What has to be true before you build a Copilot Studio agent, which tools already exist to do the work, and where the recurring revenue lives once the build is finished.
Start with The Copilot Studio Agent Engagement — the same seven phases as phase cards, decision tables, rate cards, checklists and a drift register, and the version to work from when you are scoping, quoting or running the account. This page is where its figures come from: the reasoning in full, the evidence and its weaknesses, and the sources behind every claim. Read it once; deliver from the other one.
This section is the whole engagement on one page: the first conversation, the assessment that pays for itself, the build, and the thing that is still generating revenue two years later. Everything after it is detail. A partner who reads only this section should be able to describe a complete, well-run Copilot Studio engagement to a customer — what happens, in what order, how long it takes, who does it, what gets signed, and what has to be true in the tenant at each step. Every phase below links down to the section that does the work.
Two other staircases exist on this site, and this is neither of them. The six-stage ladder in section 9 of the Frontier Partner Playbook measures your practice as it matures across many customers. The five-phase worklist in section 4 of the Ops Companion is your internal delivery instrument — Discover, Design, Build & Test, Deploy & Train, AgentOps — and it is the right document to hand a delivery lead on day one of a build. This arc is one customer's engagement, end to end, and it is wider than the worklist at both ends. It adds two billable phases ahead of Discover, and it carries a credit-management layer after go-live that the worklist has no concept of because it predates metered agents.
Read the table across, not down. The Paper column names the shape of the commercial instrument, never a rate — the rates live in section 10 of the Frontier Partner Playbook, and this page does not restate them. Who delivers names the organisation, not the job title; for roles, the minimum viable team and what you can safely subcontract, see section 15 of the Copilot Readiness Engagement.
| Phase | Duration | Who delivers | Paper | Licensing — what must be true | Detail in |
|---|---|---|---|---|---|
| 0 · Standing and visibility no paper The conversation you are already entitled to have |
One conversation, 30–60 minutes. Longer if a discovery scan runs first | Partner — the existing account relationship | None. If you are writing paper here you have mistimed it | Any Microsoft 365 or Office 365 subscription. No Copilot seat. Copilot Chat is included and can consume custom agents on a metered basis | §2, §3, and the Shadow AI Assessment Guide for the discovery-led opening |
| 1 · The agent governance baseline assessment What is already running, and how far it can reach |
1–2 weeks | Partner. No vendor purchase required first | Fixed-fee assessment. Short-form — this is not the build SOW | Power Platform administrator access, plus AI Administrator or Global Reader. Microsoft recommends least privilege over Global Admin. Nothing needs buying | §6 — and section 9 of the Copilot Readiness Engagement for why the Copilot equivalent of this phase stalls in an SMB tenant |
| 2 · Candidate and baseline assessment One named workflow, and the number you will be judged against |
1–2 weeks — Weeks 1–2 of the build-side clock | Partner, with the customer’s named process owner. The owner is not optional | Assessment, or the first phase of the SOW | None new. The constraint here is organisational, not licensing — somebody has to own the process | §9 |
| 3 · Prerequisites and harness sow The environment, the boundary, and which runtime you are building on |
2 weeks — Weeks 2–4 | Partner, with the customer’s Power Platform admin. Distributor for the licensing conversation | SOW | A Power Platform environment with Dataverse, production or sandbox — trial and developer environments are not eligible for pay-as-you-go. A DLP policy separating Business from Non-Business connectors. Managed Environments if you need sharing limits or pipelines — see the open question at §7 | §5, §7 |
| 4 · Economics the skipped one What it costs to run, and who pays for the build burn |
2–3 days, inside phase 3’s window. It gates the quote | Partner. Distributor for capacity packs | None of its own — its output is the number the build SOW is written around | Copilot Credit capacity packs. Since April 2026 these can be bought without an Azure subscription. Per-agent monthly caps configured before launch, not after | §8 |
| 5 · Build and deploy sow The part that looks like the project |
Weeks 4–8 simple, 4–14 complex; live by Weeks 8–10 | Partner — or a prebuilt-agent vendor for the first 80%, with the partner carrying the last mile | SOW. The retainer is signed here, not later | Capacity packs live. The harness decides when billing starts — on one of them your own development and QA consume the customer’s credits before anything is published | §5, §12 |
| 6 · Managed AgentOps recurring Where it stops being a project |
Indefinite. 90-day measurement cycle, then a sponsor review that scales it or retires it | Partner. Microsoft operates the platform beneath you and changes it without asking | Retainer — a managed services agreement, not a renewal of the build | Capacity packs and caps under active management. Agent 365 only when a trigger fires, not as an entry ticket | §10, §11, and section 10 of the Frontier Partner Playbook for what to charge |
Every other phase in this arc has an obvious owner and an obvious moment. Economics does not. It sits between the design work and the quote, it produces no deliverable the customer asked for, and it is the easiest thing in the engagement to defer. So partners defer it — they quote build labour, sign the SOW, ship the agent, and let the customer discover the monthly run rate on a Microsoft invoice they were never shown a forecast for.
