Microsoft 365 Copilot · Federated connectors
Copilot is about to update the apps it could only read. Write tools arrive through the connectors you already enabled.
Beginning in early October 2026, Microsoft 365 Copilot can create, update, and delete content in third-party services through federated connectors, wherever the connector's publisher provides those tools. Each of those actions runs with the signed-in user's own permissions and asks for approval first, unless that user has already allowed the tool for the conversation or chosen Always allow. Write tools are part of the connector, so any connector already enabled in your tenant can gain them as soon as its publisher ships them.
- Early October 2026: write, update, and delete tools start rolling out, with completion expected by late October
- October 5, 2026: Microsoft says the Copilot Connectors page honors the Allowed agent types setting for all tenants
- Copilot Chat, agents, Cowork, and Copilot in Word, Excel, PowerPoint, and Outlook can write. Researcher stays read-only
- Enabled connectors bring any write tools their publishers add
- Each write asks first, unless the user allowed that tool for the conversation or always
- Disable a connector and all of its tools go with it
The sequence
What changes in October, and in what order?
Where connectors stand today, then three dates from Microsoft's Message Center and Microsoft Learn. The first date is already behind you. The rest fall inside October.
Connectors read, in real time
Federated connectors use Model Context Protocol to fetch data live from the outside service, with the signed-in user's identity and permissions. The external data stays where it lives, and Microsoft states that no data is indexed into Microsoft 365. Read tools run without asking, and that part stays the same after October.
The PowerShell switch retired
Microsoft deprecated the command-line toggle it calls setFederatedConnectors, the one run with the Set-FederatedConnectorToggle cmdlet. Connector governance moved to one place: the Allowed agent types setting in the Agent 365 section of the Microsoft 365 admin center.
One setting governs connectors
Microsoft's Message Center post says the Copilot Connectors page honors Allowed agent types for all tenants from this date, and it asks administrators to review that setting beforehand. In Microsoft's words, a tenant that takes no action is governed by its existing configuration and the default posture of that setting, and Microsoft asks for the review to avoid governance gaps.
Connectors learn to write
Supported connector tools that create, update, and delete content in the connected service become available in Copilot. Microsoft expects the rollout to finish by late October, so tenants will see it on different days.
Microsoft publishes two dates for the old switch
The Message Center post, MC1454973, puts the handover to Allowed agent types on October 5, 2026. Microsoft Learn's page on managing federated connectors says a tenant-wide disable made with the retired Set-FederatedConnectorToggle cmdlet is honored until October 20, 2026, and that administrators must update Allowed agent types by then to keep it. The Learn overview adds that tenants which used the cmdlet receive a Message Center post asking them to reapply the choice within a limited window.
ABT's recommendation is to plan to October 5, the earlier date. October 5 is when governance moves to the setting, October 20 is how long an old cmdlet choice survives, and the write tools themselves roll out on their own schedule through October. The choice that lasts is the one recorded in Allowed agent types.
The mechanics
How do Copilot connector write actions work?
At the level of a single action, the design is careful. The decisions a governance team owns sit one level up, at the connector.
A user asks Copilot to do something in a connected service. Copilot selects a tool the connector exposes and shows a confirmation card that names the connector and the tool, and the user can expand the card to see the parameters that will be sent. While the action waits for that answer, nothing is sent to the connected system. Microsoft's own examples are everyday office work: turning an escalation email into an issue in a project tracker, updating a record in a CRM system, adding a comment to a ticket.
That is the productivity case, and it is a good one. The work finishes inside the conversation where it started, and the record in the other system is current before anyone switches windows.
The four answers on the approval card
Runs the action now. Copilot asks again the next time it wants to use that tool.
Runs the action and stops asking for that tool for the rest of the current conversation.
Runs the action and stops asking for that tool until the user changes the setting or the publisher changes the tool.
Declines the action. The connected system is left exactly as it was.
Source: Microsoft Learn, Federated connectors overview. The Message Center post lists three of these answers, and the Learn page lists all four.
