflow isn’t required

Question 4: Does it have a dependent plugin?

Yes → Make sure the plugin is configured

No → Continue with normal setup

Question 5: What identity should it use?

Prefer a dedicated agent identity where supported and appropriate.

Question 6: How should it execute?

Choose the appropriate:

  • Triggered execution
  • Manual execution
  • Pause/resume

Question 7: What permissions should it receive?

Apply least privilege.


36. High-Value Exam Comparison

ScenarioThink
Find Microsoft-built agentsSecurity Copilot Agents library
Acquire partner-built agentsSecurity Store
Configure an agentSecurity Copilot
Agent needs Microsoft product permissionsGlobal Administrator consent may be required for partner-built agents
Agent does not need Microsoft product permissionsNo special Global Administrator approval workflow
Give agent its own identityCreate agent identity
Agent should use a user’s permissionsExisting user account
Agent requires additional capabilityPlugin
Agent has dependent plugin but fails setupConfigure the plugin
Stop an agent temporarilyPause
Change agent settingsEdit
Review stored agent feedbackManage memory
Cancel partner subscriptionSecurity Store
Control agent executionTrigger / Run / Pause
Reduce security exposureLeast privilege

37. Key Takeaways

For the SC-500 exam, remember these points:

  1. Security Copilot agents automate specialized security tasks and workflows.
  2. Microsoft-built agents can be discovered in the Security Copilot agent library.
  3. Partner-built agents can be discovered and acquired through Microsoft Security Store.
  4. An agent must generally be set up before it can be used.
  5. Agent setup can involve identity, permissions, plugins, products, triggers, and RBAC requirements.
  6. Where supported, Microsoft recommends using a dedicated agent identity.
  7. An existing user account can also be used, in which case the agent operates with that account’s permissions.
  8. Identity and permissions are different concepts.
  9. Plugins extend an agent’s capabilities.
  10. A dependent plugin can be enabled for an agent without being fully configured.
  11. Security Store handles acquisition and billing for partner offerings; Security Copilot handles agent configuration and operation.
  12. A partner-built agent that requires access to Microsoft tools and Microsoft product data requires the documented Global Administrator consent workflow.
  13. After consent, Security Copilot Owners and Contributors can complete the agent setup.
  14. Partner agents that don’t require Microsoft product permissions don’t require that specific Global Administrator approval workflow.
  15. Microsoft recommends using the fewest permissions necessary.
  16. Agents can be configured to run automatically or manually.
  17. Agents can be paused when they shouldn’t operate.
  18. Owners and Contributors can edit agents and manage agent memory.
  19. Removing an agent and managing a partner subscription are separate considerations.
  20. Always distinguish Microsoft-built agents, partner-built agents, plugins, Security Store, identities, permissions, triggers, and agent lifecycle states.

Practice Exam Questions

Question 1

A security administrator wants to use a Microsoft-built Security Copilot agent for the first time. The agent appears in the Security Copilot Agents library but has not been configured.

What should the administrator do first?

A. Select the agent and choose Set up.

B. Purchase the agent through Microsoft Security Store.

C. Assign the Global Administrator role to the agent.

D. Create a custom plugin for the agent.

Answer: A

Explanation: Microsoft-built agents must be set up before they can be used. The administrator can select the agent from the Security Copilot Agents library and select Set up. Microsoft agents do not require the partner-agent acquisition workflow simply because they are Microsoft-built.


Question 2

An organization wants a Security Copilot agent to have its own identity and permissions rather than using an employee’s account.

Which option should the administrator select when configuring the agent?

A. Create an agent identity

B. Security Copilot Contributor

C. Microsoft Entra Global Administrator

D. Security Store subscription identity

Answer: A

Explanation: Microsoft-built agents can be configured with a dedicated agent identity. Microsoft recommends creating an agent identity where that option is available.


Question 3

A company acquires a partner-built Security Copilot agent. During setup, the agent requests access to Microsoft Sentinel and Microsoft Defender data.

What is required before the Security Copilot Owner can complete the setup?

A. The agent must first be converted into a Microsoft-built agent.

B. A Security Copilot Contributor must approve the permissions.

C. The agent must be published to Security Store again.

D. A Global Administrator must approve the required Microsoft permissions.

Answer: D

Explanation: When a partner-built agent requires access to Microsoft tools and Microsoft product data, a Global Administrator in the tenant must approve the required permissions. After approval, the Security Copilot Owner or Contributor can complete setup.


