Elliot Margot Logo
  • Home
  • About
    Portrait of a Microsoft AI Specialist at work.
    Overview
    Abstract image of a strategic AI framework.
    Methodology
    Professional experience timeline visual.
    Experience
    Academic background and education visual.
    Education
    Certifications and diplomas visual.
    Certificates
    Letters of recommendation and testimonials visual.
    Testimonials
    Editorial photo of a resume on a warm wooden desk with fountain pen and coffee.
    Resume / CV
  • Work
    Projects portfolio hero visual.
    Projects
    Architectural tech stack hero visual.
    Tech Stack
    Open source coding and development visual.
    Open Source
    Blog header visual.
    Blog
  • Insights & Press
  • Community
    Copilot Studio Hub Discord community logo featuring Saphir the cat.
    Discord Community
    Agentic Weekly - the Microsoft AI weekly newsletter.
    Newsletter
    Microsoft AI Daily Brief - free daily digest of the Microsoft AI ecosystem.
    Microsoft AI Daily Brief
    Collaborative mentorship session visual.
    Free Mentorship
    Elliot at his workbench solving a steampunk problem - the clinic in spirit.
    Copilot Studio Clinic
    Conference stage spotlight with holographic AI agent diagrams floating above.
    Talks
My Cat SaphirContact
/
Elliot Margot Logo
/
My Cat Saphir

Navigation

  • Home
    • Overview
    • Methodology
    • Experience
    • Education
    • Certificates
    • Testimonials
    • Resume / CV
    • Projects
    • Tech Stack
    • Open Source
    • Blog
  • Insights & Press
    • Discord Community
    • Newsletter
    • Microsoft AI Daily Brief
    • Free Mentorship
    • Copilot Studio Clinic
    • Talks
Contact
  1. Community
  2. Agentic Weekly
  3. Edition 17
Agentic Weekly Edition 17 header
Edition 17

The meter becomes the model policy: the week Copilot split in two and the changelogs went dark

Week of September 21 to 27, 2026·11 signals·View on LinkedIn →

I took five weeks off from this newsletter. Reading the backlog in one sitting turned out to be more useful than reading it weekly, because you see the shape of a quarter instead of the noise of a week: agents learned to start themselves, the approval gate came back at the tool call, Copilot handed everyone an app builder, and a spending policy quietly turned into an access policy. This week Microsoft finished that last thought. Copilot's price split in two on 25 September, the app split in three into Home, Code and Autopilot, and buried in the announcement is the line nobody is quoting: the model-family setting an admin uses to control cost also decides which models Auto may route to. A budget control is now a quality control, and the user who gets a thinner answer cannot see why. The second story is quieter. The pages I use to verify any of this are going dark, starting with release plans, which stop being published from September 2026.

This week's thread: the bill grew a second job

The Copilot app stopped being an app. It is now Home, Code and Autopilot, three capabilities with different billing behind one icon, plus Copilot Managed Runtime to host what people build with them. Underneath, a flat subscription covers everyday work and usage-based billing covers anything agentic or frontier, rolling out in Q4. Most coverage stopped at the pricing story. My read is that it is a governance story, because the same control that scopes model families to a group also narrows the pool Auto routes to, so a cost decision quietly becomes an answer-quality decision. Nobody in a budget conversation is accountable for answer quality. Meanwhile Copilot Studio's what's-new is frozen at July, its Released Versions page has not moved since 30 June, and release plans stop being published altogether. The product is accelerating and the record of it is thinning.

On this page

  1. Signal of the week
  2. 1The app becomes three products
  3. 2Every agent gets an identity it did not ask for
  4. 3The automation layer goes managed, with warnings attached
  5. 4The record of what shipped is being switched off
  6. 5Fresh authentication beats another scope list
  7. 6Grounding arrives on the meter
  8. Voices to follow
  9. Coming up
  10. Question

Signal of the week

The Copilot bill is now also the model policy

Microsoft split Copilot pricing on 25 September. A user subscription licence covers everyday AI across Chat, Word, Excel, PowerPoint, Outlook and Teams, plus model selection and Auto, which weighs accuracy, speed and cost to route each call. Usage-based billing covers Cowork, Code, Autopilot, long-running agentic work and frontier models including Astra and Fable. It is visible to every end user but does nothing in an enterprise tenant until an admin creates a spending policy, and it rolls out in Q4 2026. Cost management in Agent 365 now reaches past Cowork and Work IQ APIs to Copilot Code and Copilot Managed Runtime, with Copilot Studio agents due in October. Buried in the same announcement: admins can set which model families are available to which groups of users, and Microsoft states those settings also shape which models Auto can select from.

