Skip to the main content.

Microsoft Copilot · Microsoft 365 admin center

Copilot's Agents button becomes Plugins: one place for the tools your staff use with Copilot. Decide what your staff can install and use before the new button arrives.

Microsoft's new plugin registry packages agents, skills, connectors, and Model Context Protocol (MCP) servers into plugins that staff reach through one Plugins menu in Copilot and supported Microsoft 365 apps. The registry is rolling out now, and Microsoft expects the Plugins button to replace Agents, Agents & Skills, and Customize between late October and late November 2026. Microsoft asks for no setup to turn it on. Settings in the Microsoft 365 admin center decide what your users can install, and Microsoft Learn lists all users as the default for who can use agents and plugins, subject to existing app policies and user assignments.

  • Late September to late October 2026: Microsoft expects the plugin registry rollout to complete by late October (Message Center MC1484008)
  • Late October to late November 2026: Microsoft expects one Plugins button to replace Agents, Agents & Skills, and Customize, with Frontier users seeing it in October (MC1484008, MC1479277)
  • The controls live under Agents in the Microsoft 365 admin center: publisher categories, user access, plugin scope, access requests, and MCP server approval
Microsoft Copilot Navigation pane
Today
Agents Agents & Skills Customize
Late October to late November 2026
Plugins
Agents Skills Connectors MCP servers
Governed in Agents › Tools
Microsoft 365 admin center, where your settings decide what each user can install
100+
Plugins Microsoft says are already available, with more being added.
Source: Microsoft Copilot Blog, September 30, 2026
3
Publisher categories an administrator chooses from in Agent and plugin access: Microsoft, your organization, and certified external publishers.
Source: Microsoft Learn, Manage plugins, skills, and MCP servers
Late Nov
When Microsoft expects the Plugins button to finish reaching users worldwide, after starting in late October 2026.
Source: Microsoft 365 Message Center, MC1484008
2 roles
Roles Microsoft Learn names as meeting both requirements to approve an MCP server: AI Administrator and Global Administrator.
Source: Microsoft Learn, Manage plugins, skills, and MCP servers

What is the Microsoft plugin registry, and what changes for your users?

The plugin registry is Microsoft's catalog for discovering, publishing, and governing plugins across Copilot and the Microsoft 365 apps. A plugin can bundle agents, skills, connectors, and MCP servers into one package. Your users find the plugins you allow through one Plugins button, and your administrators decide what is allowed under Agents in the Microsoft 365 admin center.

The decision in brief

What
Microsoft's plugin registry gathers agents, skills, connectors, and MCP servers into plugins, and one Plugins button replaces Agents, Agents & Skills, and Customize.
When
The registry began rolling out in late September 2026, and Microsoft expects it to complete by late October. The Plugins button is expected to follow from late October to late November 2026, and users in Microsoft's Frontier program see it in October.
Users
Staff find approved plugins through one Plugins menu in Copilot Home (Chat and Cowork), Code, Autopilot, and supported Microsoft 365 apps. A plugin your settings restrict shows as blocked by your organization's policy, and eligible users can request access.
Owner
Your Microsoft 365 administrator, an AI Administrator or Global Administrator (the two roles Microsoft Learn names) for MCP server approvals, and whoever owns vendor and AI decisions at your institution.
Action
Choose which publishers users can install from, who can use agents and plugins, who answers access requests, and who approves MCP servers, then tell staff about the new button.
September 25, 2026

The new Microsoft Copilot

Microsoft introduces the new Copilot app: Chat and Cowork together in Home, plus Code and Autopilot (Message Center MC1479277).

September 30, 2026

The plugin registry announced

MC1484008 and the Microsoft Copilot Blog announce the registry, rolling out now, with more than 100 plugins already available.

Late September to late October

The registry rolls out

Administrators gain the plugin catalog under Tools in the Microsoft 365 admin center and in Microsoft Agent 365.

