Microsoft 365 Copilot tasks you can try in Outlook

Reading Time: 11 minutes


Email is still one of the tools many of us use every day, and it’s also one of the areas where Microsoft 365 Copilot can save a significant amount of time. From drafting emails and replying more effectively to summarising long threads or adjusting tone, Copilot can help with a wide range of everyday email tasks.

In this blog post, I’ll be sharing a collection of practical Copilot prompts you can try yourself to see how Copilot can support the way you work with email.

Important:

Most of the examples in this post require a Microsoft 365 Copilot license. Some of the features demonstrated may not yet be available in your environment. Microsoft 365 Copilot features are rolled out gradually, so availability can vary depending on your tenant, region, and release cycle. Additionally, the experience may differ depending on the version of Outlook you are using (for example, classic Outlook vs the new Outlook), and the platform (desktop, web, or mobile). To ensure the best experience, make sure you are using the latest version of Outlook and that Copilot is enabled in your organisation.

Let’s get started


Task 1: Summarise an email conversation

  1. Launch Microsoft Outlook
  2. Select the Copilot icon in the top‑right corner
  3. Select the Work tab
    – The Work tab allows Copilot to use your Microsoft 365 organisational data (such as emails, meetings, and files) to provide more relevant responses.
    – The Work tab will automatically appear if your organisation has assigned you a Microsoft 365 Copilot licence.
  4. Enter a prompt (Example below):

    Summarise the email conversation about the Microsoft 365 Copilot Adoption – Project Kick off project. List the team members involved and highlight any outstanding actions I need to be aware of in table format.

CopilotOutlook1


Task 2: Find out when you last had a meeting with a colleague


Prompt:

When did I last have a meeting with my colleague Andrew Doe?

  • You could also press the / (forward slash) key on your keyboard and start typing your colleague’s name.
CopilotOutlook2


Task 3: Ask Copilot to check when you and your colleague are next available for a meeting


Prompt:
When is Andrew Doe available for a Teams call in the week commencing 18 May? Please suggest suitable 30‑minute slots that work for both of us.

CopilotOutlook3



Task 4: Ask Copilot in Outlook to draft you an email


Prompt:

Draft a polite follow‑up email to Darren O’Malley suggesting one of the available 30‑minute Teams meeting slots for the week commencing 18 May. Insert this into a new email

CopilotOutlook4


Note: Click the edit and Send button and check your drafts folder in Outlook for the email. Review and send.

CopilotOutlook5


Did you notice?


My email started with:

Hi,
Hope you’re doing well 🙂

and ended with:

Thanks,
Imran

This is because I’ve asked Copilot to always start and end my emails using this format through Copilot Instructions.

To do this:

  • Select the three dots (⋯) as shown in the image below.
CopilotOutlook6

  • Select Settings.
CopilotOutlook7


  • Select Personalisation, and then Custom instructions.
CopilotOutlook8


Task 5: Rewrite an email to adjust the tone

  1. Open the draft email
  2. Select the Copilot icon in the top-right corner

    Example prompts:
    – Rewrite this email to sound more friendly and conversational.
    – Make this email more concise without losing the key message.
    – Rewrite this email to better match Andrew Doe’s communication style.
  3. The email is changed directly inside the draft email as shown in the image below. You can go back to the previous draft if needed. When you’re happy with the final version of the email, click Replace.
CopilotOutlook9

It is also possible to make changes to the email by clicking on the copilot pencil icon as shown in the images below

CopilotOutlook10
CopilotOutlook11
CopilotOutlook12

Task 6: Summarise an email directly from the message

  1. Open an email or email thread in Microsoft Outlook.
  2. Select Summary by Copilot at the top of the email.
  3. Review the summary, which highlights the key points and any actions for that specific email thread.
CopilotOutlook13

Task 7: Ask Copilot to generate a reply to an email



Prompt:
Chase Andrew for an update on the draft proposal. Remind him that the draft proposal is due this Friday.

CopilotOutlook14

Task 8: Ask Copilot to schedule a follow-up reminder


Prompt:
Schedule a follow-up reminder for me if there’s no response by Friday 1pm GMT+1

Switch to Allow Actions

CopilotOutlook16
CopilotOutlook15

Note: You need to be part of the Frontier program to get early access to new Microsoft 365 Copilot default experience in Outlook. Frontier connects you directly with Microsoft’s latest AI innovations. Frontier previews are subject to the existing preview terms of your customer agreements. As these features are still in development, their availability and capabilities may change over time.


Task 9: Ask Copilot to help you catch up on unread emails


Prompt:
Summarise my unread emails and draft suggested replies for the ones that require my action, so I can review them before sending.


Task 10: Turn emails into a clear list of actions


Prompt:
Review my recent emails and create a concise list of actions I need to complete, including who the action is for and any suggested deadlines.


Task 11: Prioritise emails that need your attention


Prompt:
Review my emails and highlight the most important messages I should focus on first.


Task 12: Catch up on emails after time away


Prompt:
I’ve been away from work. Summarise what I’ve missed in my inbox over the last 5 days and highlight any messages that require my attention or action.


Task 13: Check emails which need urgent replies


Prompt:
What emails need urgent replies? List in a table format.


Task 14: Prepare for an upcoming meeting using email context


Prompt:
Review my recent email and Teams conversations with Andrew Doe and summarise any relevant context, key discussion points, and questions I should be prepared to discuss in my upcoming meeting.


Task 15: Schedule a meeting directly from an email


Steps:

  1. Open an email in Microsoft Outlook that contains a discussion which would benefit from a meeting.
  2. In the email ribbon, select Schedule with Copilot.
Copilot outlook

3. Review the meeting details Copilot suggests, such as:

  • Attendees
  • Suggested time
  • A draft agenda generated from the email content

4. Make any changes if needed, then send the meeting invitation.


Task 16: Ask Copilot to create an Outlook rule using natural language


Prompt
Create an Outlook rule that moves newsletters and automated updates into a separate folder called newsletters so I can keep my inbox focused on emails that need my attention.

CopilotOutlook18

Task 17: Summarise email attachments without opening them


Open an email in Microsoft Outlook that contains an attachment (for example, a Word, PowerPoint, or PDF file). Select Summary by Copilot for the attachment (shown in the reading pane). Review the AI‑generated summary to quickly understand the contents without opening the file.

CopilotOutlook19

Task 18: Catch up on emails using Copilot voice (audio summary)


Microsoft documents Copilot Voice as a way to listen to and talk to Copilot while on the move, including catching up on email and calendar content hands‑free. Ask Copilot when your next meeting with your manager is via voice.

CopilotOutlook20

Check out a short demo at: Copilot Voice Demo


Task 19: Understand why an email is important


Prompt:

Explain why this email has been marked as important and whether it requires my action.


Task 20: Compare different email drafts before sending


Prompt:
Create two alternative drafts of this email:
one that is more concise and direct, and another that is more friendly and conversational.


Task 21: Set up custom draft instructions for Copilot


Instruct Copilot to always respond in a way that matches your preferred style. For example, you could ask it to always start your emails with: “Hi, I hope you’re doing well.”

  • Select the three dots (⋯) as shown in the image below.
CopilotOutlook6

  • Select Settings.
CopilotOutlook7

  • Select Personalisation, and then Custom instructions.
CopilotOutlook8



Task 22: Create an executive summary across related emails


Prompt:

Review my email conversations from the last 14 days related to the Copilot Adoption project and create a one‑page executive summary covering key updates, decisions made, open questions, and next steps.


Task 23: Create an email based on a financial income statement in a Word document


Using /Income Statement Q1 FY26.docx, draft a clear, professional email summarising the key financial results for senior stakeholders.


Task 24: Create an FAQ from an email conversation


Prompt:
Review this email thread and create an FAQ that includes:

  • the most common questions raised
  • clear, concise answers based on what was agreed
  • any open questions that still need confirmation

Write it so it can be shared with people who were not part of the original email conversation.


Task 25: Adapt one email for different audiences


Prompt:

Rewrite this email in three versions:

  1. for senior leadership (high‑level, concise)
  2. for a non‑technical audience (plain English)
  3. for the project team (more detail and context)

Keep the core message consistent. I will review and decide which version to send.


Task 26: Get a critical review of an email before sending


Prompt

Review this email and act as a critical stakeholder.

  • What assumptions am I making?
  • What questions might the recipient push back on?
  • What risks, ambiguities, or misunderstandings could this message create?

Do not rewrite the email. I want feedback only.


Task 27: Identify missing information in an email


Prompt

Review this email and tell me:

  • what important information might be missing
  • what assumptions the recipient would need to make
  • what follow‑up questions the recipient is likely to ask

Do not rewrite the email. I want feedback only.


Task 28: Get started with Copilot Cowork (Frontier preview)


What is the Microsoft 365 Frontier programme?

The Microsoft 365 Frontier programme provides early access to Copilot features that are still in development. It allows organisations to safely trial, evaluate, and provide feedback on upcoming AI capabilities before they reach general availability. Because these features are in preview, behaviour and availability may change over time, and some capabilities may be limited to specific tenants or regions.

What is Copilot Cowork?
Copilot Cowork is an agentic Copilot experience designed for long‑running, multi‑step work across Microsoft 365. Copilot Cowork is powered by Anthropic’s Claude model, which enables more advanced reasoning, planning, and the ability to manage multiple tasks in parallel, while keeping the human in control through explicit approvals.

Unlike standard Copilot prompts (which respond and stop), Cowork:

  • creates a plan
  • carries work forward over time
  • coordinates tasks across apps
  • can pause for your explicit approval before taking actions

Microsoft describes Cowork as moving Copilot from assistant to collaborator, while still keeping the human in control.

What can Copilot Cowork do?

Cowork can:

  • Draft, reply to and send emails (with approval)
  • Schedule and manage meetings
  • Create and edit files across Word, Excel, and PowerPoint
  • Post updates in Teams
  • Coordinate multi‑step workflows (for example: monthly reporting or executive briefings)
  • Track progress and show each step as it works

All actions are visible, reviewable, and require user approval before execution.

Step‑by‑step: Accessing Copilot Cowork

  1. Open the Microsoft 365 Copilot app.
  2. Go to the Agent Store.
  3. Find Copilot Cowork and install it.
  4. Pin Cowork to the left‑hand navigation.
  5. Open Cowork to start a new task.

Note: The prompts below are intentionally detailed to show what Cowork can handle. You don’t need to be this specific when you start. Cowork will ask follow‑up questions if needed.


Prompt 1:

Help me organise my inbox. Please review my email from Outlook.

First, review my inbox from the last 24 hours and show me a summary:

  • Total number of emails and a rough breakdown
  • Any emails from my manager or my management chain
  • Any urgent emails – look at the subject, contents, and if it is marked as high importance

Let’s do a basic triage of each email. Ask me before making any changes.

  • If spam, let’s delete the email.
  • If not important to me, like a broad email update, let’s provide a synopsis and archive it.
  • If a meeting invite, let’s accept, decline, or mark as tentative.
  • If requiring a reply, let’s draft a reply and save it as a draft.
  • If urgent, let’s draft a reply together. Let’s even SEND the reply!

Start with the easiest changes first. Once I approve each change, take the action directly in my inbox one at a time.

After we complete the last 24 hours, let’s offer to review the last few days (or weeks) of emails.

Prompt 2:

Help me organise my week. Please review my Outlook calendar.

