
Employees can now build Copilot agents themselves and submit them for organisation-wide use. Microsoft has rolled out a formal approval workflow through the Agent Store: IT admins review submissions, approve or reject, and control what becomes available across the organisation. How does this process work and what does your IT team need to set up?
Over the past months, Microsoft has made it easier for regular Microsoft 365 users to build their own Copilot agents via Agent Builder. No code, no IT ticket. A sales team member builds an agent that answers questions about the product catalogue. An HR employee creates an agent that handles the most common questions about leave policies. And then what?
Until recently, such an agent stayed with its creator, or was shared informally. From early July 2026 that has changed. Microsoft has rolled out a formal submission process that lets employees offer their agent for use across the organisation, via the Agent Store. The IT admin is central to that process.
The Microsoft 365 Agent Store is the central place where users discover and activate Copilot agents. Until now, only external agents from the Microsoft and partner catalogue appeared there. That has been expanded with a third category: 'Built by your org'. These are agents that employees within the organisation have built and that an admin has approved for broad use.
An employee who has built an agent in Agent Builder can now submit it via the 'Submit for org use' button. This places the agent in the IT admin's queue as a request under Agents in the admin centre. Only after approval does the agent become visible in the Agent Store for all users or a selected target group.
Agent Builder is built into Microsoft 365 Copilot. Every user with an active Copilot licence can use it to build an agent. The principle is straightforward: the creator defines what the agent does, which knowledge sources it consults, and how it communicates. An agent can be connected to SharePoint libraries, public websites, and externally approved API connections that the admin has enabled.
The power lies in the combination of a clearly defined system prompt and the right knowledge sources. An agent connected to the legal department's current SharePoint site and instructed to always reference the source page gives noticeably more consistent answers than when everyone queries Copilot freely. For departments with many repetitive information questions, that is a direct time saving.
When an employee submits an agent, the Microsoft 365 admin receives a notification in the admin centre. Via Agents in the left menu, then All agents and then Requests, the admin sees the queue of submitted agents.
For each submission, the following information is available: the name and description of the agent, the creator, the connected knowledge sources, and the agent's configuration. Based on this, the admin decides whether the agent meets organisational standards for security, data protection, and quality. Clicking Approve makes the agent immediately available in the Agent Store. Clicking Reject sends the creator a notification, after which they can revise the agent and resubmit.
Admins can also restrict an approved agent to a specific group. This makes it possible to first make an agent available to the creator's own department, and after positive feedback to broaden it to the whole organisation. That makes phased rollout achievable without additional development effort.
Alongside the Agent Store expansion, a second related capability has been rolled out: agents built on the Model Context Protocol are now directly accessible from Word, Excel, PowerPoint, and Outlook. Via the Copilot pane in these apps, users can invoke MCP agents without switching applications.
Where this previously only worked through the separate Copilot interface, the agent is now embedded in the workflow. An agent that retrieves contract information from a SharePoint library works directly from Word. An agent that displays sales data from a CRM system is accessible from Excel. IT admins control which MCP servers are approved for use, similar to managing other integrated apps.
The rollout of these capabilities creates a new area of attention for IT teams. Four concrete actions to maintain control over the growing agent landscape within your organisation.
Define the licensing policy. Agent Builder is available to users with a Microsoft 365 Copilot licence. If not everyone in the organisation has a Copilot licence, it is worth determining who may build and submit agents. Communicate this clearly so employees know which channel to use.
Establish review criteria. Before submissions arrive, it helps to agree internally on what requirements an agent must meet to gain approval. Consider: which data sources are permitted, how is confidential information handled, is a privacy assessment required for agents that process personal data, and who is responsible if an agent provides incorrect information.
Assign review responsibility. Approving agents is not a purely technical action; it also requires substantive judgement about use and risk. Consider an approval committee with representatives from IT, legal, and where relevant compliance, especially for agents that touch sensitive business processes.
Communicate the existence of the official route. Employees who do not know that a formal channel exists will share agents informally via chat or email. That undermines the purpose of the Agent Store. A short announcement via Teams or an intranet post about the new capability is enough to drive usage through the approved route.
Building Copilot agents was already possible, but distributing them happened without oversight. With the Agent Store, Microsoft has created a formal channel that enables IT teams to safeguard quality and security without limiting employee autonomy. The employee who builds a useful agent now has a legitimate route to share it more broadly. The IT admin retains oversight and control. That is a better starting position than the informal distribution that was the norm before.
Want help setting up a review process for Copilot agents, drafting an agent policy, or connecting secure knowledge sources to your organisation's agents? Contact Zarioh for a no-obligation conversation.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

AI Agents

AI Agents

AI Agents