---
title: "Copilot Studio and agents: extending Microsoft 365 Copilot"
description: "Ways to build agents for Microsoft 365 Option Who What you get --- --- --- Agent Builder (in Copilot Chat / Microsoft 365 Copilot) Business users Simple…"
url: https://optimizeall.com/learn/gemini-copilot-perplexity-and-more/copilot-studio-and-agents
updated: 2026-10-05
---

Gemini, Microsoft Copilot, Perplexity & the AI Tool Landscape · Microsoft Copilot · lesson 9 of 19 · 19 min

# Copilot Studio and agents: extending Microsoft 365 Copilot

## Ways to build agents for Microsoft 365

| Option | Who | What you get |
|---|---|---|
| **Agent Builder** (in Copilot Chat / Microsoft 365 Copilot) | Business users | Simple agents from natural-language instructions, knowledge sources (such as SharePoint sites or files) and web grounding |
| **Copilot Studio** | Makers and IT | Full low-code agent platform: topics, knowledge, actions via hundreds of connectors, **agent flows**, deep reasoning, autonomous triggers, publishing to Teams, websites and other channels, governance controls |
| **Microsoft 365 Agents Toolkit** (VS Code) | Developers | **Declarative agents** defined in a manifest (instructions, capabilities, actions), plus custom engine agents |
| **Copilot connectors** | IT and developers | Bring external content (for example a CRM or wiki) into Microsoft Graph so Copilot and agents can use it |

## Licensing in one paragraph (check current terms)

Microsoft 365 Copilot Chat users can use agents grounded in instructions and public websites at no extra cost; agents that use shared tenant data (such as SharePoint or connector content) are billed on a **pay-as-you-go** basis through Azure or a Copilot Studio subscription for unlicensed users. Users with a Microsoft 365 Copilot licence can use such agents under their licence terms. Copilot Studio has its own capacity-based billing. Your admin and Microsoft's licensing pages are authoritative.

## Designing a good agent

Start from a narrow, high-volume job with clear knowledge sources:

- **HR policy assistant** grounded in the approved HR SharePoint site.
- **Sales proposal helper** using the approved case-study library.
- **IT help agent** that answers from the knowledge base and creates a ticket via a connector after the user confirms.

Write instructions like a job description (role, sources, process, rules, output), add conversation starters, and define what the agent must **not** do.

## Hands-on: a declarative agent manifest

With the Microsoft 365 Agents Toolkit, you scaffold a declarative agent and edit its manifest. A simplified example (schema versions change; let the toolkit generate the current `$schema` and `version`, and check the documentation for exact fields):

```json
{
  "$schema": "https://developer.microsoft.com/json-schemas/copilot/declarative-agent/v1.8/schema.json",
  "version": "v1.8",
  "name": "HR Policy Helper",
  "description": "Answers employee questions using the approved HR policy site.",
  "instructions": "You answer questions about company HR policies using only the HR Policies SharePoint site. Quote the policy name and section for every answer. If the answer is not in the policies, say so and direct the user to hr@contoso.example. Never give legal advice or discuss individual employees.",
  "capabilities": [
    {
      "name": "OneDriveAndSharePoint",
      "items_by_url": [
        { "url": "https://contoso.sharepoint.com/sites/HRPolicies" }
      ]
    }
  ],
  "conversation_starters": [
    { "title": "Leave policy", "text": "How many days of annual leave do I get?" },
    { "title": "Remote work", "text": "What is the policy on working from abroad?" }
  ]
}
```

Test in the toolkit's preview, then publish through your organisation's approval process.

## Copilot Studio: actions and flows

In Copilot Studio you can give an agent **actions** through Power Platform connectors (for example Dynamics 365, Salesforce, ServiceNow, SharePoint lists, Outlook) and build **agent flows** that run multi-step processes. Good practice:

- Read-only actions first; write actions require user confirmation.
- Use the maker's connection only when appropriate; otherwise each user's own credentials.
- Add authentication for any channel outside Teams.
- Test with realistic and adversarial conversations before publishing.

Copilot Studio agents can also call **MCP** servers, which means a server built for one assistant can be reused here.