First, review my calendar and show me a summary:

  • Total meetings and hours spent in meetings
  • Where I have focus time (e.g. 2+ hours)
  • Days with the most meetings

Before making any changes, ask clarifying questions and look up information. For example:

  • My manager and management chain – note if they are on a meeting
  • How many attendees are included on the meetings, and if they would be easy to move
  • What I’m trying to accomplish this week
  • How should I prioritise meeting conflicts based on attendees or topics
  • Any commitments not on my calendar, like personal events in the evening
  • Which types of meetings I should decline or shorten
  • Personal commitments or boundaries I want to protect

Then show me a few proposed changes with explanations:

  • Meetings to accept (if not already), decline, or reschedule
  • Meeting conflicts to resolve, including emailing the organisers
  • Focus blocks to add to ensure I can get work done

Start with the highest-impact changes first. Once I approve each change, make the edits directly in my calendar one at a time.

Prompt 3:
Help me prepare for an upcoming meeting. Please review my Outlook calendar, emails, and Teams messages.

First, find my next meeting (or ask me which one) and show me:

  • Meeting title, time, duration, and location (or virtual link)
  • Who organised it and the full attendee list
  • Any agenda, attachments, or notes included in the invite
  • Whether I’ve accepted, declined, or not yet responded

Then gather context by reviewing:

  • Recent email threads and Teams messages with the attendees related to the meeting topic
  • Any documents or files shared in those threads
  • Notes or outcomes from the last meeting with the same group, if one exists
  • Open action items assigned to me from previous discussions

Ask me a few questions before drafting my prep:

  • What’s my role in this meeting – am I presenting, contributing, or just listening
  • Are there specific topics I want to raise or decisions I need
  • Any concerns or blockers I should flag
  • Do I need to prepare any materials (slides, data, demos)

Then create a meeting prep summary:

  • Background context – a brief recap of what led to this meeting
  • Key attendees and what they care about
  • My talking points, ordered by priority
  • Questions I should be ready to answer
  • Questions I want to ask
  • Any materials or documents I should have open during the meeting

Share the prep summary in the chat. Offer to save it as a document, or send it to myself via email so I can review it before the meeting.


Note: The prompts (Cowork) above are intentionally detailed to show what Cowork can handle. You don’t need to be this specific when you start. Cowork will ask follow‑up questions if needed.


I hope you found this post useful. Thank you for tuning in.

Practical Microsoft 365 Copilot Tasks You Can Try in Excel

Reading Time: 8 minutes


In this blog post, I share a number of practical Microsoft 365 Copilot tasks in Excel that focus on real, everyday data analysis and reporting scenarios.

These examples demonstrate how Copilot can help with understanding data, creating formulas, and uncovering insights. While this post includes a selection of tasks, they are intended to get you thinking. Copilot in Excel can support many more scenarios, especially when working with larger or more complex datasets.

My goal is to provide ideas and practical prompts that you can try yourself and build upon as you explore further.

Note: A Microsoft 365 Copilot license is required to use Copilot in Excel.

Let’s get started.

Task 1: Explore what the dataset contains


Prompt:
summarise what the dataset contains in bullet point format

Excel Copilot


Result

Excel Copilot


Task 2: Identify missing values


Prompt:
Highlight missing values in red

Excel Copilot


Task 3: Calculate and populate empty fields


Prompt
Calculate and populate any empty fields with the correct values

Result: Cells F14, F15, F16 and F17 populated

Excel Copilot


Task 4: Replace all names with new demo names


In this task, I will use Copilot to replace the existing names in the dataset with new demo names.

Prompt:
Replace all existing demo names with new, unique names in every row, ensuring each includes a first name and surname.

Excel Copilot


Task 5: Change the date format


Prompt:
Change the date format to MM/DD/YEAR format and remove the time

Excel Copilot


Task 6: Extract surname and add to a new column


Prompt:
Add a new column named “Surname” after the “Full Name” column by extracting the surname from “Full Name”. Rename the “Full Name” column to “First Name”

Excel Copilot


Task 7: Explain the Total Sales calculation


Prompt:
Explain the formula used to calculate Total Sales

Excel Copilot


Task 8: Identify the top 5 highest‑value orders


Prompt:
Show top 5 highest value orders

Excel Copilot


Task 9: Identify low‑performing products or regions


Prompt:
Find low‑performing products or regions

Excel Copilot


Task 10: Review sales trends with a line chart


Prompt:
Create a line chart showing sales over time. Insert into a new sheet

Excel Copilot


Task 11: Visualise sales by product with a bar chart


Prompt:
Build a bar chart of sales by product. Insert into a new sheet

Excel Copilot


Task 12: Highlight top‑performing orders using conditional formatting


Prompt:
Highlight the top 5 performing orders in green

Excel Copilot


Task 13: Analyse summer sales performance


Prompt 1:
How did we perform over the summer?

Copilot requests for additional information as shown in the image below:

Excel Copilot


I respond as shown in the image below, and Copilot in Excel then completes my request.

Response from me: 1 and 1

Excel Copilot


Prompt 2:
Add this information to a new sheet

Excel Copilot

Task 14: Compare sales performance across regions


Prompt:
Compare sales by region

Excel Copilot


Task 15: Insert a row to calculate total sales


Prompt:
Add a row calculating total sales only

Excel Copilot


Task 16: Create an email summarising sales performance


Prompt:
Draft a professional email providing a simple summary that I will send to my colleague Andrew Doe summarising all sales, lows and highs.

Excel Copilot


Task 17: Work out the average order value


Prompt:
Calculate average order value

Excel Copilot


Task 18: Filter sales for a specific region


Prompts:
Filter sales for from the UK only

Excel Copilot


Task 19: Add a VAT (20%) calculation column


Prompt:
Calculate and add a column for VAT (20%) after the total sales column

Excel Copilot


Task 20: Generate a sales dashboard


Prompt:
Create me a dashboard, surprise me

Excel Copilot


Task 21: Sort names alphabetically


Prompt:
Sort the first name field in alphabetical order

Excel Copilot


Task 22: Protect customer identity in the dataset


Prompt:
Anonymise customer names

Excel Copilot


Task 23: Generate 10 additional rows of demo data


Prompt:
Add another 10 lines of demo data

Excel Copilot


Task 24: Analyse customer sentiment


Prompt:
Analyse customer reviews and label each review as positive, negative, or neutral.

Excel Copilot


Result

Excel Copilot



Task 25: Extract information from a Word document and create an Excel table


Prompt:
Extract the information from the following word document and create a nice table / attach filename

Excel Copilot


Result:

Excel Copilot


Task 26: Identify the main trends in the data


Prompt:
What are the main trends in this data?

Excel Copilot


Task 27: Identify date formatting issues and data inconsistencies


Prompt:
Check for date formatting and data inconsistencies

Excel Copilot
Excel Copilot


Task 28: Summarise the data in another language


Prompt:
Summarise the data in 2 paragraphs in the french language

Excel Copilot


Task 29: Translate the spreadsheet content into another language


Prompt:
Change the language in the spreadsheet to German

Excel Copilot


Task 30: Verify the Total Sales values and correct any errors


Prompt:
Check whether all Total Sales values are correct and fix any errors.

Excel Copilot


Task 31: Add a column for initials based on customer names


Prompt:
Create a new column after Column C containing initials based on the names in this table.

Excel Copilot


Task 32: Capitalise the first name


Prompt:
Capitalise the first name

Excel Copilot


Task 33: Create a PivotTable to summarise sales by region and product


Prompt:
Build a PivotTable summarising Total Sales by region and product.

Excel Copilot


Task 34: Clear any conditional formatting rules


Prompt:
Remove conditional formatting

Excel Copilot


Task 35: Identify trends, anomalies, or outliers in the data


Prompt:
What trends, anomalies, or outliers do you see in this data? Add to a new sheet

Excel Copilot


Task 36: Create a 12‑month revenue forecast


Prompt:
Forecast revenue for all areas of the business for the next 1 year. Use the year-over-year growth rate from the annual totals to project monthly figures. Add this to a new sheet

Excel Copilot


Task 37: Assess the impact of a 10% cost increase on profit


Prompt:
What happens to profit if all costs increase by 10%? Add this to a new sheet

Excel Copilot


Task 38: Detect duplicate records in the dataset


Prompt:
Identify any duplicate records in this dataset and highlight them in purple

Excel Copilot


Task 39: Analyse the drivers behind changes in sales performance


Prompt:
Explain the key factors contributing to changes in sales performance over time

Excel Copilot


Task 40: Recommend actions to improve sales performance


Prompt:
Based on this data, suggest three actions to improve sales performance.

Excel Copilot


Task 41: Model how price increases impact revenue


Prompt:
Create a what‑if scenario showing how revenue changes if prices increase by 5%, 10%, and 15%. Add to a new sheet

Excel Copilot


Task 42: Identify which variables drive total sales


Prompt:
Which variables have the biggest impact on total sales? Show this clearly

Excel Copilot


Task 43: Improve and standardise column headers


Prompt:
Rename the column headers to make them clearer and more business‑friendly

Excel Copilot


Task 44: Identify the best visualisation for the data


Prompt:
Suggest the most appropriate visualisation for this data and explain why

Excel Copilot


Task 45: Generate a one‑page summary for senior stakeholders


Prompt:
Create a one‑page executive summary of all data for senior stakeholders.

Excel Copilot


Task 46: Tailor the summary for a beginner audience


Prompt:
Summarise this so a beginner who is new to finance can understand the data

Excel Copilot

That’s it. I hope you find these Copilot in Excel tasks useful.

If you have other examples or use cases for Microsoft 365 Copilot in Excel, feel free to share them in the comments below.





Extending Microsoft 365 Copilot with Microsoft Copilot Studio

Reading Time: 31 minutes


In this blog post, I’ll explore why and how to extend Microsoft 365 Copilot with Microsoft Copilot Studio using declarative agents.

Microsoft 365 Copilot is already a powerful AI assistant that uses large language models (LLMs) and integrates with your data in the Microsoft Graph and Microsoft 365 apps and services. It’s designed to help users stay productive across the familiar Microsoft 365 experiences they use every day. However, out of the box, Microsoft 365 Copilot is designed to support a broad range of scenarios. Rather than being a single, standalone experience, it appears across multiple Microsoft 365 surfaces. You can access Microsoft 365 Copilot through several entry points, including:

  • Copilot in Loop
  • Microsoft 365 Copilot Chat – a central place where users can ask questions and reason over information across their organisation. Copilot Chat is grounded in Microsoft Graph and only has access to the data that the signed‑in user already has permission to access. Under the hood, Copilot uses an intelligence layer (often referred to as Work IQ) to understand context, relationships, and work patterns across your organisation, enabling more relevant and personalised responses.
  • Copilot in Outlook
  • Copilot in Teams
  • Copilot in Word
  • Copilot in PowerPoint
  • Copilot in Excel
  • Copilot in Whiteboard
  • Copilot in OneNote

Using Microsoft 365 Copilot, organisations benefit from integration with their Microsoft 365 data, such as, SharePoint, email, OneDrive, Word files and more.

Microsoft 365 Copilot isn’t a single, standalone app; rather, it’s a collection of intelligent capabilities built directly into Microsoft 365 applications. These capabilities are powered by Microsoft Graph, an orchestration service, large language models (LLMs), and Work IQ, all working together to deliver context-aware assistance.

Microsoft Graph and Work IQ: How Copilot understands your work

Microsoft Graph is the foundation that gives Microsoft 365 Copilot access to your organisation’s data. It securely connects information from across Microsoft 365, such as emails, files, meetings, chats, and calendars. It understands how this information relates to people, teams, and projects. This allows Copilot to find the right information at the right time, while always respecting your existing permissions and security controls.

