Skip to the main content.

Microsoft 365 Copilot · Admin Control

Somebody at your institution can already put an AI agent into your tenant. Now you can decide who. On October 25 the default decides for you.

On September 25, 2026 a setting appears in the Microsoft 365 admin center that has never been there before. It governs who may upload an advanced agent or plugin, and Microsoft draws that line at a package carrying actions or an MCP server. On October 25 the default takes effect. Do nothing and the setting lands on all users, which for most tenants is what is already true today. The thirty days are the opportunity here, not the threat.

  • September 25: rollout begins, and the control appears under Copilot Settings in the Microsoft 365 admin center
  • October 25: the setting resolves to all users unless somebody chooses otherwise
  • Advanced means a Declarative Agent with actions, or an MCP server. Those are Microsoft's words
Default applies
October 25, 2026
The default takes effect
  • All users, specific users, Entra ID groups, or no users
  • Choosing nothing leaves uploads set to all users
  • Basic packages are untouched either way
Sep 25
Rollout begins. Microsoft describes it as General Availability worldwide, starting September 25 and expected to complete by the end of October 2026.
Source: Microsoft 365 Message Center, MC1472007
30
Days from the start of rollout to the decision date. Microsoft gives administrators until October 25 to pick an option, and completes the rollout by the end of October, so a tenant reached later gets a shorter run at it.
Source: Microsoft 365 Message Center, MC1472007
4
Options in the setting: all users, selected users, Microsoft Entra ID groups, or no users.
Source: Microsoft 365 Message Center, MC1472007

What actually changes, and what does not

Read this one carefully, because the obvious reading is wrong. Microsoft is not switching something on. It is handing administrators a switch that did not exist, and the position it defaults to is the position the tenant is already in.

Today

Uploads are already allowed

Users who build a Copilot agent can upload it, subject to whatever app-upload and Copilot access settings your tenant already applies. Microsoft's reason for adding this control is that nothing has previously drawn a line between an ordinary package and one carrying actions or an MCP server. The capability gap is the control, not the upload.

September 25, 2026

The control appears

It shows up in the Microsoft 365 admin center under Copilot Settings. Microsoft describes this as the start of a General Availability rollout expected to complete by the end of October, so tenants will not all see it on the same day. From this date an administrator can see which users have uploaded packages, and the details page shows the components of each one.

October 25, 2026

The setting resolves

Microsoft's wording is precise: advanced-package uploads will be enabled by default unless the admin has selected no users or specific users or groups. Silence is read as all users. A chosen setting and an unchosen one land in the same place, and only one of them is defensible in writing.

What it covers

Three limits worth knowing

The setting reaches user-uploaded packages only, so first-party and third-party built agents sit outside it. It applies only to packages uploaded after the control appears. And basic packages stay allowed regardless of what you choose.

The two sentences that should lower your blood pressure

Microsoft states both of these plainly in the notice: "No action is required to maintain current behavior" and "If no action is taken, advanced-package uploads remain allowed by default."

Nothing opens on October 25. Nothing new becomes possible for your users on October 25. What arrives is a question, and October 25 is the day it gets answered with or without you.

Timeline of the Microsoft 365 Copilot advanced agent upload control showing September 25 2026 when the control appears in the Microsoft 365 admin center under Copilot Settings, the thirty day decision window, and October 25 2026 when the setting resolves to all users by default, with Microsoft 365 branding
Thirty days, one setting, four options. The default on October 25 preserves the behaviour the tenant already has.

What makes a package advanced?

This is the part worth reading twice. Microsoft's definition is one sentence long, it draws a capability boundary, and it tells you exactly what the control is protecting.

"An advanced agent is a package that has either a Declarative Agent with actions or with an MCP server. All other packages are considered basic."

Microsoft 365 Message Center, post MC1472007, Manage who can upload advanced agents and plugins, updated September 15, 2026

Two triggers, and both of them describe a package that can take an action. Everything else is basic, and basic uploads sit outside this control. Worth being precise about what the definition covers: it sorts packages by the capability they carry. Where the data goes is a separate question, and a basic package can still draw on outside data, because Microsoft's own guidance describes agent knowledge as able to connect external data through Microsoft 365 Copilot connectors.

