Analysts and an AI robot monitor global network dashboards in a futuristic operations center.
Microsoft published a customer story on September 23, 2026. It says consulting firm ZS moved its SIEM and SOAR tooling to Microsoft Sentinel and then added Microsoft Security Copilot to four analyst workflows: threat hunting, incident investigation, detection engineering and script analysis. ZS's internal tracking reports about 5,000 tasks automated at roughly 80% accuracy. The order of work is the most useful part of the story. ZS rebuilt its data foundation first, then added AI to specific tasks, and it says analysts still make the final call. The headline number deserves care. It comes from a vendor customer story, and the story never says what counts as a task or how accuracy was scored.

No outlet has reported on the ZS deployment independently. Everything below about ZS comes from Microsoft's customer story and the ZS executives quoted in it. The licensing and product details come from Microsoft's own documentation and pricing pages, and they apply to any organization weighing a similar project.

ZS Moved to Microsoft Sentinel Before It Added Security Copilot​

Microsoft describes ZS as a management consulting and technology firm founded in 1983, with more than 15,000 professionals in over 40 offices. Its clients are in healthcare, life sciences and other highly regulated industries. The story's metadata puts the company in the "1,000–9,999 employees" band, which doesn't match the 15,000 figure. Microsoft doesn't explain the gap.

ZS already had a working Security Operations Center (SOC) handling threat hunting, detection engineering and incident response. According to Atman Trivedi, ZS's director of information security, the aim was to run those functions consistently across a global environment while keeping analysts on the higher-value decisions. The team specifically wanted less manual work gathering context, writing summaries and turning security signals into clear decisions. It also didn't want to weaken what the story calls a strict governance and human-led accountability model.

The project ran in phases. ZS first moved its SIEM (security information and event management) and SOAR (security orchestration, automation and response) capabilities to Microsoft Sentinel. It connected priority log sources and set up analytics and automation there. Only once that central base across the Microsoft Security stack was in place did ZS bring in Security Copilot. The story doesn't name the tools ZS replaced, list the log sources it connected, or give any dates. Readers shouldn't try to rebuild ZS's architecture from this account.

This sequence is a real lesson for other SOC teams. An AI assistant that answers natural-language questions about security data can only draw on the data it can reach. Microsoft says Sentinel gave ZS that centralized base, and Copilot was added afterward. Trivedi says Copilot changed the internal question to how security operations could be redesigned so analysts move faster and more consistently with AI help. Microsoft frames Copilot as an accelerator on a platform that was already working, not as a replacement for one.

The Four Security Copilot Workstreams​

Microsoft says ZS put Copilot to work in four targeted areas, each tied to one of its highest-priority SecOps workstreams:

WorkstreamReported role of Security Copilot
Threat huntingHelps develop hypotheses and hunting logic, so analysts rely less on specialized query-writing skills
Incident investigationSpeeds triage and summarizes context, aiming to shorten threat exposure windows and move analysts from signal to decision faster
Detection engineeringSpeeds up tuning, validation and improvement of detection logic
Script analysisSupports quick evidence review and structured analysis during investigations

These describe what ZS intended each workstream to do. They don't spell out how it was built. The story doesn't say whether ZS used standalone chat sessions, promptbooks, Microsoft-built agents, custom agents, or Copilot features embedded in Defender or Sentinel. That choice drives both cost and governance, so a team trying to copy ZS will have to work it out for itself.

The threat-hunting entry deserves attention. Hunting in Sentinel usually means writing queries against log data, and that skill is scarce on most SOC teams. Microsoft says Copilot's summaries and explanations of unfamiliar signals help newer ZS analysts take on complex work like threat hunting, while experienced analysts get more time for response strategy. That is the "extend specialized expertise" claim at the center of the story. It's plausible, and the story doesn't measure it.

What ZS's 5,000-Task, 80%-Accuracy Figure Can and Cannot Tell You​

The one hard number is attributed to ZS's own tracking. ZS reports that its early AI-assisted security operations use cases, "including those supported by Microsoft Security Copilot," automated about 5,000 tasks at roughly 80% accuracy to date. It says ongoing analyst review validated the accuracy.

The wording is careful, and readers should read it just as carefully. The count covers AI-assisted use cases in general, with Copilot as one contributor. It doesn't say Copilot did 5,000 tasks by itself. "Task" isn't defined. It could mean an incident summary, a script review, a draft detection rule or something else. The story gives no measurement period, no baseline for how long the work took before, and no split by workstream. It also doesn't say what the 20% error rate looked like: how serious the errors were, and what happened when analysts caught them.

An 80% figure makes sense when a human reviews every output. It would be a different proposition in an unattended pipeline. ZS's own framing points the same way. Microsoft says analysts still own final decisions but get there faster because less manual effort is involved. The practical reading is that an AI-assisted SOC at this accuracy speeds up the analyst's first draft. It can't be trusted to act alone, and ZS doesn't say it lets it.

The story doesn't claim anything about analyst hours saved, staffing, incident outcomes or financial return, and none should be inferred.