Work IQ builds on top of Microsoft Graph and focuses on understanding how work actually happens. Instead of treating emails, documents, meetings, and chats as separate items, Work IQ looks at patterns across your daily work, such as, who you collaborate with, what you’re working on, and how information flows through the organisation. Over time, this creates a shared work memory that helps Copilot provide more relevant, personalised responses without you needing to explain context every time.

Together, Microsoft Graph and Work IQ allow Copilot to move beyond simple search. Copilot can understand intent, not just keywords. For example, if you ask about “project delivery status,” Copilot can surface a document titled “Team Milestone Update” even if the wording doesn’t exactly match. If a manager asks for “team updates”, Copilot can understand who the people in the team are and pull together the most relevant recent activity.

The result is an experience where Copilot feels aware of your role, your work, and your organisation, delivering answers and suggestions that are grounded in real data, meaningful context, and the way you actually work.

The below diagram demonstrates how Copilot works under the hood.


As shown in the diagram above, Microsoft 365 Copilot has access to Microsoft 365 data through Microsoft Graph. This includes content such as emails, files, meetings, chats, and calendar data that users already have permission to access. However, many organisations rely on business-critical data that lives outside Microsoft 365. This raises an important question: how can Copilot work with third‑party systems such as Jira, ServiceNow, and other applications used daily across the organisation? In the remainder of this blog post, we’ll explore the options available for extending Microsoft 365 Copilot so it can incorporate and reason over both Microsoft 365 data and third‑party data.

As organisations look to apply Copilot to specific business processes, domains, or knowledge areas, the ability to extend and tailor Copilot becomes essential. One of the primary ways Microsoft enables this is through declarative agents. Before we continue, it’s important to first understand what declarative agents are and the role they play in extending Microsoft 365 Copilot.


What are Declarative Agents?

Declarative agents, also known as Copilot agents, extend the capabilities of Microsoft 365 Copilot. These agents use the same orchestrator and models as Microsoft 365 Copilot. By reusing the existing infrastructure and controls, they provide a consistent experience for end users, as shown in the image above, but are scoped to specific business needs or scenarios.

These agents act as subject matter experts by using defined instructions, knowledge, and actions, while still running inside the familiar Microsoft 365 Copilot chat experience. This allows users to interact through the same Copilot interface.

If you require custom orchestration or the use of a different large language model, a declarative agent isn’t suitable; in that case, you should consider building a custom agent instead.

Declarative agents work best when the information relevant to your scenario is already available within Microsoft 365. If you need to ingest data from an external system into Microsoft 365, you can use a Copilot connector. If you need to interact with external systems in real time, you can expose those systems through custom actions; however, the agent will still rely on Microsoft 365 Copilot’s built‑in orchestration.

Do I really need to create an agent?

Declarative agents, also known as Copilot agents, extend the capabilities of Microsoft 365 Copilot. These agents use the same orchestrator and models as Microsoft 365 Copilot. By reusing the existing infrastructure and controls, they provide a consistent experience for end users, as shown in the image above, while being scoped to specific business needs or scenarios.

These agents act as subject‑matter experts by using defined instructions, knowledge, and actions, while still running inside the familiar Microsoft 365 Copilot chat experience. This allows users to interact with them through the same Copilot interface.

If you require custom orchestration or the use of a different large language model, a declarative agent isn’t suitable; in that case, you should consider building a custom agent instead.

Declarative agents work best when the information relevant to your scenario is already available within Microsoft 365. If you need to ingest data from an external system into Microsoft 365, you can use a Copilot connector. If you need to interact with external systems in real time, you can expose those systems through custom actions; however, the agent will still rely on Microsoft 365 Copilot’s built‑in orchestration.

To understand this in more detail, it’s helpful to look at the two types of Copilot connectors available today: synced connectors and federated connectors.

Copilot Connectors: Synced vs Federated (Live)

Microsoft 365 Copilot supports two connector models for bringing third party data into Copilot experiences.

Synced connectors ingest external content into Microsoft Graph, where it is indexed and added to the semantic index. This allows Copilot to search and reason over that content in the same way it would with native Microsoft 365 data.

In contrast, federated connectors retrieve information in real time using Model Context Protocol (MCP) and do not index content into Microsoft Graph. This makes federated connectors useful for sensitive or fast changing data, while synced connectors are usually better for large knowledge bases where you want broad discovery and consistent answers across Copilot.

Note: Federated connectors are currently available in early access preview and may not appear in all Microsoft 365 tenants, depending on release ring and licensing.

Why would you want to extend Microsoft 365 Copilot?
As shown in the diagram above, Microsoft 365 Copilot has access to a number of your files by default and can reason over this data. However, it doesn’t have access to everything. Microsoft 365 Copilot does not have access by default to the rest of your organisational data, such as line‑of‑business applications like Salesforce, SAP, Jira, ServiceNow, and others. This is because Microsoft 365 Copilot Chat is primarily grounded in data available through Microsoft Graph, including Word, PowerPoint, email, SharePoint content, Teams conversations, and files stored in OneDrive.

Microsoft 365 Copilot supports multiple ways of bringing third‑party data into Copilot experiences. One approach is synced connectors, which ingest external data into Microsoft Graph and make it available through semantic indexing. Another approach is federated connectors, which retrieve data in real time without indexing it into Microsoft Graph. At the time of writing this post, federated connectors are available in.

However, we won’t be using either synced or federated connectors as we continue through this post.

Instead, we’ll focus on a declarative agent approach, where knowledge and connectors are added directly to the agent and scoped specifically to that agent. This method is commonly used when integrating systems such as ServiceNow, Jira, Monday.com, and more, where the agent retrieves or interacts with data at runtime under the user’s permissions, without making that data tenant‑wide or indexing it into Microsoft Graph.

This approach allows Copilot to reason over the information relevant to a specific business scenario, while keeping the knowledge controlled, targeted, and scoped to the agent itself.

How Copilot Understands Knowledge from External Systems

When you connect Microsoft 365 Copilot to external systems such as Salesforce, ServiceNow, or Confluence, simply retrieving data is not enough. Copilot needs to understand what that information means.

Traditional keyword‑based search looks for exact words or phrases. For example, if you searched for “holiday allowance policy”, you might miss a document titled “Annual Leave Guidelines” because the wording does not match exactly.

The semantic search built into Microsoft 365 Copilot works differently. Instead of relying only on keywords, it understands the meaning and context behind a question. This allows Copilot to surface relevant information even if the wording does not match.

For example:

User asks:
“What’s the policy for booking time off?”

Copilot might retrieve information from a document titled:
“Annual Leave Request Procedure”

even though the words “time off” were never used in the document.

In many scenarios, the knowledge required by Copilot may already exist within Microsoft 365, such as documents stored in SharePoint sites.

Scenario we will build:

Employees across your organisation regularly need to refer to internal policies and procedures to complete everyday tasks. These documents are stored in a SharePoint Online site, such as expense policies, dress code policy, onboarding guides, sick leave, return to work, training and flexible working policies and more. However, searching through multiple documents can be time consuming.

You want to create a declarative agent that allows users to ask questions in natural language and receive accurate answers based on the documentation stored within SharePoint.

Now that you have an idea of what declarative agents are, let’s build a declarative agent based on this scenario. We will also explore agent options as we go through the demo.

Create a declarative agent built specifically for Microsoft 365 Copilot

Prerequisites:
To follow along and build declarative agents that run inside Microsoft 365 Copilot using Copilot Studio, you must have a Microsoft 365 Copilot licence.

If you don’t have a Microsoft 365 Copilot licence, you can still build agents in Copilot Studio using a Copilot Studio Trial or pay‑as‑you‑go (Copilot Credits). However, without a Microsoft 365 Copilot licence, you won’t be able to run or test the agent within the Microsoft 365 Copilot experience demonstrated in this post.

Note: If you plan to run declarative agents at scale, enable actions, or publish agents beyond basic internal usage, it’s worth reviewing how Copilot Studio usage is measured and managed using Copilot Credits. For more details, see Billing rates and management in Microsoft Copilot Studio.

  1. Visit https://copilotstudio.microsoft.com

  2. Click agents
Image1


3. Select Microsoft 365 Copilot

Image2


4. Select Add or New Agent (label may vary depending on tenant and release)

Image3


5. Configure the agent:
– Agent language: English
– Agent name: Policy Advisor
– Agent image: Upload a custom image (optional but recommended)

Image4



6. Description – Use your own words to describe what your agent should help with, including the target audience and end goal.

Note: The description helps Microsoft 365 Copilot identify when your agent is relevant for a specific task or situation. Keep it short, precise, and simple. This description will also be made visible to users when they start to make use of your agent. Character limit at the time of writing this post: 1,000 characters.

Description
The Policy Advisor helps employees quickly find clear, accurate answers to Contoso Ltd. policies and procedures. Ask natural language questions about onboarding, benefits, leave, remote work, training, conduct, and more.


7. Instructions – below

Note: These instructions define how the agent should behave when extending Microsoft 365 Copilot. They control what the agent does, how it responds, and the boundaries it must follow. You can update and refine these instructions later as you test the agent. These instructions are not visible to end users.


Your goal is to make policies easy to understand, easy to navigate, and less intimidating.

You are Policy Advisor, an employee facing assistant for Contoso Ltd.

Your role is to help employees understand internal policies, procedures, and guidelines based only on the documents provided in SharePoint. These include, but are not limited to, onboarding guides, workplace policies, code of conduct, benefits, training requirements, remote working, career progression, and wellbeing resources.

How you should respond

  • Answer questions clearly, calmly, and professionally
  • Use plain, friendly language suitable for all employees
  • Be supportive and reassuring, especially for new starters
  • Summarise policies in an easy‑to‑understand way rather than repeating them word for word
  • If appropriate, explain what employees can expect, do next, or who to contact

Grounding and accuracy

  • Only answer based on the content available in the connected SharePoint documents
  • Do not guess, invent, or assume information
  • If the answer is not clearly covered in the documents, say so politely and suggest contacting HR or a manager. Do not make information up if it’s not documented.

Boundaries

  • Do not provide legal advice
  • Do not make decisions or approvals on behalf of Contoso Ltd.
  • Do not speculate about disciplinary outcomes
  • Never assist with any other queries unless they are related to internal contoso policies. You are strictly a policy advisor and that is it.

Tone and behaviour

  • Be inclusive, neutral, and non‑judgmental
  • Encourage employees to ask questions
  • Reinforce that policies exist to support employees, not catch them out

When unsure

  • Clearly state that the information may vary by role or location
  • Recommend speaking with HR or a manager for confirmation
Image5


8. Click to Add suggested prompts. When done, click save.

I’ll be adding the starter prompts below.

Note: Suggested prompts are predefined example questions or actions that appear when a user opens a Copilot agent. They act as conversation starters and show users what the agent is capable of, especially when they don’t yet know what to ask.

Image6


Title: First day at Contoso
Prompt: What should I expect on my first day at Contoso Ltd?

Title: Mandatory training
Prompt: What mandatory training do I need to complete and by when?

Title: Remote or hybrid working
Prompt: How does remote or hybrid working work at Contoso?

Title: Booking time off
Prompt: How do I book annual leave or time off at Contoso?

Title: Dress code
Prompt: What is the dress code at Contoso, including for remote work?