Actions are the first trigger. Microsoft's own extensibility documentation describes a declarative agent as one you configure by adding "custom instructions, additional knowledge, and actions to automate business processes", and it is specific about what actions do: "Custom actions to integrate with APIs to interact with external systems in real-time." The overview page puts the consequence in plain language, saying agents can retrieve information, summarize data, "or even take actions like sending emails or updating records."

An agent without actions answers. An agent with actions can write, send, and call. That capability is the line the control is drawn on.

How Microsoft splits the two package types, and what the split means in practice. Source: Microsoft 365 Message Center post MC1472007 and Microsoft Learn Copilot extensibility documentation.
  Basic package Advanced package
What it contains Instructions and knowledge, without actions and without an MCP server A Declarative Agent with actions, or an MCP server
What the package itself can do Answer from its instructions and its knowledge sources. The package carries no actions and no MCP server Act. Microsoft describes custom actions as integrating with APIs to interact with external systems in real time, and an MCP server exposes tools the agent can call
Covered by the new control No. Basic uploads remain allowed and are not impacted Yes, for user-uploaded packages uploaded after the control becomes available
Who can upload it after October 25 Unchanged All users, unless an administrator picked specific users, Entra ID groups, or no users
Visible to administrators Listed among user-uploaded packages Listed too, and the details page shows the components of the package

The second trigger is the one most people have not thought about yet

An MCP server is the other half of Microsoft's definition, and it is newer than most governance documents in a bank or credit union. Microsoft's extensibility guidance describes the relationship this way: plugins let declarative agents in Microsoft 365 Copilot interact with Model Context Protocol servers, or with REST APIs that carry an OpenAPI description. Connecting to one gives the agent access to that server's tools, which are functions a language model can call.

Microsoft's own worked example is a remote third-party server, reached over OAuth, with a token obtained on behalf of the signed-in user every time the agent calls it. In its words, Copilot uses the registration to "obtain an access token on behalf of the signed-in user each time the agent calls the MCP server." So the agent acts with the permissions of whoever is using it, against a service outside your tenant.

"Agents Toolkit configures the generated plugin manifest (ai-plugin.json) for dynamic tool discovery, so the agent resolves the MCP server's tools ... at runtime, and you don't add tools manually."

Microsoft Learn, Build a plugin for a declarative agent from an MCP server, last updated August 11, 2026

Read that sentence with a governance hat on and it says something sharp. With dynamic tool discovery, the approved package does not carry a fixed list of what it can do. The agent asks the server what tools it has, and it asks at runtime. An approval recorded on the day of upload describes the package. It does not necessarily describe everything that package will be able to do next quarter, because the answer lives on a server somebody else operates.

Microsoft documents the alternative in the same breath, and it deserves equal billing: a builder can pin a fixed, curated set of tools, which settles the list at build time. So this is a choice somebody makes, and it is a property of how the plugin was built. The governance question is simply whether anyone at your institution is in a position to know which choice was made.

There are two similarly named controls, and they do different jobs

Microsoft's published admin guidance already documents a setting called Agent access settings, which controls how members of your organization can access and install agents, with options for all users, no users, or specific users and groups. It reads almost identically to the new one and governs something else.

The control arriving on September 25 governs who can upload an advanced package in the first place. Access is about consuming what exists. Upload is about introducing something new. An institution can have the first one locked down and the second one wide open, and until now there was no way to tell them apart.

Comparison of basic and advanced Microsoft 365 Copilot agent packages. The basic column lists instructions and knowledge only, no actions, no MCP server, not covered by the new control, and uploads remain allowed. The advanced column lists a Declarative Agent with actions or an MCP server, actions integrating with APIs in real time, covered by the new control, and governed by Microsoft Entra ID groups. The footer states that Microsoft sorts these by the capability the package carries
One sentence from Microsoft splits every uploaded package into two groups. The right-hand group is the only one the new control touches.

Find out what is already uploaded before the setting resolves

ABT reviews which agents and plugins exist in your tenant, which of them carry actions or an MCP server, and which of the four options fits how your institution actually works.

Get the free Copilot readiness assessment

Why ten minutes on this is worth more than it looks

The setting takes one click. What makes it worth a meeting is that it forces an institution to answer a question about its own AI programme that most have not written down yet.

