Microsoft 365 Copilot · Admin Control
Somebody at your institution can already put an AI agent into your tenant. Now you can decide who. On October 25 the default decides for you.
On September 25, 2026 a setting appears in the Microsoft 365 admin center that has never been there before. It governs who may upload an advanced agent or plugin, and Microsoft draws that line at a package carrying actions or an MCP server. On October 25 the default takes effect. Do nothing and the setting lands on all users, which for most tenants is what is already true today. The thirty days are the opportunity here, not the threat.
- September 25: rollout begins, and the control appears under Copilot Settings in the Microsoft 365 admin center
- October 25: the setting resolves to all users unless somebody chooses otherwise
- Advanced means a Declarative Agent with actions, or an MCP server. Those are Microsoft's words
- All users, specific users, Entra ID groups, or no users
- Choosing nothing leaves uploads set to all users
- Basic packages are untouched either way
The sequence
What actually changes, and what does not
Read this one carefully, because the obvious reading is wrong. Microsoft is not switching something on. It is handing administrators a switch that did not exist, and the position it defaults to is the position the tenant is already in.
Uploads are already allowed
Users who build a Copilot agent can upload it, subject to whatever app-upload and Copilot access settings your tenant already applies. Microsoft's reason for adding this control is that nothing has previously drawn a line between an ordinary package and one carrying actions or an MCP server. The capability gap is the control, not the upload.
The control appears
It shows up in the Microsoft 365 admin center under Copilot Settings. Microsoft describes this as the start of a General Availability rollout expected to complete by the end of October, so tenants will not all see it on the same day. From this date an administrator can see which users have uploaded packages, and the details page shows the components of each one.
The setting resolves
Microsoft's wording is precise: advanced-package uploads will be enabled by default unless the admin has selected no users or specific users or groups. Silence is read as all users. A chosen setting and an unchosen one land in the same place, and only one of them is defensible in writing.
Three limits worth knowing
The setting reaches user-uploaded packages only, so first-party and third-party built agents sit outside it. It applies only to packages uploaded after the control appears. And basic packages stay allowed regardless of what you choose.
The two sentences that should lower your blood pressure
Microsoft states both of these plainly in the notice: "No action is required to maintain current behavior" and "If no action is taken, advanced-package uploads remain allowed by default."
Nothing opens on October 25. Nothing new becomes possible for your users on October 25. What arrives is a question, and October 25 is the day it gets answered with or without you.
The definition
What makes a package advanced?
This is the part worth reading twice. Microsoft's definition is one sentence long, it draws a capability boundary, and it tells you exactly what the control is protecting.
"An advanced agent is a package that has either a Declarative Agent with actions or with an MCP server. All other packages are considered basic."
Microsoft 365 Message Center, post MC1472007, Manage who can upload advanced agents and plugins, updated September 15, 2026Two triggers, and both of them describe a package that can take an action. Everything else is basic, and basic uploads sit outside this control. Worth being precise about what the definition covers: it sorts packages by the capability they carry. Where the data goes is a separate question, and a basic package can still draw on outside data, because Microsoft's own guidance describes agent knowledge as able to connect external data through Microsoft 365 Copilot connectors.
Actions are the first trigger. Microsoft's own extensibility documentation describes a declarative agent as one you configure by adding "custom instructions, additional knowledge, and actions to automate business processes", and it is specific about what actions do: "Custom actions to integrate with APIs to interact with external systems in real-time." The overview page puts the consequence in plain language, saying agents can retrieve information, summarize data, "or even take actions like sending emails or updating records."