Image7


9. Click Create. I’ll configure the agent further shortly.

Image8


Image9


10. Let’s test the agent. Click the Test button located at the top right, next to the Publish button, as shown in the image below. 

The test pane is a great way to test your agent, fine‑tune its behaviour, and test again.

Image10


11. In the test pane, the agent name and the icon you uploaded earlier appear, along with some of the starter prompts.

I’ll click the Mandatory training prompt. This is one of the suggested prompts created earlier and acts as a conversation starter in case users are unsure what to ask the agent.

Image11


The response from the agent indicates that it was unable to locate any relevant information.

This is expected behaviour at this stage. The agent does not yet have access to any knowledge sources, and it is not allowed to search the internet. At the moment, the agent can only respond based on the instructions provided, but no supporting content has been connected.

The policy documents the agent needs to answer these questions are stored in SharePoint, and we haven’t connected that SharePoint data to the agent yet. In the next step, we’ll add the required SharePoint content as a knowledge source so the agent can start answering questions accurately.

Image12


12. Note about web search

Copilot Studio also provides an option to enable web search, as shown in the diagram below.

For this scenario, web search remains disabled. The Policy Advisor agent is designed to answer questions based only on approved internal policy documents stored in SharePoint. Enabling web search could result in answers being grounded in public web content, which is not appropriate for an internal policy advisor.

Clear instructions help guide the agent’s behaviour, but best practice is to control grounding by enabling only the knowledge sources you intend the agent to use.

Image13


Before adding a knowledge source, let’s do some further testing to validate the agent’s behaviour and boundaries.

At this stage, the agent is operating only on the instructions we defined earlier, without access to any internal knowledge sources. This allows us to confirm that the agent responds appropriately to questions that fall outside its intended scope.

13. Click the + icon visible under the Publish button to start a new conversation

Image14


14. Let’s try a different prompt to test the agent’s boundaries.

I’ll ask the agent:

“Can you recommend a 22‑inch Dell monitor under £500?”

The agent is not able to help with this request. This is expected behaviour.

Although Copilot Studio provides an option to enable web search, web search remains disabled for this scenario. More importantly, the instructions provided earlier clearly define the agent’s role as a Policy Advisor for Contoso Ltd.

The agent is designed to answer employee questions about internal policies and procedures only. Recommending products or equipment falls outside that scope.

Image16


I’ll try another prompt:

“Can you recommend a desk for my home office

Again, the agent correctly explains that it cannot help with this request. This confirms that the instructions and boundaries are working as intended.

Image15


15. So what next? let’s add my SharePoint URL including all my policy documents.

When you build an agent in Copilot Studio, you’re not technically training the AI in the traditional sense.
Instead, you’re connecting it to trusted information sources that it can search when responding to users. This is done using the Add Knowledge feature.

Think of this as:

“Where should my agent look to find answers?”

When you select Add Knowledge, Copilot Studio allows you to connect your agent to different data sources across your organisation (or public web content). These are grouped under the Featured and Advanced tabs as I will demonstrate next.

Click Add knowledge

Image17



You’ll find that there are additional knowledge source options available.

Public websites
This allows your agent to answer questions using information from selected public websites, such as a company website or publicly available documentation.

Note: By default, Copilot Studio uses generative orchestration, which allows you to add up to 25 public website URLs per agent when using Public websites as a knowledge source. Generative orchestration is enabled automatically for new agents, but you can switch to classic orchestration if required. It’s important to note that classic orchestration supports fewer public website URLs and is typically used for more narrowly scoped or legacy scenarios.

SharePoint:
This allows your agent to retrieve answers from documents stored in SharePoint sites, including:

  • Word documents
  • PDFs
  • Policy documents
  • Standard Operating Procedures
  • Internal guidance documentation

For SharePoint content, Copilot Studio uses Microsoft Graph and semantic search to retrieve relevant sections from documents in response to user questions. If this sounds familiar, that’s because we covered semantic search earlier in this post when explaining how Copilot understands and retrieves relevant information from connected data sources.

Dataverse:
Microsoft Dataverse is the secure data platform for Power Platform. It’s used to store and manage structured business data, such as customers, requests, or records, in a way that apps, automations, and Copilot agents can reliably read from and write to.

Data in Dataverse is stored in tables, similar to Excel tables, with rows and columns that represent business information. Dataverse includes built‑in tables for common business scenarios and also allows you to create custom tables tailored to your organisation’s needs.

Dataverse provides important capabilities such as security, relationships, business rules, validation, and auditing, which help ensure data remains consistent and trustworthy, regardless of which app, flow, or agent accesses it. For example, you can track changes to data, including who made the change and the previous and new values.

In Copilot Studio, Dataverse is typically used when an agent needs to work with structured business data, such as creating or updating records, tracking requests, or retrieving information in a consistent format.

If you already use another data source, such as SharePoint, Excel, or an external database, you can connect to those using connectors. However, if you need a native data source built into Power Platform, Dataverse is a good choice because it supports relationships between tables, rich security controls, and scalability without manual infrastructure management.

Dataverse integrates with Microsoft Entra ID (Microsoft’s Cloud Identity and Access Management Solution), allowing admins to control who can read, write, or modify data. It works across all Power Platform services, including Power Apps, Power Automate, and Copilot Studio.

Dynamics 365
When you add Dynamics 365 as knowledge, you’re allowing your Copilot agent to retrieve information directly from live CRM (Customer Relationship Management) or operational system used by these applications. Instead of answering questions based on documents, your agent can answer questions based on, customer case history, order records, account data, sales opportunities and more.

For example, an organisation uses Dynamics 365 Customer Service. A user asks, “What’s the latest update on my support case?”. The agent retrieves the relevant case record, including the latest status update and assigned support engineer, and then returns a real‑time response.

Under the hood, Dynamics 365 applications store their data in Microsoft Dataverse, so access to Dynamics 365 data in Copilot Studio is provided through Dataverse with the appropriate permissions applied.

Under the Advanced tab in Add knowledge, another option is available: Bing Custom Search.

Image19


Bing Custom Search:
Bing Custom Search allows you to control how your Copilot Studio agent retrieves information from the internet by limiting it to search only trusted public websites that that you explicitly approve. Rather than performing a broad web‑wide search, the agent uses Bing to retrieve information only from the domains, sub‑paths, or individual webpages you configure.

When a user asks a question, Copilot Studio generates an optimised search query and sends it to Bing Custom Search. The response is then grounded only in content from your approved sources, helping ensure accuracy and governance.

When adding websites directly using the Public websites knowledge option, there are platform limits:

  • In classic orchestration, you can add up to 4 public website URLs
  • In generative orchestration (enabled by default), this increases to 25 public website URLs

Bing Custom Search is useful when knowledge is spread across many trusted external domains, as it allows you to manage significantly more approved sources within a single custom search configuration, rather than adding each URL individually in Copilot Studio. A single Bing Custom Search instance can include up to 400 configured web slices, such as domains, sub‑paths, or individual pages.

To use Bing Custom Search, you first create a custom search instance by visiting https://customsearch.ai
and signing in with a Microsoft account (for example, @hotmail @outlook or another Microsoft backed account). After adding and publishing your approved websites, you copy the Custom Configuration ID from the Production tab and paste it into Copilot Studio when adding Bing Custom Search as a knowledge source.

Summary:

SharePoint = Internal documents such as policies, PDFs, or Word files.
Dataverse = Structured business data stored in tables (for example employee records or support cases)
Dynamics 365 = Business applications (such as CRM systems) that store ana manage their data in Dataverse
Public Websites = Specific websites your agent is allowed to access
Bing Custom Search = A controlled search across multiple approved websites. A controlled search across multiple approved websites

Important clarification: “Add knowledge” vs “Copilot connectors”

The Add knowledge options in Copilot Studio refer to knowledge sources that an individual agent can use to ground its generative answers. These sources are configured directly within Copilot Studio and define where the agent is allowed to look for information when responding to users. Examples include SharePoint, Dataverse, Public websites, and Bing Custom Search.

Microsoft 365 Copilot connectors (such as Synced or Federated connectors) which I briefly mention earlier are a separate capability. They are used to extend Microsoft 365 Copilot and Microsoft Search across Microsoft 365 experiences and are configured centrally by administrators in the Microsoft 365 Admin Center (admin.microsoft.com → Copilot → Connectors), rather than within Copilot Studio.

Synced connectors ingest and index third‑party content into Microsoft Graph so that it can participate in semantic indexing and discovery across Microsoft 365 Copilot experiences. Microsoft describes synced connectors as crawling and indexing content from external sources into Microsoft Graph so the data becomes discoverable in Copilot and Microsoft Search experiences.

In contrast, federated connectors (Preview at the time of writing) retrieve information in real time using Model Context Protocol (MCP) without indexing external data into Microsoft Graph. This makes federated connectors useful for sensitive or fast‑changing data, while synced connectors are typically more suitable for large knowledge repositories where broad discovery and consistent grounding is required.

Note: Federated connectors are currently available in early access preview and may not appear in all Microsoft 365 tenants.

For more information, see Microsoft’s overview of Copilot connectors (synced vs federated):
https://learn.microsoft.com/en-us/microsoft-365/copilot/connectors/overview


16. I’ll now add documents from SharePoint. Click SharePoint.

Image18


17. From here, you can either browse for content or paste a SharePoint URL directly.

Image20


18. Browsing allows you to select individual files, folders, or document libraries from SharePoint, as shown in the image below.

Image21


19. I’ll add the SharePoint URL that contains all of the policy documents.

Image22

Image23


Note: SharePoint knowledge sources are only available to authenticated users. If a user interacting with the agent does not have permission to a specific file or location in SharePoint, the agent will not be able to access or use that content when generating a response.

After adding the URL, the SharePoint knowledge source displays an error:

Error details: No SharePoint connection was found in this environment. The knowledge source cannot access SharePoint content. Recommended action: Please add a SharePoint connection to this environment and re-authenticate.

This error indicates that no active SharePoint connection has been configured for the Copilot Studio environment yet. In other words, although the URL is valid, Copilot Studio cannot currently authenticate to SharePoint to retrieve the content.

This is expected behaviour if a SharePoint connection has not previously been set up or if the existing connection has expired. Once a SharePoint connection is added to the environment and authentication is completed, the knowledge source will be able to access the SharePoint content and move into a Ready state.

Image24


There are several ways to create the required SharePoint connection. In this example, I’ll create the connection using the Power Apps portal.

  • Go to https://make.powerapps.com
  • In the top‑right corner, make sure you select the same environment that your Copilot Studio agent is using
  • From the left‑hand navigation, select Connections
  • Click + New connection
  • Choose SharePoint from the list
  • Sign in using an appropriate account (for example, an admin or service account)

This creates a SharePoint connection within the selected environment. Copilot Studio automatically detects the new connection, typically within a minute, and the SharePoint knowledge source status updates to Ready, as shown in the image below.

Image24



20. Let’s test the agent again. Click the + icon in the test pane to start a new conversation.

I’ll run the same prompt as before:

“What mandatory training do I need to complete and by when?”

This time, the agent is able to respond successfully. Because the SharePoint knowledge source is now connected and in a Ready state, the agent retrieves the required information from the policy document stored in SharePoint and uses it to generate an accurate, grounded response.

Image24


It also includes clear attribution, showing which SharePoint document the information was retrieved from. This helps users understand where the answer came from, reinforces trust in the response, and makes it easy to verify or follow up by opening the source document directly.