Picture how an advanced agent actually arrives. A loan officer who is good with technology builds something useful, because that is what Copilot invites people to do and it is genuinely how work gets faster. It connects to a system the team uses every day. It saves an hour a week per person and it spreads by word of mouth, which is a good outcome and the reason to have Copilot at all.

Now the questions an examiner asks about third-party connections start applying to it. What data does it reach. Which service is on the other end. Who reviewed it. Who approved it. Those questions were always reasonable. What has been missing is a tenant-level place to stand when answering them, and that is what the setting provides.

The useful part is not the restriction. It is that the decision becomes a record. An institution that picks a named Entra ID group has a documented control with a named population behind it, which is a sentence you can put in a policy and an answer you can give without going and finding out first.

"To help organizations manage the deployment of advanced Copilot extensibility scenarios, we are introducing a new admin control that determines who can upload advanced agents and plugins. This enhancement strengthens enterprise governance and manageability by allowing administrators to limit advanced-package uploads to specific users or Microsoft Entra ID groups while maintaining flexibility for organizations that want broader access."

Microsoft 365 Message Center, post MC1472007, Manage who can upload advanced agents and plugins

Worth keeping in proportion, because the opposite error is just as costly: declarative agents are not unmanaged software running loose. Microsoft's extensibility documentation states that because they use Copilot's own infrastructure, model, and orchestrator, declarative agents "adhere to the security, compliance, and Responsible AI (RAI) requirements for Microsoft 365." They inherit that framework.

What that framework covers is worth reading carefully, and it is the reason actions and MCP servers are singled out. When an agent calls an MCP server, Microsoft's walkthrough has the user sign in to that service separately and has Copilot obtain an access token on behalf of the signed-in user for each call. The permissions on the far side of that connection belong to the other service, and they are configured there. So the useful question about an advanced package is not only what it can see in Microsoft 365, it is what it has been authorised to do everywhere else.

So the risk being managed here is narrower than "AI in the tenant" and more specific than it sounds. It is about packages that can act, uploaded by individuals, into an environment where somebody will eventually be asked to produce a list of them. For an institution that has approved builders and some way of reviewing what they connect to, a named group tends to fit. For one that has neither yet, no users buys time to put them in place.

Nobody sends you a checklist called "AI audit"

The questions an institution gets asked about AI tend to arrive inside the reviews that already exist: third-party risk, change management, access control, vendor oversight. An agent that calls an outside service is a third-party connection, and it reads like one on paper.

ABT manages Microsoft 365 tenants for credit unions, banks, and mortgage companies, which means the Copilot questions and the examination questions land on the same desk. They are easier to answer together than separately.

Short watch

From the ABT Technology channel

What to do between September 25 and October 25

Microsoft's own recommendations run to four lines. Here is the version that gives an institution something to file afterwards.

1

Look for the setting from September 25

It appears in the Microsoft 365 admin center under Copilot Settings. Seeing the four options in front of you takes a minute and turns an abstract question into a concrete one. Put a calendar reminder on the 25th now, because a control you have never seen is easy to forget. If it is not there yet, that is consistent with what Microsoft published: the rollout runs from September 25 to the end of October, so check again in a week.

2

Find out what has already been uploaded

Administrators can view user-uploaded packages in the admin center, and the details page shows the components of each package. This is the first time that inventory has been straightforward to pull, and it is the single most useful artifact to come out of this change. Do it before you decide anything.

3

Sort what you find by whether the package can act

Packages carrying actions or an MCP server are the ones the control governs and the ones worth attention, because those are the packages that can do something. Two piles, and the small one is the one to look at.

4

Pick the option, and make it a decision

For most institutions that want the productivity, a named Microsoft Entra ID group is the answer: the people who build these things, scoped to a named list, changed through the same process that changes any other group membership. All users is a legitimate choice as long as somebody made it. No users is a real option for an institution that has not started its AI programme yet.

5

Ask the builders one question about dynamic tool discovery

For any agent connected to an MCP server, ask whether its tools are resolved at runtime or pinned to a fixed set. Both are supported and both are defensible. Knowing which one you have is what turns an approval into an accurate one.