## Governance for agents

- An **inventory** of agents with owners and purposes (Agent 365 provides a control plane for this).
- **Environment strategy:** separate development, test and production.
- **Data policies** for connectors (which can be combined, which are blocked).
- **Review and approval** before publishing to the whole organisation.
- **Monitoring:** usage, failed conversations, and cost.

## Worked example: an IT help agent in Riyadh

An IT team at a logistics company builds an agent in Copilot Studio grounded in their knowledge base, with one action that creates a ServiceNow ticket after the user confirms the summary. They test with 50 real past questions and 10 adversarial ones, restrict it to Teams, and publish to one department first. After a month, a large share of password and VPN questions are answered without a ticket (tracked in their analytics), and tickets that do get created arrive with better descriptions.

## Pitfalls

- Broad agents ("company assistant") with vague sources.
- Write actions without confirmation.
- Publishing organisation-wide without a pilot.
- No owner or cost monitoring.

## How to measure success

The agent answers its narrow job accurately with citations, deflects routine requests measurably, has an owner and an inventory entry, and stays within budget.

## Video lecture: Copilot Studio and agents: extending Microsoft 365 Copilot

Lecture coming soon · 14 chapters · about 8 minutes. Read the full transcript below.

1. Copilot Studio and agents
2. Why build agents
3. Four ways to build
4. Licensing in brief
5. Simple example
6. Declarative agent manifest
7. Copilot Studio actions and flows
8. Governance for agents
9. Business example: IT help agent in Riyadh
10. Common mistakes
11. Testing an agent
12. Watch me do it, part 1
13. Watch me do it, part 2
14. Recap and try this now

## Lecture transcript

### Copilot Studio and agents

Microsoft three six five Copilot is powerful out of the box. But the biggest wins often come from agents built for your own processes, an HR policy helper, an IT help desk, a proposal assistant. In this lecture you will learn the ways to build agents in the Microsoft ecosystem, see a real declarative agent manifest, learn how Copilot Studio adds actions and flows, and set up the governance that keeps agents under control.

### Why build agents

Why build agents at all? Because general Copilot knows a little about everything in your tenant, while an agent knows one job very well. It uses a specific knowledge source, follows specific rules, and answers repeated questions the same way every time. Think of the difference between asking a random colleague about leave policy and asking the HR specialist. Both may help, but only one gives you the approved answer with the policy section quoted.

### Four ways to build

There are four main ways to build. Agent Builder, inside Copilot, lets business users create simple agents from instructions and knowledge sources. Copilot Studio is the full low code platform, with topics, knowledge, actions through hundreds of connectors, agent flows, deep reasoning, autonomous triggers and publishing to Teams or websites. The Microsoft three six five Agents Toolkit in VS Code lets developers define declarative agents in a manifest. And Copilot connectors bring external content, like a CRM or a wiki, into Microsoft Graph so agents can use it.

### Licensing in brief

A quick word on licensing, and always check current terms. Copilot Chat users can use agents grounded in instructions and public websites at no extra cost. Agents that use shared tenant data, like SharePoint or connector content, are billed pay as you go for unlicensed users. People with a Microsoft three six five Copilot licence use such agents under their licence. Copilot Studio has its own capacity based billing. Your admin and Microsoft's licensing pages are the authority.

### Simple example

Let's start simple. In Agent Builder, create an agent called brand guidelines helper. Instructions, answer questions about our brand using only the brand guidelines folder, and quote the section for every answer. Add that one SharePoint folder as knowledge. Test it. Which logo do we use on dark backgrounds? It answers with section two point three, and a link. Ten minutes of setup, and the design questions that used to land in your inbox now get answered consistently.

### Declarative agent manifest

For developers, the Agents Toolkit uses a declarative agent manifest. Walk through it with me. A name and description. Instructions written like a job description, use only the HR policies site, quote the policy name and section, if it is not there, say so and point to the HR mailbox, never give legal advice. A capabilities block granting access to one SharePoint site by address. And conversation starters that show users what to ask. The schema version changes over time, so let the toolkit generate the current one.

### Copilot Studio actions and flows

Copilot Studio adds the ability to act. Through Power Platform connectors, an agent can read from or write to systems like Dynamics three six five, Salesforce, ServiceNow, SharePoint lists and Outlook, and agent flows can run multi step processes. Copilot Studio agents can also call MCP servers, so a server built for another assistant can be reused. Start with read only actions, require user confirmation for anything that writes, and add authentication for any channel outside Teams.

