Skip to main content Search content Microsoft Digital Customer Zero Office of the CISO AI and Copilot Business applications Cloud platform Data and analytics Developer and automation Modern work Security and governance IT Careers About us Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Software companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap
We’ve learned valuable lessons at Microsoft about which agent-building tool to enable for agent builders with different needs. This guide will walk you through how you can do the same at your company.

Our Customer Zero guide: Enabling agent creation across Microsoft 365 Copilot, Copilot Studio, and Foundry

Generating value by empowering your employees to build agents

AI agents are an increasingly important way for organizations to scale knowledge, help their employees boost productivity, and automate business processes.

In Microsoft Digital, the company’s IT organization, we think of agents as more than tools that the company rolls out and employees adopt. They represent a new way of working, where employees have the power to create and modify their own AI tools to help them solve problems, streamline their work, and create value in their unique roles.

As our use of AI has matured, we’ve seen employees across the company identify opportunities to create agents that help them retrieve information, answer common questions, automate repetitive tasks, and reimagine workflows. Rather than limiting agent creation to developers, we’ve made agent-building capabilities available for every employee at Microsoft. Our goal is to enable the people closest to the work to build their own agentic solutions.

Meeting the needs of different builders across the organization

As we expanded agent adoption across Microsoft, we quickly discovered that not all employees need to build the same kinds of agents. A knowledge worker who wants to create a simple retrieval agent for a project team has very different requirements from a business unit building workflow automations or an engineering organization tasked with creating enterprise-scale agentic solutions.

In the course of this journey, we’ve faced a challenge that’s becoming common for many organizations: Equipping different groups of employees to build agents without forcing everyone into the same development model.

A photo of Chand

“Frontier transformation depends on empowering every employee to participate in creating AI solutions. The more people who can turn ideas into agents, the more value organizations can unlock.”

We’ve learned that effective agent enablement is about matching the right tools to the right builders and scenarios:

  • Some employees benefit from natural-language tools that allow them to build agents with little or no technical experience.
  • Others need low-code environments that support more sophisticated workflows and integrations.
  • Still other workers require pro-code platforms that provide the flexibility, extensibility, and governance needed for enterprise-scale solutions.

Creating pathways for every type of agent builder

Our approach has been to enable a spectrum of agent-building pathways that meet employees where they are. We focus on providing clear guidance, skilling resources, governance frameworks, and tool recommendations that help people move from ideas to working solutions with the appropriate level of complexity and oversight. Crucially, this approach helps us ensure innovation can scale responsibly as agent usage continues to grow.

“Frontier transformation depends on empowering every employee to participate in creating AI solutions,” says Mohit Chand, general manager of Corporate Functions Engineering in Microsoft Digital. “The more people who can turn ideas into agents, the more value organizations can unlock.”

In this IT playbook, we’ll share how we’ve approached agent enablement across Microsoft, how we think about different agent-building audiences and tools, and the lessons we’ve learned along the way. We believe these insights can act as a blueprint for your own strategy as you empower employees to build agents with confidence, regardless of their level of technical knowledge.

Chapter 1: Choosing the right path for agent creation

Laying the foundation for different builders to meet their needs with agents

As agent creation became more widespread at Microsoft, one question stood out: How could we help employees use the tool that’s best for the problem they’re trying to solve or the opportunity for innovation they’re trying to explore?

Early on in our journey, we observed a common pattern: Employees would often gravitate toward the most powerful and flexible tools available because they seemed like the safest choice. If a platform could handle every scenario, why not start there?

In practice, that approach often introduced unnecessary complexity. Some builders found themselves navigating security, privacy, and compliance requirements that far exceeded the scope of their projects, let alone their level of technical expertise. Others invested time learning advanced capabilities they ultimately never needed to use.

A photo of Jangir

“The most successful agents often start with a practical business problem. Once builders see the results, they quickly discover new opportunities to automate and improve adjacent processes.”

We’ve learned that enabling successful agent building depends on providing the right development path. The goal is to help employees innovate quickly with AI agents while applying the right level of governance and technical complexity. When employees start with a clear objective and work backwards from there, they tend to build faster, encounter fewer obstacles, and achieve stronger results.

“The most successful agents often start with a practical business problem,” says Naveen Jangir, a principal architect in Microsoft Digital. “Once builders see the results, they quickly discover new opportunities to automate and improve adjacent processes.”

We also learned that choosing the wrong tool can have unintended consequences. Employees may run into compliance reviews they weren’t expecting. Projects might slow down as builders try to understand governance processes.

Choosing the tool that isn’t the right fit for a builder’s scenario might also direct them to the wrong model for their agent. In some cases, that could lead to using something more complex and expensive instead of a lower-cost model that’s ideal for a simpler scenario. More advanced tools often assume more advanced models that aren’t inherently necessary for every task.

In some cases, builders abandon promising ideas before they deliver value. The result is losing out on innovation, not because an idea wasn’t worthwhile, but because the path to implementation became more difficult than necessary.

To avoid these situations, we encourage builders to start by considering their problem scenario, rather than the tool itself. When evaluating an idea, we ask employees to think through a few key questions:

  • What business outcome are they intending to achieve?
  • What data does the agent need to access?
  • Is that data personal, team-based, or enterprise-wide?
  • Is the agent retrieving information, taking actions, or operating autonomously?
  • How broadly do they intend to share the agent?

Understanding the needs of different builders

Roughly speaking, we describe agents as belonging to three categories, ranging from simpler and lower risk to more complex and more reliant on sensitive or external data.

A graphic demonstrating the spectrum of simple to advanced agents, running from retrieval through task and autonomous agents.
Different agent-creation tools cover different areas of the development spectrum, ranging from simpler to more advanced agentic solutions.

As AI maturity at Microsoft has advanced, three primary sets of needs and cohorts of agent builders have emerged, based on user scenarios, needs, and technical capability.