That is the single most relationship-damaging move in this motion, and it is entirely avoidable. The estimate takes days, the tooling is free and published by Microsoft, and the per-agent cap that prevents the worst outcome is a setting nobody has to buy. §8 is the whole method — estimate, cap, monitor, true-up — and it is also where the recurring revenue in this arc actually comes from.
Phases 0 and 1 sit entirely before the point where the build worklist begins, and both are billable. A partner whose engagement starts at Discover has given away the assessment that qualifies the customer, the finding that justifies the SOW, and the only work in the arc that can be sold into a tenant which has bought nothing yet. Phase 1 is the wedge — §6 is why it works where the Copilot readiness assessment does not.
Agent Inventory has not yet been run against a real SMB tenant for this guide. How many agents already exist in a typical Business Premium tenant — and how many use maker credentials, no authentication, or have no named owner — is unknown. Phase 1’s duration is scoped on the work the assessment requires, not on a measured finding count, and a tenant with dozens of undocumented agents would push it past two weeks.
What would settle it: run Agent Inventory from the Copilot Agent Kit against three real SMB tenants and record agent count, authentication mode, credential mode and ownership state for each. The tool is free and the run is non-invasive.
§1 is the standard. This section is what is actually being sold instead, and the three ways it breaks. Each break is resolved by a later section, and it is worth naming which one now, because the rest of this guide is the resolution.
Partners gravitate to building an agent because an agent is project-shaped. It has a scope, a demo, a delivery date and a number. It fits the way a partner already sells — a statement of work, a fixed fee, a handover. Nothing about that instinct is irrational, and that is exactly the problem: familiarity is doing the work that analysis should be doing. The engagement gets structured around the part that is easiest to quote rather than the part that carries the risk or the revenue.
This guide does not re-argue how to price outcome-based work — the fixed base, the kicker, and the five gates are already written up in the outcome-based project work primer. The argument here is narrower and comes earlier: the shape of the engagement is wrong before the pricing model is even chosen.
Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027, and names three causes: escalating costs, unclear business value, and inadequate risk controls. It also names “agent washing” — vendors rebranding assistants, RPA and chatbots as agentic — and estimates that only about 130 of the thousands of agentic AI vendors are real. A January 2025 Gartner poll of 3,412 webinar attendees found 19% had made significant investments in agentic AI, 42% conservative, 8% none, and 31% waiting or unsure.
Read the three cancellation causes against the arc in §1 and they are not abstract risks. Escalating cost is phase 4 skipped. Unclear business value is phase 2 skipped. Inadequate risk controls is phase 1 skipped. Gartner is describing, in aggregate, engagements that started at the build.
This one is not an analyst's opinion. It is Microsoft describing its own customers, in the guidance page that also supplies the ROI formula:
Instrumentation is strong during the pilot, and then drifts as the agent moves to production.Microsoft Learn — Measure the impact of your agents, “Measurement that stops at pilot”
A project-shaped engagement makes this almost inevitable. Instrumentation is scoped as part of the build, the build ends, and nobody owns the signal afterwards. §9 is the whole answer — including the two further failure patterns Microsoft names in the same breath, one of which retires the slide most of the channel is currently presenting.
The third break is the reason this page exists. A partner sells a flat monthly fee. The cost of delivering it is not flat — it moves with prompts, with actions, with how long an agent runs in the background. The customer's invoice stays the same every month while the cost of honouring it does not. ChannelE2E put the state of the channel plainly in its own headline: AI-native is the new pitch; MSPs are still working out the pricing.
A flat-fee managed service over a metered cost base is a margin trap, and it is the single most likely way for a partner to lose money on an agent that is working perfectly. §8 resolves it — not by avoiding metered billing, but by turning the meter into the recurring service. That is the argument this whole guide is built to land.
Through mid-2026 a large, sustained community grievance ran about GitHub Copilot credit consumption: allocations exhausted in days, and a core complaint that there was no cost preview before a task runs. That is GitHub Copilot credits, not Copilot Studio Copilot Credits. They are different meters on different products and this guide does not conflate them.
It is admissible for exactly one thing, and it is worth having in mind before phase 4: it shows how customers react when metered AI billing surprises them. The reaction is not a renegotiation. It is a loss of trust in whoever sold it.
Gartner says these projects get cancelled on cost and unclear value. Microsoft says measurement drifts after the pilot and that time-savings claims undermine credibility. The channel's own trade press says the pricing model does not match the cost base.
Every one of those is a gap between a project ending and an outcome being demonstrated. That gap is the partner's job, and it is where the recurring revenue is — which is the same claim as “the agent is never done,” approached from the commercial side rather than the technical one.