Late October to late November

Plugins replaces three buttons

MC1484008: Microsoft expects that by late November 2026 Plugins is where users find agents, replacing Agents, Agents & Skills, and Customize. Frontier users see it in October.

"Plugins can bundle agents, skills, connectors, and Model Context Protocol (MCP) servers into a single package that can be published, discovered, governed, and acquired through the Microsoft 365 admin center and Microsoft Agent 365."

Microsoft 365 Message Center post MC1484008, Microsoft Copilot: Introducing the Microsoft plugin registry for Microsoft Copilot experiences, plan for change, published September 30, 2026

Microsoft's definitions are short. Skills "provide reusable instructions for specialized work," connectors "give Copilot approved access to services and data," and agents "customize Copilot for specific uses." An MCP server exposes tools that agents can call, and Microsoft Learn's description of the block control shows the scale of one approval: blocking a server "disables all the tools it exposes."

In the Copilot app, MC1479277 describes the swap in detail: Plugins replaces the standalone Agents entry point in Chat, which some preview users saw as Agents & Skills, and the Customize entry point in Cowork.

Microsoft says the catalog already holds more than 100 plugins, for areas such as finance, sales, project management, IT service management, and market research, and that the registry will support Copilot Studio, GitHub Copilot, and Microsoft Foundry in the future. Staff can already pull available agents and skills into a prompt by typing / or @, a change Microsoft describes in MC1479519.

Microsoft asks for no setup: "No action or setup is required to enable this change, and no technical migration is required." Its recommendations are the work: update documentation and training that mention Agents, Agents & Skills, or Customize, prepare users for the new button, and "Review which plugin capabilities should be available to users based on your organization's governance requirements." Agents keep their own settings: "Admins will continue to manage agents in the Agents settings within the Microsoft 365 admin center and Microsoft Agent 365."

Infographic titled What a Copilot plugin bundles, and where you govern it, with the Microsoft four-square logo and Microsoft 365 in the header. Under What a plugin can bundle: agents, skills, connectors, and MCP servers, which flow into one plugin package. The Microsoft plugin registry governs it in the Microsoft 365 admin center under Agents > Tools. Under Where users reach it: one Plugins button, in Copilot, Word, Excel, PowerPoint, and SharePoint. Footer: registry rollout late September to late October 2026, expected, per Message Center MC1484008; Plugins button late October to late November 2026, expected.
One package for users, one place for administrators: what a plugin carries and where the decisions about it are made.

Which admin center settings decide what your users can install?

Six settings and two approval queues, all under Agents in the Microsoft 365 admin center. Microsoft Learn documents each one. The table lists where each lives, the choices it offers, and what it decides.

Copilot plugin controls in the Microsoft 365 admin center. Sources: Microsoft Learn, Manage plugins, skills, and MCP servers in Microsoft 365 admin center (dated September 28, 2026) and Agent settings in Microsoft 365 admin center (updated September 30, 2026). Read October 6, 2026; unchanged on October 7, 2026.
Control Where it lives Choices What it decides
Agent and plugin access Agents > Settings > Agent and plugin access Microsoft; your organization; certified external publishers Which publisher categories users can install from. Plugins built by Microsoft stay visible to users when that category is off, and users can't install them.
User access Agents > Settings > User access All users (the default); No users; Specific users or groups Who in the organization can use agents and plugins at all.
Plugin availability Agents > Tools > Plugins, then Users All users; No users; Specific users and groups Who can use one plugin. Installing it for a group makes it ready without each person adding it.
Access requests Agents > Tools > Requests Approve; Reject What happens when a user asks for a plugin your settings restrict.
Upload Agents > Tools > Registry, then Upload All users or specific users or groups, chosen at install Your own plugins and skills, which a developer packages in a manifest file.
Block, uninstall, delete Agents > Tools > Plugins Block; Uninstall; Delete (uploaded packages only) Block stops users and agents from using a plugin across the organization. Delete removes an uploaded package from the registry.
MCP server requests Agents > Tools, Requests (preview) tab Approve, then grant Microsoft Entra consent; or Reject Which MCP servers join your registry. Microsoft Learn names AI Administrator and Global Administrator as the two roles that meet both approval requirements.
Tool-level control Agents > Tools > Registry, the server, Tools tab Enabled or Disabled for each tool Individual tools inside supported MCP servers registered on Agent 365. Rolling out to tenants.