Two details deserve more attention than they will get. Always allow applies to a single tool, and it holds until the user changes it or the publisher changes the tool. When a publisher adds a write tool or changes an existing one, that tool returns to Needs approval. Users manage all of this in Copilot under Settings, then Sources, where each connector's write and delete tools are grouped apart from its read tools. Read tools always run without asking.
| Read tools | Write, update, and delete tools | |
|---|---|---|
| What they do | Retrieve information from the connected service in real time | Create, update, or delete content in the connected service |
| Approval | Run without asking | Ask first, until the user picks Allow for conversation or Always allow for that tool |
| When the publisher changes a tool | Keep running | Return to Needs approval |
| Where they work | Copilot Chat, agents, Cowork, Copilot in Word, Excel, PowerPoint, and Outlook, and the Researcher agent | The same experiences except Researcher, which stays read-only |
| What leaves Microsoft 365 | Data is fetched live from the service, and no data is indexed into Microsoft 365 | Customer Data is exported to the connected system to make the change |
| Admin control | Enable, disable, or stage the connector to groups | The same connector-level controls. The write tools arrive with the connector |
"Write, update, and delete tools are part of the connector and aren't enabled separately."
Microsoft Learn, Federated connectors overview, updated September 22, 2026Read that sentence against your own connector list. A connector someone enabled when all it could do was read becomes a connector that can write once the rollout reaches your tenant and its publisher ships the tools. Any review it received was a review of a read-only integration, and a Microsoft-published connector may have arrived with no review at all, because those are enabled by default. The same Microsoft page gives the reverse just as plainly: disabling a connector removes all of its tools.
Know which connectors can write in your tenant before users start approving
ABT reviews the federated connectors enabled in your Microsoft 365 tenant, the write and delete tools each one exposes, and whether your Allowed agent types setting says what your institution means.
Get the free security assessmentThe default
Which connectors are already enabled in your tenant?
Microsoft-published connectors arrive switched on, so the list in your tenant can be longer than the list anyone approved.
Microsoft-published federated connectors are enabled for a tenant by default unless an administrator disables them, and partner connectors need an administrator's approval before they are enabled. Both kinds appear in the Microsoft 365 admin center under Copilot connectors, then Your connections. The table Microsoft publishes for its Connectors Gallery currently lists 125 federated data sources across 16 categories in the federated connectors table on Microsoft Learn, by ABT's count on September 23, 2026, among them HubSpot, Box, Gmail, Xero, Asana, monday.com, Notion, PandaDoc, and GoDaddy.
Which of those will offer write tools is up to each publisher. Microsoft says the available actions depend on the tools the connector's publisher exposes, and that publishers can add or change tools over time. So the write capability of your tenant keeps moving after October, one publisher update at a time, and an AI governance framework has to be built to notice.
Enable or disable, tenant-wide
Each connector can be switched on or off for the whole tenant. Disabling a connector removes all of its tools, read and write together.
Stage to Microsoft Entra ID groups
Add staging limits a connector to chosen groups, which keeps the productivity with the people who need it and leaves everyone else out.
Allowed agent types
Three choices in the Microsoft 365 admin center: apps and agents built by Microsoft, by your organization, and by external publishers. With the Microsoft-published and third-party-published options deselected, connectors, including ones released later, stay off until an administrator enables each one.
The Tools section
Each connector's details page lists its tools, including the ones that can modify or delete data. Microsoft advises signing in with a high-access account, because the list reflects the permissions of whoever signs in.
The approval belongs to the user. The decision belongs to the connector list.
The admin controls Microsoft documents for this change work at the connector level: enable, disable, stage to groups, and Allowed agent types. Approving a single write happens on the user's side, tool by tool, and Always allow is the user's choice to make.
So for an institution, the connector list is where the real decision lives. It is worth making that decision in writing before the rollout reaches your tenant, while every write tool still starts at Needs approval. Microsoft handles the upload side of the same question with a separate control, covered in our guide to the advanced agent upload setting.
For credit unions, banks, and mortgage companies
Why does a write-capable connector matter more at a financial institution?
The productivity is the reason to want it. The data flow is the reason to review it first.
Picture the good version first. A processor asks Copilot to log a borrower's question as a ticket in the team's tracker. An operations lead updates a vendor record in the CRM straight from the email in front of them. Nobody copies and pastes, and the record is current before the meeting ends. That is where Microsoft is taking Copilot, and it is worth having.
Every one of those actions sends institution data to an outside service. At a regulated institution, a data flow to a third party is a vendor question, and vendor oversight programs already have a place for it. The connector is the new route. The review is the familiar one, and the vendor due diligence file is where its answer belongs.