An agent without actions answers. An agent with actions can write, send, and call. That capability is the line the control is drawn on.
| Basic package | Advanced package | |
|---|---|---|
| What it contains | Instructions and knowledge, without actions and without an MCP server | A Declarative Agent with actions, or an MCP server |
| What the package itself can do | Answer from its instructions and its knowledge sources. The package carries no actions and no MCP server | Act. Microsoft describes custom actions as integrating with APIs to interact with external systems in real time, and an MCP server exposes tools the agent can call |
| Covered by the new control | No. Basic uploads remain allowed and are not impacted | Yes, for user-uploaded packages uploaded after the control becomes available |
| Who can upload it after October 25 | Unchanged | All users, unless an administrator picked specific users, Entra ID groups, or no users |
| Visible to administrators | Listed among user-uploaded packages | Listed too, and the details page shows the components of the package |
The second trigger is the one most people have not thought about yet
An MCP server is the other half of Microsoft's definition, and it is newer than most governance documents in a bank or credit union. Microsoft's extensibility guidance describes the relationship this way: plugins let declarative agents in Microsoft 365 Copilot interact with Model Context Protocol servers, or with REST APIs that carry an OpenAPI description. Connecting to one gives the agent access to that server's tools, which are functions a language model can call.
Microsoft's own worked example is a remote third-party server, reached over OAuth, with a token obtained on behalf of the signed-in user every time the agent calls it. In its words, Copilot uses the registration to "obtain an access token on behalf of the signed-in user each time the agent calls the MCP server." So the agent acts with the permissions of whoever is using it, against a service outside your tenant.
"Agents Toolkit configures the generated plugin manifest (ai-plugin.json) for dynamic tool discovery, so the agent resolves the MCP server's tools ... at runtime, and you don't add tools manually."
Microsoft Learn, Build a plugin for a declarative agent from an MCP server, last updated August 11, 2026Read that sentence with a governance hat on and it says something sharp. With dynamic tool discovery, the approved package does not carry a fixed list of what it can do. The agent asks the server what tools it has, and it asks at runtime. An approval recorded on the day of upload describes the package. It does not necessarily describe everything that package will be able to do next quarter, because the answer lives on a server somebody else operates.
Microsoft documents the alternative in the same breath, and it deserves equal billing: a builder can pin a fixed, curated set of tools, which settles the list at build time. So this is a choice somebody makes, and it is a property of how the plugin was built. The governance question is simply whether anyone at your institution is in a position to know which choice was made.
There are two similarly named controls, and they do different jobs
Microsoft's published admin guidance already documents a setting called Agent access settings, which controls how members of your organization can access and install agents, with options for all users, no users, or specific users and groups. It reads almost identically to the new one and governs something else.
The control arriving on September 25 governs who can upload an advanced package in the first place. Access is about consuming what exists. Upload is about introducing something new. An institution can have the first one locked down and the second one wide open, and until now there was no way to tell them apart.
Find out what is already uploaded before the setting resolves
ABT reviews which agents and plugins exist in your tenant, which of them carry actions or an MCP server, and which of the four options fits how your institution actually works.
Get the free Copilot readiness assessmentFor credit unions, banks, and mortgage companies
Why ten minutes on this is worth more than it looks
The setting takes one click. What makes it worth a meeting is that it forces an institution to answer a question about its own AI programme that most have not written down yet.
Picture how an advanced agent actually arrives. A loan officer who is good with technology builds something useful, because that is what Copilot invites people to do and it is genuinely how work gets faster. It connects to a system the team uses every day. It saves an hour a week per person and it spreads by word of mouth, which is a good outcome and the reason to have Copilot at all.
Now the questions an examiner asks about third-party connections start applying to it. What data does it reach. Which service is on the other end. Who reviewed it. Who approved it. Those questions were always reasonable. What has been missing is a tenant-level place to stand when answering them, and that is what the setting provides.
The useful part is not the restriction. It is that the decision becomes a record. An institution that picks a named Entra ID group has a documented control with a named population behind it, which is a sentence you can put in a policy and an answer you can give without going and finding out first.
