From Copilot to agents
You'll be able to Explain what agents add beyond out-of-the-box Copilot.
Agents fill the gaps
Out-of-the-box Copilot assists inside the apps. Agents go further: pre-built or custom assistants that carry specialised knowledge and can take actions to fill gaps in specific workflows. They are how you extend Copilot to your own processes.
Check what you know
What do agents add beyond standard Copilot?
Agents extend Copilot with specialised knowledge and actions for your workflows.
Sources for this bite
Building agents with Copilot Studio
You'll be able to Describe how Copilot Studio builds agents using generative answers, actions and knowledge sources.
Low-code authoring
Copilot Studio is a low-code canvas for building agents. Generative answers respond from connected knowledge sources with citations; generative actions connect the right tools in real time; knowledge sources ground the agent in SharePoint, Dataverse, documents, websites and connectors.
Three building blocks
answer from connected knowledge with summarisation and citations.
chain topics, knowledge and actions; call APIs and flows.
ground the agent in trusted internal and external content.
Agent Builder vs Copilot Studio
For a quick agent for yourself or a small team, use Agent Builder in Microsoft 365 Copilot. For a broader audience or advanced needs (multi-step workflows, custom integrations), use Copilot Studio.
Check what you know
What do knowledge sources do in Copilot Studio?
Copilot Studio builds agents from generative answers, actions and grounded knowledge sources.
Sources for this bite
Governing agents at scale with Agent 365
You'll be able to Explain what Microsoft Agent 365 is and the pillars it provides.
A control plane for agents
Microsoft Agent 365 is the control plane for AI agents. It provides a registry (a unified inventory of all agents, Microsoft and non-Microsoft, including discovered 'shadow' agents), identity via Entra Agent ID, access control, observability and security through Entra, Defender and Purview. It is included with Microsoft 365 E7.
What Agent 365 gives you
- Registry — one inventory of every agent, including shadow agents.
- Identity — first-class agent identity via Entra Agent ID.
- Access control — RBAC/ABAC and risk-based Conditional Access for agents.
- Observe & secure — monitor behaviour; protect with Defender and Purview.
Check what you know
What problem does the Agent 365 registry solve?
Agent 365 is the control plane: a registry, agent identity, access control, observability and security.
Sources for this bite
Agent security and risk
You'll be able to Explain why agents carry higher consequence and how governance makes risk observable.
Acting agents raise the stakes
An agent that takes actions can have more consequence than a chat reply. Prompt-injection is a real risk class — Microsoft documents that Copilot blocks prompt-injection (jailbreak) attempts, but no control is absolute. Governance does not remove risk; it makes risk observable and bounded. Teach this honestly.
[author: verify before teaching specifics]
If you reference a specific vulnerability or CVE, confirm it against a primary Microsoft source first. Do not state a patch date or CVE number from memory.
Check what you know
What does governance do for agent risk?
Acting agents carry higher consequence — governance makes risk observable, not absent.
Sources for this bite
Multi-agent systems and workflows
You'll be able to Describe how agents combine into multi-step workflows.
Agents working together
Generative orchestration lets an agent chain topics, knowledge and actions, and recognise several intents at once. Agents can be composed into deterministic workflows and connect to tools, including via the Model Context Protocol (MCP). Capabilities here ship in release waves — check current status.
Check what you know
What does generative orchestration let an agent do?
Orchestration composes agents into multi-step workflows — verify wave status before building.
Sources for this bite
Agent lifecycle and ownership
You'll be able to Explain who owns an agent across its lifecycle and how to avoid 'shadow AI'.
Every agent needs an owner
Decide who owns an agent, what data it touches, and what happens when its maker leaves. Untracked agents become 'shadow AI'. The Agent 365 registry and the Copilot Control System manage the lifecycle: publish, deploy, block, remove, reassign owner.
Lifecycle controls
- Register — every agent in the inventory, with an owner.
- Govern — policies, access scope, data access.
- Review — periodic access reviews and owner attestation.
- Retire — deprovision agents that are no longer needed.
Check what you know
How do you avoid 'shadow AI'?
Every agent gets an owner and a lifecycle — unowned agents are shadow AI.
Sources for this bite
Standing up the product function
You'll be able to Describe the repeatable build–measure–govern loop that makes innovation continuous.
A function, not a project
To keep finding value, make innovation a standing function: an intake for ideas, a backlog, an evaluation step, and a repeatable build–measure–govern loop. This framing is the studio's — Microsoft does not define a single 'product function' model — but it sits on top of Microsoft's governance and measurement tools.
The loop
- Intake — capture ideas and requests in one place.
- Evaluate — score by value, feasibility, risk.
- Build — Agent Builder or Copilot Studio.
- Measure & govern — quality metrics, Agent 365, Control System.
Check what you know
What makes innovation continuous rather than a one-off?
Make innovation a standing loop: intake, evaluate, build, measure, govern.
Sources for this bite
Measuring agent quality
You'll be able to Explain why agents are measured on outcomes, not just usage.
Outcomes, not just clicks
Usage alone doesn't tell you an agent is good. Copilot Studio provides evaluation and analytics — generated-answer rate and quality, knowledge-source use — and you can define outcome metrics like resolution rate or conversions. Measure whether the agent actually does its job.
Check what you know
How should agent quality be measured?
Judge an agent by outcomes — resolution and quality — not by usage counts.
Sources for this bite
Sources & notes
Everything here traces to Microsoft Learn, retrieved June 2026.
Microsoft Learn sources used in this stage
- Choose between Microsoft 365 Copilot and Copilot Studio to build agents
- Explore AI capabilities in Copilot Studio
- Knowledge sources in Copilot Studio
- Microsoft Agent 365 (service description)
- Why does an enterprise need Agent 365?
- Agent Registry convergence with Microsoft Agent 365
- Copilot Control System — management controls
- Manage your Copilot Studio projects — governance and security
- Govern and secure AI agents (Cloud Adoption Framework)
- Extend and optimize Microsoft 365 Copilot (Extend & optimize)
- Data, Privacy, and Security for Microsoft 365 Copilot
Accuracy flags
- Recency: Agent 365 reached general availability in 2026 and is included with Microsoft 365 E7; Copilot Studio ships in release waves. Re-check all Stage 9 facts at build time.
- The specific prompt-injection vulnerability and CVE referenced in the original taxonomy (CVE-2026-21520) was NOT verified against a primary Microsoft source this run. Teach prompt-injection risk in general terms (Microsoft documents that Copilot blocks prompt-injection / jailbreak attempts) and verify any specific CVE before naming it.