Module 8: Microsoft 365 Copilot & Agents

📚 M365 Admin Center Course · Module 8 of 9

Microsoft 365 Copilot & Agents

MS-102
MS-102 Exam Alignment
MS-102

Implement and manage Microsoft 365 Copilot: plan and manage Copilot licensing, configure Copilot settings and connectors, manage prompts and cost, and administer Copilot agents.

  • Understand Copilot licensing — separate add-on licence required on top of M365 E3/E5
  • Navigate the Copilot section: Overview, Connectors, Prompts, Billing & usage, Settings, Cost management
  • Configure Microsoft Graph connectors to extend Copilot's knowledge to external data sources
  • Manage the Agents section: Overview, All agents, Tools, Settings
  • Understand data governance — Copilot respects M365 permissions; agents run in user context
Exam Tip: MS-102 now tests Copilot governance. Know that Copilot requires a separate paid add-on licence on top of a qualifying base licence, and that agents strictly operate within the signed-in user's existing M365 permissions — they cannot access data the user cannot already see.
Microsoft 365 Copilot is an AI assistant deeply integrated across Teams, Outlook, Word, Excel, PowerPoint, and other M365 apps. As an administrator, you govern it through a dedicated Copilot section in the M365 Admin Center — controlling licensing, data connections (Connectors), prompt libraries (Prompts), cost monitoring, and agent deployment. This module walks through the actual admin center navigation as it exists today.

🤖 What Is Microsoft 365 Copilot?

💡 Copilot = LLM + Microsoft Graph + Your M365 Data

Microsoft 365 Copilot combines a Large Language Model (LLM) with Microsoft Graph — the data layer that connects emails, calendar, Teams messages, SharePoint documents, OneDrive files, and meeting transcripts. When a user asks Copilot a question, it grounds its response in that user's actual organisational data, within their existing permission boundaries. It is not a general internet search — it works on your organisation's content.

Copilot Licensing Requirements

Requirement Details
Qualifying base licence Microsoft 365 E3, E5, Business Standard, or Business Premium
Copilot add-on licence Microsoft 365 Copilot — purchased separately per user per month; assigned via Billing → Licenses
Service prerequisites User must have OneDrive and Exchange Online enabled; Microsoft Search must be active
Where to assign Billing → Licenses → Microsoft 365 Copilot → Assign licenses

🗺️ The Copilot Section — Current Admin Center Navigation

The Copilot section is a top-level navigation item in the M365 Admin Center left-hand menu. It contains two groups: Copilot (platform settings) and Agents (AI agent management). The navigation below reflects the current M365 Admin Center as shipped by Microsoft.


M365 Admin Center Copilot

Microsoft 365 admin center
|
Copilot › Overview
Copilot
Overview
Connectors
Prompts
Billing & usage
Settings
Cost management
Agents
Overview
All agents
Tools
Settings

Copilot — Overview
127
Licences assigned
89
Active users (30d)
38
Inactive licences
Top Copilot apps this month
Teams — 76 users
Word — 54 users
Outlook — 41 users

📋 Copilot Section — Tab-by-Tab Reference

Connectors — Microsoft Graph connectors extend Copilot's knowledge beyond built-in M365 services to external data sources such as ServiceNow, Confluence, Jira, Salesforce, and custom line-of-business systems. Each connector indexes external content into Microsoft Search, making it available for Copilot to reference. Connectors require configuration and are subject to their own licencing (Microsoft 365 Copilot connector capacity units).
Prompts — Admins can create and publish prompt libraries for their organisation — curated prompt templates that guide users on how to get the best results from Copilot for specific tasks (e.g. "Summarise this meeting", "Draft a project status update"). Published prompts appear in the Copilot prompt gallery for licensed users across M365 apps.
Billing & usage — Shows detailed Copilot adoption metrics: active users per app, message volume, feature usage breakdowns, and licence utilisation. Unlike the Overview's headline numbers, Billing & usage provides exportable, date-range-filterable reports. Admins use this to identify inactive licences for reclamation and to build adoption business cases.
Settings — Controls platform-level Copilot configuration for the tenant, including: whether Copilot can reference public web content (via Bing — toggle off for data sovereignty requirements), intelligent recap in Teams meetings, image generation via Microsoft Designer, and whether users can access Copilot in Edge sidebar. Also contains privacy settings governing how interaction data is handled.
Cost management — Provides visibility into Copilot consumption against purchased capacity, particularly relevant for pay-as-you-go Copilot features (such as agent message capacity in Microsoft 365 Copilot Studio). Admins set spending limits, view consumption trends, and configure alerts when usage approaches defined thresholds.

🤖 Agents Section — Tab-by-Tab Reference

All agents — The central catalogue of all Copilot agents available in or deployed to the tenant. This includes Microsoft-built agents (e.g. Interpreter, Facilitator, Employee Self-Service) and custom agents built in Microsoft Copilot Studio. Admins review, approve, deploy, or block agents from this view. Agents listed here may show statuses such as Available, Deployed, Pending admin review, or Blocked.
Tools — Manages the tools (also called actions or plugins) that agents can invoke — connectors to external APIs, Microsoft Power Platform flows, and other integrations that give agents the ability to take actions beyond just generating text (e.g. creating a ticket, updating a CRM record, triggering an approval). Admins control which tools are available and to which agents.