The prevailing channel sequence is sell Copilot seats → prove adoption → then talk about agents. That sequence gates the entire agent conversation behind a per-seat commitment the customer has not made, and for most SMB customers it is the reason the conversation never starts.
It is not a real prerequisite. Microsoft's own agent governance documentation says so directly:
Microsoft Copilot Chat is available at no additional cost for all Microsoft Entra account users with a Microsoft 365 or Office 365 subscription. … If your organization requires agents that incorporate your organization's data, you can provide access to agents that are billed based on metered consumption.Microsoft Learn — Prerequisites, Microsoft Copilot agent governance
Read that as a partner rather than as an admin. An agent engagement can begin in a tenant with zero Microsoft 365 Copilot seats. The customer's existing Microsoft 365 or Office 365 subscription is the entitlement; the agent's usage is metered separately in Copilot Credits. The seat is a capability upgrade, not an entry gate — and it can be sold later, on evidence, instead of first, on faith.
Metered is not free, and narrower is not the same as cheaper. Three things get given up on the no-seat path, and a partner who presents the unlock without them will be corrected by the customer's first invoice or the agent's first bad week.
| What you give up | Detail | Consequence |
|---|---|---|
| Free at the point of use | Agent usage is billed in Copilot Credits. Employee-facing usage is included for users who hold a Microsoft 365 Copilot licence, so the meter runs precisely because nobody has one | The run rate is now a line item somebody has to forecast — §8 |
| Reach | The Copilot chat harness publishes to internal teams only. Files, skills and memory are “not a focus”, and it does not retry or find alternative paths when a step fails | Scoping constraint, not a blocker — but it decides which harness you are on, which decides the bill. §5 |
| What the agent can read | Without a Microsoft 365 Copilot licence in the same tenant, generative answers can only use SharePoint files under 7 MB. With a licence, and tenant graph grounding with semantic search turned on, the limit is 200 MB | A licensing decision silently changes what the agent can read. Nothing errors. The agent simply does not know things |
That third row deserves to be read twice. It is the first appearance of a pattern that runs through this entire guide and gets its own component in §7: the failures that matter in Copilot Studio are usually silent. The agent reports healthy, answers confidently, and is simply missing the file that would have made the answer right.
Two mechanisms, and the difference matters at phase 4 because only one of them protects the customer from being switched off:
That is a genuine architectural choice with a commercial consequence, and it belongs in the phase 4 conversation rather than being discovered later. §8 carries it.
The documentation supports every sentence above, and the full path has not been walked in a live tenant for this guide. What is untested: in a Microsoft 365 Business Premium tenant with zero Copilot seats, can you purchase Copilot Credit capacity, allocate it to an environment, and publish a working agent that users reach through Copilot Chat — without hitting a licensing wall that the docs do not mention?
One related claim circulating in the channel is not asserted here: that since April 2026 capacity packs can be bought with no Azure subscription at all. What Microsoft Learn does state is narrower and is what this section relies on — that prepaid credits are managed through the Power Platform admin center, and that it is pay-as-you-go which requires linking an Azure subscription billing plan.
What would settle it: run it once. A Business Premium tenant, no Copilot seats, buy the smallest capacity allocation, publish one agent to Copilot Chat, and record every point at which a licence was requested. This is the cheapest high-value test in the register and it validates the central claim of the page.
This section exists to make §3 safe to say out loud. The obvious objection to “you don't need a Copilot seat” is that the readiness work still has to happen — and the readiness work is exactly what an SMB cannot afford or, as it turns out, cannot license. That objection is right about the work and wrong about which work.
Microsoft 365 Copilot grounds on the whole tenant graph. The moment a seat is assigned, every oversharing defect anywhere in the tenant becomes reachable. That is why the channel's readiness playbook is SharePoint Advanced Management, Data Access Governance reports and EEEU cleanup — the blast radius is the tenant, so the remediation has to be too.
And that path does not execute in most SMB tenants. The licence wall is documented in section 9 of the Copilot Readiness Engagement: the tooling the playbook depends on requires an E-SKU base, and Microsoft 365 Business Premium does not qualify.
An agent's blast radius is not the tenant graph. It is three much smaller things: what the maker explicitly pointed it at, who it acts as, and who can reach it. Those are Power Platform and Copilot Studio controls.
None of them require an E-SKU base. Authentication mode, credentials, sharing scope, connector policy and environment strategy are all reachable in a Business Premium tenant, and all of them are configuration rather than remediation.
The no-seat path does not remove the plumbing. It swaps it — trading a tenant-wide permissions remediation the SMB cannot license for a scoped agent-governance job it can.
This is not a licensing coincidence that happens to be convenient. It follows from the same constraint that §3 listed as a cost.
No Microsoft 365 Copilot licence in the tenant means tenant graph grounding is not on the table. The agent reads only the knowledge sources a maker explicitly attached — and under generative orchestration each agent is capped at 25 SharePoint site URLs. The metered path is narrower than the licensed path, and the narrowness is the safety property. You assess twenty-five named sites, not the whole tenant.