Why it matters

That last sentence is the one I would act on. Cost and quality now share one switch. Auto is the default router for everyone on the subscription, so a model-family restriction written by someone managing a budget silently narrows what Auto can reach for. The user does not see a policy. They see a worse answer, then raise a ticket about quality that lands with the wrong team. A spending policy already decided which usage-billed services a group could reach. Now it shapes the answer too. Before Q4, list who can edit model-family scope in your tenant, and check they know they are making a quality decision. I do not know how the narrowing surfaces in the product, because the announcement does not say.

Source →Microsoft Copilot Blog, Evolution of the Copilot pricing model →
One admin control, two jobs. Scoping model families to a group caps what that group can spend, and narrows the pool Auto is allowed to route to. The user never sees the policy, only the thinner answer.
One admin control, two jobs. Scoping model families to a group caps what that group can spend, and narrows the pool Auto is allowed to route to. The user never sees the policy, only the thinner answer.

1The app becomes three products

Home, Code and Autopilot replace the app you documented

Copilot now has three capabilities. Home merges Chat and Cowork and carries Office in Copilot, so Word, Excel and PowerPoint edit live in the conversation. Code lets non-developers build apps, dashboards and automations, runs sandboxed, and is powered by the same technology as GitHub Copilot. Autopilot, previously called Scout, is a cloud-hosted persistent agent with its own identity, memory and workspace, which you @mention like a colleague. Home and Code start rolling out through Frontier in the coming weeks, and Autopilot moves to private preview at the end of the month. Copilot Managed Runtime, the in-tenant hosting layer for what Cowork, Code and Copilot Studio produce, is in preview. Fabric IQ is generally available in Chat and Cowork today.

Why it matters

The navigation changed with it, and that is the part that will cost you a morning. Plugins replaces the standalone Agents entry point in Chat and the Customize entry point in Cowork, and Automations moves into Home. Every internal training deck I have seen that says "click Agents" is now wrong, and adoption teams find out from users rather than from the message centre. Users notice first. I would rather rewrite three slides this week than field the tickets in October.

Source →

Skills in declarative agents hit GA, and Information Barriers shuts them out

MC1476977 took Skills in declarative agents to general availability worldwide, rolling out from mid-September and completing at the end of September. A skill bundles instructions, scripts, templates and assets into a module that loads only when needed, in both user-created and admin-deployed declarative agents. Scripts run sandboxed and MIP sensitivity labels are honoured. Organisations using Information Barriers cannot use skills at this time.

Why it matters

The exclusion is the whole story for half my pipeline. Information Barriers is how banks, insurers and law firms keep deal teams apart, and those are exactly the clients who want expertise packaged once and deployed everywhere. Ask before you scope, not at the build stage. For everyone else, the unit Microsoft keeps reaching for is a skill, and it is still a Markdown file.

Source →
  • QuickThe Copilot blog says Claude Opus 5.5 and GPT-6 Sol are rolling out across Word, Excel, PowerPoint, Chat, Cowork and Copilot Studio. Cowork's own what's-new for September lists Fable 5.1 and GPT 6 Astra and names neither, so check your selector, not the blog.
  • QuickResearcher retires its report length control and its Saved Prompts, History, Reports and Explore tabs between 21 October and 30 December, with no tenant opt-in (MC1476269).

2Every agent gets an identity it did not ask for

Your pre-May agents are being moved to Entra Agent ID whether you file a ticket or not

Self-service migration of Copilot Studio agents to Microsoft Entra Agent ID began on 24 August through Power Platform Advisor, and from September Microsoft also started automatically migrating agents that have none. Agents built before May 2026 may still run on legacy app-registration identities. Learn confirms the other half: since July, Copilot Studio creates an Entra Agent ID for every new agent and you can no longer opt out at environment level. Migration brings Entra audit logging, agent lifecycle management, Entra ID Governance integration, and connector permissions surfaced as API permissions on the agent identity, so Conditional Access can target them on network location, device compliance or risk. The self-service path needs Power Platform inventory enabled for the tenant.

Why it matters

Connector permissions becoming API permissions on an agent identity is the sentence to read twice. A Conditional Access policy someone wrote for humans can now catch an agent, and an agent that has run happily for a year can start failing a check nobody aimed at it. I have watched a legacy app-registration agent break for less. Enable Power Platform inventory and walk the list yourself. You want to know which agents moved before a connector stops answering.