📊 Copilot Data Governance — Settings Deep Dive

Setting What It Controls Default & Recommendation
Web search (Bing) Allows Copilot to use Bing to supplement responses with current public web information On by default. Disable if data sovereignty or industry regulations prevent query data leaving the M365 boundary.
Intelligent recap Automatically generates AI meeting summaries, action items, and chapter markers for recorded Teams meetings On for licensed users. Requires Teams Premium or Copilot licence. Summaries stored in meeting chat.
Image generation Copilot can generate images via Microsoft Designer integration within supported apps On for licensed users. Can be disabled organisation-wide in Settings if not appropriate for the workplace.
Copilot in Edge sidebar Licensed users can access Microsoft 365 Copilot from the Microsoft Edge sidebar, referencing open browser tabs On by default. Edge must be the browser; context from open pages can be included in prompts.
User pinning of Copilot Whether users can pin the Copilot chat pane in Teams as a persistent sidebar item Controlled via Teams app setup policies; not a standalone toggle in the Copilot settings page.

⚠️ Public Web Content (Bing) — Data Sovereignty Consideration

When web search is enabled, user query context may leave the Microsoft 365 data boundary to retrieve Bing results. For organisations in regulated sectors (financial services, healthcare, government, legal) or under strict GDPR data residency requirements, this setting should be reviewed with your Data Protection Officer. Disabling it ensures all Copilot interactions remain fully within the Microsoft 365 trust boundary.

🔌 Connectors — Extending Copilot's Knowledge

By default, Copilot can only reference data in Microsoft 365 — Exchange, Teams, SharePoint, OneDrive, and OneNote. Microsoft Graph connectors extend this to external business systems.

  • Pre-built connectors — Microsoft provides connectors for common platforms: ServiceNow, Confluence, Jira, Azure DevOps, Salesforce, GitHub, Box, and others. Available in the Microsoft Admin Center under Copilot → Connectors.
  • Custom connectors — Organisations can build custom connectors via the Microsoft Graph connector SDK to index proprietary systems or databases not covered by pre-built options.
  • Indexing & permissions — When a connector indexes external content, it respects the access controls of the external system. Users only see connector results they have permission to access in the source system.
  • Connector capacity — Each Microsoft 365 Copilot licence includes a connector capacity allocation (measured in items indexed). Exceeding this may require purchasing additional Microsoft 365 Copilot connector capacity.

🔤 Agent Types in All Agents

Agent Type Built By How Deployed Example
Microsoft-built agents Microsoft Available in All agents; admin deploys to users via the admin center Interpreter agent (Teams meeting translation), Facilitator agent (meeting notes), Employee Self-Service agent (HR/IT Q&A)
Declarative agents Developers / admins via Microsoft Copilot Studio Submitted for admin review; appear in All agents as "Pending review" until approved and deployed Custom IT helpdesk, Sales territory assistant, HR leave policy Q&A
Custom engine agents Developers via Azure AI Foundry + Teams Toolkit Deployed via Teams app packages; appear in All agents once submitted Fully custom LLM-backed agents with proprietary reasoning engines

🛡️ Agent Security — Key Principles

✅ Agents Always Operate in User Context

Every Copilot agent runs under the identity of the signed-in user and can only access M365 data that user already has permission to view. An agent cannot read a SharePoint document library the user has no access to, cannot see another user's emails, and cannot bypass Conditional Access policies. All agent activity is logged in the Microsoft 365 Unified Audit Log under the user's UPN — providing a full audit trail for compliance and security reviews.

  • Admin approval required — Custom agents built in Copilot Studio must be reviewed and explicitly deployed by an admin via Copilot → Agents → All agents before users can access them.
  • User creation controls — Under Agents → Settings, admins can restrict who may create and publish agents: allow all licensed users, restrict to specific groups, or block all user-created agents entirely.
  • Tools governance — The Tools tab (Agents → Tools) lets admins review and restrict which external API integrations (tools/plugins) are available for agents to call, preventing agents from connecting to unapproved external endpoints.
  • Data Loss Prevention — Microsoft Purview DLP policies apply to Copilot interactions. Sensitive data labels on documents are honoured; Copilot will not surface content that DLP policies restrict from the user.