6

Write down the choice and the date

Three sentences naming the option selected, who selected it, and why. Microsoft suggests updating administrator and help desk documentation and telling support teams about the new control, which is the same idea. That note is the artifact most often missing, and it is where a governed setting starts. Who owns the setting, who is allowed to change it, and how the group gets reviewed are the rest of it.

Read the notice in your own tenant

The public Microsoft Learn documentation had not caught up with this change when this page was written on September 21, 2026. The admin guide does not define advanced against basic, and it does not carry either date. The Message Center post in your own Microsoft 365 admin center is the authoritative version, and it takes two minutes to read. Search your Message Center for MC1472007.

A free Copilot readiness assessment

ABT is a Tier 1 Microsoft Cloud Solution Provider. We manage Microsoft 365 tenants for more than 750 financial institutions, and questions like this one arrive on our desk every month.

We tell you what is in your tenant, and which of the four options fits it

  • The inventory, in writing. Which agents and plugins have been uploaded into your tenant, by whom, and what each package contains.
  • The advanced list, separated out. Which of them carry actions or an MCP server, and what sits on the other end of each connection.
  • The recommendation, with the reasoning. Which of the four options fits your institution, and who belongs in the group if a group is the answer.
  • The wider Copilot picture. Licensing, the settings around agent access and sharing, and where your current configuration sits against what examiners are asking financial institutions about AI.
  • The note for the file. A short written record of the decision and its date, which is the part that answers the question later.

ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies. Learn about M365 Guardian

If this opened a bigger question

One setting tends to surface the programme behind it: what people are building, how it authenticates, and what an examiner will want to see.

Custom Agents vs. Custom Skills: Two Ways to Extend Microsoft 365 Copilot

Custom Agents vs. Custom Skills: Two Ways to Extend Microsoft 365 Copilot

Both extend Copilot, and they are governed differently. How banks and credit unions choose the right approach before any build work starts.

Read the guide
AI Governance Assessment for Financial Institutions: The 25-Point Checklist

AI Governance Assessment: The 25-Point Checklist

Built on the NIST AI Risk Management Framework and mapped to Microsoft 365 Copilot, for credit unions, banks, and mortgage companies.

Read the checklist
Copilot Studio agent authentication: end-user credentials versus maker-provided credentials

Copilot Studio Agent Authentication: The August 25 Question

A Microsoft control that switches agent tools to authenticate as the signed-in user. It is off by default, and it breaks unattended agents.

Read the guide

The advanced agent upload control, answered

The new advanced-package upload setting resolves. Microsoft states that starting October 25th, advanced-package uploads will be enabled by default unless the administrator has selected no users or specific users or groups. Nothing new becomes possible for your users on that date. Microsoft is explicit that no action is required to maintain current behavior, and that if no action is taken, advanced-package uploads remain allowed by default. The change is that an administrator now has a way to narrow them, and October 25 is when the choice takes effect.
Microsoft defines it in one sentence: an advanced agent is a package that has either a Declarative Agent with actions or with an MCP server, and all other packages are considered basic. Both triggers describe a package that can take an action. Microsoft's extensibility documentation describes custom actions as integrating with APIs to interact with external systems in real time, and an MCP server as something a plugin lets an agent interact with to use that server's tools. A package carrying only instructions and knowledge is basic, and basic uploads remain allowed and are not impacted by the control. The definition sorts packages by the capability they carry, and it leaves the separate question of where a package's data comes from to the knowledge sources configured inside it.
Yes. That is why Microsoft frames this as a new control that strengthens enterprise governance and manageability. Uploading is possible now, and the October 25 default preserves that. Microsoft's developer documentation also notes that sideloading a package requires Custom App Upload Enabled and Copilot Access Enabled to be present on the account, and tells builders to check with their organization administrator if those are not shown, so some tenants will already be narrower than others.
Model Context Protocol is a way of exposing a service's capabilities to an AI agent. Microsoft's guidance describes plugins as enabling declarative agents in Microsoft 365 Copilot to interact with MCP servers, or with REST APIs that have an OpenAPI description, and connecting to one gives the agent access to that server's tools, meaning functions a language model can call. Microsoft's own worked example uses a remote third-party server reached over OAuth, where Copilot obtains an access token on behalf of the signed-in user each time the agent calls the server. It is singled out because it is an outbound integration point that acts with a real user's permissions.
No. Microsoft states that the setting is only applicable to user-uploaded packages and does not cover first-party or third-party built agents. It governs the act of an individual in your organization uploading a package they have created or obtained. Agents that arrive through other routes are managed by the other Copilot and agent settings in the Microsoft 365 admin center, including the separate agent access settings that control how members of your organization can access and install agents.
Microsoft states that the setting applies only to advanced agents and plugins uploaded after the control becomes available. Packages already in the tenant are not retroactively removed or blocked by choosing a narrower option. This is worth knowing before you decide, because it means the setting governs the future and an inventory governs the past. Administrators can view user-uploaded packages in the Microsoft 365 admin center, where the details page shows the components of each package, which is how you find out what is already there.
For most institutions that want the productivity benefit, a named Microsoft Entra ID group is the practical answer, because it scopes the capability to people who understand what an action or an MCP server is while changing through the same group process the institution already uses. All users is a legitimate choice where an institution has made that call and can say so. No users suits an institution that has not started building agents yet and wants the door closed until it has a policy. The choice that creates a problem is the one nobody makes, because on October 25 it resolves to all users and there is no record of anyone deciding that.
In your own Microsoft 365 admin center, under Health and then Message center, search for MC1472007, titled Manage who can upload advanced agents and plugins. Microsoft flags it as a major change in the plan for change category and updated it on September 15, 2026. That post is the authoritative source for the dates, the definition of an advanced package, and the four options. As of September 21, 2026 the public Microsoft Learn admin documentation did not yet describe the advanced and basic distinction or carry either date, so the Message Center post is the version to read.