Source →
An agent built before May 2026 on a legacy app registration was invisible to Conditional Access. After migration its connector permissions are API permissions on an agent identity, so a policy written for people can now block it.
An agent built before May 2026 on a legacy app registration was invisible to Conditional Access. After migration its connector permissions are API permissions on an agent identity, so a policy written for people can now block it.

The Agent Registry stops double-counting, so your agent number will drop

MC1477184 collapses duplicate Agent Registry records in the Microsoft 365 admin center into one entry per agent. An agent published across scopes or versions now shows once, defaulting to the latest published organisational version, with a version selector in the details flyout. Governance actions such as Block still apply across every version. Rollout is worldwide from mid to late September.

Why it matters

Every agent count I have reported to a steering committee off this registry was inflated, and I did not know by how much. Now the number falls without a single agent being retired, which is an awkward slide if last month's figure is already in a board pack. Screenshot your current count first. Then the drop reads as a fix rather than as someone deleting things.

Source →
  • QuickA Microsoft-managed Agent 365 CLI enterprise app means new CLI setups no longer need a tenant-owned client application (MC1477186). Existing customer-owned configurations keep working.
  • QuickDeclarative agents built with the Microsoft 365 Agents Toolkit can now use A2A-capable Agent 365 agents as connected agents, alongside OpenAPI and MCP servers. Only an administrator can install them.

3The automation layer goes managed, with warnings attached

Routines went from preview to GA in seven days

Foundry Routines entered public preview on 18 September and reached general availability on 24 September. A routine runs a published agent on a schedule, at a future time, or on an external event, replacing the scheduler, event listener, webhook, queue, authentication, run history and monitoring you would otherwise assemble. Three trigger types ship: timer for a single future run, recurring with cron expressions, and event-based, with GitHub and Microsoft Teams as the first event sources. A routine runs either under the creator's delegated identity or under an agent identity holding its own Entra permissions. A reminder tool is in preview, letting an agent schedule itself to run again after a delay.

Why it matters

Six days from preview to GA is not a cadence I can explain. The identity choice outlasts the feature. A routine running under a creator's delegated identity produces an audit trail shaped like a person for work nobody was present for, and when that person changes role the automation inherits the change. Pick the agent identity and accept the extra setup. I do not know how much real load that preview week carried, and Microsoft has not said.

Source →

Two warnings in Microsoft's own release notes are worth more than the features

Agent Framework shipped AG-UI, an event-based protocol for driving application interfaces from an agent, stable in Python and public preview in .NET, with a new AG-UI .NET SDK built on Microsoft.Extensions.AI. Memory gained FoundryMemoryProvider, backed by Foundry Agent Service, plus a preview CosmosMemoryContextProvider. A Resilient Responses Host adds background execution with checkpointing and recovery in both languages, and CodeAct with Hyperlight reports roughly 50 percent lower latency. Microsoft states plainly that recovery does not imply exactly-once execution of external effects, so handlers must be idempotent, and that a session ID is not an authorisation boundary.

Why it matters

Those two lines describe the incidents this feature will cause. Recovery is not a transaction. Checkpointing reads like a safety net, and then a recovered workflow re-sends an email or re-posts a payment, because the external effect was never transactional. The session ID warning is the same shape: it looks like a tenant boundary in a demo and it is not one. Write the idempotency key before the happy path. That applies to anyone wiring AG-UI into a customer-facing surface this quarter.

Source →
  • QuickVoice agents in Foundry entered public preview with more than 80 languages and 140 locales. Long-running resilience and Toolboxes for prompt agents are in preview, tool search and A2A reached GA. Microsoft states the rubric evaluator, traces-to-dataset generation and Agent Optimizer reach GA later this month, which is its wording and not something I could confirm.
  • QuickGPT-6 Astra, Sol and Luna are all GA in Foundry, across 28 Global regions plus the US and EU Data Zones.
  • QuickUser and session isolation shipped for hosted agents, though the AgentServer SDKs stay pre-release. Network egress controls are in preview with no SLA and Microsoft's own note that they are not for production.

4The record of what shipped is being switched off

Release plans stop being published, and the dated commitment goes with them

The Power Automate 2026 wave 1 page now carries a banner: release plans will no longer be published starting in September 2026. New Dynamics 365, Power Platform and Dataverse capabilities go to the AI at Work roadmap instead, and existing release plans stay available for historical reference until further notice. I fetched the Power Automate wave page myself to confirm it, and the same banner sits on the Dynamics 365 and Power Platform wave overviews.