"To help organizations manage the deployment of advanced Copilot extensibility scenarios, we are introducing a new admin control that determines who can upload advanced agents and plugins. This enhancement strengthens enterprise governance and manageability by allowing administrators to limit advanced-package uploads to specific users or Microsoft Entra ID groups while maintaining flexibility for organizations that want broader access."
Microsoft 365 Message Center, post MC1472007, Manage who can upload advanced agents and pluginsWorth keeping in proportion, because the opposite error is just as costly: declarative agents are not unmanaged software running loose. Microsoft's extensibility documentation states that because they use Copilot's own infrastructure, model, and orchestrator, declarative agents "adhere to the security, compliance, and Responsible AI (RAI) requirements for Microsoft 365." They inherit that framework.
What that framework covers is worth reading carefully, and it is the reason actions and MCP servers are singled out. When an agent calls an MCP server, Microsoft's walkthrough has the user sign in to that service separately and has Copilot obtain an access token on behalf of the signed-in user for each call. The permissions on the far side of that connection belong to the other service, and they are configured there. So the useful question about an advanced package is not only what it can see in Microsoft 365, it is what it has been authorised to do everywhere else.
So the risk being managed here is narrower than "AI in the tenant" and more specific than it sounds. It is about packages that can act, uploaded by individuals, into an environment where somebody will eventually be asked to produce a list of them. For an institution that has approved builders and some way of reviewing what they connect to, a named group tends to fit. For one that has neither yet, no users buys time to put them in place.
Nobody sends you a checklist called "AI audit"
The questions an institution gets asked about AI tend to arrive inside the reviews that already exist: third-party risk, change management, access control, vendor oversight. An agent that calls an outside service is a third-party connection, and it reads like one on paper.
ABT manages Microsoft 365 tenants for credit unions, banks, and mortgage companies, which means the Copilot questions and the examination questions land on the same desk. They are easier to answer together than separately.
The short list
What to do between September 25 and October 25
Microsoft's own recommendations run to four lines. Here is the version that gives an institution something to file afterwards.
Look for the setting from September 25
It appears in the Microsoft 365 admin center under Copilot Settings. Seeing the four options in front of you takes a minute and turns an abstract question into a concrete one. Put a calendar reminder on the 25th now, because a control you have never seen is easy to forget. If it is not there yet, that is consistent with what Microsoft published: the rollout runs from September 25 to the end of October, so check again in a week.
Find out what has already been uploaded
Administrators can view user-uploaded packages in the admin center, and the details page shows the components of each package. This is the first time that inventory has been straightforward to pull, and it is the single most useful artifact to come out of this change. Do it before you decide anything.
Sort what you find by whether the package can act
Packages carrying actions or an MCP server are the ones the control governs and the ones worth attention, because those are the packages that can do something. Two piles, and the small one is the one to look at.
Pick the option, and make it a decision
For most institutions that want the productivity, a named Microsoft Entra ID group is the answer: the people who build these things, scoped to a named list, changed through the same process that changes any other group membership. All users is a legitimate choice as long as somebody made it. No users is a real option for an institution that has not started its AI programme yet.
Ask the builders one question about dynamic tool discovery
For any agent connected to an MCP server, ask whether its tools are resolved at runtime or pinned to a fixed set. Both are supported and both are defensible. Knowing which one you have is what turns an approval into an accurate one.
Write down the choice and the date
Three sentences naming the option selected, who selected it, and why. Microsoft suggests updating administrator and help desk documentation and telling support teams about the new control, which is the same idea. That note is the artifact most often missing, and it is where a governed setting starts. Who owns the setting, who is allowed to change it, and how the group gets reviewed are the rest of it.
Read the notice in your own tenant
The public Microsoft Learn documentation had not caught up with this change when this page was written on September 21, 2026. The admin guide does not define advanced against basic, and it does not carry either date. The Message Center post in your own Microsoft 365 admin center is the authoritative version, and it takes two minutes to read. Search your Message Center for MC1472007.