Image24


21. Next, let’s explore the tools available under the Knowledge section. Click Add tool.

Ms 4022 copilot studio



22. Here are the tools available to me.

I’ll briefly explain what each tool does.

CopilotStudioTools


Agent Flow


Agent flows are structured, deterministic (meaning they follow a fixed, predefined set of steps and produce the same outcome every time given the same input), step‑by‑step automations that an agent can run to complete tasks reliably. They follow a defined sequence of actions and rules, ensuring consistency and predictability rather than generative reasoning. Agent flows can be triggered on demand by an agent, on a schedule, or in response to specific events.

Agent flows are typically used when a business process must be handled consistently and predictably, rather than relying on generative AI behaviour alone.

Use case 1:
HR policy advisor agent

When a user asks, “How do I request parental leave?”, an agent flow can be triggered to collect the required details (such as dates and type of leave) and then submit the request by creating a ticket, starting an approval process, or sending a notification email.

Use case 2:
Operations/administration 

Agent flows can automate repeatable operational processes, such as creating a case, notifying a team in Microsoft Teams, and logging the interaction. This ensures the same steps are followed every time, improving reliability, auditability, and governance.

Note:
Agent flows can also make use of hundreds of built‑in actions and connectors available through Power Automate. This allows an agent to interact with both Microsoft and third‑party services as part of a structured workflow.

Common examples include adding data to an Excel file, creating or updating records in third‑party applications, sending emails via Outlook, posting messages to Microsoft Teams, copying files from one folder to another in SharePoint or OneDrive, starting and managing approval processes, creating or updating tasks in tools such as Planner, and generating documents from templates and storing them in SharePoint or OneDrive. Because these actions can be executed as part of an agent flow, they run in a predefined, deterministic sequence, ensuring the process is carried out consistently every time.

Prompt

This concept is easiest to understand with an example.

Example 1 – Prompt Tool:
An employee asks the HR Policy Advisor agent:

“Can I book more than 3 weeks leave?”

The agent identifies the user by retrieving their profile from Microsoft Entra ID (via the Office 365 Users connector), including details such as their location and manager.

Next, the agent checks the HR leave policy using a knowledge source, such as SharePoint, where the organisation’s policy documents are stored.

In this scenario:

  • Their manager is David Smith
  • The employee is based in the UK

Based on the policy, the agent responds:

“Hi Imran, I can see you’re based in the UK and are entitled to a maximum of 3 weeks’ annual leave. Anything beyond this requires manager approval. Would you like me to draft an email to David Smith requesting approval?”

If the employee agrees, the agent asks for additional details, such as the requested leave dates and the reason for the extended leave.

How the Prompt Tool is used

The Prompt Tool takes the structured information gathered during the conversation, for example:

  • Employee name
  • Manager name
  • Leave dates
  • Reason for the request

and transforms it into a consistent, well‑written output based on predefined instructions.

For example, the following prompt could be added to the agent using the Prompt Tool in Copilot Studio:

“Write a professional email from the employee to their manager requesting approval for extended annual leave. Include the employee name, manager name, leave dates, and reason. Address the manager appropriately and sign off from the employee.”

The Prompt Tool is used to transform structured data gathered during the interaction into a consistent, well‑written output, such as an email, message, or document, based on predefined instructions.

Example 2 – Prompt tool

Prompt Tools can also be used when an agent needs to understand, analyse, or extract information from documents, such as invoices, receipts, or reports.

For example, a user uploads an invoice and asks:

“Can you extract the supplier name, invoice number, total cost and due date from this document?”

The agent receives the uploaded file and passes the contents of the invoice to a Prompt Tool for processing.

The Prompt Tool analyses the document and extracts the required information based on predefined instructions, returning the results in a structured format.

For example, the Prompt Tool could be configured with the following instructions:

“You are an accounts assistant.
From the uploaded invoice document, extract the following information:
– Supplier name
– Invoice number
– Invoice date
– Total amount
– Due date
Return the information in a clear and structured format.
If a value cannot be found, state this explicitly.”

The agent can then return a response such as:

  • Supplier Name: Contoso Ltd
  • Invoice Number: INV‑10421
  • Invoice Date: 28/03/2026
  • Total Amount: £2,450
  • Due Date: 28/12/2026

Prompt Tools – Other Common Use Cases

Prompt Tools can be used across a wide range of business scenarios where an agent needs to generate, interpret, transform, or structure content. Common examples include:

  • Custom summarisation – summarising a policy document into plain English for an employee
  • Image description – explaining what a user has uploaded (for example, identifying that an image is a receipt)
  • Information extraction – extracting key details such as supplier name, invoice number, or due date from a document
  • Document creation – generating a report, letter, or approval email based on user‑provided information
  • Chart generation – turning extracted sales or performance data into a simple chart‑ready format
  • Email replies – drafting responses to customer or internal enquiries in a consistent tone
  • Content classification – identifying whether a document is, for example, a contract, invoice, or policy
  • Data reshaping – converting unstructured or extracted data into a structured format such as a table or list
  • and many more.

In each of the scenarios above, the Prompt Tool allows you to define a prompt that the agent runs to transform information into a clear and usable output.

The image below shows an example of a Prompt Tool configured to analyse an uploaded image and generate an output in a humorous and poetic style. The Prompt Tool also allows you to upload sample data, enabling you to test whether the prompt produces the expected result before deploying it as part of your agent.

In this example, a sample image has been uploaded to validate that the prompt correctly analyses the uploaded file and generates a creative description based on the predefined instructions provided by the maker.

Copilot studio AI prompt anaylse image


Sample image of rabbit below

Copilot Rabbit


It is also possible to configure which AI model is used by a Prompt Tool. This allows you to experiment with different models and select the one most suitable for your scenario, such as optimising for creativity, accuracy, or reasoning capability.

As shown in the image below, the maker can choose the model to be used by the Prompt Tool and test the prompt against sample input. This makes it easy to compare outputs across models and validate that the selected model produces the desired result before the Prompt Tool is used within the agent.

Copilot studio AI prompt


Model Context Protocol (MCP)

Model Context Protocol (MCP) is an open standard introduced by Anthropic in November 2024 to help AI agents connect to external business systems such as databases, ticketing platforms, and collaboration tools.

A simple way to understand MCP is to think of it as a USB‑C connector for AI. Just as USB‑C provides a single, standard way to connect different devices, MCP provides a standard way for AI applications such as Microsoft Copilot to connect to business systems, access their data, or perform tasks, without requiring a completely bespoke integration for each system.

AI agents are good at conversation, but they don’t automatically know how to interact with your business applications (such as HR systems, Jira, or service desks). MCP (Model Context Protocol) was introduced as a standard way for AI tools to connect to those systems, rather than needing a custom integration every time.

In Copilot Studio, you can connect to apps using built‑in connectors or APIs, but MCP is useful when you want a more “plug‑and‑play” approach where an MCP server publishes a set of tools the agent can use, and Copilot Studio can automatically discover and use those tools over time. As those tools evolve, the MCP server can surface changes centrally, without requiring you to manually rebuild integrations for each agent over time.

Example: Jira MCP Server

Jira is a widely used work management and issue‑tracking system. Atlassian (the company behind Jira) has released an official Jira MCP Server, which allows AI assistants to securely access Jira data and create or update issues on behalf of users.

Although Copilot Studio provides built‑in connectors for Jira, these typically require you to manually configure individual actions—for example:

  • Create an issue
  • Update a ticket
  • Check issue status

Each action also needs to be configured with specific inputs such as issue title, description, priority, or assignee. If Jira introduces new capabilities, these changes must be manually configured for each agent.

With MCP, the agent connects instead to a central Jira MCP Server. This server publishes Jira’s available capabilities as tools that Copilot Studio can automatically discover and use. If new Jira capabilities are added in the future, the MCP server can expose them centrally, allowing multiple agents to benefit without manual reconfiguration.

In short, with MCP, you connect once to a Jira MCP Server and gain access to multiple Jira tools (such as searching, creating, or updating issues), rather than configuring each action individually inside every agent.

In simple terms, an MCP server doesn’t just list what actions are available. It also handles the hard work behind the scenes, such as finding the right data, checking permissions, and applying rules. This lets the agent focus on using the tools, without needing complex configuration or prompts.

The screenshot below shows several Jira tools available in Copilot Studio that can be added manually. It also shows that you can connect to the Jira MCP Server instead. After connecting, specific tools exposed by the MCP server can be enabled or disabled based on your requirements.

Ms4022 mcp

Copilot Studio Config MCP Jira


Example: Microsoft Learn MCP Server

Another example is Microsoft Learn, which also provides an MCP Server.

If I added the public Microsoft Learn website address as a knowledge source, the agent would rely on indexed or stored copies of documentation. This means responses could be based on information that is slightly out of date.

By connecting to the Microsoft Learn MCP Server instead, the agent can query Microsoft’s documentation live, at runtime, using a structured interface. This allows the agent to retrieve the latest guidance directly from Microsoft Learn whenever a user asks a question.

As a result, the agent can provide:

  • more up‑to‑date information
  • more accurate answers
  • responses that reflect the current state of Microsoft documentation

rather than relying on pre‑indexed content or the model’s existing knowledge.

Connect to your own MCP Server

You can also create your own MCP Server for internal systems or products and connect it to Copilot Studio. This allows your organisation to publish custom tools that agents can use securely, without having to build or configure separate integrations for each agent.

Copilot Studio Config MCP


Rest API

Let’s move on to the Rest API tool

RestAPI CopilotStudio
CustomConnector CopilotStudio


You may wonder why you would choose to use a REST API Tool if built‑in connectors or MCP Servers are available.

In many cases, these pre‑built or simplified integrations may not exist yet for the system you want to connect to. However, the system may still expose a REST API, which allows external applications to communicate with it securely.

For example, your organisation may have an internal HR system, customer booking platform, or finance application which provides API access but does not have a built‑in connector or MCP Server available. REST APIs act as a standard interface between applications, allowing systems to exchange data and trigger actions.

By using the REST API Tool in Copilot Studio, you can configure your agent to:

  • Retrieve data from external systems
  • Submit or update information
  • Trigger processes within another application

without manual intervention.

Use Case Rest API Copilot Studio – Example 1 (Internal System)

For example, your organisation may use an internal equipment booking system that allows employees to reserve laptops or meeting rooms. While this system might not have a Copilot Studio connector or an MCP Server available, it may still expose a REST API endpoint.

Using the REST API Tool in Copilot Studio, the agent can call this API to:

  • check equipment or room availability
  • create a new booking
  • retrieve existing reservations

on behalf of the employee.

This allows the agent to interact with internal systems that already expose APIs, even when no pre‑built integration is available.

Use Case Rest API Copilot Studio Example 2 (Third‑Party Application)

Similarly, your organisation may use a third‑party e‑commerce platform to track customer orders. If this platform provides API access, the agent can use the REST API Tool to retrieve information such as order status or update delivery details.

For example, a user could ask:

“What is the status of my order?”
or
“Can you update the delivery address for my order?”

API integrations like this allow organisations to connect systems and automate processes in near real‑time, helping to reduce manual effort and improve operational efficiency.

When REST APIs are typically used:

  • a built‑in connector is not available
  • an MCP Server has not been provided
  • an internal or third‑party system exposes API access

Custom Connector

CustomConnector CopilotStudio

While the REST API Tool allows your agent to connect directly to an external system, a Custom Connector is useful when you want to create a reusable integration that can be used across multiple agents or solutions within your organisation.