That is what makes the phase 1 assessment in §1 a fixed-fee, one-to-two-week engagement instead of an open-ended remediation programme. The scope is bounded by the product.
Overstating this would be the most damaging thing in the guide, so here is the limit, stated in the section rather than buried in a footnote.
With end-user credentials — the secure default — the agent resolves the signed-in user's own permissions. So a genuinely overshared site inside those twenty-five remains reachable by exactly the people who could already reach it. The oversharing defect is not fixed by scoping the agent.
What shrinks is amplification: the problem of a machine surfacing something a user could technically open but would never have found. That shrinks from tenant-wide to twenty-five named sites, which is the difference between a programme and a task.
And it shrinks only while the credential setting holds. Flip it to maker-provided credentials and the whole argument inverts — every invoker inherits the maker's permissions, and the twenty-five-site boundary stops being a boundary at all. That setting is the first thing §6 audits, and it is the reason §6 exists.
So the honest formulation, and the one to use in front of a customer: you still assess the sources you ground in — but you assess twenty-five sites, not the tenant, and you can do it on the licences they already own.
Before this guide, the word harness did not appear anywhere on this site. It is now the most consequential word in a Copilot Studio scope, because it is the single choice that determines what the agent can do, where it can be published, and when the meter starts running.
Whatever you build in Microsoft Copilot Studio, a harness powers it behind the scenes. You design your agent or workflow, while the model you select supplies the reasoning and generation. The harness is a runtime that exists between the two: it determines when to call the model, what components to send it, interprets what comes back, and calls the right tools.Microsoft Learn — Harnesses in Copilot Studio
Microsoft lists four things the harness decides. Three are capability questions a maker cares about. The fourth is “How your usage is billed” — and that one is the partner's problem, not the maker's.
| Consideration | GitHub Copilot harness | Standard harness | Copilot chat harness |
|---|---|---|---|
| Best for | Complex, multi-step business processes | Rule-based agents and structured conversations | Extending M365 Copilot Chat with enterprise knowledge |
| How it works | Reasons through a goal on its own, step by step | Follows the topics and rules you define | Connects enterprise knowledge to M365 Copilot Chat |
| Recovers from problems | Retries and finds alternative paths automatically | Follows the paths you’ve built | Not a focus |
| Works with files | Creates, edits and reasons over Word, Excel, PowerPoint and PDF | Not a focus | Not a focus |
| Skills and memory | Yes | Not a focus | Not a focus |
| Publishing | Internal teams or external customers | Internal teams or external customers | Internal teams only |
| Billing | Usage-based — and it starts when you start building | Copilot Credits per the rate card, after publish | Consumption, or included in Microsoft 365 Copilot licences |
“Build me an agent that answers questions from our policy documents” is a Copilot chat harness job: knowledge grounding, internal only, billed as consumption or covered by a Copilot licence. “Build me an agent that reads invoices, matches them to purchase orders and routes the exceptions” is a GitHub Copilot harness job — a different capability set, a different failure mode, and a different meter that starts running during your own development.
Those two sentences arrive in a discovery call sounding equally vague. They are not the same engagement and they are not the same price.
A partner who quotes without naming the harness has not scoped the work. Name it in the design phase, write it into the SOW, and treat a request to change it mid-build as the scope change it actually is — because it moves both the capability and the invoice.
This section scopes the engagement. It does not price it: §8 does that, and everything there assumes a harness has already been chosen. One consequence is sharp enough to flag here rather than leave to §8 — on the GitHub Copilot harness, your own build, preview, test and evaluation runs consume the customer’s credits before anything is published. That needs a clause and a cap, and almost no SOW in the channel currently has one.
This is phase 1 of the arc, and it is the assessment that earns the rest of the engagement. It is distinct from §7 in a way worth stating precisely: this section is auditing what already exists in the tenant. §7 is preparing to build something new. Partners routinely collapse the two and lose the billable assessment in the process.
Microsoft's framing is that agents are secure by default and that makers can change those defaults “for valid scenarios without knowing the risk.” Copilot Studio runs an automatic security scan and warns the maker before publishing. It warns. It does not stop them.
| Setting | Secure default | The dangerous value | What it means |
|---|---|---|---|
| Authentication mode | Authenticate with Microsoft | No authentication | Anyone who has the link can interact with the agent |
| Credentials to use (connectors and flows) |
End user credentials | Maker-provided credentials | Every user of the agent operates with the maker’s permissions, not their own |
| Sharing scope | Shared with no one | Shared with everyone in the organisation | No access boundary |
The middle row is the one to audit first. It is permanent privilege escalation for every person who invokes the agent, configured by a single dropdown, with a warning at publish time as the only friction.
And it is invisible to every Copilot readiness report the channel currently sells. Data Access Governance does not see it. SharePoint Advanced Management does not see it. It lives in Power Platform, and it is precisely the setting that inverts the containment argument in §4.
