Elliot Margot Logo
  • Home
  • About
    Portrait of a Microsoft AI Specialist at work.
    Overview
    Abstract image of a strategic AI framework.
    Methodology
    Professional experience timeline visual.
    Experience
    Academic background and education visual.
    Education
    Certifications and diplomas visual.
    Certificates
    Letters of recommendation and testimonials visual.
    Testimonials
    Editorial photo of a resume on a warm wooden desk with fountain pen and coffee.
    Resume / CV
  • Work
    Projects portfolio hero visual.
    Projects
    Architectural tech stack hero visual.
    Tech Stack
    Open source coding and development visual.
    Open Source
    Blog header visual.
    Blog
  • Insights & Press
  • Community
    Copilot Studio Hub Discord community logo featuring Saphir the cat.
    Discord Community
    Agentic Weekly - the Microsoft AI weekly newsletter.
    Newsletter
    Microsoft AI Daily Brief - free daily digest of the Microsoft AI ecosystem.
    Microsoft AI Daily Brief
    Collaborative mentorship session visual.
    Free Mentorship
    Elliot at his workbench solving a steampunk problem - the clinic in spirit.
    Copilot Studio Clinic
    Conference stage spotlight with holographic AI agent diagrams floating above.
    Talks
My Cat SaphirContact
/
Elliot Margot Logo
/
My Cat Saphir

Navigation

  • Home
    • Overview
    • Methodology
    • Experience
    • Education
    • Certificates
    • Testimonials
    • Resume / CV
    • Projects
    • Tech Stack
    • Open Source
    • Blog
  • Insights & Press
    • Discord Community
    • Newsletter
    • Microsoft AI Daily Brief
    • Free Mentorship
    • Copilot Studio Clinic
    • Talks
Contact
  1. Community
  2. Agentic Weekly
  3. Edition 18
Agentic Weekly Edition 18 header
Edition 18

The registry grew an enforcement engine

Week of September 28 to October 4, 2026·10 signals

Edition 017 ended on a spending policy that had quietly become an access policy. This week the same idea came back with a rules engine behind it. Agent 365 put Agent Management Rules into public preview on 30 September, so an admin can now write a condition and have the platform block an agent, reject a publication request or apply a policy template without a human in the loop. Tools management went generally available in the same post, widening the central allow and block pane from MCP servers out to plugins, skills and connectors. Custom MCP servers got an approval queue. Microsoft says nearly 50 million agents have been registered since Agent 365 launched in May, which is the only number that makes a natural-language registry search sound necessary rather than decorative. The defaults are the part I keep coming back to. Observability collection on new third-party connections, Business Skills in Work IQ, and spending policies on newly supported services all arrived switched on, with an opt-out rather than an opt-in. Two corrections also belong in the record this week, both of them a secondary source promoting something to general availability that Microsoft's own pages still call preview.

This week's thread: the governance surface turned on, pointing at you

For a year the governance story around Microsoft agents has been inventory. Here are your agents, here is their telemetry, here is a dashboard. This week it became enforcement. A rule can now act on an agent on its own, a tenant-wide list decides which tools an agent may reach, and a custom MCP server waits in a queue for a named reviewer. All of that is good, and I would rather have it than the alternative. The part that needs saying out loud is that the switches arrive pre-flipped, and the criteria the rules engine reads are exactly the fields that are messiest in a real tenant. Ownership. Tags. Publisher. If you build agents inside someone else's tenant, the thing that breaks your deployment next quarter is a rule you never saw written, keyed on a field nobody kept clean.

On this page

  1. Signal of the week
  2. 1The registry grew an enforcement engine
  3. 2Most of it arrived switched on
  4. 3An agent with its own mailbox
  5. 4Preview, general availability, and the distance between them
  6. 5Copilot learns to click, in two places only
  7. Voices to follow
  8. Coming up
  9. Question

Signal of the week

Agent 365 can block your agent without a human looking at it

Agent Management Rules entered public preview on 30 September. In the Microsoft 365 admin center, admins write custom rules that fire automatically when conditions match, taking actions such as blocking an agent, rejecting a publication request, or applying a policy template. The criteria include ownership status, agent tags, Microsoft Entra Agent ID, publisher, risk signals and usage activity. Microsoft shipped it in the same post as Tools management reaching general availability, which widens the central allow and block pane from MCP servers out to plugins, skills and connectors. From one pane an admin can discover connected tools, review metadata and usage, and apply tenant-wide allow or block controls. Power Platform connector governance is still in progress.