🎓 Interview Q&A

Q: A user has Microsoft 365 E3 and wants to use Copilot. What do they need and where is it assigned?
E3 alone is insufficient — the user also needs a Microsoft 365 Copilot add-on licence purchased separately. It is assigned in Billing → Licenses → Microsoft 365 Copilot → Assign licenses. Once assigned, Copilot becomes available in Teams, Outlook, Word, Excel, PowerPoint, and other M365 apps within a few minutes. The user must also have OneDrive and Exchange Online active on their account.
Q: What is the purpose of Microsoft Graph connectors in the Copilot admin center?
Microsoft Graph connectors, found under Copilot → Connectors, extend Copilot's knowledge beyond native M365 services to external business systems — ServiceNow, Confluence, Jira, Salesforce, and others. When a connector is configured and indexing is complete, Copilot can reference content from those external sources when responding to user queries, subject to the user's access permissions in the external system.
Q: Your CISO is concerned Copilot may be sending employee data to Bing for web search. Which setting controls this, and where is it?
The web search (Bing) setting under Copilot → Settings controls whether Copilot can use Bing to supplement responses with public web content. When enabled, user query context may leave the M365 data boundary to retrieve Bing search results. Disabling this setting ensures all Copilot processing remains within the Microsoft 365 trust boundary.
Q: A developer has built a custom Copilot agent in Microsoft Copilot Studio. What must happen before employees can use it?
Custom agents built in Microsoft Copilot Studio appear in Copilot → Agents → All agents with a "Pending admin review" status. An administrator must review the agent and explicitly deploy it before it becomes accessible to users. This governance checkpoint ensures no unapproved agent can access organisational data. Once deployed, the agent still operates strictly within the requesting user's existing M365 permissions.
Q: What is the Cost management section in the Copilot admin area used for?
Copilot → Cost management provides visibility into Copilot consumption against purchased capacity — particularly relevant for metered/pay-as-you-go features such as agent message capacity in Microsoft Copilot Studio. Admins can set spending limits, monitor usage trends against thresholds, and configure alerts to prevent unexpected overages.

🎯 MS-102 Mock Test
Module 8 — Microsoft 365 Copilot & Agents
5 questions · Scenario-based · MS-102 exam style · Pass mark: 70%

Question 1 of 5

A user with Microsoft 365 E3 reports that Copilot is not available in Word or Teams. What is the most likely reason?

ACopilot requires Microsoft 365 E5 — E3 is not a qualifying base licence
BThe Microsoft 365 Copilot add-on licence has not been assigned to the user
CCopilot must be enabled per-app by the admin in Copilot → Settings
DThe user's OneDrive storage quota has been exceeded
Correct answer: B. Microsoft 365 E3 is a qualifying base licence, but Copilot is a separate add-on licence that must be purchased and assigned in addition. Assign it via Billing → Licenses → Microsoft 365 Copilot. E3, E5, Business Standard, and Business Premium are all qualifying base licences.
Question 2 of 5

An organisation wants Copilot to be able to answer questions drawing from their ServiceNow incident database. Which feature in the Copilot admin section enables this?

ACopilot → Prompts — create a prompt template pointing to ServiceNow
BAgents → Tools — add ServiceNow as an agent tool
CCopilot → Connectors — configure the ServiceNow Microsoft Graph connector
DCopilot → Settings → External data sources → Add ServiceNow
Correct answer: C. Microsoft Graph connectors, managed under Copilot → Connectors, index content from external systems (ServiceNow, Jira, Confluence, Salesforce etc.) into Microsoft Search. Once indexed, Copilot can reference that content in responses, subject to each user's access permissions in ServiceNow.
Question 3 of 5

Your legal team has flagged that Copilot may be sending user query context to Bing for web search. Which setting should you review, and where is it in the admin center?

ACopilot → Connectors → Bing web connector
BCopilot → Settings → Web search (Bing) toggle
CSettings → Org settings → Bing integration
DCopilot → Cost management → External query limits
Correct answer: B. The web search toggle is under Copilot → Settings. When enabled, Copilot can supplement responses using Bing, which may involve query context leaving the M365 data boundary. Disabling it keeps all Copilot interactions within Microsoft 365.
Question 4 of 5

A developer submits a custom Copilot agent built in Microsoft Copilot Studio. A manager reports that employees still cannot access it a week later. What is the most likely reason?

ACustom agents require Microsoft certification before deployment
BCustom agents can only be used by the developer who built them until published
CAn administrator has not yet reviewed and deployed the agent via Copilot → Agents → All agents
DThe agent requires a separate Copilot Studio licence for each end user
Correct answer: C. Custom agents submitted from Microsoft Copilot Studio appear in Copilot → Agents → All agents with a "Pending admin review" status. An administrator must review and explicitly deploy the agent before it becomes available to users. This admin approval step is a required governance checkpoint — agents do not auto-deploy.
Question 5 of 5

An administrator wants to monitor Copilot metered feature consumption and set spending alerts before costs exceed budget. Which section of the Copilot admin area provides this?

ACopilot → Billing & usage — provides licence adoption and active user metrics
BCopilot → Settings — contains spending limit controls
CBilling → Subscriptions — shows all subscription costs
DCopilot → Cost management — tracks metered consumption and enables spending limits and alerts
Correct answer: D. Copilot → Cost management is specifically designed to track metered Copilot consumption (such as agent message capacity) against purchased limits, set spending thresholds, and configure alerts. Billing & usage (option A) focuses on adoption metrics (active users, app usage) rather than cost consumption.

🔒

This module is lockedComplete Module 7 and pass its mock test to unlock this module.