Share via


Manage Microsoft 365 Copilot agents in the Microsoft 365 admin center

Important

  • This article is intended for IT administrators.
  • The capability is enabled by default in all Microsoft 365 Copilot licensed tenants.
  • The management of agents is currently transitioning to the Copilot Control System. During this transition phase, certain features are still managed on the Integrated Apps page.

Microsoft 365 Copilot combines the power of large language models with your data and apps in Microsoft 365 to capture natural language commands to produce content and analyze data. It enables access to and use of other apps, such as Jira, Dynamics 365, or Bing Web Search.

You can manage agents for Copilot by using the Copilot Control System in the Microsoft 365 admin center. You can enable, disable, assign, block, or remove agents for your organization, and manage Copilot capabilities.

Overview

Agents enhance the functionality of Copilot by adding search capabilities, custom actions, connectors, and APIs. Agents are custom versions of Microsoft 365 Copilot that combine instructions, knowledge, and skills to perform specific tasks or scenarios. To learn more, see Get started with agents for Microsoft 365 Copilot.

Microsoft Copilot Studio is a low-code development platform that offers a graphical environment to build agents tailored to the internal needs of an organization. Copilot Studio enables developers and makers to create and test their applications in a user-friendly interface.

However, before users can access these agents, the agents must undergo a streamlined process of submission and approval. To learn more, see Publish agents.

The hub Copilot experience shows the list of agents that are available and deployed for the user. Users can toggle it on or off to restrict access of Copilot to any specific agents during the interaction. Users can also add or remove agents in their Copilot experience by right-clicking on the agents and selecting the appropriate option. Users can only access the agents that the admin allows and that they install or are assigned to.

Agent types you can manage

You can manage several types of agents in Microsoft 365 Copilot, each serving different purposes:

  • Custom agents: Built with predefined instructions and actions. These agents follow structured logic and are best for predictable, rule-based tasks. Before becoming available to users, custom agents go through an admin approval and publishing process to ensure compliance and readiness.
  • Shared agents: Configured for use by multiple users or groups. These agents are individually shared by their creators with other users.
  • First-party agents: Developed by Microsoft and integrated with Microsoft 365 services.
  • External agents: Created by external developers or vendors. You can control their availability and permissions.
  • Frontier agents: Experimental or advanced agents that use new capabilities or integrations. These might be in early stages of development or testing and could require more oversight or limited rollout.
  • Flow Builder agent: A type of Frontier agent developed by Microsoft that can be managed as part of Microsoft 365 Copilot. Flows created in Copilot are saved to the default environment (unless environment routing is enabled for Copilot Studio). You can also manage flows using the Power Platform admin center.

Get started

The following administrator roles can manage agents in the Microsoft 365 admin center:

  • AI Admin
  • Global Reader (view-only, no edit)

Important

Use roles with the fewest permissions. Lower permissioned accounts help improve security for your organization. Global Administrator is a highly privileged role. Limit its use to emergency scenarios when you can't use an existing role. For more information, see About admin roles in the Microsoft 365 admin center.

Screenshot showing the Agents & connectors page in the Microsoft 365 admin center.

You can manage agents in the Microsoft 365 admin center by using the Agents page under the Copilot Control System. On this page, you can:

  • View available, deployed, or blocked agents.
  • Configure agent availability and access.
  • Perform actions such as deploying, blocking, or removing agents.

You can view agents by going to Copilot > Agents, or by using the filter option of Host products > Copilot on the Agents page.

You can also check if a specific app has Copilot support by selecting it from the apps list and checking if the app overview mentions Copilot as a host product.

Shared agents

You can also manage shared agents, which are agents that you configure for use by multiple users or groups within your organization. For more information, see Manage shared agents for Microsoft 365 Copilot.

Settings for agents

Use the following settings to manage agents for Copilot:

  • Enable or disable agents: Control whether agents are available in your organization.
  • Advanced agent settings: Configure more controls for agent behavior.
  • Agent inventory: View and manage all agents, including first-party, external, shared, and custom agents.
  • Metadata: View key details for each agent, such as capabilities, data sources, and custom actions. Example data sources include OneDrive, SharePoint, Graph connectors.
  • Shared agents: Manage agents configured for use by multiple users or groups. You can:
    • Change availability (Edit users)
    • Deploy
    • Block
    • Unblock
    • Export all
  • Requested agents: Review user-submitted agent requests. You can:
    • View all pending requests
    • Act on requests (for example, Publish pending, Update pending)

Manage access to Copilot agents

Screenshot showing the option to enable agents for all users in the organization.

You can manage access to Copilot agents for your organization by using a setting to control who can access agents in your organization.

To manage access to Copilot agents, follow these steps:

  1. Go to Copilot > Settings in the Microsoft 365 admin center.
  2. Select Agents.
  3. Choose your preferred setting.

The setting has three options:

  • All users: This option is the default. It means that all users in the organization can access agents, subject to the existing app policies and user assignments.