All users is the starting point

Microsoft Learn lists All users as the default for user access: "all users in the organization can access agents and plugins, subject to the existing app policies and user assignments." The other layers in the table still apply on top of it: the publisher categories users can install from, who can use each plugin, which MCP servers have consent, and, where supported, which tools run.

With no setup required on Microsoft's side, a tenant that changes nothing meets the Plugins button with the settings it has today. Reviewing them before the button reaches your users turns each default into a decision your institution made, with a name and a date beside it.

Know what your users can install before the Plugins button arrives

ABT reviews your agent and plugin settings with your administrators, lists the plugins, agents, and MCP servers in your tenant and who can use each, and marks the ones from external publishers, as part of a free Copilot readiness assessment.

Request the free assessment

How do you set Copilot plugin governance before the Plugins button arrives?

Seven recommended governance actions, in the order the decisions depend on each other. Six are settings Microsoft Learn documents in the Microsoft 365 admin center, and the seventh is telling staff what changes. Together they take the Plugins button from a default to a decision.

1
Agents > Settings > Agent and plugin access

Choose the publishers your users can install from

Microsoft offers three categories: Microsoft, your organization, and certified external publishers. Microsoft Learn's answer to the question of blocking third-party plugins is to clear the category for certified external publishers, which stops users from installing plugins from that category. Plugins from Microsoft and from your organization are governed separately, and MCP servers, uploaded packages, and existing connections have their own controls. Plugins built by Microsoft stay visible to users when you turn their category off, and users can't install them.

2
Agents > Settings > User access

Decide who can use agents and plugins at all

The choices are All users, No users, or Specific users or groups, and All users is the default. A named pilot group is a sound first position for an institution that wants a few teams to start while policy, training, and vendor review catch up.

3
Agents > Tools > Plugins

Scope each plugin you approve to the people who need it

Select a plugin, open Users, and choose All users, No users, or Specific users and groups. You can also install a plugin for a group so it is ready to use without each person adding it, which keeps a plugin with the team whose work it supports.

4
Agents > Tools > Requests

Name who answers access requests

A user who finds a restricted plugin sees it marked as blocked by your organization's policy, and eligible users can select Request access. Each request arrives in the Microsoft 365 admin center with the user and the plugin, for an administrator to approve or reject. Decide who reviews requests and how quickly, so every request has an owner from the first day.

5
Agents > Tools, Requests (preview) tab

Treat every MCP server as its own approval

When a developer registers a remote MCP server, it appears there for review with its name, publisher, requester, and declared tools. Approval needs access to the Tools page and the right to grant tenant-wide consent, and Microsoft Learn names two roles that have both: AI Administrator and Global Administrator. Its roles page describes these two as having "tenant-wide visibility and governance authority," while product-specific admin roles govern only within their own products.

The server becomes available to agent-building surfaces only after consent is granted, so the consent step is where the review of its permissions belongs. Microsoft notes an approved server can take up to 30 minutes to appear in all Copilot Studio environments in the tenant.

6
Agents > Tools > Registry, the server, Tools tab

Turn off the high-risk tools the control reaches

Tool-level control switches individual tools inside a supported MCP server on or off. Microsoft's own example is to keep tools "that write, delete, or process payments" turned off by default while allowing lower-risk tools on the same server. It is rolling out to tenants, it covers specific types of MCP servers registered on Agent 365, and the Agent 365 Tooling Gateway enforces it at runtime.

For a server that doesn't support tool discovery, the decision is the whole server: allow it or block it.