1. Simple retrieval agents for any employee: Agent Builder in Microsoft 365 Copilot

The first cohort consists of employees solving everyday productivity challenges. These builders need agents that retrieve information, summarize content, answer questions, evaluate inputs against a declared rubric to provide feedback, and help them work more efficiently with existing knowledge sources.

For these scenarios, Agent Builder in Microsoft 365 Copilot provides an accessible starting point. Employees can use natural language to create lightweight retrieval agents grounded in their Microsoft 365 knowledge and data. It lets employees begin creating value without requiring extensive technical skills or development experience.

Many employees discover that this level of functionality meets their needs. By starting here, they can experiment quickly without introducing unnecessary complexity.

2. Citizen development without DevOps overhead: Microsoft Copilot Studio

Some employees want agents to do more than retrieve information. These builders need tools that can connect to business systems, automate workflows, orchestrate processes, and take actions on behalf of users.

Copilot Studio serves as an important middle ground for agent development, supporting retrieval, task, and autonomous agent scenarios while providing access to a broad ecosystem of connectors and integrations. It combines low-code development with broader connector capabilities, workflow automation, built-in telemetry, and evaluation tools.

These features allow employees to create more sophisticated business solutions without needing to be professional software developers.

3. Professionally developed agents that meet organizational needs: Microsoft Foundry and pro-code tools

The most complex and flexible tools are primarily the domain of professional developers and engineering teams building line-of-business or enterprise-scale solutions. These builders need architectural control, advanced integrations, specialized security requirements, and custom orchestration capabilities. For these scenarios, Microsoft Foundry and other pro-code pathways like Microsoft 365 Agents Toolkit provide the flexibility they need to design highly customized systems.

But they also introduce additional responsibility. Teams operating at this level assume ownership for architecture, compliance, privacy, security reviews, operational monitoring, and lifecycle management.

The distinction is important. Advanced development platforms create tremendous possibilities, but they’re most effective when a scenario truly requires that level of control.

A photo of Wan

“Get people excited about agents first, and then educate them. Encourage people to become builders and get their hands dirty through advocacy and education.”

These aren’t rigid boundaries, but they’re helpful in understanding what each agent creation tool can accomplish. We’ve distilled our perspective into the following list of characteristics of different agent builders and of the creation platforms most appropriate for their needs:

Agent Builder in Microsoft 365 Copilot

  • Low difficulty
  • For all roles
  • Function: information-retrieval only
  • Microsoft 365 content and web sources
  • Light governance
  • Low risk

Microsoft Copilot Studio

  • Low to moderate difficulty
  • For all roles
  • Function: task completion
  • Microsoft 365 content plus connectors to other data sources and platforms
  • Advanced governance
  • Higher potential for risk

Microsoft Foundry, Agent Toolkit

  • Highest difficulty
  • For developers
  • Function: workflow automation
  • Multiple internal and external channels
  • Advanced governance
  • Highest potential for risk
  • Highest level of capability

Whatever your potential builder’s level of expertise or needs, we’ve discovered that encouraging experimentation while providing learning opportunities is key.

“Get people excited about agents first, and then educate them,” says Myron Wan, a principal group product manager in Microsoft Digital. “Encourage people to become builders and get their hands dirty through advocacy and education.”

What IT organizations should consider

In Microsoft Digital, our objective is to enable innovation while maintaining appropriate safeguards.

Good agentic architecture starts with data

Whenever we’re considering any agent development path, data is at the center of our thinking. Where data resides, how agents access it, who can use it, and the actions agents will execute with it form the foundation of every agent-building solution. In many cases, the data itself determines the appropriate platform.

We take a “self-service with guardrails” approach to our productivity estate, which means we give employees the ability to create new workspaces across their Microsoft 365 applications while securing assets by default and expanding access based on employee needs. The same is true for agent creation. We rely on well-established governance in the form of sensitivity labels, established software development lifecycle procedures, and risk-based app and agent management policies that trigger reviews when we detect risk.

We also frame governance in terms of who owns the risk: the platform itself, the administrator, or the organization.

  • Agent Builder operates according to intrinsic governance, where the platform itself is responsible for managing risk. Users build agents within existing Microsoft 365 boundaries, which include built-in guardrails that simplify governance for lower-risk scenarios. Builders can create meaningful experiences while staying within well-understood security and compliance frameworks.
  • Copilot Studio follows a configurable governance model where the administrator owns the risk. It introduces greater flexibility through workflows, actions, and connectors. That flexibility creates powerful opportunities, but it also requires thoughtful governance around how data moves between systems and which connectors are approved for use.
  • Microsoft Foundry features explicit governance, where the organization owns the risk. That need arises from more complex capabilities like model selection, custom orchestration, architectural design capabilities, and more.

Regardless of the agent-creation platform your employees use, investing in data classification, labeling, and governance will put you in a better position to scale safely.

AI-ready data is especially crucial for more advanced agent creation tools like Foundry. It ensures secure access to the high-quality, accurate information employees need when they need it.

AI-ready data rests on five pillars:

  • Accelerating time to value through managing powerful AI models
  • Data democratization to promote informed decision-making, innovation, and continuous learning
  • Connectivity among subject matter experts across domains and regulatory divisions to accelerate innovation
  • Quality and governance to maintain data accuracy, reliability, and compliance
  • Unification, delivering accessible and scalable infrastructure by breaking down silos

Balancing risk and innovation

A risk-based approach informs one of our primary guiding principles: reviews should scale with risk.

Thanks to the guardrails we’ve established, we don’t subject a personal productivity agent created in Agent Builder to the same review process as an autonomous agent operating across enterprise systems. The result is a matrixed model of agent governance that matches the need for oversight and review to the level of risk, access, or action-taking ability an agent presents.

This principle helps employees experiment early, validate ideas quickly, and gain confidence as builders. It also helps us avoid creating unnecessary barriers that can discourage adoption before builders can realize value.

