Security Copilot Agents in Intune
Security Copilot agents observe, reason and recommend inside the Intune admin center — but administrators still decide. Know which agents exist today, what each one is actually scoped to, and where the licensing traps are.
What an agent actually is
An agent is a very well-read analyst who does the reading for you and then hands you a recommendation to approve.
It looks across your devices, policies and threat data, works out what it thinks you should do, and writes it up. What it does not do is press the button. You press the button.
The single most examinable idea on this page
Agents recommend; administrators decide.
If an answer option describes an agent autonomously deleting devices, silently changing policy, or acting with no review, it is wrong. The documented model is explicit that agents operate with oversight and review from your administrators.
When a question asks “what happens next”, the answer is almost always an administrator reviews the recommendation and approves or rejects it.
The agents available today
🔴 Read this before you trust any agent list — including Microsoft's own
The Device Offboarding Agent has been retired. Microsoft’s timeline is explicit:
- 30 April 2026 — you can no longer set the agent up.
- 1 June 2026 — the agent is removed from the Intune admin center and isn’t available.
This matters for study material because the general Security Copilot agents in Intune overview page still lists it among available agents, while the agent’s own page carries the retirement notice. When Microsoft’s own docs disagree, the specific, dated page wins over the general overview.
Older blogs, courses and question banks — including earlier versions of this one — will still teach four agents. Treat any “Device Offboarding Agent” answer option as a distractor, and use the pre-existing device lifecycle and remediation options in Intune for cleanup instead.
| Agent | What it is actually scoped to | Status | Typical trigger in a question |
|---|---|---|---|
| Change Review Agent | Evaluates Multi Admin Approval requests for PowerShell scripts on Windows devices, with risk-based recommendations | Public preview | Multi-admin approval of a script; “is this script safe to approve?” |
| Policy Configuration Agent | You supply a document or plain-language instructions; it finds matching settings catalog settings, recommends values, and can create the policy | — | “We have a hardening standard as a Word document” |
| Vulnerability Remediation Agent | Uses Defender Vulnerability Management data to identify CVEs, prioritise them, and give step-by-step Intune remediation guidance | Public preview | CVE backlog; “which do we fix first?” |
| Stale/misaligned device cleanup | Retired 1 Jun 2026 | Now a distractor |
Watch the Change Review Agent scope
This is the detail most study material gets wrong. The Change Review Agent is not a general-purpose “reviews any approval request” agent. Microsoft scopes it to Multi Admin Approval requests for PowerShell scripts on Windows devices, and it builds its recommendation by aggregating signals from three places:
- Microsoft Defender Vulnerability Management — threat insights
- Microsoft Entra ID — identity risk
- Microsoft Intune — the MAA request itself, plus historical context from similar requests
If a scenario describes multi-admin approval of an app deployment or a device wipe rather than a script, be suspicious of the Change Review Agent as the answer.
Reading the question
Most exam items reduce to match the scenario to the right agent:
- Multi Admin Approval of a PowerShell script → Change Review Agent
- A written standard, benchmark or document to turn into policy → Policy Configuration Agent
- CVEs, Defender findings, patch prioritisation → Vulnerability Remediation Agent
- Stale device cleanup → not an agent any more — use standard device lifecycle and remediation options
| Feature | Copilot (chat/assist) | Security Copilot agent |
|---|---|---|
| Interaction | You ask a question, it answers | It works a defined scenario end to end and returns recommendations |
| Scope | Whatever you ask about | One purpose-built use case per agent |
| Output | An explanation or summary | Prioritised, actionable recommendations you approve or reject |
| Autonomy | None — reactive | Proactive analysis, still gated on admin review |
Prerequisites — the part people skip
You cannot simply switch agents on, and the requirements are not identical for every agent.
Common to all of them:
| Requirement | Why it matters |
|---|---|
| Security Copilot enabled | Agents are built on Security Copilot; it must be set up first |
| Security Compute Units (SCU) available | SCUs are the capacity currency Security Copilot consumes. No available SCU capacity, no agent run |
| Least-privileged Intune role | Sign in with the least privileged role the agent requires — agents work within RBAC and scope tags |
| Reviewed privacy and data handling | Documented prerequisite before enabling |
| Public cloud | The agents are supported on public cloud only — not government clouds |
Per-agent extras — the Change Review Agent is the one people under-license:
| Agent | Additional licensing called out by Microsoft |
|---|---|
| Change Review Agent | Intune Plan 1 + Microsoft Entra ID P2 + Microsoft Defender Vulnerability Management + Security Copilot with sufficient SCUs |
| Vulnerability Remediation Agent | Defender Vulnerability Management data is the agent’s entire input |
Agents are found in the Intune admin center under Agents, where you select View details to configure one. The Vulnerability Remediation Agent can also be reached from the Endpoint security node — same agent, two paths.
Watch the licensing distractor — and note what changed
Security Copilot capacity (SCU) is not the same thing as the Intune Suite add-on. A very typical wrong answer is “purchase Intune Suite to enable the agents”. Intune Suite unlocks capabilities such as Endpoint Privilege Management, Remote Help and Advanced Analytics — it does not provision Security Copilot compute.
However, do not over-learn the old “E5 gets you nothing” line. Microsoft announced that Security Copilot is included for eligible Microsoft 365 E5 and E7 customers, with rollout beginning 18 November 2025 and continuing in phases. So “we own E5” may well mean capacity is available — the honest troubleshooting question is whether this tenant has available SCU capacity yet, not whether E5 categorically excludes it.
If an agent will not run, check SCU capacity before you check anything else — and check the agent’s own extra licensing (Entra ID P2, Defender Vulnerability Management) second.
Using agents to investigate and to analyse performance
The blueprint splits agent work into three verbs, and they map cleanly:
- Investigate threats — the Vulnerability Remediation Agent surfaces Defender-derived CVEs with a risk-based ordering, so you triage by real exposure rather than raw CVE count. Each suggestion carries affected systems, exposed devices, potential impact and step-by-step Intune remediation guidance.
- Analyse device performance — you use agent output, alongside Copilot in Intune, to see which devices and policies are causing pain rather than reading raw reports device by device.
- Review and respond to recommendations — you accept, reject or refine. After you act on a Vulnerability Remediation suggestion you can mark it as applied, so the agent keeps a record you can track over time. The decision, and the accountability, stay with the administrator.
How this connects to the rest of Domain 5
Agents do not replace the monitoring stack — they sit on top of it. Endpoint Analytics still produces the scores, Intune reports still hold the data, and Remediations still do the fixing. An agent’s value is triage: deciding what deserves attention first.
A well-written question will therefore sometimes have a non-agent correct answer. If the requirement is “automatically fix a known issue on 5,000 devices”, that is a Remediation script package, not an agent.
Preview features and the exam
Microsoft’s exam guidance says most questions cover generally available features, but the exam may include preview features when they are commonly used. Two of the three current agents — Change Review and Vulnerability Remediation — are in public preview, so know what they do, and do not be thrown if a question quietly labels a capability as preview.
A multi-admin approval request has been raised for a PowerShell script targeting Windows devices, and the reviewing administrator wants an AI-generated risk assessment before approving. Which agent is designed for this?
Security Copilot agents appear in the Intune admin center but fail to run. What should you verify first?