7
Your training and adoption materials

Tell staff about the new button

Microsoft recommends updating internal documentation, training, and adoption materials that reference Agents, Agents & Skills, or Customize, and preparing users for the Plugins button. Tell staff where approved plugins appear, how to request one, and who decides.

Checklist infographic titled Seven actions before the Plugins button arrives, with the Microsoft four-square logo and Microsoft 365 in the header and the subtitle Six settings in the Microsoft 365 admin center, then one message to staff. 1, choose publisher categories, Agents > Settings > Agent and plugin access. 2, decide who can use agents and plugins; user access: All users is the default. 3, scope each plugin you approve, Agents > Tools > Plugins. 4, name who answers access requests, Agents > Tools > Requests. 5, approve each MCP server on its own, with an AI Administrator or Global Administrator. 6, turn off high-risk tools the control reaches, where tool-level control is supported. 7, tell staff about the new button through training and documentation. Highlighted box: Plugins button, late October to late November 2026, expected, Message Center MC1484008.
Seven actions in the order the decisions depend on each other: six settings under Agents in the Microsoft 365 admin center, then the message to staff.

What should you check before you approve a plugin?

Start with the publishing record and read every component in the package. Microsoft's administrator guide for Copilot plugins lists what to confirm, and it warns that a control applied to one object can stop short of the components that object references.

What to confirm, from Microsoft's list

  • Identity and version. The exact package and version, and the publisher or creator behind it.
  • Audience and reach. The intended users or groups, the publishing route, and the Microsoft experiences it supports.
  • What is inside. The agents, skills, connectors, and MCP servers it includes, with their descriptions and dependencies.
  • What it reaches. Permissions and consent, connections and external services, and the licenses it requires.
  • Who looks after it. Known limitations, and the support and update owner.

How far one decision reaches

  • Blocking a plugin stops users and the agents that depend on it, while its MCP servers and connectors stay available to other plugins.
  • Blocking an MCP server also blocks the plugins that depend on it and the connectors linked to it.
  • Connections are separate. Microsoft Learn: "A per-user connection isn't the same as organization-level deployment."
  • Check each surface. Microsoft Learn: "Don't assume that one approval, assignment, or block propagates to every Microsoft experience or dependency unless the linked product procedure confirms it."

Who owns an agent after the person who built it leaves?

Microsoft Learn: "Agents become ownerless when their original creator leaves the organization." Agent management rules in the Microsoft 365 admin center can reassign ownerless agents built with Agent Builder to the previous owner's manager, based on the Microsoft Entra ID hierarchy, and can block ownerless agents that have no usage. At a financial institution, that check belongs in the offboarding steps beside the mailbox and the license.

Microsoft's guide also asks for the program around the settings before the first approval: "Establish review, approval, and exception processes," and "Assign support and lifecycle owners." A short written standard covering who approves which publisher category, who answers requests, and how often installed plugins are reviewed is enough to start.

Why does a plugin decision matter at a credit union, bank, or mortgage company?

Because a plugin from an external publisher can hand your staff's work to a service outside Microsoft, and that turns a productivity decision into a vendor decision your institution has to stand behind.

Get the work done. Microsoft's case for plugins is productivity: plugins "can connect Copilot to approved business data and actions, helping users complete more workflows without leaving the experience where they're working." Microsoft says the single Plugins menu cuts "repeated discovery and setup" as staff move between apps. For a lending team or a member services team, the right plugin in the right hands is time back in the day.

Protect the data. Microsoft Learn is direct about plugins from other publishers: "Data processed by non-Microsoft services isn't subject to Microsoft agreements." It asks administrators to review the terms provided by non-Microsoft agent and plugin publishers and to consult internal policies before allowing access. Plugins can also act as well as read, and Microsoft suggests using its tool-level control to keep high-risk tools, such as tools that write, delete, or process payments, turned off by default. Our page on Copilot connector write actions covers the connectors that gain write tools in October.