In February 2026 Microsoft's security organisation published the ten agent misconfigurations it observes in the wild. This is the assessment checklist for phase 1, and it did not have to be invented by anyone in the channel.
| # | Misconfiguration | Consequence |
|---|---|---|
| 1 | Broad organisational sharing | Unintended access, expanded attack surface |
| 2 | Missing authentication | Public exposure, unauthorised access |
| 3 | Risky HTTP request actions | Governance bypass, insecure communications |
| 4 | Email-based data exfiltration | Data leakage via prompt injection |
| 5 | Dormant agents and connections | Hidden attack surface, stale privileged access |
| 6 | Author (maker) authentication | Privilege escalation, separation-of-duties bypass |
| 7 | Hardcoded credentials | Credential leakage, unauthorised system access |
| 8 | Model Context Protocol (MCP) tools | Undocumented access paths, unintended interactions |
| 9 | Generative orchestration lacking instructions | Prompt abuse, behaviour drift, unintended actions |
| 10 | Orphaned agents | Lack of governance, outdated logic, unmanaged access |
Note items 5 and 10. Dormant agents and orphaned agents are not build failures. They cannot be prevented at build time at all — they only appear with the passage of time, and only a recurring review finds them. They are the strongest available evidence for the argument in §10, and they come from Microsoft's security organisation rather than its marketing.
The February blog directs readers to Advanced Hunting community queries in the AI Agents folder of the security portal. On 1 July 2026 that path moved behind a Microsoft Agent 365 licence — Microsoft published the risk list in February and licensed its recommended detection method five months later. §11 covers the transition in full.
The checklist itself is still free to read, and it is still free to run — just not Microsoft's way. The no-licence path is the Copilot Agent Kit: Agent Inventory for the tenant-wide registry of every custom agent with its features, authentication mode and knowledge sources, and the Agent Review Tool for the anti-pattern scan. Both are free and open source, from Microsoft's Power CAT team. §13 has the links.
The tenant-wide Copilot readiness path needs an E-SKU base that Business Premium does not provide — the Copilot Readiness Engagement, section 9. This assessment needs Power Platform admin access and an AI Administrator or Global Reader role.
An oversharing report describes what could happen. An agent running on maker credentials with no authentication is something that is happening, today, with a name attached to it.
No Copilot seats, no capacity packs, no governance licence. The assessment is sellable into a tenant at its current licensing, which is what makes it phase 1 rather than a post-sale activity.
In most SMB tenants there are already agents nobody inventoried — made in Copilot Chat, in Teams, in Agent Builder, by people who were not thinking about authentication modes. Finding them is the finding that justifies everything after it.
Agent Inventory has not been run against a real SMB tenant for this guide. The claim that “in most SMB tenants there are already agents nobody inventoried” is a reasonable inference from how Copilot Chat and Agent Builder work — it is not a measurement, and this guide does not present it as one. If a typical Business Premium tenant turns out to hold two agents, both owned and both authenticated, phase 1 is a much shorter conversation.
What would settle it: run Agent Inventory across three real SMB tenants and record, for each agent found, its authentication mode, its credential mode, whether it is shared organisation-wide, and whether it has a named owner. That single table would turn this section from an argument into evidence — and it is the same run that would let a partner price phase 1 properly.
Phase 3 of the arc. §6 audited what exists; this is what has to be put in place before anything new is published. Five layers, in dependency order — and then the failures that do not announce themselves, which are the reason this section is long.
The environment strategy overlaps with Phase 2 of the Agent Build Engagement Worklist, which carries the ALM detail for a delivery lead. This section covers what that worklist assumes rather than restating it.
The default Power Platform environment is open to every licensed user in the tenant, and production agents should never live there. Restrict environment creation, decide who holds a maker role, and adopt the zoned governance model Microsoft describes at maturity level 300 — environments designated safe, supported and IT managed, each with different controls.
Present the zoned model as a named deliverable rather than a bullet in a methodology slide. It is a discrete, explicable piece of work with a before and an after, and it is one of the few governance artefacts a non-technical sponsor can actually picture.
A Power Platform DLP / data policy separating Business from Non-Business connectors is the agent's real safety boundary. Microsoft's maturity model names failing to treat it as one an anti-pattern, in these words:
Teams allow agents to connect broadly (connectors, actions, HTTP) without consistent policy constraints, which increases data exfiltration and unintended action risk.Microsoft Learn — Agentic AI maturity model, universal governance anti-patterns
Restrict raw HTTP actions and unreviewed MCP tools by policy — risks 3 and 8 in §6. And prefer an approval workflow over a silent block: Power Shield in the Copilot Agent Kit lets a maker request connector access through a DLP approval flow rather than discovering they are blocked and routing around you. Governance that gets bypassed is not governance.