Why it matters

Every agent I have handed to a client has had a messy ownership record at some point, usually in the gap between a proof of concept and a named owner. That gap is now a trigger. Ownership status is one of the conditions a rule can read, and the registry's AI mode, announced in the same post, uses "agents without owners" as its own example. I expect the first rule a nervous admin writes to catch the agent you are halfway through handing over. That is my guess. I have not tried it. Tag your agents and assign owners first. I would also ask every client admin whether Tools management already carries a block list. It is generally available and tenant-wide, so it can already be shaping which tools your agents reach.

Source →Connected platforms on Microsoft Learn →
An Agent Management Rule reads fields such as ownership status, tags and publisher, and acts without asking. Blocking an agent mid-handover is the failure mode to plan for.
An Agent Management Rule reads fields such as ownership status, tags and publisher, and acts without asking. Blocking an agent mid-handover is the failure mode to plan for.

1The registry grew an enforcement engine

Custom MCP servers get an approval queue

In public preview from September, developers can register custom MCP servers through the Agent 365 CLI and submit them for administrator review before any agent is allowed to invoke them. Administrators inspect the server description, publisher, requestor, endpoint and capabilities in the Microsoft 365 admin center, then approve or reject the request. Separately, the integration between Agent 365 and Azure API Management began rolling out on 30 September. AI assets onboarded to API Management, including agents, tools, models and MCP servers, can now be discovered in Agent 365 automatically, with API Management applying authentication, routing and runtime controls.

Why it matters

This is the first time the path from "I wrote an MCP server" to "an agent in production may call it" has a named reviewer and a visible queue. I prefer it to the alternative. That was a connector appearing in a maker's tool list with nobody accountable for it. Budget for the review step in your delivery plan. An approval queue with no agreed turnaround is just a new place for work to stop.

Source →

A general availability date I am not going to repeat

A widely syndicated write-up said third-party agent observability ran in Targeted Release in late September, reaches general availability in late October, and completes by Ignite. Microsoft's own documentation says something different. The capability sits inside the Frontier preview programme. Observability is supported today for Amazon Bedrock, Google Vertex AI and Anthropic Claude Managed Agents, and listed as coming soon for Salesforce Agentforce, Databricks Genie, Oracle Generative AI Agents and Snowflake Cortex. The same page carries a detail the write-up omitted. Collection is enabled by default on new connections, and off by default on connections created before the capability existed.

Why it matters

Frontier and generally available are not the same promise. I am not telling a client to plan an October cutover on a preview programme. The default-on collection matters more than the label. Connecting a third-party platform to Agent 365 now pulls that platform's agent telemetry into Microsoft 365 unless someone clears the box. Have that conversation with a security team before you create the connection, not after.

Source →
  • QuickAgent 365 met all FedRAMP High controls as of 1 October, as reviewed by Microsoft's independent third-party assessor. Final authorization by the accrediting agency is still pending, so it is a milestone rather than an authorization.
  • QuickAI mode for the Agent 365 registry is in public preview. Admins prompt the registry in natural language to find agents without owners, inactive agents, or agents that warrant a closer look, instead of building filters by hand.

2Most of it arrived switched on

Business Skills in Work IQ turned on by default

As of 30 September, Business Applications in Work IQ were enabled by default for new environments where Microsoft Copilot Premium and either Power Apps Premium or Dynamics 365 are active. That covers Dataverse search and query, semantic modeling, Business Skills, and access to declarative agents in Dataverse. Enabling the capability creates additional supporting indexes and consumes tokens in use. Microsoft notes exceptions for tenants in the EEA and those relying on FedRAMP accreditation, which are offered an opt-in instead.

Why it matters

Default-on plus token consumption deserves a look in any tenant you bill for. The carve-out is the tell. If Microsoft thought this was uncontroversial, the EEA would not need its own path. Work IQ is also due to start invoking custom agents and third-party tool calls, listed for preview in October, so the surface this default applies to is about to get wider.