We also learned that excessive control isn’t necessarily a safe default; it’s another category of risk. Over-restriction doesn’t eliminate risk, but redirects it to shadow AI, where we lose both productivity and compliance visibility.

Before setting your employees free to create, speak with stakeholders from IT, security, privacy, legal, compliance, data, and other teams responsible for policy and protection. Together, these groups can help you work toward a cohesive but flexible approach to agents and the risks they present.

Throughout this process, it’s important to stay curious about the processes builders will face before, during, and after creating their agents. Administrators should ask several key questions:

  • What is the origin of this process, how relevant is it for agent creation, and which products are affected?
  • What can we do to remove friction and allow safer innovation?
  • Where can we get involved with processes when agents present more risk, while allowing agents that meet our standards to get built and shared broadly, with minimum friction?

Adoption through intention

We’ve invested a lot of time, strategy, and effort into adoption efforts across Microsoft. First, builders can use self-serve tools to meet their own needs. Builders Central is our internal SharePoint page dedicated to supporting agent builders at Microsoft. Crucially, it features a section that helps people understand which agent-creation tool might be best for them, along with instructions and factors to consider throughout the process.

AskMica (Ask Microsoft Intelligent Compliance Agent) is our IT agent built on top of this content. It walks makers through the decision-making process and answers questions about what tool to use, what environment to choose, how to get exceptions for security, privacy, sensitive data access, and more.

AI Skills Navigator, a program now available to customers, extends AI learning by allowing leaders to create structured paths that guide teams toward specific outcomes, such as becoming AI literate, managing agents in the enterprise, or building expertise in agent development. In Microsoft Digital, we’ve tailored AI Skills Navigator content to differentiate learning for our IT employees.

This is an essential piece of the equation, because IT teams are so integral to AI implementation efforts. As you promote AI more widely, it’s important to ensure your own IT team has the skills they need to support this technology.

Since we’ve put these efforts in place at Microsoft, the number of active makers has grown roughly 10 times, from around 2,000 to 20,000 a month. We now have about 150,000 personal development environments under governance, and we drove measured maker friction down from roughly 50% to 5%.

Letting outcomes drive platform selection

We encourage teams to focus on business outcomes first. Before selecting a platform, builders should identify the process they want to improve, define success criteria, and determine whether an agent is the best solution. We have an entire SharePoint site dedicated to helping employees navigate agent creation, including decisions around which agent tool to choose.

In some cases, a traditional workflow, existing application, or agent that someone else has already created may be the better choice. But if an employee or team sees a genuine need, starting small allows them to validate assumptions, measure impact, and expand capabilities over time.

As you consider ways to empower your own employees to create agents of their own, the lessons we’ve learned can form a foundation for creating policy, enabling workers, and protecting your organization.

Key takeaways

As you look for ways to empower your own employees to create agents, the lessons we’ve learned building our approach at Microsoft can serve as a guide:

  • Start with the business problem, not the development tool. Encourage employees to think about what they’re trying to accomplish before beginning.
  • Choose the right platform for the job. Throughout your enablement and adoption efforts, teach employees to evaluate data requirements, impact, and sharing needs before selecting a platform that meets their scenario’s requirements.
  • Reviews should scale with risk and business impact. Build systems that only create review workflows on agents that genuinely pose risk. With the right guardrails in place, simple agents may qualify for streamlined or automated review.
  • Treat governance as an enabler. Embed guardrails into platforms, data, and processes, so employees can build and experiment confidently without exposing the organization to unnecessary risk or slowing progress.
  • Tailor metrics to goals. A governance team that tracks only compliance metrics will optimize for restriction. Add adoption metrics to your security dashboard that include measures like active makers, time to production, and user friction scores, and the team’s behavior will change.

Learn more

How we did it at Microsoft

Further guidance

Chapter 2: Empowering every employee with Agent Builder

Giving employees a starting point for agent creation

As agents began to show their potential for significant impact on day-to-day work, we wanted employees across the organization to participate in creating them—not just developers and technical specialists. We found that the people closest to a business problem were often the ones best positioned to identify opportunities for AI to help. That insight helped shape our approach to Agent Builder in Microsoft 365 Copilot.

A photo of Heath.

“Everyone at Microsoft is a potential builder. The key is giving people opportunities to learn through hands-on experience, because reading about AI is very different from building with it. Agent Builder provides a safe environment where they can do just that.”

Agent Builder provides an accessible entry point into agent creation. Employees can create simple retrieval agents using natural language and ground them in approved knowledge sources, including SharePoint sites, websites, and Microsoft Graph connectors. The experience allows users to create agents that retrieve information, summarize content, answer questions, and help employees navigate organizational knowledge without requiring software development expertise.

The audience for Agent Builder is intentionally broad. It serves knowledge workers, subject matter experts, project teams, and employees looking to solve specific productivity challenges without learning advanced development tools. It also provides an important first step for employees who are new to building AI solutions.

“Everyone at Microsoft is a potential builder,” says Tom Heath, a change management lead in Microsoft Digital. “The key is giving people opportunities to learn through hands-on experience, because reading about AI is very different from building with it. Agent Builder provides a safe environment where they can do just that.”

Understanding Agent Builder’s place in the agent journey

Agent creation should scale with the complexity of the problem an employee wants to solve. Agent Builder creates agents devoted to knowledge-centric experiences: finding information, accessing expertise, navigating documentation, and surfacing insights from existing content.

We encourage employees to start with a simple question: Does this agent primarily need to help people find, understand, use, interpret, or validate information? If the answer is yes, Agent Builder is usually the right starting point.

Common use cases include team knowledge hubs, readiness and adoption resources, project-specific information assistants, meeting preparation support, and product or policy guidance. These scenarios allow employees to create immediate value without taking on unnecessary complexity.