Keep the record. In a proposal published in the Federal Register on September 15, 2026, the OCC, the Federal Reserve Board, the FDIC, and the NCUA set out new interagency guidance on third-party risk management, with comments due November 16, 2026. It defines a third-party relationship as "a business arrangement between a banking organization and an entity or individual for the provision of one or more products, services, and other activities that support the banking organization," and for this guidance, banking organizations include insured credit unions. It also observes that "Risks presented by third-party relationships are varied and may change over time or may not be immediately apparent."

The proposal speaks to third-party relationships in general terms, and whether a given plugin publisher is one is your program's call. Record that determination with its reasoning: the publisher and its terms, the permissions and data flows the plugin uses, who approved it, and when it is next reviewed. Who can upload custom agent packages that carry actions or an MCP server is a separate Copilot setting, covered in our page on the advanced agent upload control.

Should you block every third-party AI tool?

The registry gives an institution a governed middle path: allow publisher categories, scope plugins to groups, answer requests, and approve MCP servers one at a time. The Short from our channel makes the same case in under a minute, and its advice reads like a map of the new settings: "Approve specific connectors, scope their permissions, monitor their activity."

Approving and scoping now happen in the Microsoft 365 admin center. Microsoft's administrator guide treats monitoring as its own lifecycle stage: monitor use, review updates, adjust access, and retire the solution and its dependencies safely.

Featured Short

A free Copilot readiness assessment

ABT is a Tier 1 Microsoft Cloud Solution Provider serving more than 750 financial institutions, and the plugin settings review is part of this assessment.

We review your agent and plugin settings with your administrators and leave you a written record of the decisions

The assessment is free and ends with written findings you keep. We work through the settings with an administrator on your team, and your team decides what changes in the tenant and who makes each change.

  • The settings map. Each control in the table above, as your tenant has it set today.
  • The inventory. The plugins, agents, and MCP servers available, installed, or requested in your tenant, and who can use each.
  • The external list. Which of them come from external publishers, with the terms your vendor review should read.
  • The recommendation. Publisher categories, user access, and who answers requests and approves MCP servers, with the reasoning.
  • The wider Copilot picture. Licensing, agent sharing settings, and readiness for the rest of the Copilot rollout.
  • The record. A dated summary of the decisions your team makes, ready for your change-management and vendor files.

ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies. Learn about M365 Guardian

If this opened a bigger question

A plugin decision tends to surface the program behind it: which outside AI services may touch the tenant, how AI use is governed, and how data stays protected once agents are working.

A chief information security officer reviews a decision framework for connecting third-party AI tools to a Microsoft 365 tenant

Should You Connect Claude or ChatGPT to Your M365 Tenant? A CISO Decision Framework

A five-question framework for CISOs deciding whether a third-party AI tool such as Claude or ChatGPT should connect to the Microsoft 365 tenant.

Read the article
AI governance assessment checklist on a tablet beside Microsoft 365 Copilot, Microsoft Purview, and the NIST AI Risk Management Framework

AI Governance Assessment for Financial Institutions: The 25-Point Checklist for Banks, Credit Unions, and Mortgage Companies

A 25-point checklist for credit unions, banks, and mortgage companies, built on the NIST AI Risk Management Framework and mapped to Microsoft 365 Copilot and Microsoft Agent 365.

Read the article
Microsoft Purview and Microsoft Agent 365 protecting member data as AI agents work in a Microsoft 365 tenant

Microsoft Purview for AI Reaches GA: What Banks, Credit Unions, and Mortgage Companies Must Configure Before AI Agents Touch Member Data

What Microsoft Purview's AI data security and compliance protections cover, and what an institution configures before AI agents touch member data.