"These actions export Customer Data to the connected system."
Microsoft Learn, Federated connectors overview, section on confirming an actionThe terms were updated on September 22
Microsoft updated the terms of use for Copilot connectors on September 22, 2026. They say that by enabling connectors you authorize Microsoft, subject to your configuration, to send Customer Data to third-party services and to modify data in those services, and that you, as the data controller, are "solely and exclusively responsible" for that connector functionality. The terms also point out that the third-party service may carry terms of its own. Microsoft's recommendations for this change ask administrators to review those agreements for licensing, privacy, data residency, and acceptable use.
For a compliance officer, that reads as a familiar allocation. Microsoft provides the plumbing, the institution owns the decision to turn it on, and the other end of each connection answers to its own contract.
The evidence has to exist before anyone asks for it
Microsoft states that administrators can audit connector activity in Microsoft Purview, and Purview's Copilot interaction records carry a property listing the plugins or extensions enabled for an interaction. Before a policy relies on that trail, run one approved write against a test service and find the record. A control you have watched fire is one you can describe to an examiner with confidence. Our guide to auditing AI with Purview and Sentinel covers the quarterly review that record would feed.
What should be in place before a third-party connection can write?
The Short from our channel names three guardrails for any outside AI that touches a tenant: Conditional Access over which apps and devices connect, data loss prevention over sensitive data, and audit logging, so the institution can say what connected and what it touched. Connectors that can write raise the stakes on the third, because the record now has to show changes as well as reads.
ABT manages Microsoft 365 tenants for credit unions, banks, and mortgage companies, so the Copilot questions and the examination questions arrive at the same desk. They are easier to answer together, starting with how agents get built and approved at your institution.
The short list
What should an administrator do before October?
Microsoft's own recommendations run to six lines. Here is the version that leaves an institution with something to file afterwards.
List the federated connectors enabled today
In the Microsoft 365 admin center, open Copilot connectors, then Your connections. Note which connectors are Microsoft-published, and therefore on by default, and which partner connectors somebody approved. That list is the population the October rollout reaches.
Open the Tools section on each one
On each connector's details page, sign in to the third-party service and read the tool list, marking every tool that can create, update, or delete data. Use an account with a high level of access, because Microsoft notes the list reflects the permissions of the account that signs in.
Decide per connector: enable, stage, or disable
Staging to a Microsoft Entra ID group keeps a useful connector with the people who need it. Disabling removes the connector and every tool on it. Both are sound answers, and the useful thing is that somebody chose one.
Choose your Allowed agent types setting before October 5
It lives in the Microsoft 365 admin center under Agent 365, then Allowed agent types. If your tenant ever ran Set-FederatedConnectorToggle, make that choice again here: Microsoft Learn says the cmdlet's setting is honored only until October 20, 2026. Our Agent 365 governance guide walks through the neighboring controls.
Read the terms on both ends of the connection
Review Microsoft's updated connector terms of use and your agreement with each publisher whose connector stays enabled, against your licensing, privacy, data residency, and acceptable-use requirements. Microsoft lists that review in its own recommendations for this change.
Tell users what Always allow means
Update user and help-desk guidance: actions run with your own permissions in the other service, Always allow stops the prompt for that tool, and the setting can be reset in Copilot under Settings, then Sources. Microsoft recommends the same guidance update.
Prove the audit trail, then watch the usage
Run one approved write against a test service and find it in Microsoft Purview before relying on the record. Microsoft's Message Center post MC1404326 describes a Connectors usage report under Reporting, then Usage, then Microsoft 365 Copilot, then Connectors, showing active users and responses per connector, with general availability rolling out in late September 2026 and a Microsoft 365 Copilot license required. Confirm your federated connectors appear in it before relying on it for this purpose.
Read the notices in your own tenant
In your Microsoft 365 admin center, open Message center and search for MC1476316, on connectors gaining create, update, and delete actions, and MC1454973, on the move to Allowed agent types. They are the authoritative versions for your tenant, and each takes about two minutes to read. The two newest Microsoft Learn pages cited below both show an update date of September 22, 2026.
How ABT helps
A free security assessment
ABT is a Tier 1 Microsoft Cloud Solution Provider. We manage Microsoft 365 tenants for more than 750 financial institutions, and questions like this one reach our desk every month.
