Bite 1 / 9
Lesson 9.1

From Copilot to agents

You'll be able to Explain what agents add beyond out-of-the-box Copilot.

Agents fill the gaps

Out-of-the-box Copilot assists inside the apps. Agents go further: pre-built or custom assistants that carry specialised knowledge and can take actions to fill gaps in specific workflows. They are how you extend Copilot to your own processes.

Check what you know

What do agents add beyond standard Copilot?

What do agents add beyond standard Copilot?
Takeaway

Agents extend Copilot with specialised knowledge and actions for your workflows.

Lesson 9.2

Building agents with Copilot Studio

You'll be able to Describe how Copilot Studio builds agents using generative answers, actions and knowledge sources.

Low-code authoring

Copilot Studio is a low-code canvas for building agents. Generative answers respond from connected knowledge sources with citations; generative actions connect the right tools in real time; knowledge sources ground the agent in SharePoint, Dataverse, documents, websites and connectors.

Three building blocks

answer from connected knowledge with summarisation and citations.

Agent Builder vs Copilot Studio

For a quick agent for yourself or a small team, use Agent Builder in Microsoft 365 Copilot. For a broader audience or advanced needs (multi-step workflows, custom integrations), use Copilot Studio.

Check what you know

What do knowledge sources do in Copilot Studio?

What do knowledge sources do in Copilot Studio?
Takeaway

Copilot Studio builds agents from generative answers, actions and grounded knowledge sources.

Lesson 9.3

Governing agents at scale with Agent 365

You'll be able to Explain what Microsoft Agent 365 is and the pillars it provides.

A control plane for agents

Microsoft Agent 365 is the control plane for AI agents. It provides a registry (a unified inventory of all agents, Microsoft and non-Microsoft, including discovered 'shadow' agents), identity via Entra Agent ID, access control, observability and security through Entra, Defender and Purview. It is included with Microsoft 365 E7.

What Agent 365 gives you

  1. Registry — one inventory of every agent, including shadow agents.
  2. Identity — first-class agent identity via Entra Agent ID.
  3. Access control — RBAC/ABAC and risk-based Conditional Access for agents.
  4. Observe & secure — monitor behaviour; protect with Defender and Purview.

Check what you know

What problem does the Agent 365 registry solve?

What problem does the Agent 365 registry solve?
Takeaway

Agent 365 is the control plane: a registry, agent identity, access control, observability and security.

Lesson 9.4

Agent security and risk

You'll be able to Explain why agents carry higher consequence and how governance makes risk observable.

Acting agents raise the stakes

An agent that takes actions can have more consequence than a chat reply. Prompt-injection is a real risk class — Microsoft documents that Copilot blocks prompt-injection (jailbreak) attempts, but no control is absolute. Governance does not remove risk; it makes risk observable and bounded. Teach this honestly.

[author: verify before teaching specifics]

If you reference a specific vulnerability or CVE, confirm it against a primary Microsoft source first. Do not state a patch date or CVE number from memory.

Check what you know

What does governance do for agent risk?

What does governance do for agent risk?
Takeaway

Acting agents carry higher consequence — governance makes risk observable, not absent.

Lesson 9.5

Multi-agent systems and workflows

You'll be able to Describe how agents combine into multi-step workflows.

Agents working together

Generative orchestration lets an agent chain topics, knowledge and actions, and recognise several intents at once. Agents can be composed into deterministic workflows and connect to tools, including via the Model Context Protocol (MCP). Capabilities here ship in release waves — check current status.

Check what you know

What does generative orchestration let an agent do?

What does generative orchestration let an agent do?
Takeaway

Orchestration composes agents into multi-step workflows — verify wave status before building.

Lesson 9.6

Agent lifecycle and ownership

You'll be able to Explain who owns an agent across its lifecycle and how to avoid 'shadow AI'.

Every agent needs an owner

Decide who owns an agent, what data it touches, and what happens when its maker leaves. Untracked agents become 'shadow AI'. The Agent 365 registry and the Copilot Control System manage the lifecycle: publish, deploy, block, remove, reassign owner.

Lifecycle controls

  1. Register — every agent in the inventory, with an owner.
  2. Govern — policies, access scope, data access.
  3. Review — periodic access reviews and owner attestation.
  4. Retire — deprovision agents that are no longer needed.

Check what you know

How do you avoid 'shadow AI'?

How do you avoid 'shadow AI'?
Takeaway

Every agent gets an owner and a lifecycle — unowned agents are shadow AI.

Lesson 9.7

Standing up the product function

You'll be able to Describe the repeatable build–measure–govern loop that makes innovation continuous.

A function, not a project

To keep finding value, make innovation a standing function: an intake for ideas, a backlog, an evaluation step, and a repeatable build–measure–govern loop. This framing is the studio's — Microsoft does not define a single 'product function' model — but it sits on top of Microsoft's governance and measurement tools.

The loop

  1. Intake — capture ideas and requests in one place.
  2. Evaluate — score by value, feasibility, risk.
  3. Build — Agent Builder or Copilot Studio.
  4. Measure & govern — quality metrics, Agent 365, Control System.

Check what you know

What makes innovation continuous rather than a one-off?

What makes innovation continuous rather than a one-off?
Takeaway

Make innovation a standing loop: intake, evaluate, build, measure, govern.

Lesson 9.8

Measuring agent quality

You'll be able to Explain why agents are measured on outcomes, not just usage.

Outcomes, not just clicks

Usage alone doesn't tell you an agent is good. Copilot Studio provides evaluation and analytics — generated-answer rate and quality, knowledge-source use — and you can define outcome metrics like resolution rate or conversions. Measure whether the agent actually does its job.

Check what you know

How should agent quality be measured?

How should agent quality be measured?
Takeaway

Judge an agent by outcomes — resolution and quality — not by usage counts.

Wrap-up

Sources & notes

Everything here traces to Microsoft Learn, retrieved June 2026.

Accuracy flags

  • Recency: Agent 365 reached general availability in 2026 and is included with Microsoft 365 E7; Copilot Studio ships in release waves. Re-check all Stage 9 facts at build time.
  • The specific prompt-injection vulnerability and CVE referenced in the original taxonomy (CVE-2026-21520) was NOT verified against a primary Microsoft source this run. Teach prompt-injection risk in general terms (Microsoft documents that Copilot blocks prompt-injection / jailbreak attempts) and verify any specific CVE before naming it.
Fonts (Anton, Archivo Black, Inter) stand in for the licensed LearningBites faces — swap before publishing. Microsoft's Copilot and agent surface changes monthly; re-verify before reuse.