Read the article

The Microsoft Copilot plugin registry, answered

It is Microsoft's shared catalog for discovering, publishing, and governing plugins across Microsoft Copilot experiences (Chat, Cowork, Code, and Autopilot), Word, Excel, PowerPoint, and SharePoint, announced in Message Center post MC1484008 on September 30, 2026. A plugin can bundle agents, skills, connectors, and Model Context Protocol (MCP) servers into one package. Administrators manage plugins under Agents in the Microsoft 365 admin center and in Microsoft Agent 365.
Message Center post MC1484008 gives two worldwide rollouts: the plugin registry began in late September 2026 and is expected to complete by late October 2026, and the user interface change begins in late October 2026 and is expected to complete by late November 2026. By late November, Plugins is where users find agents, replacing Agents, Agents & Skills, and Customize. MC1479277 says the Plugins entry point reaches users in Microsoft's Frontier program in October.
No. MC1484008 says "No action or setup is required to enable this change, and no technical migration is required." Microsoft recommends updating documentation and training that mention Agents, Agents & Skills, or Customize, preparing users for the new Plugins button, and reviewing which plugin capabilities should be available to users based on your organization's governance requirements.
Microsoft describes three kinds of capability a plugin can include: skills, which provide reusable instructions for specialized work; connectors, which give Copilot approved access to services and data; and agents, which customize Copilot for specific uses. MC1484008 adds Model Context Protocol (MCP) servers to what a plugin can bundle, and Microsoft Learn describes plugins as including tools, MCP servers, connectors, skills, and other AI artifacts that extend agents.
Under Agents. Agents > Settings holds the organization-wide choices: Agent and plugin access, which sets the publisher categories users can install from, and User access, which sets who can use agents and plugins. Agents > Tools holds the registry: Plugins for availability, install, block, and delete; Requests for user access requests; and Registry for uploads and MCP servers. Microsoft's announcement calls this the Agent 365 experience in the Microsoft 365 admin center.
Yes, by publisher category. Microsoft Learn's answer is to go to Agents > Settings > Agent and plugin access and clear the publisher category for certified external publishers, which stops users from installing plugins from that category, while plugins from Microsoft and from your organization are governed separately. MCP servers, uploaded packages, and existing connections have their own controls, and you can block any individual plugin under Agents > Tools > Plugins, which stops users and the agents that depend on it from using it.
All users. Microsoft Learn lists All users as the default User access setting, meaning all users in the organization can access agents and plugins, subject to the existing app policies and user assignments. The other options are No users and Specific users or groups, under Agents > Settings > User access in the Microsoft 365 admin center.
Microsoft Learn names two roles: AI Administrator and Global Administrator. Approving an MCP server registration request needs access to the Tools page in the Microsoft 365 admin center and the ability to grant tenant-wide consent, and those two roles have both. After approval, the administrator consents to the Microsoft Entra permissions the server requires, and the server becomes available to agent-building surfaces only after consent is granted. Microsoft notes it can take up to 30 minutes to appear in all Copilot Studio environments in the tenant.
Microsoft Learn says the plugin appears as blocked by organizational policy, with the message "This plugin is blocked by your organization's policy," and eligible users can select Request access. The request goes to Agents > Tools > Requests in the Microsoft 365 admin center, where an administrator reviews the user and the requested plugin and approves or rejects it.
No. Microsoft Learn says blocking a plugin prevents users from accessing it and any agents that depend on it, while its MCP servers and connectors remain available to other plugins. Blocking an MCP server works the other way: it also blocks the plugins that depend on it and the connectors linked to it.
Microsoft Learn says "Data processed by non-Microsoft services isn't subject to Microsoft agreements," and asks administrators to review the terms provided by non-Microsoft agent and plugin publishers and to consult internal policies before allowing access. For a credit union, bank, or mortgage company, that review belongs with the institution's third-party risk management program.
Microsoft's announcement says "Basic registry and management capabilities for Microsoft Copilot experiences are included with qualifying Microsoft cloud subscriptions." Each plugin's publishing record lists the licenses it requires, and Microsoft's administrator guide asks organizations to confirm licensing and cost requirements as part of readiness, so check both before you approve a plugin.
The proposal, published in the Federal Register on September 15, 2026 by the OCC, the Federal Reserve Board, the FDIC, and the NCUA with comments due November 16, 2026, speaks to third-party relationships in general terms. It defines a third-party relationship as a business arrangement between a banking organization and an entity or individual for the provision of one or more products, services, and other activities that support the banking organization, and it includes insured credit unions in banking organizations. Whether a plugin publisher fits that definition is your program's determination, and the record should carry that determination with its reasoning, the permissions and data flows involved, the approver, and the next review date.