We show you which outside services Copilot can reach from your tenant, and which of them it will soon be able to change
- The connector inventory. Every federated connector enabled in your tenant, whether Microsoft or a partner published it, and who it is staged to.
- The write list. Which tools on each connector can create, update, or delete data, read from the Tools section with a high-access account, dated, with anything that account cannot see noted.
- The settings that decide it. Allowed agent types, staging groups, and any PowerShell-era connector setting that expires in October.
- The wider picture. Conditional Access, guest access, and data loss prevention around Copilot, measured by what each policy actually does in your tenant.
- The note for the file. A short written record of what was decided and when, which is the part that answers the question later.
ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies. Learn about M365 Guardian
Related reading
If this opened a bigger question
A connector that can write is a third-party integration, a vendor relationship, and an audit record at the same time. These three pick up each thread.
Should You Connect Claude or ChatGPT to Your M365 Tenant?
A five-question decision framework for CISOs weighing third-party AI access to a financial institution's tenant.
Read the framework
Vendor Due Diligence on Microsoft 365: What Goes in the File
What belongs in a bank or credit union vendor file for Microsoft 365, built from the audit reports Microsoft publishes.
Read the guide
AI Governance Auditing: The Purview and Sentinel Quarterly Cycle
The audit, data loss prevention, and monitoring cycle examiners look for when a community bank or credit union runs AI.
Read the guideAnswered
Copilot connector write actions, answered
Verify it yourself
Where the facts on this page come from
Every Microsoft date, count, and quotation above was read from the Microsoft sources listed here on September 23, 2026.
- Microsoft 365 Message Center post MC1476316, Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions, plan for change, published September 21, 2026. Source for the early to late October 2026 rollout, actions running with the signed-in user's permissions, the approval requirement, the Researcher agent staying read-only, the new tools section on each connector's details page, and Microsoft's recommendations to review connectors, third-party agreements, and user guidance. Visible to administrators in your own Microsoft 365 admin center.
- Microsoft Learn, Federated connectors overview, updated September 22, 2026. Source for Model Context Protocol and real-time access, no data indexed into Microsoft 365, federated connectors not copying or storing data in Microsoft 365, Microsoft-published connectors enabled by default, partner connectors needing admin approval, Add staging, the Connectors Gallery table (125 data sources in 16 categories, counted by ABT on September 23, 2026), the supported-experiences table, the four approval answers, per-tool approvals, tools returning to Needs approval when a publisher changes them, Customer Data export, write tools not being enabled separately, the Tools section, auditing in Microsoft Purview, and OAuth 2.0.
- Microsoft 365 Message Center post MC1454973, Manage Copilot connectors (Global setting) from Agent 365: SetFederatedConnectors CLI toggle is retiring, published August 14, 2026. Source for the August 25, 2026 deprecation and the October 5, 2026 date on which the Copilot Connectors page honors Allowed agent types for all tenants.
- Microsoft Learn, Manage federated connector availability, updated August 27, 2026. Source for the October 20, 2026 date through which a Set-FederatedConnectorToggle disable is honored, and for the behavior of disabling the agent type used by Copilot connectors.
- Microsoft Learn, Agent settings in Microsoft 365 admin center, updated September 3, 2026. Source for the three Allowed agent types choices.
- Microsoft Learn, Microsoft 365 Copilot connectors: Terms of use, updated September 22, 2026. Source for the authorization to send Customer Data to and modify data in third-party services, and for the customer's responsibility as data controller.
- Microsoft Learn, Audit logs for Copilot and AI applications, updated August 26, 2026. Source for the plugin and extension details carried in Copilot interaction audit records.
- Microsoft 365 Message Center post MC1404326, Microsoft 365 admin center: New usage report for Copilot connectors, updated September 11, 2026. Source for the Connectors usage report location, its general availability timing, and its license requirement.
The connector list you approved
is about to matter more.
Listing the connectors enabled in your tenant and the tools each one exposes is straightforward work today. Doing it after users have started choosing Always allow means reconstructing what changed, where, and on whose permissions.
Tell us a little about your environment and we will come back with what we would check first.
What should we look at? Optional.
Encrypted. Private.
Thank you. That is with us.
An ABT specialist will be in touch shortly. If your rollout date is this week, say so in your reply and we will move it to the front.