Sharing limits and pipelines require Managed Environments. Public guidance indicates Managed Environments is gated on premium per-user licensing across the tenant — Power Apps Premium, Power Automate Premium, Power Pages or qualifying Dynamics 365 — with no standalone SKU. This guide does not assert that, because it has not been confirmed, and it is the most likely place for the no-seat path in §3 to hit a wall with a real cost attached.
Two things are unresolved: whether every user needs a premium licence or only makers, and whether a Copilot Studio standalone licence qualifies on its own.
What would settle it: the current Microsoft Power Platform Licensing Guide, read against a distributor quote for the specific tenant — and get the answer in writing before it goes in a proposal.
This layer belongs to §6 and is listed here only so the dependency order is complete: end-user credentials rather than maker credentials, authentication on, and — for an agent that acts on its own rather than as a signed-in user — its own identity in Entra, which makes it a new principal subject to conditional access and identity governance. Microsoft also recommends Privileged Identity Management for just-in-time activation of the AI Administrator and Search Administrator roles, with approval and MFA.
Scope the twenty-five sites deliberately and assess those. Microsoft frames knowledge readiness as four dimensions: source scope, permissions, source authority and ownership. Source authority is the one nobody checks — not can the agent read this? but is this content approved, current, and the version the business actually follows? An agent grounded in a superseded policy document is confidently, fluently wrong, and no permissions review will catch it.
Purview treats agents as auditable entities: agent interactions are auditable, prompts and responses are discoverable, and retention policies apply to AI prompts and outputs. What of this is reachable on Business Premium is not established here — it is the same unresolved question left open in the Copilot Readiness Engagement, section 21, which asks whether DSPM for AI is genuinely reachable for a Business Premium customer. This guide does not settle it on that page’s behalf.
Then the cheapest control on the list: a named accountable owner for every agent. Risks 5 and 10 in §6 are unfixable without one, and Agent Inventory is the registry that holds it.
These are the highest-frequency real-world failures in Copilot Studio and they have one property in common: nothing errors. The status says Ready. The agent answers. The answer is just missing something.
Microsoft's wording is unambiguous: “You can't index documents that use sensitivity labels of confidential or highly confidential, or are password protected. If you add these types of documents, they show as ready for use but don't provide responses.”
They show as ready for use. A customer who has done classification well — exactly the mature customer a partner wants — gets an agent that answers nothing about its most important content, with no error anywhere to explain why.
The inverse is a genuinely useful control. Labelling is a cheap, reliable way to hold content out of an agent, it needs no extra tooling, and it works on Business Premium. Used deliberately it is a feature; discovered accidentally it is a failed pilot.
Microsoft states it for every unstructured knowledge source type: “Application Lifecycle Management (ALM) isn't supported for this feature. Importing agents doesn't result in automated knowledge source processing.”
This breaks the clean dev → test → prod story that every governance conversation depends on, and it needs saying out loud in the design phase rather than discovered on promotion day. Plan for knowledge sources to be reconfigured per environment, and budget for it.
Across OneDrive, SharePoint upload, Salesforce, Confluence, ServiceNow and Zendesk sources, Microsoft gives the same figure: synchronisation frequency is four to six hours. Whatever the demo implied, the agent is answering from a corpus that is up to six hours stale.
That is fine for policy documents and wrong for anything with a deadline attached. If the workflow needs current data, it needs an action against a live system, not a knowledge source — which is a different harness conversation and a different price.
Microsoft says a labelled document shows as ready and returns nothing. What has not been checked is whether any signal reaches anyone — a warning in the maker experience, an entry in the knowledge status detail, or a trace in the Agent Debugger. If there is a signal, it belongs in the phase 3 checklist. If there is genuinely none, that is worth telling every customer before they classify anything.
What would settle it: add one Confidential-labelled document as a knowledge source, wait for Ready, ask a question only that document can answer, and record what the maker sees, what the user sees, and what the debugger shows.
Generative AI rate limits are set per Dataverse environment and they scale with how much capacity the tenant owns:
| Quota per Dataverse environment | Tenant billing capability |
|---|---|
| 50 RPM / 1,000 RPH | 1–10 prepaid packs |
| 80 RPM / 1,600 RPH | 11–50 prepaid packs |
| 100 RPM / 2,000 RPH | 51–150 prepaid packs |
| 10 RPM / 200 RPH | Trial or developer environments |
| 100 RPM / 2,000 RPH | Pay-as-you-go environments |
| 100 RPM / 2,000 RPH | Microsoft 365 Copilot users |
Read the fourth row against the first. A pilot run in a developer environment has one-fifth the throughput of the environment it will launch into — and it passes anyway, because six testers never approach ten requests a minute. Launch day puts a hundred people on it inside an hour and the user-visible symptom is a failure notice when they send a message.
