Post

Govern Microsoft 365 Copilot agents with pilots and ownership rules

Diesen Beitrag auf Deutsch lesen

Use agent settings to limit users, publishers, sharing and individual agents while checking oversharing before rollout.

TL;DR

Microsoft 365 Copilot declarative agents use the requesting user's permissions and do not receive an independent Entra ID identity. Before enabling them, run Purview and SharePoint Advanced Management oversharing checks, pilot selected users, review external publishers individually, and use Agent Management Rules to address ownerless agents.

Original by Anders Jensen, on andersjensenorg. Read the original

This is our own summary, not a republication or full translation.

Governance takeaway

  • Admins/CoE: Limit User access to a pilot group, then expand only after observing usage and reviewing each agent's data sources.
  • Security/Compliance: Use Purview and SharePoint Advanced Management to identify broad legacy access before agents surface it faster.
  • Admins/CoE: Allow Microsoft and organisational agents first, assess external publishers individually, and define sharing and owner-transfer rules.
  • Leadership/Business: Document the enablement decision, rationale and metered-consumption exposure so future reviews do not depend on institutional memory.
This post is licensed under CC BY 4.0 by the author.