  • No users: This option means that no users in the organization can access agents, and the external agents are disabled in the agents flyout. This option also hides agents from the list of Available and Deployed apps on the Agents page.

  • Specific users/groups: This option lets you select specific users or groups in your organization to have access to agents. While some users in your organization might have permissions to install and use apps from the Available apps and Deployed apps lists, only the users or groups you select in this setting can use agents.

Note

When you disable extensibility, users can't see the Microsoft pinned Visual Creator agent or the entry point for Copilot Studio (lite) in Copilot Chat. After you disable extensibility in the tenant, it can take up to 24 hours for agents to disappear for users and for Copilot Studio (lite) and Visual Creator to disappear.

Disable Copilot access

You can remove users from the Microsoft 365 Copilot sign-in page or restrict their access through the Microsoft 365 Admin Center.

After logging-in to the Admin Center,

  1. Navigate to Settings > Organization Settings > Services > Copilot

  2. Use the Integrated Apps section to:

  • Unassign Copilot licenses
  • Block the Copilot app from launching on web, desktop, or mobile
  • Disable Copilot Chat pinning

Manage how users install agents

You can assign or unassign agents to specific users or groups by using the same gestures and controls that work for any other app in the Microsoft 365 admin center.

Screenshot showing the option to assign an agent to users in your organization.

Select an app that has a plugin for Copilot from the Available apps or Deployed apps list and select the Assign or Unassign option.

You can also choose to assign or unassign the app to everyone or specific users or groups. Assigning or unassigning an agent affects its availability and functionality in Copilot and in the other host products, such as Outlook, Teams, or Microsoft 365.

Important

Developers can update the existing apps to work with Microsoft 365 Copilot. If an admin preapproves or preinstalls the updated app, it updates for the assigned users and starts working with Copilot. If a developer updates a previously blocked app to work with Microsoft 365 Copilot, and then the admins make the app available to the users, the app also works with Copilot.

Actions for agents

The following list describes the actions you can take to manage an agent for your organization:

  • Publish: Make an agent available to specific users or groups. This action lists the agent in the store and users can install it.
  • Deploy: Install an agent on behalf of a user by accepting Microsoft Entra permissions for them. This action makes the agent active and usable for specific users or groups.
  • Remove: Remove the agent from the inventory. This action applies only to first-party or external agents. You can readd the agent to the inventory by acquiring it from the store.
  • Block: Prevent any users in the tenant from accessing the agent. This action ensures that no one in the organization can use the agent.

Publish agents

The Microsoft 365 admin center publishing process for agents submitted through Copilot Studio ensures governance and quality of custom applications. It also reduces manual work by automating the submission of manifests, freeing developers and admins from tedious tasks. The simplified approval process reduces the time it takes for you to approve apps, making it easier for you to manage custom applications in the Microsoft 365 admin center.

The publishing process involves the following steps:

  1. Developers create and test agents in Copilot Studio, which provides a user-friendly interface for inputting the parameters and data for the applications.

  2. Developers submit their agents for approval from within Copilot Studio to the Microsoft 365 admin center.

  3. To discover the apps with agents that are submitted but not yet approved, go to the Requested Apps tab in the Integrated Apps section of the admin center. The tab shows the name, host products, status, and Copilot readiness of the applications. The status of a new app is Publish pending. The status of an update to an existing app is Update pending.

  4. To see more details and metadata, select a pending application. This information includes the description, requester, request date, and the status. These details help you to make an informed decision on whether to publish or reject the application.

  5. You can approve or disapprove any pending application by selecting Publish or Reject.

    1. If you approve the application, it becomes available to the org users based on the org default settings for custom apps. The application also becomes part of the Agent inventory list in the admin center, where admins can manage user assignments and other settings as any other app.

    2. If you disapprove the application, the service removes it from the Pending approval list in the admin center. Then the service shares the app's status with Copilot Studio. The developer can make changes and resubmit the application for approval.

    Screenshot showing the pop-up window to publish an agent.

  6. If the developer publishes an update to an existing application, the update is available for approval and follows the same workflow as a new application. It shows in the Pending approval list with the status Update pending. Until you approve the update, the previous version of the application remains available to the users.

Deploy agents

Screenshot showing the configuration screen to deploy an agent.

You can deploy agents across the whole organization or for specific users or groups by using the same gestures and controls that work for any other app in the Microsoft 365 admin center.

To deploy an agent, follow these steps:

  1. In the admin center, go to Copilot > Agents.
  2. Filter the list by Availability.
  3. Select an agent from the list.
  4. Select Deploy.
  5. Decide whether to deploy the agents for everyone or specific users or groups.

Deploying an agent affects its availability and functionality in Copilot and in the other host products, such as Outlook, Teams, or Microsoft 365.