Source →

Cost management widens, and the spending policy opts you in

Cost management in Agent 365 expanded beyond Copilot Cowork and Work IQ to cover Code and Copilot Managed Runtime, with Copilot Studio support planned for October. Admins can scope spending policies so different groups reach different models and effort levels, and those policies also shape which models Auto is allowed to select in Cowork. A consumption dashboard in Insights ties Cowork usage to task categories and an estimate of assisted value in time and money. Usage-based billing for SharePoint and OneDrive advanced work came under the same policies, and spending policies apply to newly supported services by default unless an admin turns that setting off.

Why it matters

The default on newly supported services is the line to read twice. A policy you wrote in August silently acquires new scope in October, which is fine until the service it acquires is one a team depends on. SharePoint Agents configured as pay-as-you-go are excluded from these policies, so a place a client may well be spending is a place the guardrail does not reach. I would reconcile the policy scope against the service list once a month until this settles.

Source →
  • QuickTwo more defaults, neither agent-related. New Viva Engage communities start with member email and calendar subscriptions on, with rollout completing by mid-October. External federated Teams chats get file sharing and automatic permissions turned on from late October (MC1479514), with PowerShell as the off switch.

3An agent with its own mailbox

Three roadmap entries that change what an agent is, none of them on the product's what's-new yet

On 30 September the Microsoft 365 roadmap gained three Copilot Studio entries. Persistent identity gives an agent its own governed Microsoft 365 identity with a mailbox, Teams presence and Office access, listed preview September 2026 and general availability November 2026. Self-learning has an agent spot repeated tool sequences in completed runs and propose them as workflows, with supporting evidence and expected impact, for a maker to accept, test and publish as a refined copy. A skills catalog lets makers discover and reuse approved organizational skills from a shared catalog powered by the Microsoft 365 App Store, spanning Copilot Studio, Microsoft 365 Copilot and Cowork.

Why it matters

I want to be precise about what these are. Copilot Studio's own what's-new page still ends at July 2026, so none of this is documented as shipped. These are roadmap listings with roadmap dates, and roadmap dates move. Persistent identity is the one I would plan around anyway. An agent with a mailbox needs a joiner-mover-leaver process, and I have never seen a client who had one ready. Self-learning is the one I am least sure about. An agent that rewrites its own tool sequences is a change-control problem wearing a productivity feature's clothes, and I do not know whether the accept-and-publish gate is enough to keep it reviewable.

Source →Copilot Studio what's-new, still ending at July 2026 →
Four defaults that start out on, and where the off switch lives. Each one is defensible on its own; together they leave the noticing to whoever administers the tenant.
Four defaults that start out on, and where the off switch lives. Each one is defensible on its own; together they leave the noticing to whoever administers the tenant.

The Authors setting was never a governance control, and Microsoft said so

The Copilot Studio Authors tenant setting in the Power Platform admin center was renamed to "Copilot Studio pay-as-you-go users" on 1 October. Microsoft's stated reason is that the setting was never built as a governance feature. It is a licensing access-control mechanism that makes the Copilot Studio pay-as-you-go meter usable by granting maker-portal access on a pure pay-as-you-go plan.

Why it matters

I have sat in governance reviews where this setting was presented as the control that limits who can build agents. It never was. A rename is a blunt way to find out. If a client's agent-governance story rests on this toggle, that story needs rewriting this month. The real controls live in the agent tenant settings and in Agent 365.

Source →

4Preview, general availability, and the distance between them

Foundry IQ in Copilot Studio is preview, and a trade report said otherwise

Connecting a Copilot Studio agent to a Foundry IQ knowledge base is documented as preview, for agents on the GitHub Copilot harness, on the Copilot Studio what's-new page since June 2026. A report circulating on 3 October called it generally available. The Foundry IQ documentation itself splits the difference by product area. Some agentic-retrieval behaviour is generally available and some is still in preview, depending on the Search Service REST API version in use. An agent can hold only one Foundry IQ connection. Connections support API key, client certificate, service principal and Microsoft Entra ID integrated authentication, and work with Azure Private Link and Power Platform VNet.

Why it matters

The pattern repeats often enough to be a rule. When a secondary source promotes something to general availability, check the product's own what's-new before you put it in a client's architecture document. Procurement reads general availability as a commitment and preview as a risk, and the difference lands in a contract. One tuned knowledge base grounding several agents is genuinely the right shape, and I would still build it today. I would label it preview on the slide.