A Custom Connector acts as a wrapper around a REST API and allows Microsoft Power Platform services such as Copilot Studio, Power Apps, Power Automate and Power Pages to securely communicate with internal or external systems using a shared set of actions and authentication rules.

Instead of configuring the same REST API calls separately in each agent or application, a Custom Connector lets you define the integration once. This includes:

  • expected outputs
  • available actions
  • required inputs
  • authentication methods

That connection can then be reused across multiple solutions.

For example, Imran works in HR and frequently needs to retrieve payroll information when employees ask questions about salary adjustments or overtime payments. The organisation’s internal payroll system exposes a REST API which does not have a built‑in Copilot Studio connector or an MCP Server.

Initially, this integration could be set up using the REST API Tool inside a single HR agent. However, other solutions, such as a Payroll Advisor agent, an internal Power App, or an external Power Pages website may also need access to the same payroll system.

If the REST API Tool were used directly, each solution would need its own copy of the same API configuration. Instead, a Custom Connector can be created to define this integration once and store it centrally within the Power Platform environment.

Where Custom Connectors are created

When selecting the Custom Connector option within Copilot Studio, you may notice that you are redirected to the Power Apps Maker Portal. This is expected, because Custom Connectors are not created directly inside Copilot Studio. They are part of the wider Microsoft Power Platform and are managed at the environment level.

Once created, the same Custom Connector can be reused by:

  • Copilot Studio agents
  • Internal Power Apps
  • External Power Pages websites
  • Power Automate workflows
  • Logic Apps

without needing to configure the REST API integration separately within each solution.

Computer Use

Next, let’s move on to Computer use, as shown in the images below.

Copilot Studio Computer Use

Copilot Studio Computer Use


So far, we’ve seen how agents can use tools to send emails, retrieve data, or integrate with third-party applications such as ServiceNow using connectors, REST APIs, or MCP. However, many organisations still rely on legacy systems which do not support modern integrations. These may include older desktop applications or internal web based systems that are too costly or complex to redesign and do not expose APIs or MCP servers.

For example, employees might currently need to manually copy invoice details from a Word or PDF document into a legacy invoice management system, such as the one shown below. (Image source: Microsoft Events)

LegacyApp


In many organisations, this type of manual process could involve processing hundreds or even thousands of invoices every month.

With the Computer Use in Copilot Studio, an agent can interact directly with applications in the same way a human would, by using a virtual keyboard and mouse to control what appears on screen. This allows agents to automate tasks even when no API integration exists.

Example: Automating invoice entry in a legacy system

Using Computer use, you could configure your agent to monitor a shared mailbox for incoming invoices. When a new invoice arrives, the agent can:

  • open a legacy desktop application or browser‑based system
  • sign in using securely stored credentials (for example, via a secure credential store or Azure Key Vault)
  • copy invoice details from the uploaded document
  • enter the information into the system
  • save the record and move on to the next invoice

The agent navigates the application by clicking buttons, entering text, and interacting with the user interface exactly as a person would. If required information is missing or unclear, the agent can pause the process and notify a human by sending an email or message, supporting human‑in‑the‑loop supervision.

Copilot Studio: Where Computer use can run

Computer use can run on different machine types, including:

  • a hosted browser environment
  • a Windows machine registered for Computer use
  • a Windows 365 Cloud PC

This flexibility allows organisations to automate legacy processes without modifying their existing applications.

Publish agent to Microsoft 365 Chat and Teams


Finally, let’s look at how to make your agent available to users in Microsoft 365 Copilot chat and Microsoft Teams.

Once you’ve configured your agent’s instructions, knowledge sources, and tools, the next step is to publish it. Publishing applies the latest version of your agent and makes it ready to be used in Microsoft 365 Copilot experiences and other supported channels.

Think of Publish as deploying the agent so it can be accessed outside of Copilot Studio. Users will only see the most recently published version of your agent.

To publish your agent:

  1. In Copilot Studio, open your agent
  2. Select Publish
  3. Confirm to make the latest version available.
Publish Agent


4. After clicking Publish, you’ll be prompted to add some additional details, such as:

  • the developer name
  • a short description of the agent
Publish Agent


5. Once completed, click Publish.
The publishing process usually completes in under a minute.

Publish Agent


6. Configure user access
After publishing, you’ll need to decide who can access the agent. At this stage, you can either grant access to specific users or groups or click Copy link to test the agent yourself.

Note: To make an agent available to the entire organisation, an administrator must approve the request in the Microsoft 365 admin centre: admin.microsoft.com → Agents (left navigation) → Requests

Granting permissions to individual users or groups does not require admin approval. Admin approval is only required when making the agent available to the entire organisation, as shown in the image below.

Publish Agent


The owner or maker of the agent is automatically granted full control. If I were to select a different user or group, I could configure specific permissions, such as whether they are allowed to view, edit, configure, share, publish, or delete the agent.

Publish Agent


7. Click Copy

Publish Agent


8. Open a web browser and paste the link.
Sign in using an account that has permissions to access the agent.

After a few seconds, you’ll be prompted to add the agent as shown in the image below.

Publish Agent


Success. The agent has now been added to my Microsoft 365 Copilot Chat.

Publish Agent


The agent is also visible in the agent store, making it easy for authorised users to find and access it.

Publish Agent


Note: If you make any changes to the agent in Copilot Studio, you must publish again. After publishing, updates can take 5–15 minutes to appear consistently across Microsoft 365 Copilot experiences.

9. You can optionally pin the agent, so it appears in the left‑hand navigation for quick access. Alternatively, you can invoke the agent directly within Microsoft 365 Copilot Chat by typing the @ symbol followed by the agent’s name, and selecting it from the list.

Publish Agent

Publish Agent


To validate the behaviour, I asked the agent an off‑topic question, such as:

“Can you help me bake a chocolate cake?”

Result: The Policy Advisor agent correctly declined to help, as expected, in line with the instructions and scope defined earlier.

When asked questions related to internal policies, the agent responds correctly.

Publish Agent


I hope you found this post useful.

If you have any feedback or questions, please feel free to leave a comment below.

See you in the next post

Copilot Agents: Agent Builder, Copilot Studio, or Foundry?

Reading Time: 9 minutes


In this blog post, I’ll explore the different ways you can build and deploy agents. We’ll compare Agent Builder in Microsoft 365 Copilot, Microsoft Copilot Studio, and Microsoft Foundry, focusing on when to use each option. The goal is to help you understand the trade offs around complexity, cost, control, and required skills, so you can confidently choose the right approach (or a combination) for your scenario.

Microsoft provides several ways to build agents because different audiences need different levels of control. Some users want a quick, no‑code experience, while others require deeper engineering flexibility and operational controls. Instead of a single tool, Microsoft offers multiple platforms that sit at different levels of complexity, each designed for a specific type of use case.

What do we mean by an agent?

Before looking at the different platforms, it’s important to clarify what we mean by an agent.

In the Microsoft ecosystem, an agent is a customised AI assistant created for a specific purpose. Unlike Microsoft 365 Copilot’s out of the box experience included in Microsoft 365 Copilot Chat, Word, Excel, PowerPoint, Outlook, Teams and more, an agent has clearer instructions, can be grounded in specific knowledge, and may be able to take actions (such as calling tools, workflows, or APIs).

Not every agent needs the same level of capability. Some agents are simple and focus on answering questions consistently from approved content, while others are designed for multi-step workflows, deep integrations, or full application style deployment and monitoring. This is why Microsoft provides multiple ways to build agents, rather than a single platform. It is also possible to start with the simpler options before moving on to the others.

The three levels of agent building in Microsoft

Rather than thinking about these platforms as competing tools, it’s more helpful to think of them as different levels of agent complexity and control. Organisations can start with the simplest option and move up as their requirements (and skills) grow.

Microsoft provides three main ways to build agents, each designed for a different audience and level of control listed below:


  1. Copilot‑native agents (Agent Builder) – built directly inside Microsoft 365 Copilot Chat for fast internal use and simple scenarios. Accessible via m365copilot.com

    Best for: quick, focused agents that help you (or a small team) get consistent answers and guidance using approved content, without building workflows or managing deployment.

    Example use case:
    Team onboarding helper – An agent that answers common questions like:

    “Where’s the onboarding checklist?”
    “What’s the process for requesting access?”
    “Who do I contact for a laptop or software?”

    It can be grounded in SharePoint pages, onboarding documents, and internal FAQs so new starters get consistent answers without asking the same questions repeatedly.

    Choose this when: you want a quick internal agent that stays within the Copilot experience and doesn’t need complex automation or multi-channel deployment.

2. Low‑code business agents (Copilot Studio) – built using Microsoft Copilot Studio when you need richer automation, connectors, and broader rollout. Accessible via copilotstudio.microsoft.com

Best for: agents that can do more than answer questions, that can take action, follow a conversation flow, connect to systems, and be rolled out to more users and channels.

Example use case:
IT helpdesk agent – An agent that answers common questions like:

Answer: “How do I reset my VPN / access a shared mailbox?”

Take action: “Create a support ticket”, “Check ticket status”, “Route to the right team”

Run a workflow: gather device details, confirm urgency, trigger an approval, notify support

This is where connectors and workflows really help, your agent doesn’t just talk, it gets things done.

Choose this when: you need automation/workflows, integrations (connectors/APIs), or a wider deployment across Teams, web or other supported channels.


3. Engineered AI agents (Microsoft Foundry) – built and operated as applications using Microsoft Foundry on Azure for full engineering control, deeper integrations, and production monitoring. This approach is more powerful, but also more complex and typically requires developer/DevOps skills. Accessible via Azure Portal or https://ai.azure.com

Best for: pro‑code, production-grade agent solutions where you need maximum control over how the agent is built, deployed, secured, monitored, and scaled.

Example use case:
Customer order assistant embedded in an app – A customer facing agent that:

  • Looks up orders in multiple systems
  • Applies business rules (refund thresholds, fraud checks, region specific policies)
  • Uses advanced monitoring/telemetry so engineers can troubleshoot issues in production
  • Scales reliably during peak demand
  • This is ideal when the agent is part of a larger application or service and needs full engineering and operational control.
  • Agents in Microsoft Foundry can be integrated with agents in Copilot Studio as part of a hybrid approach.

Choose this when: you need a code first approach, more control, complex integrations, advanced observability/evaluation, integration with pipelines, or you’re building an agent as an application that must run at scale.


These options are not mutually exclusive. Many organisations start with simpler agents and move up the stack as requirements around control, scale, integration, and observability increase.

Naming note: Microsoft’s naming has evolved over time. The embedded agent experience inside Microsoft 365 Copilot (Agent Builder) has also been referred to as Copilot Studio “Lite”. The standalone Microsoft Copilot Studio experience evolved from Power Virtual Agents (PVA).

Quick decision guide

  • Choose Agent Builder if you want a quick internal agent for yourself or a small team, built directly in the Microsoft 365 Copilot experience with no coding experience needed.
  • Choose Copilot Studio if you need workflows/actions, connectors, publishing, authentication options, and broader rollout across different channels, such as a website/web app, Microsoft Teams, Microsoft 365 Copilot, SharePoint, and other supported channels.
  • Choose Microsoft Foundry if you’re building an agent as an application and need pro-code control, deeper Azure integration, DevOps, and production-grade monitoring/evaluation.

Copilot Studio vs Microsoft Foundry (the simplest way to understand the difference)

A way to view this is SaaS (Software as a Service) vs PaaS (Platform as a Service).