Where the facts on this page come from

Every Microsoft date, setting, path, and quotation above was read from the sources listed here on October 6, 2026, and each source was confirmed unchanged on October 7, 2026.

  • Microsoft 365 Message Center post MC1484008, Microsoft Copilot: Introducing the Microsoft plugin registry for Microsoft Copilot experiences, plan for change, published September 30, 2026. Source for what the registry is, what a plugin can bundle, the two rollout windows, the Plugins button, the no-setup statement, and Microsoft's recommendations. Visible to administrators in your own Microsoft 365 admin center; a public archive copy is at mc.merill.net/message/MC1484008.
  • Microsoft 365 Message Center post MC1479277, Microsoft Copilot: New ways to work across Microsoft Copilot and Microsoft 365, published September 25, 2026 and updated October 5, 2026. Source for the new Copilot app, the Plugins entry point in Chat and Cowork, and the Frontier timing. Public archive copy: mc.merill.net/message/MC1479277.
  • Microsoft 365 Message Center post MC1479519, Agents and Skills in CIQ, updated October 5, 2026. Source for inserting agents and skills into a prompt with / or @. Public archive copy: mc.merill.net/message/MC1479519.
  • Microsoft Copilot Blog, Introducing the plugin registry, September 30, 2026. Source for the more than 100 plugins, Microsoft's definitions of skills, connectors, and agents, the productivity case, the future Copilot Studio, GitHub Copilot, and Microsoft Foundry support, and the note on what qualifying subscriptions include.
  • Microsoft Learn, Manage plugins, skills, and MCP servers in Microsoft 365 admin center, dated September 28, 2026. Source for the publisher categories, plugin availability, access requests, uploads, block and delete, MCP server approval and its two roles, consent, the 30-minute note, and tool-level control.
  • Microsoft Learn, Agent settings in Microsoft 365 admin center, updated September 30, 2026. Source for the User access options and default, the Microsoft-built exception, the statement on non-Microsoft services, and the agent management rules for ownerless agents.
  • Microsoft Learn, Administer Microsoft 365 Copilot plugins and agents, dated September 30, 2026. Source for the review list, the readiness steps, and the limits of a single approval, assignment, or block.
  • Microsoft Learn, Agent management roles and permissions in Microsoft 365 admin center. Source for the tenant-wide governance authority of the AI Administrator and Global Administrator roles.
  • Federal Register, Proposed Third-Party Risk Management Guidance, 91 FR 58536, published September 15, 2026 by the OCC, the Federal Reserve Board, the FDIC, and the NCUA. Source for the comment deadline, the definition of a third-party relationship, the inclusion of insured credit unions, and the quoted line on risk.

Copilot's Plugins button is on its way to your users.
Decide what they can install first.

The work starts with your agent and plugin settings and the plugins, agents, and MCP servers already in your tenant. When it is done, you know who can install what, which publishers sit outside Microsoft, and who approves the next request.

Tell us a little about your environment and we will come back with what we would check first.

Tier 1 Microsoft CSP 750+ financial institutions SOC 1 Type 2 · Security Controls SOC 2 Type 1

What should we look at? Optional.

Agent and plugin settings review
Third-party plugin review
MCP server approvals
Copilot readiness assessment

Encrypted. Private.

Thank you. That is with us.

An ABT specialist will be in touch shortly. If plugins are already reaching users ahead of your review, say so in your reply and we will start there.