As they experimented with agent building tools, many employees assumed they needed a more advanced platform than they actually did. In practice, we’ve observed that most use cases are knowledge-centric, and employees can address them effectively with Agent Builder.

A photo of Auguillard.

“Agents are only as good as the data behind them. Strong data governance and protection practices create the foundation for successful agent experiences.”

At the same time, it’s important to understand where the tool’s boundaries lie. Organizations should consider moving to Microsoft Copilot Studio when requirements expand beyond knowledge retrieval and begin to include higher-order capabilities:

  • Accessing data outside Microsoft 365
  • Integrating with external business applications
  • Automating business processes
  • Triggering workflows and actions
  • Including advanced telemetry and evaluation capabilities

This distinction helps employees select the right platform without overwhelming them with technical decisions: Agent Builder helps people interact with information, while Copilot Studio helps them take action on it.

The Customer Zero story: Implementing Agent Builder internally at Microsoft

Because Agent Builder is intentionally simple, most of our work enabling it within Microsoft has been organizational rather than technical.

Skilling and education

Employees understand Microsoft 365 Copilot, but they’re often less familiar with the role agents can play in their daily work. Successful adoption means helping people understand when prompting alone is sufficient and when an agent they build can deliver more value. Adoption initiatives like Agent Launchpad that feature hands-on ideation and gamified building activities have helped our employees make those leaps.

Agent sprawl

As adoption grows, organizations need visibility into what agents exist, who owns them, and whether they remain relevant over time. Ownership, automation, explicit lifecycle policy, and governance become increasingly important for monitoring the proliferation of agents. For example, we use a 60-day inactivity threshold that triggers alerts and automated cleanup. In this context, Microsoft Agent 365, the control plane for agents, is emerging as a powerful tool for observability, management, tracking, and security.

Data readiness

Agent Builder surfaces information users can already access, which means the quality of an agent experience depends heavily on the quality of the underlying data. We saw this principle in action repeatedly during our adoption efforts. Well organized, properly governed content consistently led to stronger agent experiences. Meanwhile, poorly maintained data limits an agent’s usefulness, regardless of how well it was designed. The systems we’ve put in place for governing agents provide the necessary guardrails for this level of agent.

“Agents are only as good as the data behind them,” says Ken Auguillard, a principal program manager in the Power Platform product group. “Strong data governance and protection practices create the foundation for successful agent experiences.”

We also found that many employees wanted agents to perform actions, automate workflows, or orchestrate processes across systems. Those are valuable scenarios, but they sit outside the scope of Agent Builder. Helping employees understand boundaries reduced frustration and created clearer pathways into Copilot Studio when additional functionality was needed.

Enabling Agent Builder at Microsoft

As adoption accelerated, our focus shifted from simply making Agent Builder available to helping employees use it successfully.

It may seem elementary, but people need to understand why they may want to create an agent instead of simply using Copilot. They do that by learning how agents apply AI capabilities more specifically than a broad-based assistant. Then, they need help knowing how to make their idea a reality.

We invested heavily in hands-on learning experiences. Employees learned fastest when they could experiment with real scenarios, test ideas, and refine agents in the context of their own work. Workshops, guided exercises, office hours, and peer-to-peer sharing all played important roles in helping employees build confidence. Real examples from early adopters were especially useful for encouraging people to take their first steps.

Our priority was making agent creation approachable, so we positioned Agent Builder as a capability available to everyone, not just technical users. We then encouraged employees to start with a business problem, build agents with a clear purpose, and focus on measurable outcomes rather than experimentation for its own sake.

We also emphasized thoughtful agent design. We found that employees who spent more time defining an agent’s purpose, instructions, and knowledge sources produced significantly better outcomes.

“Be direct, be descriptive,” Heath says. “Spending more time in the ‘Describe’ interface typically means spending less time troubleshooting later.”

Because Agent Builder benefited from the governance foundation already present in Microsoft 365, we had already embedded identity controls, permissions models, data loss prevention policies, sensitivity labels, and compliance protections within the environment. As a result, we didn’t need to invest too heavily in building employees’ understanding of governance structures. Instead, we could focus more on helping them understand how to use the platform effectively.

As a result, much of our enablement work centered on communication, celebrating wins, peer-led support, and helping employees understand where Agent Builder fit within the broader agent ecosystem.

Campaign Prediction Agent

Created using Agent Builder

The content team in Microsoft Digital is responsible for developing and executing content strategies that drive technology adoption, awareness, and excitement for Microsoft employees. They were looking for an easier way to predict the performance of internal communications campaigns.

Typically, people would have to sift through mountains of data to determine the potential reach and impact of a campaign. The team created the Campaign Prediction Agent to make it much easier.

The employee simply asks the agent to predict the performance of a particular internal campaign, and it returns a report that includes potential reach, overall effectiveness, and measurement confidence. The agent also breaks the data down by channel to help the team assess where they’ll make the maximum impact.

To ground the Campaign Prediction Agent in the necessary data, the team created a SharePoint folder that includes project-specific reports, multi-year and multi-channel analysis, benchmark data, and other useful information. That way, they maintain a robust grounding in data all in one place, making it easier for the agent to find what it needs and create helpful predictions in seconds.

For us, Agent Builder became an important foundation for employee agent creation. It provides a low-friction way for our employees to build, learn, and solve business problems quickly. While many builders remain within the platform long-term, others use it as a stepping stone to more advanced tools. In both cases, it helps create a culture where building with AI is accessible to everyone.

As you look for ways to empower a workforce of agent builders at your organization, consider ways that our efforts can provide a framework for secure and empowering experiences for employees who want to solve their day-to-day business challenges.