  • Copilot Studio is a managed, low‑code SaaS experience, designed for business teams, makers, and IT pros who want to build agents quickly with plug and play integrations and minimal infrastructure management.
  • Microsoft Foundry is a more Azure native, pro‑code PaaS approach, designed for professional developers and engineering teams who need fine-grained control over runtime, integrations, security configuration, and DevOps practices.

The key trade off: Copilot Studio optimises for speed and simplicity, while Foundry optimises for control and flexibility, especially at scale.


Security and governance


A common worry is: “Will an agent expose data users should not see?”

1) The most important principle: agents are designed to respect existing permissions and access controls

In Microsoft 365, agents are designed to respect your existing access model. For example, SharePoint agents respond based on what the current user is allowed to access. If the user doesn’t have permission to a file or site, the agent will not surface information from it. This is why cleaning up overshared SharePoint sites and using clear permissions is one of the best security improvements you can make before rolling out agents.

2) Microsoft Purview: governance for prompts, responses, and AI usage

Microsoft Purview is the place to apply security and compliance controls to AI interactions (prompts and responses) using the same tools you already use for Microsoft 365 data. This can include:

  • Auditing and investigation support (who asked what, when)
  • Data classification and sensitivity labels
  • Data Loss Prevention (DLP) to reduce accidental oversharing
  • eDiscovery, retention, and lifecycle management
  • Insider Risk and Communication Compliance

In other words: Purview helps you treat AI interactions as governed business data, not random chat.
Purview Auditing = who did what where in Copilot?
Purview eDiscovery = searching for the actual prompt and response

3) Controlling rollout: block agents, limit who can use them, and require approval

You don’t have to let everyone build or use agents on day one. A safe rollout usually looks like this:

  • Start with a pilot group (selected users)
  • Allow only approved agents to be available broadly
  • Block or remove agents that aren’t compliant or aren’t needed

For Copilot native agents built with Agent Builder, sharing is intended for limited access (for example, a small team) rather than formal organisation wide deployment. For broader rollout and multi channel publishing, use Copilot Studio and follow your organisation’s approval process before the agent becomes widely available.

4) Microsoft Foundry (Azure): security looks like an Azure workload

Foundry is the engineered option, so governance is handled like any other Azure application:

  • Identity and access control using Azure roles and Microsoft Entra ID
  • Network controls (private endpoints/VNET where needed)
  • Secrets management (for example Key Vault)
  • Monitoring and tracing (so you can see what happened and debug issues)

This is ideal when you need deeper control, but it also means more responsibility and stronger engineering discipline.

5) Defender for Cloud for AI: detecting agent specific attacks

Agents introduce new attack paths (prompt injection, jailbreaking, data leakage, credential theft, and more). Microsoft Defender for Cloud includes threat protection for AI services that helps detect and respond to these threats, and can integrate with Defender XDR so AI related alerts appear alongside the rest of your security incidents. For Foundry agents, Microsoft has also introduced specific protections and recommendations focused on the agent lifecycle (inputs, memory, tool calls, and actions).

6) What’s coming next: Microsoft Agent 365 (the control plane for agents)

As organisations create more agents, the challenge becomes visibility and control:

“How many agents exist, who owns them, what can they access, and are they behaving safely?”

Microsoft Agent 365 is designed to address this by giving IT and security teams a central control plane to discover, govern, and manage agents including third party agents at scale, including agent identity, access control, observability, and integration with Purview and Defender. As this matures, it should help organisations move from agent sprawl to governed, auditable deployments.

7) and others – Check out the Zero Trust Workshop

I’d recommend checking out Microsoft’s free Zero Trust Workshop, which now includes an AI security pillar with guidance for securing AI resources and agents. You can access it here: https://zerotrust.microsoft.com/


Agent Builder vs Copilot Studio vs Foundry Comparison

.Agent BuilderMicrosoft Copilot StudioMicrosoft Foundry (Azure)
Best forQuick, internal agents for individuals or small teams, ideal for simple, scenario specific help (for example onboarding or coaching) built directly inside Microsoft 365 Copilot Chat.Business agents that can answer and take action (workflows, integrations, and broader rollout beyond a small team).Production grade, engineered AI agents built as applications (complex scenarios, full engineering control).
Primary audienceInformation workers and beginners who want to create simple, Copilot native agents quickly (no code).Business teams, makers (low‑code builders), and IT adminsDevelopers, software engineers, and data/AI teams with strong coding and DevOps
Skill levelNo‑code
(built using natural language inside Microsoft 365 Copilot).
Low‑code
(UI‑based building; minimal coding for most scenarios).
Pro‑code
(engineering and DevOps skills typically required).
Platform modelCopilot native experience inside Microsoft 365 Copilot Chat (designed for quick, straightforward agent creation without managing infrastructure).Managed, Microsoft‑hosted service (SaaS‑style), so you don’t manage servers/infrastructure.Azure native PaaS (Platform as a Service) in your Azure subscription for maximum control.
Where it runsInside Microsoft 365 Copilot experiencesRuns in a Microsoft hosted Copilot Studio service within a Power Platform environment. You publish it to channels (Teams/M365, web, etc.) rather than hosting it yourself.Runs on Azure. You manage the supporting Azure resources and operational setup (like any other cloud application).
Integration approachFocused on simple, Copilot‑native configuration with selected knowledge sources (for example SharePoint content and Microsoft 365 Copilot connectors) to keep the agent scoped and easy to maintain.Uses built‑in connectors and low‑code workflows/topics to connect to Microsoft 365 and other systems.Deep integrations via code with Azure services and enterprise systems (ideal for complex architectures).
Dev experienceSimple build experience using natural language and basic configuration (Describe/Configure). Includes a built‑in test experience so you can try the agent and refine it quickly.Build with a visual UI (topics, tools/actions, publish), designed for fast iteration.Code first development with SDK/tooling and CI/CD integration into your existing engineering workflows.
Deployment channelsRuns inside Microsoft 365 Copilot experiences (microsoft365.com/chat, office.com/chat, and Teams desktop/web). You typically share it with specific people for internal use rather than publishing across multiple channels.Publish to multiple channels (for example Teams and Microsoft 365, web, and other supported channels).Flexible delivery options. Expose via APIs or integrate into apps/services and custom channels (you choose the delivery pattern).
ObservabilityBasic adoption/usage visibility through Microsoft 365 Copilot agent reporting (for example active users/sessions and agent inventory), rather than deep application style tracing/telemetry.Built‑in analytics and usage insights for deployed agents (good for adoption/performance tracking).Strong production monitoring and debugging capabilities, including tracing into Azure Application Insights using OpenTelemetry.
EvaluationBasic testing through the built in “Try it” experience to validate behaviour and then refining instructions if needed.Supports testing and a publish/re‑publish lifecycle (so changes go live only when you publish).More rigorous testing and debugging options suited to production engineering and quality control.
CostIncluded with Microsoft 365 Copilot. Copilot Chat business users (without a Copilot license) can use web grounded agents free, but tenant data grounding requires metered billing.If users have a Microsoft 365 Copilot license, they can use Copilot Studio agents inside Microsoft 365 without separate per‑use billing in many employee scenarios. Otherwise, Copilot Studio usage is paid via Copilot Credits (packs or pay‑as‑you‑go). More info hereAzure consumption billing, you pay for the Azure resources and services used by your solution.
Model Choice and Fine TuningNo explicit model selectionLimited model selection available (choose the primary model; admins can control access to preview/experimental and external models).Largest model choice and fine‑tuning (broad model catalog including over 10,000 models; fine tune supported models to fit your needs).


Examples (Mapping a scenario to a platform)


Example 1: Internal policy helper
A small HR team wants an agent that answers common policy questions using approved internal content (for example, leave policy, expenses, onboarding). Agent Builder is a good fit because it’s quick to set up inside Microsoft 365 Copilot and works well for simple internal scenarios.

Example 2: IT helpdesk agent that can take actions
You want the agent to answer questions and trigger workflows (for example, create a ticket, check ticket status, notify an on-call engineer, or run an approval). Copilot Studio is typically the better fit because it’s designed for business workflows, connectors, and publishing to multiple channels.

Example 3: Customer support agent embedded in a production application
You’re building a customer facing agent inside a web/app experience that must securely access order data, enforce business rules, and perform actions like creating tickets or initiating refunds. You need strong operational controls (monitoring/tracing) and private networking options. Microsoft Foundry is built for this agent as an application scenario.

Summary: how to choose without overthinking it


There isn’t a single best option. The right choice depends on your team, your audience, and how much control you need.

If you need something quick and internal, start with Agent Builder.
If you need automation, connectors, and broader rollout, use Copilot Studio.
If you need full engineering control, deep Azure integration, and production operations, use Microsoft Foundry.
Organisations can also use a mix of the above.

The images below summarise the three solutions:

AgentBuilder vs CopilotStudio vs Foundry

One last example that usually makes it click:

Agent Builder = enter a store and grab a pre‑packed sandwich (fast, minimal choices).

Copilot Studio = enter a restaurant and order a freshly made sandwich from a menu (more options, still managed for you).

Microsoft Foundry = you’re the chef. You choose the ingredients and the recipe, and you’re responsible for all operations.

I hope you found this post useful. See you at the next one.

Backups vs Replication vs High Availability vs Fault Tolerance vs Disaster Recovery

Reading Time: 10 minutes


In IT, the following terms come up frequently:

  • Backups
  • Replication
  • High Availability
  • Fault Tolerance
  • Disaster Recovery

In this post, I will explain what each one means, why they exist, and when to use them, using simple language and real‑life examples.

An important thing to remember is that these are not competitors, they work together.

A good setup often uses:

Backups → recover from mistakes, corruption, or attacks (get my data back)
Replication → keep data in sync between locations (supports faster recovery)
High Availability → reduce or avoid downtime (stay online during failures)
Fault Tolerance → keep running even if something fails (no interruption)
Disaster Recovery → survive major outages and disasters (recover from the worst)

Let’s start in the following order: Backups, Replication, High Availability (HA), Fault Tolerance and then Disaster Recovery (DR).

Backups


What is a backup?
A backup is a saved copy of your data from the past. If something goes wrong, for example, files are deleted, corrupted, or a system fails, you can use a backup to restore your data to an earlier point in time.

Backup Example 1:
You regularly copy your important files (documents, photos, work files) from your laptop to an external hard drive and then disconnect it. If your laptop is lost, damaged, or the hard drive fails, you can plug in the external drive and restore your files. The backup is a separate copy created earlier, so even if the laptop is gone, the data still exists.

Backup Example 2:
A small business stores customer records, invoices, and reports on a company server. Every night, these files are backed up to a secure off‑site location. One day, ransomware encrypts the main server. The business wipes the server and restores the data from the previous night’s backup, allowing work to continue. The business is able to restore data from a safe, unchanged copy created before the incident. This protects against accidental deletion, cyber attacks, and system failure.

Note: Ransomware attack
An attacker encrypts your files so you can’t access them and then demands a payment (usually money) in exchange for unlocking or decrypting the data.

Backup Example 3:
A company backs up its database every night. If someone deletes data by mistake, IT restores yesterday’s backup.

Summary of when backups are used


Backups are used when data needs to be recovered from a previous safe copy, such as in the following situations:

  • Accidental deletion – “Oops, I deleted the wrong file”
  • Ransomware attacks – Data is encrypted or made unusable, and systems must be restored from a backup created before the attack.
  • Data corruption – Files or databases become damaged or unreadable due to software issues, hardware failure, or crashes.

