Copilot Studio governance controls
If a company lets staff build agents in Microsoft Copilot Studio, administrators need to know what they can switch off, watch and cap. This guide summarises Microsoft's Security and governance article (the search index dates it 7 August 2026). It describes what Microsoft says exists, not how well it works. We have not used Copilot Studio.
Controls Microsoft lists
| Control | What Microsoft says it does |
|---|---|
| Data policies | Admins use Power Platform admin center data policies to govern maker and user authentication, knowledge sources, actions, connectors and skills, HTTP requests, channel publication, Application Insights and triggers. |
| Credit governance | Admins can monitor usage and set pay-as-you-go Copilot credit caps to manage spend. |
| Connector dependency insights | Admins can review which connectors agents use before deployment. |
| Audit logs | Maker audit logs in Microsoft Purview, and activity monitoring and alerts in Microsoft Sentinel. |
| Run tools with user credentials | Makers can configure tools to use the signed-in user's credentials by default. |
| Security scan | Makers see security alerts and real-time risk findings, aimed at data exfiltration, before publishing when default security settings change. |
| Environment routing | Admins route makers to a safe environment and can show a welcome message about privacy and compliance. |
| Customer-managed keys | Admins can enable customer-managed encryption keys for environments. |
| Source-control audit trail | GitHub-backed source control and deploy-from-Git with auditable deployment history. |
| Sensitivity labels | For SharePoint knowledge, makers and users can see the highest sensitivity label used in a response. |
Agent 365
Microsoft describes Agent 365 as a central control plane to observe, govern and secure Copilot Studio agents. For organisations that onboard it, agents can be represented as Microsoft Entra identities, governed with Conditional Access, role-based and attribute-based access controls and access governance workflows. Microsoft also lists Entra network egress and ingress controls through Agent 365 and says that capability is generally available. These features apply only to organisations that onboard Agent 365.
Generative AI switches and a Lockbox caveat
- Admins can turn off publishing of agents that use generative AI features for the tenant, and can disable data movement across geographic locations for generative AI features outside the United States.
- Customer Lockbox is supported, but Microsoft says it does not cover everything. Two categories are excluded: security audit logging telemetry (agent invocation, tool and action calls, policy decisions, runtime activity), which goes through the Purview pipeline, and certain Agent 365 governance and audit events.
Questions to ask before rollout
- Which data policies will block connectors, HTTP requests and triggers by default?
- Is a Copilot credit cap set, and who gets alerted?
- Do tools run as the user or as the maker, and what can each reach?
- Where do audit logs go, and does your compliance team accept the Lockbox exclusions above?
- Is Agent 365 onboarded, since some identity controls depend on it?
Pricing context is in Copilot Studio vs Agentforce. For general questions to ask any vendor, see the privacy and approval checklist and the ChatGPT workspace agents guide.
Source: Microsoft Learn, Security and governance in Copilot Studio. Spot a change? Tell us.