Nobody can just install an agent. And that's the point.
Microsoft now ships agents faster than most tenants can evaluate them. The Agent Store is where your people find them; the Agent Registry in the admin center is where somebody decides whether they get them. If you only learn one piece of Copilot governance this year, learn this pipeline — because the alternative is a tenant full of agents nobody approved.
01 The two halves of the system
There is a front door and a back office, and people confuse them constantly.
- The Agent Store lives inside the Microsoft Copilot app. Your people browse it, find an agent, and add it. It looks exactly like an app store, which is why everyone assumes it behaves like one.
- The Agent Registry lives in the Microsoft 365 admin center. It is the inventory: every agent, who created it, when, which products host it, and whether it is currently available.
The link between them is an approval gate. Microsoft's documentation is blunt about it: before users can access agents, each agent goes through a submission and approval process, and members of your organization can only access the agents you have allowed. Agent management is on by default in every Microsoft Copilot licensed tenant — so this pipeline is already running whether or not anyone in your company has looked at it.
“Who reviews agent requests, and how long is the queue?” If nobody knows the answer, you have found the bottleneck that will make every agent pilot look like a Copilot failure.
02 Five kinds of agent, five different risks
The admin center groups agents into types, and the type tells you how much scrutiny it deserves.
| Type | Where it comes from | What to watch |
|---|---|---|
| Published by your organization | Built in-house, then approved by an admin before anyone else sees it | The approval queue itself — this is the type that stalls |
| Shared by creator | Made in Copilot Studio or Agent Builder and shared directly | Sprawl. These appear in the registry, and blocking is your lever |
| Microsoft agents | Built by Microsoft, wired into M365 services | Licensing and quota, more than trust |
| External partner agents | Third-party developers and vendors | What data they touch; availability and permissions are yours to control |
| Frontier agents | Experimental Microsoft capabilities — App Builder and Workflows are both Frontier | Early-stage behaviour. Microsoft itself says these may need extra oversight or a limited rollout |
Frontier is the category most people have never heard of and the one most likely to surprise them. The Workflows agent, for example, saves the flows it creates into your default Power Platform environment unless environment routing is turned on for Copilot Studio — a detail that decides whether your automation estate stays tidy or turns into a landfill.
03 The exception that catches everyone out
This matters practically. Blocking agents wholesale does not switch off Researcher and Analyst, and approving an agent does not tell you anything about how those two are being used. They are separate controls, and you need both.
04 Where Agent 365 fits
Above all of this sits Microsoft Agent 365, which Microsoft positions as the control plane for AI agents — deploy, govern and manage every agent at scale, regardless of where it was built or bought. The M365 admin center handles agents inside Microsoft 365; Agent 365 is the layer that is supposed to cover the ones that aren't. If you are running more than a handful of agents, that distinction is the difference between an inventory and a guess.
05 Set this up before you pilot anything
The pre-pilot governance checklist
- Name the approver. One person, with a stated turnaround. Agent requests that sit for three weeks kill pilots.
- Open the Agent Registry and read it. Most tenants already have shared agents in there that leadership has never seen.
- Decide your Frontier stance before someone builds a production workflow on an experimental agent.
- Check environment routing for Copilot Studio, so Workflows agent flows don't all land in the default environment.
- Use least-privileged roles. Microsoft is explicit that Global Administrator is highly privileged and should be reserved for emergencies — agent management does not need it.
- Write down the Researcher and Analyst exception so nobody plans around a control that doesn't exist.
Governance sounds like the boring half of an AI programme. It is actually the half that decides whether anything ships. Once this pipeline is named and staffed, the rest of the agent lineup — Channel Agent, Planner Agent, SharePoint agents, the Employee Self-Service agent — stops being a series of one-off arguments.