Question 4

A partner-built agent does not access Microsoft product data or require Microsoft product permissions.

Is the documented Global Administrator approval workflow required?

A. Yes, all partner agents require Global Administrator approval.

B. Yes, but only when the agent uses a trigger.

C. Yes, but only when the agent uses a plugin.

D. No, that specific approval workflow isn’t required when Microsoft product permissions aren’t needed.

Answer: D

Explanation: Microsoft specifically states that partner-built agents that don’t require Microsoft product permissions do not require the documented Global Administrator approval workflow.


Question 5

A Security Copilot Owner has received Global Administrator approval for a partner-built agent. What can the Owner do next?

A. Nothing; the Global Administrator must perform the remainder of the configuration.

B. Delete the agent and reinstall it.

C. Complete the agent setup, including configuring identity, trigger, and other required values.

D. Convert the agent into a custom plugin.

Answer: C

Explanation: After Global Administrator approval, Security Copilot Owners and Contributors can finish setting up the partner-built agent, including identity, trigger, and other configuration values.


Question 6

An agent obtained through Security Store has a dependent plugin. The agent appears in Security Copilot, but it cannot operate successfully.

What should the administrator check?

A. Whether the dependent plugin has been configured.

B. Whether the agent has been converted to a Microsoft-built agent.

C. Whether the Security Copilot workspace has been deleted.

D. Whether the user has been assigned Global Administrator permanently.

Answer: A

Explanation: A dependent plugin can be enabled for an agent but still require configuration. Microsoft directs administrators to Manage sources, find the plugin, and configure it before using the agent successfully.


Question 7

A security team wants to temporarily stop an automated Security Copilot agent while investigating an issue with its behavior. They don’t want to remove the agent.

What should they do?

A. Delete the agent.

B. Pause the agent.

C. Remove its Security Copilot license.

D. Delete all of its plugins.

Answer: B

Explanation: Security Copilot allows an agent to be paused so that it temporarily stops operating. The agent can later be resumed. This is different from deleting or removing the agent.


Question 8

An organization wants to obtain a partner-built security agent and manage its acquisition and subscription.

Where should the organization perform the purchasing or subscription activity?

A. Azure Policy

B. Microsoft Entra admin center only

C. Security Copilot agent configuration

D. Microsoft Security Store

Answer: D

Explanation: Security Store is the security-focused storefront for discovering and acquiring Microsoft and partner-built security solutions and agents. Purchasing and subscription management are handled separately from the operational configuration of agents in Security Copilot.


Question 9

A Security Copilot administrator wants to give an agent only the access required to perform its assigned security task.

Which security principle should guide the configuration?

A. Least privilege

B. Full administrative access

C. Global Administrator inheritance

D. Shared credentials

Answer: A

Explanation: Microsoft recommends using roles with the fewest permissions when configuring partner-built agents. Least privilege reduces unnecessary access and limits the potential impact of a compromised or misconfigured agent.


Question 10

An administrator wants a Security Copilot agent to operate automatically when its configured condition occurs, rather than requiring a user to start it each time.

Which agent configuration should the administrator use?

A. User identity

B. Security Store subscription

C. Trigger

D. Agent memory

Answer: C

Explanation: A trigger is an event or condition that causes an agentic system to initiate an action or series of actions. Security Copilot supports automatic execution based on configured triggers as well as manual one-time execution.


Final Exam Mental Model

When an SC-500 question asks you to enable or configure a Microsoft or Security Store agent, use this sequence:

1. Identify the agent source

→ Microsoft-built
→ Partner-built

2. Find/acquire it

→ Security Copilot Agents library
→ Security Store

3. Determine whether consent is required

→ Does a partner agent need Microsoft product permissions?

4. Configure identity

→ Prefer a dedicated agent identity when supported
→ Or use an existing user account when appropriate

5. Configure permissions

→ Apply least privilege

6. Configure dependencies

→ Required products
→ Plugins
→ Input parameters

7. Configure execution

→ Trigger
→ Manual run
→ Pause/resume

8. Manage afterward

→ Edit
→ Review memory
→ Monitor
→ Remove when no longer required

The most important distinctions to remember are:

Microsoft agent vs. partner agent
Security Copilot vs. Security Store
Identity vs. permissions
Plugin enabled vs. plugin configured
Global Administrator consent vs. ongoing agent administration
Purchase/subscription vs. operational management
Run vs. pause vs. remove


Go to the SC-500 Exam Prep Hub main page