Source →

The same two models, billed two different ways

GPT-6.1 Sol and Claude Sonnet 5.5 began rolling out on 30 September. In Copilot Cowork and Copilot Studio they arrived on usage-based billing. Across Word, Excel, PowerPoint and Chat they were set to follow in phases during the week after, under the Microsoft 365 Copilot user subscription licence, with limits that warn users as they approach them and a fallback to Auto or another model. Cowork's own September what's-new lists GPT 6 Astra and Claude Fable 5.1 in the selector and names neither of the two new arrivals, so the selector is the thing to trust.

Why it matters

One model, two commercial regimes, decided by which window you opened. I have already had the conversation where a client picks a model in Word because a colleague recommended it in Cowork. Nobody could explain why only one of them reached a credit report. Pin the surface before you pin the model. Two editions running, the interesting part of a model launch has been the billing boundary rather than the benchmark.

Source →Cowork what's-new for September 2026 →
  • QuickModel router reached 32 Azure regions, adding Canada Central, North Europe, Norway East and UAE North. Chat Completions callers can also pass an opaque session ID to keep related turns on the same eligible model, and the response reports whether the association initialized, was retained or switched.
  • QuickCowork can now edit Word, Excel and PowerPoint files already in OneDrive and SharePoint in place, keeping the shared file and its version history instead of producing a copy. Plugins also became discoverable on the mobile app.

5Copilot learns to click, in two places only

GitHub Copilot can drive desktop applications

Computer use went to public preview on 1 October in GitHub Copilot CLI and the GitHub Copilot app, on macOS and Windows. Copilot can read accessible app content and visual context, click controls, enter and edit text, press keys, scroll, drag and move work across applications, which reaches software that offers no API, no command line and no MCP integration. Copilot asks for approval before controlling an app, and you can review or reset the apps you chose to always allow. On macOS it walks you through the required Accessibility and Screen Recording permissions. Organization-managed settings can disable the feature outright. Turn it on with /computer on in the CLI, or under Settings in the app.

Why it matters

The scope line deserves care, because this is the kind of story that widens in the retelling. The changelog names the CLI and the desktop app. It does not name VS Code or the web, so I would not assume it reaches them. The organization-managed kill switch is the first thing I would check before letting this near a regulated client's laptop. The second is that approval prompt. A tool that clicks on your behalf in legacy software is exactly where an unattended yes becomes expensive. Copilot Studio has had generally available computer use since May, so a practitioner now has two Microsoft-adjacent ways to automate a graphical interface under two different governance models.

Source →
Two surfaces named in the changelog, two not, and three gates in front of them. The organization-managed setting is the one an administrator controls, so it is the one to check before this reaches a managed laptop.
Two surfaces named in the changelog, two not, and three gates in front of them. The organization-managed setting is the one an administrator controls, so it is the one to check before this reaches a managed laptop.
  • QuickFour models were deprecated across every GitHub Copilot experience on 2 October. Gemini 3.5 Flash and 3.6 Flash give way to Gemini 3.8 Flash, Kimi K2.7 Code to Kimi K3, and Claude Opus 4.7 to Claude Opus 5.5.
  • QuickThe Microsoft Agent Framework Python train shipped on 2 October at 1.20.0, with agent-framework-foundry at 1.14.0 and the Copilot Studio, DevUI, mem0, Redis, A2A and Purview connectors at 1.0.0b261002. The .NET side sits at 1.23.0, adding origin pinning for the Foundry toolbox MCP client and fixing HTTP variable handling in declarative workflows.
  • QuickThe AI-powered Support Agent became the default support experience in the Power Platform admin center on 1 October, and the legacy experience retired the same day. A fallback preserves what you typed during a session so a handoff keeps its context.
  • QuickDefender XDR was quiet, and the quiet is informative. Its what's-new lists two September items, the Integrated Security Operations Center preview from 23 September and the Identity Security dashboard reaching general availability, and neither is agent-specific.

Voices to follow

  • Microsoft EVP - Copilot, Agents & PlatformCharles Lamanna

    Executive Vice President for Copilot, Agents, and Platform at Microsoft. He owns the strategy behind Copilot Studio, Agent 365, and the Power Platform, so when the agent stack's direction shifts, it usually shifts because of a decision his org made.

