01Use the Agent Registry as your inventoryVerified
Agents > All agents > Registry in the Microsoft 365 admin center lists Microsoft, partner, org-published and creator-shared agents.
- Open Agents > All agents > Registry in the Microsoft 365 admin center
- Filter by Publisher Type and Platform to find in-house agents
- Check the Agents without owners and Unmanaged agents counts
- Export to CSV for periodic inventory reviews
Total agents doesn't change with filters. Only Copilot Studio drafts are currently visible. The Microsoft Graph API for the registry is in preview.
Supporting passage from the source
The agent registry in Microsoft 365 admin center provides a centralized view of all agents available for your organization. This list helps you monitor, manage, and govern agents for your organization.
02Route org-wide publishing through request and approvalVerified
Agents for the whole organization reach the Agent Store only after admin approval; admins choose Publish to store or Reject submission.
- Open the Pending Requests card in Agent overview, or All agents > Requests
- Review the creator, knowledge sources and requested permissions
- After internal review (security and business owner), select Publish to store
- If requirements aren't met, select Reject submission and tell the creator why
Only AI Administrator or Global Administrator can approve requests or assign owners; other roles can only monitor.
Supporting passage from the source
However, before users can access these agents, each agent must undergo a streamlined process of submission and approval.
03Blocking reach depends on how the agent was builtVerified
Blocking Agent Builder and Copilot Studio agents affects Copilot and host products such as Outlook and Teams. Blocking SharePoint or Microsoft Foundry agents affects only Copilot Chat.
- Select the agent in Agents > All agents
- Choose Block, then Block agent, and save
- For SharePoint or Foundry agents, check whether you also need to stop them in those products
- Researcher and Analyst can't be scoped per user; block tenant-wide if needed
Admin-center actions fail for agents in environments with Power Platform IP firewall in active enforcement; use the Power Platform API instead.
Supporting passage from the source
However, blocking an agent that you created by using SharePoint or Microsoft Foundry only impacts its availability in Microsoft Copilot Chat.
04Assign a new owner to ownerless agentsVerified
Shared agents become ownerless when the creator's account is deleted. Admins can assign new owners to Agent Builder and Copilot Studio agents; Agent Builder supports multiple owners.
- Filter with the Agents without owners card in the Registry
- Select Assign new owner in the details pane
- Enter the new owner and select Assign
- For Agent Builder agents, add extra owners with Add owner
- If no successor is found, consider blocking or deleting
After reassignment the previous owner loses all access, including read, and the new owner gets the previous owner's uploaded files. Groups can't be Agent Builder owners.
Supporting passage from the source
Multiple owners reduce reliance on a single person and help teams continue to edit and maintain an agent when responsibilities change.
05Retire agents knowing deletion is irreversibleVerified
Agent Builder agents can be deleted from the admin center, along with associated files and the SharePoint Embedded container. Deletion is irreversible.
- Pick retirement candidates by usage and ownership
- Block first and watch for impact
- Save needed records (instructions, knowledge list), e.g., via Export
- Filter Platform = Agent Builder in Microsoft Copilot, then … > Delete
- Tell users it can take up to 24 hours to take effect
Deleted agents can't be restored. Follow your records policy for what to keep and for how long.
Supporting passage from the source
This deletion process is irreversible. Once you delete an agent, it might take up to 24 hours for the deletion to reach all users who had access to the agent.
06Pin the agents you want people to useVerified
Admins can pin up to three deployed agents for everyone or for specific users/groups. Users can't unpin admin-pinned agents.
- Open Manage pinned agents from the … menu on All agents
- Select a deployed agent with Pin agent
- Choose scope (all deployed users or specific users/groups) and save
- Order them with Move up / Move down
It can take up to six hours to show. Undeployed or blocked agents can't be pinned.
Supporting passage from the source
Administrators can pin up to three agents in Microsoft 365 admin center for end-users using Microsoft Copilot in the organization.
07What's included for licensed users, and the exceptionsVerified
Employee-facing Copilot Studio agent usage is not charged in Copilot Credits when the user has a Microsoft 365 Copilot license and the agent runs under that user's identity, with exceptions.
- Check whether agent users hold Microsoft 365 Copilot licenses
- Check whether agent flows use triggers other than "When an agent calls the flow"
- Check whether Computer-Using Agents are used
- Estimate consumption for unlicensed users with Microsoft's agent usage estimator
Rates (table updated 2026-08-03): classic answer 1, generative answer 2, agent action 5, tenant graph grounding 10, agent flow actions 13 per 100 actions (Copilot Credits). Fair-use limits apply. Microsoft's pricing page lists packs of 25,000 Copilot Credits at $200.00/pack/month (checked 2026-09-12).
Supporting passage from the source
Employee-facing usage scenarios (Business to Employee) of Copilot Studio agents and Copilot Studio tools and features that these agents invoke are included in the Microsoft 365 Copilot USL when the user of the agent is licensed with Microsoft 365 Copilot
08When capacity overage stops agents, and per-agent capsVerified
At 125% of prepaid capacity, custom agents are disabled. Agent flows stop new runs once capacity is used up. You can set monthly caps per agent in the Power Platform admin center.