Why it matters

This is not a feature. It is the retirement of the artefact I cite most. A release wave plan was dated, reviewable and downloadable, and it let me tell a client a capability was committed for a stated window. A roadmap card can change without a diff, a worse instrument for a governance board even when it is more current. Combined with Copilot Studio's what's-new frozen since July, I now trust Message Center posts and product blogs more than the pages built for this purpose, and that is not a healthy place to be.

Source →
Three disclosure surfaces this week. Release plans stop being published, Copilot Studio's what's-new ends at July, its Released Versions page ends at 30 June. The Message Center and product blogs are carrying the load.
Three disclosure surfaces this week. Release plans stop being published, Copilot Studio's what's-new ends at July, its Released Versions page ends at 30 June. The Message Center and product blogs are carrying the load.
  • QuickCopilot Studio's what's-new on Learn has not moved past July, and its Released Versions page, which states it updates every Tuesday, still shows 2026.6.3 from 30 June.
  • QuickRoadmap 570967 puts Maker Guidelines in the Copilot Studio Review pane, naming which tools, models, connectors and channels an environment approves. Preview now, GA in November, web only.

5Fresh authentication beats another scope list

GitHub names agents as a session-hijack risk in its own release note

Proof of presence went to public preview on 24 September. It forces a re-authentication or a multi-factor challenge before a high-impact action, by sending the member back to their identity provider. Creating a token, editing webhooks, changing organisation security settings and viewing recovery codes all qualify. It is scoped to managed user enterprises on github.com and GHEC-DR using Entra ID for SSO over SAML or OIDC. A challenge lasts two hours, and cover for pull request merges is listed as coming soon. GitHub's stated reason includes blocking agents going an extra step without your knowledge.

Why it matters

Read that line again. That is a vendor naming its own agents as a credential-abuse vector in a release note, not in a research paper, and I have not seen another do it this directly. The control itself is narrow: managed users, Entra SSO, no merge coverage yet. But it points at the gap every CISO I brief asks about, which is what stops a valid token from doing something a human never approved. Fresh authentication beats another scope list.

Source →

Defender gets a unified operations centre, and nothing new for agents

From 23 September, the Integrated Security Operations Center in Microsoft Defender is in preview for eligible Microsoft 365 E5 and E7 customers without an active Microsoft Sentinel workspace, bringing XDR, SIEM, threat intelligence, automation and AI into the Defender portal. The Identity Security dashboard and Coverage and Maturity both reached general availability, covering identity risk across on-premises, cloud, SaaS, identity providers and partner technologies.

Why it matters

The scope matters more than the acronym: a unified console in front of E5 customers who never bought the SIEM changes who can run one. Defender's what's-new lists nothing new for agents in September, because AI agent posture risk, Agent 365 threat detection and real-time protection are all July items, two of them still preview. Agent security stood still this month. If you are waiting for it to mature before you scale, plan on July's feature set.

Source →
  • QuickGrok 4.7 shipped in GitHub Copilot on 21 September, billed at provider list pricing under usage-based billing. Third-party coverage claimed this weeks before the changelog carried it, which is why I date these to the entry, not the write-up. The contrast is the useful part. Grok on GitHub is default-enabled unless an admin turns it off. Grok in Microsoft Copilot sits behind a disabled-by-default setting and is blocked in the EU, EFTA and UK.
  • QuickClaude Opus 5.5 and OpenAI's GPT-6 Sol and Luna arrived in GitHub Copilot on 22 September. Local sandboxing and OpenTelemetry landed in the Copilot app. VS Code shipped 1.139.0 and 1.139.1.

6Grounding arrives on the meter

Work IQ opens in preview on 30 September, on the meter

Work IQ grounds Copilot and agents in business data, modelling it once so both share one foundation across Dynamics 365 CRM and ERP, Power Platform, Dataverse, Microsoft 365 context and third-party apps. Preview starts on 30 September, rollout runs through October, ERP apps arrive late in October. Developers get Work IQ APIs, an MCP server, a CLI, a plugin for coding agents, the Dataverse Ask API and a business-skills framework. It is charged through usage-based billing.

Why it matters

Work IQ has been the assumed foundation under every Copilot grounding story for months, and a preview you heard about rather than touched. The Dataverse Ask API and the MCP server are the difference between grounding a demo and grounding a client's actual CRM. On Tuesday I can touch both. It also arrives billed, which puts it straight under this week's hero.