How ABT helps
A free Copilot readiness assessment
ABT is a Tier 1 Microsoft Cloud Solution Provider. We manage Microsoft 365 tenants for more than 750 financial institutions, and questions like this one arrive on our desk every month.
We tell you what is in your tenant, and which of the four options fits it
- The inventory, in writing. Which agents and plugins have been uploaded into your tenant, by whom, and what each package contains.
- The advanced list, separated out. Which of them carry actions or an MCP server, and what sits on the other end of each connection.
- The recommendation, with the reasoning. Which of the four options fits your institution, and who belongs in the group if a group is the answer.
- The wider Copilot picture. Licensing, the settings around agent access and sharing, and where your current configuration sits against what examiners are asking financial institutions about AI.
- The note for the file. A short written record of the decision and its date, which is the part that answers the question later.
ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies. Learn about M365 Guardian
Related reading
If this opened a bigger question
One setting tends to surface the programme behind it: what people are building, how it authenticates, and what an examiner will want to see.
Custom Agents vs. Custom Skills: Two Ways to Extend Microsoft 365 Copilot
Both extend Copilot, and they are governed differently. How banks and credit unions choose the right approach before any build work starts.
Read the guide
AI Governance Assessment: The 25-Point Checklist
Built on the NIST AI Risk Management Framework and mapped to Microsoft 365 Copilot, for credit unions, banks, and mortgage companies.
Read the checklist
Copilot Studio Agent Authentication: The August 25 Question
A Microsoft control that switches agent tools to authenticate as the signed-in user. It is off by default, and it breaks unattended agents.
Read the guideAnswered
The advanced agent upload control, answered
Verify it yourself
Where the facts on this page come from
Every date, quotation and definition above was read from a Microsoft source on September 21, 2026.
- Microsoft 365 Message Center post MC1472007, Manage who can upload advanced agents and plugins, categorised as plan for change, flagged as a major change, updated September 15, 2026. Source for the September 25 rollout start and the end of October completion, the October 25 resolution date, the four options, the definition of an advanced agent, the statement that basic package uploads remain allowed and are not impacted, the limits to user-uploaded packages and to packages uploaded after the control becomes available, the administrator view of user-uploaded packages, and both statements that no action is required to maintain current behavior. Visible to administrators in your own Microsoft 365 admin center.
- Microsoft Learn, Agents for Microsoft 365 Copilot, last updated August 11, 2026. Source for the definition of a declarative agent as adding custom instructions, knowledge and actions, for custom actions integrating with APIs to interact with external systems in real time, for agents taking actions such as sending emails or updating records, and for the statement that declarative agents adhere to the security, compliance and Responsible AI requirements for Microsoft 365.
- Microsoft Learn, Build a plugin for a declarative agent from an MCP server, last updated August 11, 2026. Source for plugins enabling declarative agents to interact with MCP servers or REST APIs with an OpenAPI description, for dynamic tool discovery resolving the server's tools at runtime, for the pinned tools alternative, for Copilot obtaining an access token on behalf of the signed-in user on each call, and for the Custom App Upload Enabled and Copilot Access Enabled prerequisites.
- Microsoft Learn, Agents admin guide for Microsoft 365. Source for the separate agent access settings control, which governs how members of your organization can access and install agents with options for all users, no users, or specific users and groups. Read on September 21, 2026, when it did not yet describe the advanced and basic package distinction.
- Microsoft Learn, Plugins for Microsoft 365 Copilot. Background on how plugins extend a declarative agent's reach beyond the content already available to the signed-in user.
One setting.
One decision worth recording.
Pulling the inventory, looking at what carries actions or an MCP server, and settling on an option is an afternoon of work. Reconstructing in November who uploaded what and when is a much longer one.
Tell us a little about your environment and we will come back with what we would check first.
What should we look at? Optional.
Encrypted. Private.
Thank you. That is with us.
An ABT specialist will be in touch shortly. If your deadline is this week, say so in your reply and we will move it to the front.