- Check consumption under Licensing > Copilot Studio in the Power Platform admin center
- Set monthly limits per agent in Manage Agents
- Allocate capacity to environments with critical agents
- Decide in advance how to respond (reallocate, buy more, pay-as-you-go)
After enforcement, users see messages such as "There is a billing issue." Unused Copilot Credits don't carry over. Environments on pay-as-you-go aren't subject to the overage stop.
Supporting passage from the source
Enforcement is triggered when a tenant reaches 125% of their prepaid capacity.
09Set up pay-as-you-go for unlicensed Copilot Chat usersVerified
Unlicensed Copilot Chat users can use work-data agents once pay-as-you-go is set up: create a billing policy, then connect it to a Copilot service.
- Create a billing policy with an Azure subscription and target users in the Microsoft 365 admin center
- Add a budget limit and alert percentages
- Connect the policy to Microsoft Copilot Chat or SharePoint agents
- Review costs on the Cost Management page
Creating a policy alone doesn't finish setup; pay-as-you-go is off by default. Agent Builder is free for web-only agents. Cowork and Work IQ API billing is managed separately under Copilot > Cost management.
Supporting passage from the source
As an admin, when you use the pay-as-you-go service, you set up billing and users access declarative agents on a usage basis. You can manage billing, view costs, set spending budgets, and turn off services as needed.
10Restrict features per environment with data policiesVerified
Power Platform data policies can block unauthenticated publishing, knowledge sources, HTTP requests, event triggers and channels per environment. Enforcement applies to all tenants since early 2025.
- Open Security > Data and privacy > Data policy in the Power Platform admin center
- Select the environments
- Block Chat without Microsoft Entra ID authentication in Copilot Studio to stop unauthenticated agents
- Block or endpoint-filter Knowledge source with public websites and data in Copilot Studio and HTTP as needed
- Confirm Copilot Studio shows the policy violation
Connectors in different data groups can't share data. Blocking the Microsoft Copilot Studio connector also blocks automated evaluations with authenticated accounts.
Supporting passage from the source
Data policies let you govern how agents connect and interact with data and services, both within and outside your organization. Administrators can configure Copilot Studio and Power Platform data policies in the Power Platform admin center.
11Track agent use in Purview audit logsVerified
Copilot and agent interactions are logged automatically in Audit (Standard), including AgentId, AgentName and AccessedResources.
- Confirm auditing is on
- Search CopilotInteraction under Audit in the Microsoft Purview portal
- Export and filter by AgentId or AppIdentity
- Check SensitivityLabelId in AccessedResources for labeled content
- Check AISystemPlugin.Id = BingWebSearch for web use
Apps built with Copilot Studio and Microsoft Foundry are included in Audit Standard. Auditing non-Microsoft AI apps is pay-as-you-go with 180-day retention.
Supporting passage from the source
The system automatically logs these activities as part of Audit (Standard). If your organization enables auditing, you don't need to take extra steps to configure auditing support for Copilot and AI applications.
12Review quality regularly in Copilot Studio MonitorVerified
The Monitor page shows usage and outcomes for conversational and trigger-based (autonomous) agents. Data is kept up to 360 days; session details and transcripts for 28 days.
- Open the agent and select Monitor
- For conversational agents check resolved/escalated/abandoned; for triggered agents check run outcomes and tool use
- Look for periods where satisfaction dropped
- Share view-only access with the Analytics Viewer role
- Do transcript-based analysis within 28 days
Active user metrics require authentication to be set on the agent. Test-panel activity isn't counted.
Supporting passage from the source
Monitoring is available in all geographies. Monitor data is available for up to 360 days. Session details and transcript information are available for the last 28 days.
13Separate what Entra Agent ID and Agent 365 coverVerified
Microsoft Entra Agent ID is available to all Entra customers for creating and managing agent identities. Extending Entra security features (e.g., Conditional Access) to agents requires Microsoft Agent 365.
- Check whether your licenses include Microsoft Agent 365 (included in Microsoft 365 E7)
- Record an accountable owner or sponsor per agent
- Review risks such as no owner or excessive permissions on the Agents at risk card
- Investigate details in the Entra, Defender and Purview portals
Agent overview usage metrics start when Agent 365 licenses are activated. Risk counts may lag the security portals by up to an hour.
Supporting passage from the source
Microsoft Entra Agent ID is a product within Microsoft Entra that provides the platform for creating and managing agent identities and agent identity blueprints. Agent ID is available for all Microsoft Entra customers.
14Admins control preview, experimental, and external model access per environmentVerified
Admins can independently allow or block preview/experimental models and external models (Anthropic, xAI, Mistral) per environment; the two settings are separate and can overlap or diverge.
- Turn on the Preview and experimental AI models setting for the environment to allow preview/experimental models
- Check the Move data across regions setting, since experimental models may process data outside the org's region
- Turn on external models in the Power Platform admin center for the environment or environment group
- Allow access to each external model provider (Anthropic, Mistral, xAI) in the Microsoft 365 admin center
Experimental/preview and some external models may process or store data outside the organization's region (cross-geo). For environments handling confidential or patient data, confirm data-movement and external-model settings with IT/compliance beforehand.
Supporting passage from the source
Administrators can choose to allow or block preview and experimental models in an environment. To use these models, the Preview and experimental AI models setting must be turned on for your environment.