Source →
  • QuickA new plugin registry is rolling out, bringing Microsoft, partner and custom plugins into one catalogue that IT approves centrally.
  • QuickThe Microsoft Ignite session catalogue and registration are open, for 17 to 20 November.

Voices to follow

  • Microsoft Software Engineer - CoworkBas Brekelmans

    Software Engineer at Microsoft, started the Copilot Cowork project and previously CTO of Copilot Studio. The clearest voice on why Microsoft chose multi-model, MCP, and A2A architecture across the agent stack.

    Microsoft Software Engineer, Cowork - ex-CTO Copilot Studio
  • Microsoft Principal Cloud Developer Advocate - AISeth Juarez

    Principal Cloud Developer Advocate at Microsoft on AI. One of the most watchable explainers of Foundry, the Agent Framework, and GitHub Copilot for developers - deep technical content that stays accessible.

    Microsoft Principal Cloud Developer Advocate - AI
  • Microsoft EVP - Copilot, Agents & PlatformCharles Lamanna

    Executive Vice President for Copilot, Agents, and Platform at Microsoft. He owns the strategy behind Copilot Studio, Agent 365, and the Power Platform, so when the agent stack's direction shifts, it usually shifts because of a decision his org made.

    Microsoft EVP - Copilot, Agents & Platform
  • Microsoft Partner Director - Foundry Agent ServiceJeff Hollan

    Partner Director of Product at Microsoft, leading the Foundry agent platform: Agent Service, the Agent Framework, and the SDKs. The clearest source on how agents actually go from prototype to a hosted production runtime.

    Microsoft Partner Director - Foundry Agent Service + Agent Framework
  • Microsoft Principal Cloud Advocate - Power Platform + agentsDaniel Laskewitz

    Principal Cloud Advocate at Microsoft, ex-Power Platform MVP and co-founder of Forward Forever. One of the clearest voices on multi-agent systems and Power Platform governance - the bridge between the maker community and the product teams.

    Microsoft Principal Cloud Advocate - Power Platform governance + agents
  • Copilot Studio MVPLisa Crosbie

    6x Microsoft MVP, Practical AI for Business with Copilot and Agents at Barhead. Calm, hands-on voice on production-grade agent design - the one to follow when you want patterns you can ship, not just demo.

    6x Microsoft MVP - YouTuber + International Speaker - ~21K followers
  • Microsoft VP - Azure AI FoundryMarco Casalaina

    VP at Microsoft focused on Azure AI Foundry and the Foundry Agent Service. A direct source on frontier models, hosted agents, and the runtime developers build production agents on.

    Microsoft VP - Azure AI Foundry Agent Service
  • Microsoft Principal PM - Copilot Studio (Power CAT)Henry Jammes

    Principal Program Manager for Copilot Studio on the Power CAT team at Microsoft. Deep on agent-building mechanics, governance, and the release roadmap - a first-party source on what Copilot Studio can actually do.

    Microsoft Principal PM - Copilot Studio (Power CAT)

Coming up

  • 30 September · Work IQ preview opensrollout to late October
  • 30 September · Copilot Dev Camp Summit Fall Edition08:00 Pacific, Copilot and Cowork extensibility
  • 30 September · Project Online retiresin-app retirement banner is already showing
  • 19 October · GitHub Copilot model deprecationssix models including Grok 4.5 go
  • 21 October · Researcher control retirements beginno tenant opt-in, runs to 30 December
  • November · Maker Guidelines reach GA in Copilot Studiopreview now, web only
  • 17 to 20 November · Microsoft Ignitecatalogue and registration open

This week's question

If a cost control also decides which models Auto may route to, who should hold it? Finance owns the budget and will set the tightest scope that survives the quarter. Nobody in that room is accountable for answer quality. I lean towards writing model-family scope as a joint decision with a named quality owner, the way we already do for data classification. I genuinely do not know whether that survives the first month a Copilot Credits invoice lands higher than forecast.

#M365Copilot#Cowork#CopilotStudio#Agent365#Foundry#AgentFramework#GitHubCopilot#Governance#WorkIQ
← All editions

Get Agentic Weekly in your inbox

Every Monday morning. Unsubscribe any time.

Elliot Margot

© 2026 Elliot Margot. Microsoft AI Specialist & Power Platform Solutions Architect.

Working atWitivio

Site Map

HomeAboutResume / CVProjectsTech StackFree MentorshipContactSitemapPrivacy PolicyImpressum

Contact Me

Ready to build? Let's architect your next big leap.

Get in Touch