Remove agents

You can remove first-party and external agents across the whole organization or for specific users or groups by using the same controls that work for any other app in the Microsoft 365 admin center.

To remove an agent, follow these steps:

  1. In the admin center, go to Copilot > Agents.
  2. Filter the list by Availability.
  3. Select an agent from the list.
  4. Select Remove.
  5. Decide whether to remove the agents for everyone or specific users or groups.

Removing an agent affects its availability and functionality in Copilot and in the other host products, such as Outlook, Teams, or Microsoft 365.

Block or unblock agents

Screenshot showing the panel to block an agent.

You can block or unblock agents for the entire organization by using the same controls that work for any other app in the Microsoft 365 admin center.

To block or unblock an agent, follow these steps:

  1. In the admin center, go to Copilot > Agents, or the Agents page.
  2. Choose an agent from the list of agents.
  3. Select Block or Unblock.
  4. Decide whether to block or unblock the agent for everyone.

Blocking or unblocking an agent created using Copilot Studio (lite) and Copilot Studio (full) affects its availability and functionality in M365 Copilot and other host products, such as Outlook, Teams, or Microsoft 365. However, blocking an agent created with SharePoint will only impact its availability in M365 Copilot Chat.

Note

For the Researcher and Analyst agents, the Edit users panel is disabled. To manage their availability, you must block the agent for the entire tenant by using the Block action in the admin center.

Agent inventory

In Microsoft 365 admin center you can view your organization’s available agents and where members of your organization can find each agent based on supported functionality. The agent inventory is provided as a list. When you have several agents in your inventory, you can narrow the list based on different filters. Common filters include, Type, Availability, Supported in, and Created in.

Type filter

The Type filter allows you to view agents based on the their creation method. The following list provides the different Type options:

  • Custom - Agents created by members of your organization using Copilot Studio (full).
  • Shared - Agents created by members of your organization using Copilot Studio (lite).
  • Microsoft - Agents created by Microsoft.
  • External - Agents create by agent provides that are external to your organization and Microsoft.

Availability filter

The Availablity filter shows which specific agents are avialable to members of your organization. The following list provides the different Availability options:

  • Some users - Agents that are specifically available to only selected users or groups at your organization.
  • No users - Agents that are unavailable to all users at your organization are listed.
  • All users - Agents that are available to all users at your organization are listed.
  • Blocked - Agents that have been blocked for all users at your organization.

Supported in filter

The Supported in filter allows you to select which Copilot experience and M365 app the agent is available.

Created in filter

The Created in filter allows you to select agents based on the tool that was used to create the agents, such as Copilot Studio (lite), SharePoint, and Copilot Studio (full).

Agent metadata in admin center

You can access key metadata for Copilot agents in Agents > Agent inventory. When you select an agent, you can view the following tabs:

  • Overview
  • Users
  • Details
  • Security & compliance

Agent overview tab

The Overview tab for a selected agent provides the complete description of the agent. This description is the description the maker provided when the agent was created. It follows the pattern provided in the Agent Store experience. In addition, the Overview tab provides key information, such as the following items:

  • Availability
  • Publisher
  • Deployment
  • Agent type
  • Supported in
  • Created in
  • Last updated
  • Owner
  • Sensitivity
  • Version

Screenshot showing the Overview tab for an agent.

Agent users tab

The Users tab allows you to set the assigned users that the agent has been Deployed to and Assigned to.

Agent details tab

The Details tab provides metadata about the agent, including details such as the agent's capabilities, data sources, and custom actions. Example data sources include OneDrive and SharePoint files and sites, or Graph connectors. Metadata is only for custom agents, which are designed to perform specific tasks based on predefined rules and configurations.

Screenshot showing the Details tab for an agent.

Agent security & complicance tab

The Security & compliance tab provides certification information about the agent. You can view key details about the following areas:

  • Compliance
  • Operational security
  • Data security and privacy
  • Identity

For detailed information about how Microsoft 365 Copilot uses, protects, and shares organizational information to power extensibility, see Data, Privacy, and Security for Microsoft 365 Copilot.

Manage agents by using the integrated apps portal

During the transition to the Copilot Control System, you can still access some agent management features on the Integrated Apps page in the Microsoft 365 admin center. This section helps admins manage agents from that ___location.

To manage agents by using the integrated apps portal:

  1. Sign in to the Microsoft 365 admin center.
  2. Go to Settings > Integrated apps.
  3. Use the Host products filter and select Copilot to view apps that support agents.
  4. Select an app to:
    • Assign or unassign agents to users or groups
    • Deploy agents on behalf of users
    • Block or unblock agents for specific users or the entire organization
    • Remove agents from the deployed list

You can also configure who in the organization can access agents by adjusting the Allow users access to agents setting. This setting supports three options:

  • All users (default)
  • No users
  • Specific users or groups