Where the facts on this page come from

Every date, quotation and definition above was read from a Microsoft source on September 21, 2026.

  • Microsoft 365 Message Center post MC1472007, Manage who can upload advanced agents and plugins, categorised as plan for change, flagged as a major change, updated September 15, 2026. Source for the September 25 rollout start and the end of October completion, the October 25 resolution date, the four options, the definition of an advanced agent, the statement that basic package uploads remain allowed and are not impacted, the limits to user-uploaded packages and to packages uploaded after the control becomes available, the administrator view of user-uploaded packages, and both statements that no action is required to maintain current behavior. Visible to administrators in your own Microsoft 365 admin center.
  • Microsoft Learn, Agents for Microsoft 365 Copilot, last updated August 11, 2026. Source for the definition of a declarative agent as adding custom instructions, knowledge and actions, for custom actions integrating with APIs to interact with external systems in real time, for agents taking actions such as sending emails or updating records, and for the statement that declarative agents adhere to the security, compliance and Responsible AI requirements for Microsoft 365.
  • Microsoft Learn, Build a plugin for a declarative agent from an MCP server, last updated August 11, 2026. Source for plugins enabling declarative agents to interact with MCP servers or REST APIs with an OpenAPI description, for dynamic tool discovery resolving the server's tools at runtime, for the pinned tools alternative, for Copilot obtaining an access token on behalf of the signed-in user on each call, and for the Custom App Upload Enabled and Copilot Access Enabled prerequisites.
  • Microsoft Learn, Agents admin guide for Microsoft 365. Source for the separate agent access settings control, which governs how members of your organization can access and install agents with options for all users, no users, or specific users and groups. Read on September 21, 2026, when it did not yet describe the advanced and basic package distinction.
  • Microsoft Learn, Plugins for Microsoft 365 Copilot. Background on how plugins extend a declarative agent's reach beyond the content already available to the signed-in user.

One setting.
One decision worth recording.

Pulling the inventory, looking at what carries actions or an MCP server, and settling on an option is an afternoon of work. Reconstructing in November who uploaded what and when is a much longer one.

Tell us a little about your environment and we will come back with what we would check first.

Tier 1 Microsoft CSP 750+ financial institutions SOC 1 Type 2 · Security Controls SOC 2 Type 1

What should we look at? Optional.

Agent and plugin inventory
Copilot governance and AI policy
Microsoft Entra ID group design
Microsoft 365 licensing review

Encrypted. Private.

Thank you. That is with us.

An ABT specialist will be in touch shortly. If your deadline is this week, say so in your reply and we will move it to the front.