Key takeaways

As you consider using Agent Builder for employee-created agents, here are some factors to keep in mind:

  • Invest in hands-on learning. Give employees opportunities to build and test agents using real business scenarios. Practical experience is one of the most effective ways to build confidence and adoption, and Agent Builder provides a lower-complexity starting point for that kind of experimentation.
  • Help employees understand the boundaries of Agent Builder. The tool is ideal for knowledge-based and retrieval-focused experiences. More complex automation and action-taking scenarios may require Copilot Studio.
  • Prioritize high-quality instructions and knowledge sources. Clear descriptions, well-defined instructions, and trusted content sources are critical for creating effective agents.
  • Use simple retrieval agents as a springboard. Encourage employees to use Agent Builder first, then move on to more complex extensions that require a structured review process as needed.

Learn more

How we did it at Microsoft

Further guidance

Chapter 3: Leveling up citizen developers with Microsoft Copilot Studio

A bridge between simple and advanced agent development

Plenty of agentic scenarios require more than knowledge retrieval but less than a fully custom agentic application. At Microsoft, we wanted employees and teams to have the opportunity to connect their agents with business systems, automate workflows, retrieve information from external sources, and take action on behalf of users without necessarily demanding a full-featured DevOps process complete with reviews. We also wanted to provide greater capabilities while still allowing for a lightweight coding approach that accommodates citizen developers.

Copilot Studio is a low-code platform for creating agents that can automate processes, connect to enterprise systems, and extend Microsoft 365 Copilot with organizational data and business workflows. It supports both custom agent creation and agentic automations while remaining accessible to users without extensive software development experience. Everyone at the company has the freedom to create their own agents in their own Copilot Studio environment.

Unlike Agent Builder, which focuses primarily on knowledge-based experiences, Copilot Studio gives builders the tools to sync up agents to external systems through approved connectors, workflows, skills, and actions. These capabilities allow agents to move beyond answering questions and begin supporting real business processes.

“Once builders need data beyond Microsoft 365, connectors become a critical part of the solution. Copilot Studio is often the next step, because it lets teams combine enterprise data, workflows, and actions in a way that scales with business complexity.”

At Microsoft, we’ve identified several primary builder cohorts for Copilot Studio:

  • Citizen developers and makers who want to build beyond knowledge retrieval
  • Business teams that seek to automate departmental processes
  • Power Platform users who need to extend existing workflows
  • Technical teams that want low-code flexibility instead of moving to pro-code development

Understanding Copilot Studio’s place in the agent creation journey

One of the most important lessons we learned is that not every scenario requires Copilot Studio. In the simplest terms, agents created using this platform are more suited for organizational or team-level tools, or for individuals who need more complexity than Agent Builder can accommodate.

Copilot Studio becomes the natural next step when teams need more capabilities or connections:

  • Access to data that resides outside Microsoft 365
  • Connectors that provide access to external business systems
  • Workflow automation
  • Triggered or autonomous behaviors
  • Agents that perform actions rather than simply retrieving information
  • Broader publishing and sharing options

Within Microsoft, we often describe the progression between platforms as moving from knowledge to action. A retrieval agent might answer questions about policies or project documentation. A task agent built in Copilot Studio can retrieve information from multiple systems, generate reports, update records, trigger workflows, and communicate with users based on business events.

“Once builders need data beyond Microsoft 365, connectors become a critical part of the solution,” says Aisha Hasan, a principal product manager in Microsoft Digital. “Copilot Studio is often the next step, because it lets teams combine enterprise data, workflows, and actions in a way that scales with business complexity.”

Most employees only have access to a subset of approved connectors that Microsoft Digital and our Office of the Chief Information Security Officer (CISO) govern. That helps us enable the Copilot Studio experience for all employees while limiting the most advanced capabilities to qualified engineers.

Copilot Studio may not be ideal for all scenarios, which is why we have pro-code alternatives. But many business processes never require that level of complexity. We’ve consistently found that Copilot Studio can support a broad range of organizational and team-level solutions before additional development investment becomes necessary.


What our experts say:

A photo of Hasan.

“We focus on helping builders understand the risk profile of their agents as early as possible. By providing guidance during development, we can reduce friction, increase accountability, and move solutions through the process more efficiently.”

A photo of Hsu.

“Copilot Studio provides far more visibility into how agents perform over time. The evaluation and telemetry capabilities help builders improve quality, identify gaps, and build confidence that agents are delivering meaningful business value.”


The Customer Zero story: Implementing Copilot Studio internally at Microsoft

Our experience implementing Copilot Studio has helped us identify some of the key areas to carefully consider while enabling Copilot Studio at your organization.

Managing governance without slowing innovation

As capabilities increase, governance naturally becomes more important.

The reality is straightforward. When agents connect to additional data sources, integrate with external systems, and perform actions on behalf of users, organizations need appropriate safeguards.

At the outset of our journey, we already had robust systems in place for securing custom connectors, and Microsoft 365’s built-in governance capabilities ensure Microsoft 365 agents respect our labeling taxonomy and the policies it articulates. We have the power to introduce sharing limits that restrict how widely builders can distribute their agents depending on their purpose and scope.

“We focus on helping builders understand the risk profile of their agents as early as possible,” Hasan says. “By providing guidance during development, we can reduce friction, increase accountability, and move solutions through the process more efficiently.”

Three agents help us do this work:

The Risk-O-Meter

Auto-classifies submissions as green, yellow, or red based on their risk profile, then auto-approves, auto-declines, or routes them to the relevant reviewer

The Action-O-Meter

Applies the same logic to new connectors and MCP servers

The Friction Meter

Surfaces maker pain as a first-class metric

For simpler self-service agents that individual employees create and use, we define policies at the Copilot Studio environment level. Tenant administrators and partners on the security team apply data loss prevention policies to configure what individual employees can and can’t do. At this level, everyone in the company has the same configuration and tools available, and automation largely handles agent reviews and assessments based on pre-configured settings.

For more wide-reaching apps that operate at the line-of-business level or that we might publish enterprise-wide, we need to apply greater rigor. Discipline-specific professionals in security, privacy, and other spaces conduct robust reviews to ensure internal teams meet our high standards.

