‹ Back to list
Stay InformedMC1438558

Simplified access to Security Copilot in Intune for Microsoft 365 E5 customers

Services: Microsoft Copilot (Microsoft 365), SharePoint Online· Published: 2026-07-24· MS modified: 2026-07-24
New featureUser impactAdmin impact

Microsoft announcement

[What and why]

To simplify access to Security Copilot capabilities in Microsoft Intune, Microsoft is updating how Security Copilot permissions are assigned for organizations with Microsoft 365 E5 licensing. This change reduces administrative overhead by automatically granting the appropriate Security Copilot permissions to Intune role holders when Intune is enabled as a data source in Security Copilot.

This update helps organizations adopt Security Copilot more quickly while continuing to respect existing Intune role-based access controls (RBAC).

[Rollout schedule]

General Availability (Worldwide): Beginning in late August 2026 and expected to complete by early September 2026

[Impact on your organization]

Who is affected

  • Organizations with Microsoft 365 E5 licensing using Microsoft Intune and Security Copilot
  • Intune administrators and users assigned built-in or custom Intune RBAC roles

Platforms/Services

  • Microsoft Intune
  • Microsoft Security Copilot
  • Microsoft Entra ID

What will happen

When Microsoft Intune is enabled as a data source in Security Copilot:

  • Users assigned the Microsoft Entra ID Intune Administrator role will continue to receive Security Copilot Owner permissions automatically.
  • Users assigned built-in or custom Intune RBAC roles will automatically receive Security Copilot Contributor permissions.
  • Intune role holders will be able to access Security Copilot experiences in Intune without requiring separate Security Copilot role assignments.
  • The change will be applied automatically as part of this update.
  • Existing Intune RBAC permissions will continue to govern what users can access and manage within Intune.

[Action required and recommendations]

No action is required.

We recommend that administrators:

  • Review current Intune RBAC role assignments to understand which users will receive Security Copilot Contributor permissions.
  • Update internal documentation describing Security Copilot access and administration, if applicable.
  • Inform help desk and security operations teams about the new default access behavior.

Learn more

[Compliance considerations]

QuestionAnswer
Does the change introduce or significantly modify AI/ML or agent capabilities that interact with or provide access to customer data?Yes. Security Copilot capabilities remain unchanged; however, additional Intune role holders may gain access to existing Security Copilot experiences through automated role assignment.
Does the change include an admin control?Yes. Access continues to be governed through Intune RBAC role assignments and Microsoft Entra ID administrative roles.

Change history