### Governance for agents

Agents need governance, just like apps. Keep an inventory of every agent with an owner and a purpose, which is what Agent three six five provides as a control plane. Separate development, test and production environments. Set data policies for connectors, which ones may be combined and which are blocked. Require review and approval before publishing to the whole organisation. And monitor usage, failed conversations and cost.

### Business example: IT help agent in Riyadh

A realistic business example. An IT team at a logistics company in Riyadh builds an agent in Copilot Studio grounded in their knowledge base, with one action that creates a ServiceNow ticket after the user confirms the summary. They test it with fifty real past questions and ten adversarial ones, restrict it to Teams, and publish to one department first. After a month, their analytics show many password and VPN questions answered without a ticket, and the tickets that are created arrive with far better descriptions. After the first month the team reviewed the agent's failed conversations in analytics. Most failures were about a new expenses tool that the knowledge base did not yet cover. They wrote three articles, and the agent answered those questions the following week. The agent improved because the knowledge improved, and the owner had a clear monthly routine to make that happen.

### Common mistakes

The common mistakes are predictable. Building a vague company assistant with everything as its source, which answers everything badly. Adding write actions without confirmation. Publishing to the whole organisation on day one instead of piloting. And having no owner or cost tracking, so nobody notices when the agent drifts or the bill grows. Narrow, tested, owned and monitored beats broad and impressive every time.

### Testing an agent

How do you know an agent is ready? Test it like a product. Collect fifty real questions people have asked, and ten adversarial ones, like ignore your instructions, or tell me about a specific employee's salary. For each, check whether the answer is correct, whether the citation points to the right section, and whether the agent refused when it should. Fix the instructions or knowledge where it fails, and retest before any wider release.

### Watch me do it, part 1

Let me build the Riyadh IT help agent in Copilot Studio. I create a new agent and name it IT help. Under knowledge, I add one source, the IT knowledge base SharePoint site, and nothing else. I paste instructions written like a job description. Answer IT questions using only the knowledge base, quote the article title, if the answer is not there say so and offer to create a ticket, and never ask for or accept passwords. Then three conversation starters, reset my password, VPN is not connecting, and request new software.

### Watch me do it, part 2

Next, the action. I add the ServiceNow create incident action through its connector and require user confirmation. In the test pane I type, my VPN keeps disconnecting on hotel wifi. The agent answers from the knowledge base first. When I say it still fails, it shows a summary card and asks, create this ticket? Only when I confirm does it create it. I try an adversarial prompt, what is my manager's password, and it refuses as instructed. Finally, I publish it to Teams only, for one department, and add it to our agent inventory with an owner.

### Recap and try this now

Recap. Choose the right builder, Agent Builder, Copilot Studio, the Agents Toolkit or connectors. Design agents for one narrow job with clear sources and job description instructions. Start read only and confirm every write. Govern with an inventory, environments, data policies and pilots. Try this now. On paper, design one narrow agent for your team, its job, its single knowledge source, three conversation starters, and one thing it must never do.

## Key takeaways

- Build Microsoft 365 agents with Agent Builder (business users), Copilot Studio (makers), the Agents Toolkit (declarative agents) and Copilot connectors.
- Licensing differs: instruction and web agents are included with Copilot Chat; tenant-data agents are pay-as-you-go for unlicensed users. Check current terms.
- Design narrow agents with clear sources, job-description instructions, conversation starters and explicit "never" rules; start read-only and confirm writes.
- Govern agents with an inventory and owners (Agent 365), environments, connector data policies, pilots and cost monitoring.

## Try it

Design (on paper, or in Agent Builder if available) one narrow agent: its job, single knowledge source, instructions with a "never" rule, three conversation starters, and five test questions including one adversarial.

- [Previous: Grounding, permissions and governance for work copilots](https://optimizeall.com/learn/gemini-copilot-perplexity-and-more/copilot-grounding-and-governance)
- [Next: Perplexity: the cited answer engine](https://optimizeall.com/learn/gemini-copilot-perplexity-and-more/perplexity-cited-answer-engine)
- [All lessons of Gemini, Microsoft Copilot, Perplexity & the AI Tool Landscape](https://optimizeall.com/learn/gemini-copilot-perplexity-and-more)