Governance expands through bounded, risk-based arguments, not a general philosophy of openness. Internally at Microsoft, it was more than just flipping a switch. We negotiated incrementally with the Office of the CISO, then scoped sharing. That supported the CISO’s need to only approve precise, bounded requests with measurable controls.

Telemetry and evaluation matter

As agents become more sophisticated, understanding performance is increasingly important.

Observability is one area where Copilot Studio provides significant value. Agent administrators gain access to telemetry, analytics, evaluation capabilities, and performance insights that help them understand how their organization is using agents and where improvements are necessary.

We’ve found that these features become particularly important as agents move beyond personal productivity and begin supporting larger groups of users. Data-driven evaluation helps teams improve outputs, validate business outcomes, and build trust in agent experiences.

“Copilot Studio provides far more visibility into how agents perform over time,” says Jean Hsu, a product designer for Copilot Studio. “The evaluation and telemetry capabilities help builders improve quality, identify gaps, and build confidence that agents are delivering meaningful business value.”

Consider both areas carefully as you put Copilot Studio in the hands of your employees and teams. Because it straddles both simple and more complex agents, you’ll need to consider the implications of flexibility and how to maintain proper oversight and governance.

Empowering employees to use Copilot Studio at Microsoft

As adoption grew, we worked to balance empowerment and responsibility. Our Builders Central SharePoint page provides guidance on prerequisites, agent creation environments, types of agents people can build, and more.

It’s worth noting that builders who are already familiar with Power Platform concepts like environments, connectors, and data loss prevention policies will have an advantage when they use Copilot Studio, but they typically won’t need deep technical expertise.

More broadly, we’ve implemented support systems to help our employees and teams create agents safely and effectively, without a massive knowledge burden. They include:

  • Making a wide variety of approved connectors available by default so builders can move quickly.
  • Clearly defining when builders should transition from self-service to IT-guided development.
  • Providing automated guidance during development rather than waiting until publication.
  • Using AI-assisted compliance resources to keep builders working in context.
  • Investing in maker education around connectors, data governance, and Power Platform fundamentals.
  • Encouraging teams to validate business outcomes before scaling solutions broadly.
  • Creating dedicated pathways for both self-service and enterprise scenarios.

Our experience showed that user education is just as important as technical controls. Builders need help understanding what they’re creating, what data their agents access, and what responsibilities accompany increasing capability.

We often use this statement to guide our work internally: Build compliantly, use intelligently.

DigitalMe

Created using Copilot Studio

DigitalMe is an AI-powered digital twin created at Microsoft to help change management leaders scale their expertise during large transformation initiatives.

As adoption programs grew, change management leaders found themselves spending significant time answering questions during readiness sessions and stakeholder engagements instead of focusing on delivering their content. Meanwhile, when they were traveling, in meetings, or out of office, employees often had to wait for answers, creating bottlenecks that slowed progress.

Built in Copilot Studio, DigitalMe acts as a digital representation of its human counterpart for both Microsoft Teams and Outlook. We’ve created a templatized version that anyone at Microsoft can apply to their own business context.

This agent is grounded in approved knowledge sources and previous guidance, so it can answer questions during sessions. Thanks to its access to knowledge, DigitalMe has the added benefit of supporting an employee’s colleagues even when the expert is unavailable.

So far, DigitalMe has shown enormous value for people leading sessions. In one 60-minute session, the agent handled 158 questions from participants, and its response accuracy is currently around 90%.

Read more about DigitalMe.

As you explore ways to help employees create more advanced and capable AI agents, our experience can provide an example of how low-code platforms can enable sophisticated business solutions without requiring every scenario to become a large-scale software development effort.

Key takeaways

Here are some important factors to keep in mind if you are considering Copilot Studio for agent creation at your organization:

  • Help employees know when they need Copilot Studio. Move to Copilot Studio when scenarios require external data, workflow automation, or business actions beyond knowledge retrieval.
  • Build skills to match needs. Invest in maker education around connectors, environments, data governance, and Power Platform fundamentals.
  • Observability is crucial. Use telemetry and evaluation data to continuously improve agent quality and business impact.
  • Develop a tenant-wide strategy. Create separate Power Platform environments based on what people want to build, what data they want to use, and what controls your organization needs.

Learn more

How we did it at Microsoft

Further guidance

Chapter 4: Building enterprise AI solutions with Microsoft Foundry and pro-code tools

Applying software development practices to agent creation

Some business challenges require capabilities beyond the reach of low-code development. Teams need to build solutions that can operate across complex business processes. At Microsoft, these scenarios made it necessary to cultivate a professional developer practice for building agents centered around pro-code tools, especially Microsoft Foundry. It provides a flexible environment for building sophisticated AI solutions using a broad catalog of foundation models, evaluation frameworks, orchestration tools, enterprise AI services, and unique dashboard experiences.

Foundry empowers teams to compare and evaluate models, fine-tune them for domain-specific scenarios, integrate large volumes of enterprise data, orchestrate multiple agents, build custom agentic applications, and monitor performance over time. It also allows builders to combine AI capabilities with enterprise architecture patterns, security controls, observability tools, and operational workflows.

A photo of Leung.

“Model selection is one of the most important decisions in enterprise AI. Different model families excel at different tasks, and understanding those tradeoffs helps teams build solutions that align with business goals while minimizing spend and maximizing ROI.”

Microsoft 365 Agents Toolkit provides a simplified creation path for pro-code builders. Using Visual Studio Code, developers can create agents grounded in multiple data sources, integrated with APIs, enhanced through adaptive cards, and customized through instructions, plug-ins, and manifests. The toolkit enables developers to build and deploy role-specific and task-oriented agents without creating extensive back-end services from scratch.