    Microsoft EVP - Copilot, Agents & Platform
  • Microsoft Software Engineer - CoworkBas Brekelmans

    Software Engineer at Microsoft, started the Copilot Cowork project and previously CTO of Copilot Studio. The clearest voice on why Microsoft chose multi-model, MCP, and A2A architecture across the agent stack.

    Microsoft Software Engineer, Cowork - ex-CTO Copilot Studio
  • Microsoft Partner Director - Foundry Agent ServiceJeff Hollan

    Partner Director of Product at Microsoft, leading the Foundry agent platform: Agent Service, the Agent Framework, and the SDKs. The clearest source on how agents actually go from prototype to a hosted production runtime.

    Microsoft Partner Director - Foundry Agent Service + Agent Framework
  • Microsoft Principal Cloud Advocate - Power Platform + agentsDaniel Laskewitz

    Principal Cloud Advocate at Microsoft, ex-Power Platform MVP and co-founder of Forward Forever. One of the clearest voices on multi-agent systems and Power Platform governance - the bridge between the maker community and the product teams.

    Microsoft Principal Cloud Advocate - Power Platform governance + agents
  • Microsoft CVP - Security, Compliance, Identity & PrivacyVasu Jakkal

    Corporate Vice President for Microsoft Security. Defender's AI agent posture risk, the Agent 365 security integration and the wider security-for-AI story all ship out of her organisation.

    Microsoft CVP - Security, Compliance, Identity & Privacy
  • Copilot Studio MVPLisa Crosbie

    6x Microsoft MVP, Practical AI for Business with Copilot and Agents at Barhead. Calm, hands-on voice on production-grade agent design - the one to follow when you want patterns you can ship, not just demo.

    6x Microsoft MVP - YouTuber + International Speaker - ~21K followers
  • Microsoft Principal PM - Copilot Studio (Power CAT)Henry Jammes

    Principal Program Manager for Copilot Studio on the Power CAT team at Microsoft. Deep on agent-building mechanics, governance, and the release roadmap - a first-party source on what Copilot Studio can actually do.

    Microsoft Principal PM - Copilot Studio (Power CAT)
  • Microsoft CPO - Responsible AISarah Bird

    Chief Product Officer of Responsible AI at Microsoft. The authority on the safety, evaluation, and governance layer that decides whether an agent built in Foundry is one a regulated org will actually approve.

    Microsoft Chief Product Officer - Responsible AI

Coming up

  • October 2026 · Copilot Studio self-learning reaches general availabilityroadmap date, and roadmap dates slip
  • October 2026 · The Copilot Studio skills catalog reaches general availabilityshared skills span Copilot Studio, Microsoft 365 Copilot and Cowork
  • October 2026 · Copilot Studio joins Agent 365 cost managementagent credits land in the same pane as Cowork and Code
  • October 2026 · Usage-based billing models appear in the Microsoft 365 Copilot Chat model selectoradmins must allocate credits before users can pick them
  • November 2026 · Copilot Studio persistent agent identity reaches general availabilityhave an offboarding answer ready before this one lands

This week's question

An agent now gets its own mailbox, its own Teams presence and its own Entra identity, and a rules engine can block it with no human in the loop. So who is on the hook when it is blocked at the wrong moment and a business process stops? I lean toward the agent's named owner, because ownership is one of the fields the rules engine reads, and a control that keys on ownership only works if ownership means accountability. The trouble is that in most tenants I see, the owner field holds whoever clicked Create. I have no clean answer for that gap. I would rather hear how you are closing it than pretend I have closed it.

#Agent365#CopilotStudio#Governance#MCP#M365Copilot#GitHubCopilot#Cowork#Foundry#Security
← All editions

Get Agentic Weekly in your inbox

Every Monday morning. Unsubscribe any time.

Elliot Margot

© 2026 Elliot Margot. Microsoft AI Specialist & Power Platform Solutions Architect.

Working atWitivio

Site Map

HomeAboutResume / CVProjectsTech StackFree MentorshipContactSitemapPrivacy PolicyImpressum

Contact Me

Ready to build? Let's architect your next big leap.

Get in Touch