ZS's Governance Model: Confidence Scoring and Humans in the Loop​

The governance section is short but pointed. ZS says it keeps developing its AI-driven security operating model with strong governance, confidence scoring and strict human-in-the-loop safeguards. CISO Andre Elder says the team rigorously validates AI capabilities before putting them into production. He calls responsible adoption "scalable, measurable, and always with humans providing oversight and judgment."

The story doesn't describe how confidence scoring works, what thresholds send an AI output to a human, or which approval and audit steps sit around Copilot's output. A regulated organization would need those details to judge whether ZS's model fits its own compliance obligations. The story names the right controls without showing how they're built.

The general pattern still translates. Validate a use case before it goes live, keep measuring it against analyst review once it's running, and keep humans accountable for decisions. That's a reasonable template for any team adding generative AI to incident response, where a wrong summary can send an investigation in the wrong direction.


Security Copilot Licensing Has Changed Since Most SOCs Last Priced It​

Readers comparing ZS's approach to their own budgets should know that Security Copilot's commercial model has changed a lot. The ZS story doesn't say how ZS licenses Copilot or what it pays. The terms below are Microsoft's general terms, not ZS's.

Microsoft announced at Ignite 2025 that Security Copilot would be included in Microsoft 365 E5. The Microsoft 365 message center notice described a phased rollout from April 20 to June 30, 2026, providing 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products. Microsoft Learn now covers E7 as well. Customers with Microsoft 365 E5 and E7 will have 400 Security Compute Units (SCU) each month for every 1,000 paid user license, up to 10,000 SCUs each month at no additional cost. This amount scales by user license count, including for customers with fewer than 1,000 user licenses. Microsoft's worked examples: an organization with 400 user licenses gets 160 SCUs/month, and one with 4,000 user licenses gets 1,600 SCUs/month.

The SCU is the unit that everything is billed in. A Security Compute Unit is a unit measure of the compute power to run Security Copilot workloads – for AI capabilities within the standalone and embedded experiences. Organizations without E5 or E7 go a different route: non-Microsoft 365 E5 customers need to purchase SCUs by provisioning them. Under that model, provisioned capacity is billed by the hour while the overage capacity is billed on usage. Reseller TrustedTech puts standalone SCUs at $4/hour. For E5 customers who outgrow the included pool, Microsoft has said they will have an option to pay for scaling beyond the allocated amount at a future date with $6 per SCU on a pay-as-you-go basis.

One detail matters for anyone following ZS's Sentinel-first order. Microsoft's inclusion documentation says customers with Microsoft 365 E5 who also use Microsoft Sentinel can apply their included SCU allocation to run Security Copilot scenarios in Microsoft Sentinel. The inclusion has limits, though. Any capabilities beyond those that are part of the core Security Copilot value requires additional payment, and Microsoft's exclusions list includes Microsoft Sentinel data lake compute or storage costs.

Eligibility doesn't turn the product on by itself. Microsoft's onboarding guidance says Security Copilot has to be rolled out in the tenant before an E5 or E7 customer can use it. It also warns administrators not to start onboarding until they've confirmed their license category, because that determines whether capacity has to be bought. There's also a scope limit that matters for regulated readers. Microsoft's onboarding documentation says it applies only to commercial clouds, and Security Copilot currently isn't designed for US government clouds, including GCC, GCC High, DoD and Azure Government. Nothing suggests ZS runs in those clouds. But a healthcare or life-sciences organization in a government tenant can't simply copy this deployment.

What this means for you​

The decision here is about order and measurement, not about whether to buy Copilot. If your SOC's telemetry is still spread across tools that Copilot can't reach, ZS's experience points to consolidating first. If you already run Sentinel and hold Microsoft 365 E5 or E7, you may already have included capacity. Test Copilot on one narrow workflow with analyst review before spreading it further.

  • Check whether your tenant has the Microsoft 365 E5 or E7 Security Copilot inclusion and whether it has actually been rolled out, before buying any standalone SCUs.
  • Work out your included monthly allocation (400 SCUs per 1,000 paid licenses, capped at 10,000) and compare it with the Copilot scenarios you plan to run in Sentinel and Defender.
  • Start with one defined workstream, such as incident summarization or script analysis, and have analysts score every output so you get your own accuracy baseline instead of borrowing ZS's.
  • Before counting anything as an automated task, define what a task is and what counts as an error, because ZS's 5,000-task, 80% figure can't be compared without those definitions.
  • Confirm your tenant is in a commercial cloud, because Microsoft says Security Copilot isn't currently designed for GCC, GCC High, DoD or Azure Government customers.
  • Budget separately for Sentinel data lake storage and compute, which the E5 inclusion doesn't cover.

The ZS story is a vendor showcase, but what it describes holds up: build the Sentinel foundation first, add Copilot to four defined workflows, and keep humans signing off. Its numbers are still ZS's internal accounting, not a benchmark. Security Copilot capacity now comes with E5 and E7, so price is less of a barrier than it used to be. For many Microsoft-centric SOCs, the harder work is the part the story leaves out: defining tasks, scoring AI output and writing the escalation rules that make an 80%-accurate assistant safe to use.