Pros of backups

  • Backups are usually less expensive than High Availability or Disaster Recovery solutions.
  • Protects against human mistakes – Helps recover data after accidental deletion or overwriting.
  • Allows point‑in‑time restore – You can restore data from a previous state (for example, yesterday or last week).

Cons of backups

  • Systems may be unavailable during restore – Services can be down while data is being recovered.
  • Recent changes may be lost – Any data created after the last backup is not included in the restore.
  • Recovery is not instant – Restoring data can take time, especially when large amounts of data are involved.


Replication


What is replication?
Replication means automatically copying data to another location so that changes are copied continuously or near real time. Once replication is set up, it usually runs automatically in the background. When data changes on the main system, the same change is sent to the replica without manual action.

Replication Example 1:
You type notes on your laptop and they quickly sync to another laptop. If you delete a sentence on one device, it disappears on both. Replication keeps copies in sync, so any change, good or bad, is automatically copied to all replicas.

Replication Example 2:
A database is continuously replicated to another server, creating a live duplicate. The second server is kept up to date, even if no failover has happened.

Replication Example 3:
An online store uses replication to keep a second copy of its database up to date. A staff member accidentally deletes thousands of customer orders from the main database. Because replication copies every change, the deletions are also applied to the second server. As a result, both databases are missing the orders.

Replication Example 4:
A company has a file server in one data centre and continuously copies changes to a second server in another location. When a file is updated on the primary server, the same change is automatically copied to the second server after a short delay (depending on replication configuration).

When replication is used

  • To reduce downtime by keeping a ready to use copy available if the primary system fails.
  • Replication is commonly used in high availability designs and disaster recovery strategies to improve resilience.

Pros

  • Fast recovery – Systems can switch to a replicated copy quickly when a failure occurs, reducing recovery time.
  • Minimal data loss – Data is copied in near real time
    Note: A small amount of data loss may occur if the latest changes were not able to replicate before the failure.
  • Supports business continuity – Replication reduces downtime and helps businesses continue operating during outages or infrastructure failures.
  • Systems stay current – Replicated systems remain up to date with ongoing changes.

Cons

  • Replicates mistakes and corruption – If data is accidentally deleted or becomes corrupted, replication copies the same problem to all replicas. Replication improves availability, but backups are still required to recover from mistakes or data corruption.
  • Does not protect against human mistakes – Actions such as accidental deletions, overwriting data, or running the wrong command are replicated automatically and cannot be reversed using replication alone. Some platforms combine replication with snapshots or point‑in‑time recovery, which allows rollback, but this capability comes from the snapshot or recovery layer, not from replication itself.
  • More expensive than backups – Replication typically requires additional infrastructure, storage, networking, and management, making it more costly than traditional backup solutions.

High Availability (HA)


What is High Availability (HA)?
In today’s world, smooth operations of applications is crucial for businesses, but issues to those applications can pose challenges. High Availability helps IT systems stay available during common failures and periods of heavy usage. It is designed to keep services running for long periods with minimal downtime, often by automatically switching to healthy components when something fails. Many platforms also allow planned manual switchovers during maintenance or upgrades.

High Availability and replication work together, but they are not the same thing.
Replication is commonly used in High Availability, especially for data (like databases), but High Availability also uses things like load balancers and multiple servers to keep services running. High Availability focuses on keeping services online, while replication ensures that data already exists on another system. When a failure happens, High Availability mechanisms (often automatic failover) can switch to the replicated copy, allowing the system to continue operating with minimal or no downtime.

In short, High Availability keeps a service running by having another copy ready. For websites, that can mean multiple servers behind a load balancer. For data (like a database), it often means keeping a second copy of the data in sync so the system can switch over quickly.

HA Example 1:
A supermarket has multiple checkout tills. If one till breaks, customers are redirected to another till, so the shop continues operating without closing.

HA Example 2:
A shopping website runs on multiple servers at the same time behind a load balancer. If one server fails, incoming traffic is automatically redirected to another server, so customers can continue shopping as normal.

HA Example 3:
A hospital system runs patient records on two servers at the same time. If one server fails, the service continues with minimal downtime, so doctors and nurses can still access patient information.

HA Example 4:
A company uses two internet connections from different providers. If one internet connection goes down, traffic automatically switches to the other, so staff can continue working without noticing any outage.

Note: Load balancer
A load balancer distributes traffic across multiple servers so the service stays available.

When High Availability is used

  • Public websites and apps
  • Banking and payment systems
  • Online shopping platforms
  • Any service that must always be on

Pros

  • Minimal downtime
  • Automatic failover when failures occur (common in many HA setups)
  • Better user experience

Cons

  • Typically requires more infrastructure and can cost more than backup alone
  • More complex to design and manage
  • Does not protect against accidental data deletion (backups are still required)


Fault Tolerance (FT)


What is Fault Tolerance (FT)?
Fault Tolerance is related to High Availability, but it goes a step further. It is the ability of a system to continue operating during a failure, often with very little or no noticeable interruption, depending on the design. This usually requires duplicate components already running in parallel, so if one component fails, another can take over immediately. Because fault tolerance requires extra redundancy, it is usually more complex and more expensive than high availability.

Fault Tolerance Example 1:
A server has two power supplies connected to separate power sources. If one power supply fails, the server continues running on the other one, and users don’t notice any disruption.

Fault Tolerance Example 2:
A storage system uses RAID. If one disk fails, the system continues running and data remains available while the failed disk is replaced.

Fault Tolerance Example 3:
A critical service runs on two identical systems in parallel. If one system fails, the other continues processing without needing a restart, so users do not experience any downtime.

Fault Tolerance Example 4:
A network has two separate network paths (for example, two switches or links). If one path fails, traffic automatically switches to the other path and the connection stays up.

Fault Tolerance Example 5:
A company uses a Standard (zone‑redundant) Azure Load Balancer with virtual machines deployed across multiple Availability Zones. If one Availability Zone has an issue, the load balancer automatically routes traffic to the healthy zones, allowing the service to continue running.

Fault Tolerance Example 6:
A company stores important files in an Azure Storage account. Azure Storage automatically keeps multiple copies of the data to improve durability and availability during hardware, power, or network failures. The level of resilience depends on the redundancy option chosen, such as copies within one datacentre, across Availability Zones, or in a secondary region. Check out the following diagram to learn more about Storage account replication options in Azure: Storage_Replication_Options.

When Fault Tolerance is used?

Fault tolerance is used when a system must keep working even if something breaks.

Instead of waiting for someone to fix the problem, the system is designed with redundancy so another component can keep things running.

Fault tolerance is used when:

  • Even a short outage is unacceptable (downtime has a serious impact).
  • The service must continue operating even if a server, disk, or network component fails.
  • The system is considered mission‑critical (for example, payment processing or critical business systems).

Fault tolerance is achieved using techniques like redundancy and failover, so the system can continue operating even when a failure occurs.

Pros of Fault Tolerance

  • No interruption during failures, users don’t notice the issue
  • Very resilient to component failures because redundancy is already running
  • Best option for systems where downtime is not acceptable

Cons of Fault Tolerance

  • More expensive – requires extra duplicated components running in parallel
  • More complex to design and manage (because systems need to stay in sync)
  • Does not replace backups – if data is deleted or corrupted, fault tolerance can keep the service online, but you still need backups to restore a clean copy.
  • Disaster Recovery (DR) is still required for datacentre‑level or regional disasters.

High Availability (HA) is not always Fault Tolerance (FT)

A company runs two web servers behind a load balancer, so if one server fails, the other can keep the website online. However, both servers are placed in the same rack or share the same power or network equipment. If that rack fails, both servers go down and the website becomes unavailable. To make the system fault tolerant to a rack failure, the company places the servers in separate racks with separate power and network paths. Now, a single rack failure won’t take out both servers at the same time. Fault tolerance isn’t about having two servers, it’s about making sure the two servers don’t fail for the same reason.

Disaster Recover (DR)


What is Disaster Recovery (DR)?
Disaster Recovery is a plan and setup used to restore systems and data after a major failure or disaster, such as a data centre outage, cyberattack, or natural disaster.

Unlike High Availability, which tries to keep systems running, Disaster Recovery assumes a major outage can happen and focuses on how to bring everything back after a serious incident. For example, a complete data centre/region failure, such as a natural disaster, flooding, tornado, something which takes the entire region offline. You will declare a disaster and initiate a failover from your primary site to your secondary site. You could attempt to recover all of the data in the secondary site from backups but this could take a long time.

HA = stay running through smaller failures
DR = recover after a major outage that high availability alone cannot handle

Note: DR failover can be manual or automated depending on the tools used, but it usually involves a planned process and may take longer.

Why Disaster Recovery is different from High Availability


High Availability (HA) aims to prevent downtime by switching to healthy systems when something fails, often without users noticing. It is designed for small, common failures, such as a server crash or hardware fault.

Disaster Recovery (DR) is used when HA is not enough, for example when an entire site or region is unavailable. DR focuses on restoring services and data after a major outage, and it can take longer than HA.

Disaster Recovery follows planned recovery steps (which can be manual or automated) to bring systems back online after a serious incident. High Availability focuses on keeping systems running, often automatically, and often without users noticing, during smaller failures. They are different, but they work together. High Availability reduces everyday downtime, and Disaster Recovery provides a fallback when a major disaster occurs.

DR Example 1:
Your office burns down, so you move work to a backup building that was prepared in advance. This is an example of Disaster Recovery.

DR Example 2:
An organisation has two data centres: a primary and a secondary. The secondary data centre is used for Disaster Recovery. Data is continuously replicated to the secondary data centre. If the primary data centre goes offline, failover to the secondary site is performed as part of the Disaster Recovery plan.

DR Example 3:
A company’s file server is taken offline after a cyberattack. The Disaster Recovery (DR) plan is activated to rebuild the server and restore business operations. As part of the DR plan, data is restored from backups, and work resumes after recovery is complete.

DR Example 4:
A ransomware attack encrypts an organisation’s systems. The affected systems are wiped and rebuilt, and clean data is restored from backups. This is an example of Disaster Recovery.

When Disaster Recovery is used

  • Data centre failure
  • Cloud region outage
  • Floods, fires, or cyber attacks

Pros

  • Protects against large‑scale disasters
  • Covers entire systems and services, not just data
  • Can combine replication and backups for faster recovery and data protection

Cons

  • More expensive than backups alone
  • Recovery is not always instant and may involve downtime
  • Requires careful planning, documentation, and regular testing. The right test frequency depends on the organisation and workload, but disaster recovery plans should be practiced regularly.

Why do all these matter and when should an Organisation consider them?


Many organisations don’t think about backups, replication, high availability, or disaster recovery until something breaks. But when a system goes down, the impact can be serious: work stops, customers can’t access services, revenue can be lost, and trust can be damaged. For some systems, there can also be compliance or legal consequences. That’s why it helps to decide in advance what level of downtime and data loss is acceptable, then choose the right approach based on that.

A simple way to choose between these options is to understand two terms:

  • RTO (Recovery Time Objective): the maximum time you can tolerate the service being unavailable after an outage. In other words: “How long can we be down before it becomes a real problem?”
  • RPO (Recovery Point Objective): the maximum amount of data loss you can tolerate, measured in time. In other words: “If we have to restore, how far back in time can we rewind without major impact?”

Think of it like this: the faster you need to be back online (low RTO), the more you move towards HA/replication. If you mainly need to get data back (even if it takes longer), backups matter most.

I hope you found this post useful. Please feel free to share any feedback or comments below. Thank you