Microsoft's own guidance is to estimate peak traffic windows rather than relying on monthly averages, and it is right: monthly volume can look entirely comfortable while a Monday-morning spike breaks the agent. Rate-limit increases can be requested, but the path runs through support and is not guaranteed.
None of these are traps — they are documented, findable and hard. They are here because a partner who meets them mid-build is having a scope conversation instead of a design one.
| Limit | Value |
|---|---|
| Knowledge sources per agent | 500 across all types |
| SharePoint site URLs per agent, generative orchestration | 25 |
| Instructions for a Copilot agent | 8,000 characters |
| Topics per agent (Dataverse environments) | 1,000 |
| Trigger phrases per topic | 200 |
| Skills per agent | 100 |
| SharePoint lists | 15 lists, up to 35,000 rows across them |
| SharePoint list query depth | First 2,048 rows only |
| Maximum file size | 512 MB — but 7 MB for generative answers without a Copilot licence in tenant |
Phase 4 of the arc — the one partners skip. This section resolves the margin trap §2 opened with, and that is its whole job. It does not restate the AgentOps commercial architecture; the tiers, the components and what to charge for them are in section 10 of the Frontier Partner Playbook.
The billing unit is the Copilot Credit. Capacity is pooled at the tenant and allocable per environment. Channel material still talking about “messages” is working from pre-rename documentation — though the older vocabulary survives inside Microsoft's own tables, where the tenant billing capability column still reads “prepaid message packs.” The terms map; the material around them usually does not.
| Agent feature | Billing rate | Used by a Microsoft 365 Copilot licensed user |
|---|---|---|
| Classic answer | 1 Copilot Credit | No charge |
| Generative answer | 2 Copilot Credits | No charge |
| Agent action | 5 Copilot Credits | No charge (Computer-Using Agents excluded) |
| Tenant graph grounding for messages | 10 Copilot Credits | No charge |
| Agent flow actions, per 100 actions | 13 Copilot Credits | No charge, only via the “When an agent calls the flow” trigger |
| Text and generative AI tools — basic, per 10 responses | 1 Copilot Credit | No charge |
| Text and generative AI tools — standard, per 10 responses | 15 Copilot Credits | No charge |
| Text and generative AI tools — premium, per 10 responses | 100 Copilot Credits | No charge |
| Content processing tools, per page | 8 Copilot Credits | No charge |
Several 2026 channel blogs state that an autonomous agent action costs 25 or more credits. Microsoft Learn says an agent action is 5. A partner budgeting on the blog number over-quotes the run rate by a factor of five, loses on price, and never finds out why.
Check the rate card, not the commentary, and check it again before each quote — the page carries an ms.date and a 180-day update cycle for a reason.
One interaction can bill on several meters at once. Microsoft's own example: a tenant-graph-grounded agent may spend 12 credits on a single complex prompt — 10 for the grounding, 2 for the generative answer. Nobody quoting per-conversation gets this right by intuition.
Reasoning models bill twice. When an agent uses a reasoning-capable model, Copilot Studio bills the feature rate for the operation plus the premium text-and-generative-AI-tools rate for the reasoning model's token usage. Swapping in a reasoning model is a pricing decision disguised as a quality decision, and it is the single biggest silent cost driver in the platform.
This is not a billing footnote. It is a service-availability event with no user-facing warning, and it belongs in the managed-service agreement.
| Custom agents | Agent flows | |
|---|---|---|
| Trigger | 125% of prepaid capacity | Prepaid capacity fully consumed (100%) |
| What happens | Custom agents are disabled. An ongoing conversation is not interrupted; every subsequent attempt to invoke the agent is rejected | New flow runs cannot start. Runs already in progress complete. The agent remains available for everything else |
| Who is told | Email to the tenant’s designated administrator, plus a post in the Power Platform admin center | Flow authors see a design-time warning in the Copilot Studio designer |
| What the user sees | “There is a billing issue.” or “This agent is currently unavailable. It has reached its usage limit.” | Nothing obvious. The agent still answers — it just stops doing things |
| Reset | When capacity is increased or reset | Monthly, when prepaid credits renew |
Read the notification row and the user row together. The people who find out first are the customer's users, and the way they find out is the agent breaking. The admin gets an email; nobody is watching that mailbox at the moment it matters. If a partner is selling a managed service over this platform, detecting the 125% event before the customer does is a large part of what they are actually being paid for.
And the flow column is worse in one specific way: a partial failure is harder to detect than a dead one. The agent answers normally and silently stops completing actions. Nobody raises a ticket for an agent that is still talking.
Per-agent monthly consumption limits: Power Platform admin center → Licensing → Copilot Studio → Manage Agents. Microsoft's own framing is that these cap usage before enforcement is triggered.
It costs nothing, takes minutes, and converts an uncontrolled tenant-wide kill switch into a per-agent budget. Set it during phase 4, on every agent, before launch. Note the escape hatch as well: pay-as-you-go environments are exempt from enforcement entirely, because overage bills to the linked Azure subscription instead.