The primary audience for Foundry and Agents Toolkit includes software engineers, enterprise architects, IT solution owners, and advanced AI builders responsible for delivering production-grade capabilities at organizational scale.

“Model selection is one of the most important decisions in enterprise AI,” says Michael Leung, a senior software engineer in Microsoft Digital. “Different model families excel at different tasks, and understanding those tradeoffs helps teams build solutions that align with business goals while minimizing spend and maximizing ROI.”

Understanding when Microsoft Foundry and pro-code tools are right for the job

One of the most important lessons we learned is that the right platform depends on the problem we want to solve. Not every solution requires pro-code development.

In many cases, Copilot Studio provides more than enough functionality, even for agents meant to serve enterprise needs. Teams can create agents that connect to business systems, automate workflows, retrieve external information, and support business processes without requiring custom engineering. Copilot Studio supports knowledge retrieval, actions, autonomous behaviors, and extensive connector ecosystems.

Employees should consider moving to Foundry or other pro-code tools when they require greater technical depth to accomplish the following goals:

  • Fine-tune foundation models using domain-specific data
  • Compare and evaluate multiple model families
  • Build custom multi-agent orchestration frameworks
  • Implement advanced observability and evaluation pipelines
  • Develop autonomous systems that operate across multiple enterprise services
  • Integrate custom APIs, services, or proprietary architectures
  • Build solutions that require extensive engineering control and customization

The distinction between different agent-builder tools often comes down to three dimensions:

  • Low-code versus pro-code requirements
  • Solution complexity and organizational maturity
  • Short-term delivery goals versus long-term platform strategy

Don’t select Foundry simply because it is the most powerful option. Instead, start with the simplest platform that supports your business needs. That accelerates deployment and adoption while minimizing cost and operational overhead.


What our experts say:

A photo of Tripathi.

“Foundry helps us bring together data, expertise, and capabilities that often exist across separate teams. Many enterprise AI challenges are collaboration challenges, and the platform gives us a way to break down those silos.”

A photo of Mallurwar.

“Enterprise AI depends on data access and integration. The technology is powerful, but success ultimately comes from ensuring models have access to trustworthy, well-governed information.”


Enabling enterprise AI development at Microsoft

At Microsoft, our approach focuses on helping teams build responsibly while maintaining flexibility for innovation.

As organizations expand beyond information retrieval, complexity increases. AI solutions begin interacting with multiple data sources, business systems, APIs, and operational workflows. Governance, architecture, and engineering practices become increasingly important.

“Foundry helps us bring together data, expertise, and capabilities that often exist across separate teams,” says Naval Tripathi, a principal software engineering manager in Microsoft Digital. “Many enterprise AI challenges are collaboration challenges, and the platform gives us a way to break down those silos.”

Several principles guide how we enable professional developers working with agents:

  • Start with clearly defined business outcomes before selecting architecture.
  • Align development approaches with the complexity of the scenario.
  • Involve domain experts early when designing AI solutions.
  • Establish evaluation frameworks before deploying agents at scale.
  • Build governance and compliance requirements directly into development workflows.
  • Use human-in-the-loop models when introducing autonomous decision-making.

This approach helps teams focus on solving problems, rather than pursuing technology for its own sake.

The Customer Zero story: Implementing Microsoft Foundry internally

While Foundry enables powerful capabilities, it also introduces new areas for oversight. In Microsoft Digital, we play an integral role helping teams to create agents responsibly and effectively.

Security and compliance

Enterprise AI solutions often connect multiple services, models, applications, and data sources. Managing data movement securely becomes critical.

Systems need to operate within clearly defined boundaries. Models, orchestration layers, workflows, application services, and supporting infrastructure need to work together while maintaining compliance, privacy, and security controls.

In this context, it’s helpful to think of Foundry as a collaboration tool. Globally speaking at Microsoft, we work with many different solutions and manage almost everything through partner teams. Enabling Foundry depends on breaking down those silos.

Data integration and retrieval quality

One of the greatest determinants of agent success is data quality.

Enterprise AI solutions depend on retrieval pipelines, search indexes, embeddings, and grounding strategies. As IT partners with agent developers, we help them determine their data needs:

  • How to chunk and index data
  • How to refresh embeddings
  • What retrieval strategies produce the most accurate results
  • How changes to source systems propagate into AI experiences

Poor retrieval design can undermine even the most sophisticated model architecture.

Evaluation and continuous improvement

“Enterprise AI depends on data access and integration,” says Shweta Mallurwar, a senior software engineer in Microsoft Digital. “The technology is powerful, but success ultimately comes from ensuring models have access to trustworthy, well-governed information.”

As solutions become more autonomous, monitoring becomes increasingly important.

Teams need confidence that changes to orchestration frameworks, prompts, models, and workflows improve outcomes rather than introduce new issues. Foundry’s evaluation capabilities support ongoing testing, benchmarking, validation, and governance throughout the agent lifecycle. Microsoft Agent 365 is also a powerful tool for more centralized oversight and management.

MarThrive

Created using Microsoft Foundry

MarThrive is a multi-agent experience our marketing team created to help employees navigate the increasingly complex landscape of internal marketing resources, guidance, and processes.

Before MarThrive, marketers often needed to search across multiple repositories, sites, and tools to find information related to campaigns, content development, branding requirements, planning resources, and internal processes. Valuable information existed across the organization, but discovering and applying it could be time-consuming.

MarThrive brought these resources together through an AI-powered platform featuring 12 agents that help marketers quickly accomplish a variety of tasks. They include exploring our entire corpus of blogs, generating social copy, calibrating our AI-assisted writing abilities, testing quality of written outputs, generating bills of materials (BOMs), and ensuring launch readiness for campaigns.

The solution draws from multiple knowledge sources and surfaces insights through conversational interactions, creating a more streamlined way to navigate Microsoft’s marketing ecosystem and execute against our goals.

Read more about MarThrive.

Microsoft Foundry and other pro-code agent creation tools help developers bring high-value opportunities to life through agentic AI. By following our approach to enablement, management, and governance, you have a solid starting point for unlocking these capabilities in your own organization.

Key takeaways

If you want to consider pro-code development tools for agent creation at your company, here are some things to consider:

  • Ensure Foundry is the right tool. Use Foundry and pro-code tools for scenarios that require advanced customization, model tuning, orchestration, or enterprise-scale architecture.
  • Get data integration right. Build strong retrieval, indexing, and data integration strategies before scaling AI solutions.
  • Lean on expertise. Involve domain experts early to improve solution quality, evaluation practices, and business relevance.
  • Plan for management and governance from the start. Establish governance, monitoring, and evaluation frameworks from the beginning rather than after deployment. This is especially valuable for more complex agents.
  • Apply DevOps principles. Treat enterprise AI initiatives as both technical and organizational projects that require collaboration across teams.

Learn more

How we did it at Microsoft

Further guidance

  • Microsoft Foundry documentation: Get an overview of Foundry capabilities, model catalogs, evaluation tools, orchestration frameworks, and enterprise AI development practices.

Conclusion: Creating pathways for every type of agent builder

As we’ve advanced our Frontier Transformation journey, we’ve learned that successful agent adoption is not about choosing a single tool or creating a single development model. The main goal is to give employees the right pathways to solve problems at the level of complexity their scenarios require.

A photo of Kerametlian

“The future of agentic AI depends on giving people the freedom to create while providing the structure they need to do so responsibly. When organizations establish clear pathways, strong governance, and the right enablement support, they can empower every employee to become a builder and accelerate innovation at scale.”

At Microsoft, we’ve worked to create an ecosystem where every employee can participate in agent creation.

  • Some begin with Agent Builder, creating retrieval agents grounded in trusted organizational knowledge.
  • Others expand into Copilot Studio to automate workflows, connect systems, and support business processes.
  • Professional developers can build sophisticated enterprise solutions with Microsoft Foundry and other pro-code tools.

Each pathway serves a different audience, but they all share the common goal of empowering employees to turn ideas into innovation.

Throughout this guide, we’ve emphasized a principle that has shaped our own approach: Start with the business problem, not the technology, then choose the simplest tool to achieve your goal. When employees focus first on the outcome they’re trying to achieve, they’re in a better position to select the right platform, apply the appropriate level of governance, and create solutions that deliver measurable impact. We’ve found that this approach not only reduces cost but also accelerates adoption and builds confidence as employees move from simple use cases to more advanced scenarios.

Just as importantly, we’ve learned that agent enablement requires more than providing access to tools. Success depends on creating an environment where employees understand when to use each platform, how to build responsibly, and where to find support when they need it. Hands-on learning, strong data governance, clear guidance, and risk-based oversight have all played important roles in helping us scale agent creation while maintaining trust.

As agents become more capable, governance continues to evolve alongside them. Our goal is never to slow innovation. Instead, we’ve focused on creating guardrails that help employees build safely and confidently. Whether someone is creating a personal productivity agent or developing an enterprise-scale solution, the same foundational roadmap applies: Experiment, govern, scale, and optimize. All along, keep business outcomes at the center of the effort.

The AI-native organization of the future isn’t one where IT says yes to everything or no to everything. It’s one where governance is intelligent enough to know the difference and fast enough to act at machine speed.

“The future of agentic AI depends on giving people the freedom to create while providing the structure they need to do so responsibly,” says Stephan Kerametlian, a senior director for Microsoft Digital. “When organizations establish clear pathways, strong governance, and the right enablement support, they can empower every employee to become a builder and accelerate innovation at scale.”

Our experience has shown that there is no single destination in the agent journey. Employees will continue discovering new opportunities to automate work, scale expertise, and solve business challenges.

New capabilities, tools, and methods of building will emerge over time. What matters most is creating a framework that allows employees to begin where they are today and grow as their needs evolve.

As your organization develops its own approach to agent creation, we hope the lessons we’ve learned and shared can help you build a strategy that balances empowerment with oversight, innovation with governance, and experimentation with long-term value. By creating pathways for every type of builder, you can unlock the collective creativity of your workforce and help transform great ideas into lasting business impact.

Key takeaways

Here are some overall points to think about when you are picking the right AI pathway for agent creation at your organization:

  • Start with the business problem, not the tool. Encourage employees to focus on the outcome they want to achieve before selecting a platform. The most successful agent initiatives begin with a clear business need and then apply the simplest technology that can meet it.
  • Match the tool to the builder. Different employees have different needs, skills, and responsibilities. Create clear pathways that help information workers, citizen developers, and professional developers use the right agent-building experience for their scenarios.
  • Use the simplest technology solution that meets the requirement. Help employees start with retrieval and knowledge-based experiences before moving to automation, orchestration, and custom development. Complexity should increase only when the business need demands it.
  • Invest in hands-on learning. Employees learn agent creation by building. Workshops, office hours, real-world examples, and peer-to-peer learning are often more effective than documentation or training videos alone.
  • Build on a foundation of trusted data. High-quality agents depend on accurate, relevant information. Data governance, classification, permissions, and content management all play critical roles in creating useful and reliable agent experiences.
  • Treat governance as an accelerator. Establish guardrails that help employees innovate confidently while protecting organizational data. Governance should enable responsible experimentation rather than creating unnecessary friction.
  • Scale oversight with risk and impact. Personal productivity agents, departmental workflow agents, and enterprise-scale solutions should not be subject to the same level of review. Align governance, compliance, and security requirements to the potential reach and capabilities of each agent.
  • Create a journey, not a destination. Agent adoption is an evolving capability. Give employees opportunities to start small, learn, expand their skills, and move between platforms as their ideas, requirements, and business impact grow.

Try it out

Get started with Microsoft Agent 365 at your company.

Related links