Microsoft publishes an official Copilot Studio agent usage estimator and points to it from the billing page. Use it. But understand what it can and cannot be: an estimate built from agent type, traffic, orchestration, knowledge and tools, made against a rate card where a single prompt can touch three meters and a model swap can double the bill.
That gap between the estimate and the invoice is not a flaw to apologise for. It is the service.
Run the estimator against the actual design — the harness, the orchestration mode, the knowledge sources, the tools. Produce a forecast the customer has seen and signed off, not a number they discover later.
Set the per-agent monthly limit in the admin center. This is the control that turns a possible outage into a known ceiling, and it is the one most partners never touch.
Consumption details per environment in the admin center; per-agent consumption on the agent’s Monitor page. Watch the trend, not the total — the 125% event is a slope, and it is visible weeks before it lands.
Reconcile forecast against actual, reallocate capacity between environments, adjust the caps, and tell the customer what changed and why. This is a recurring deliverable with an artefact attached — which is exactly what a flat fee over a metered cost base was missing.
Four steps, recurring, tool-supported, and every one of them is labour and judgement rather than a licence resale. That is the answer to §2's margin trap: you do not fix a metered cost base by pricing around it, you fix it by selling the management of the meter.
On the GitHub Copilot harness, in Microsoft's words:
Billing starts when you start building. Unlike the standard harness, which starts billing after publish, the GitHub Copilot harness charges credits from the moment you start building. Experiences such as creating an automated solution with natural language, previewing and testing the agent, and generating and creating agent evaluations all consume credits.Microsoft Learn — Overview of usage-based billing (GitHub Copilot harness), ms.date 18 August 2026
Read that as a partner. On this harness your own development, testing and QA consume the customer's credits, before anything is published and before anything works. Every SOW that selects the GitHub Copilot harness needs a clause naming who funds development consumption and a cap on it. Almost none in the channel currently have one.
This guide names the clause and the cap. It does not name a fee — what to charge is the revenue runway's question, not this one.
Microsoft documents that pre-publish activity consumes credits. Nobody has published how much. Without a number, the clause above is a warning rather than a negotiating position, and a partner cannot tell whether the honest answer is “a rounding error, absorb it” or “a material line, cap it at a stated figure.”
What would settle it: build one trivial agent on the GitHub Copilot harness in an isolated environment, do a normal amount of previewing, testing and evaluation, and read total credits consumed on the agent’s Monitor page before publishing it. One afternoon converts a warning into a number.
Phase 2 of the arc, and it appears here — before the build sections rather than after them — for one reason: the baseline has to be captured before anything is built. It cannot be added retroactively, and a partner who reaches the end of a build and starts thinking about measurement has already lost the argument they were going to need at renewal.
The good news is larger than most partners realise. Microsoft has already published the outcome formula. You do not have to defend a home-made ROI model in front of a sceptical finance person, because the model is Microsoft's, the defaults are sourced, and the report computes it.
| Value driver | What it measures | How to price it |
|---|---|---|
| Efficiency | Productive hours your team gets back, reinvested in higher-value work | Productive hours returned × fully loaded productive-hour value |
| Quality | Error reduction, consistency and compliance | (Error rate before − error rate after) × volume × cost per error |
| Revenue | Top-line lift from retained, expanded or new business | Conversion or deflection delta × volume × unit revenue × attribution discount |
| Strategic | Decision velocity, employee confidence, optionality and resilience | Option premium on capability + retention value of talent + resilience value |
It is the last term in the revenue formula, and it is Microsoft conceding that attribution is contestable — in its own published pricing method, before anyone argues about it.
Copy that discount into the engagement rather than defending a clean attribution you cannot support. Agreeing the discount up front, with the sponsor, converts the hardest conversation at renewal into a parameter that was settled in phase 2.
For conversational agents:
Agent Assisted Hours = (Knowledge references + Weighted sessions without knowledge references) × Time savings multiplier ÷ 60Microsoft Learn — Measure the impact of your agents
Microsoft's own worked example runs 10,000 engaged sessions in a month to 1,440 hours per month of returned capacity. At the default rate that is a six-figure monthly number and a seven-figure annual one — but the hours are the durable figure, because the rate is the customer's to set.
Whoever configures the hourly rate and the multipliers owns the renewal conversation.
Those constants are not administrative trivia. They decide what number appears on the sponsor's slide every quarter, and setting them is a defensible, recurring, billable piece of judgement work performed inside Microsoft's own report — not a spreadsheet the partner has to defend line by line.
Microsoft names three reasons the value story weakens after launch. This is the highest-value short passage on the page, because all three are things partners currently do.
Instrumentation is strong during the pilot, then drifts as the agent moves to production. Microsoft’s fix: embed measurement in the deployment workflow itself, so every production agent keeps emitting the signals the review depends on.
Sessions and user counts show usage; they are not value. Every KPI has to trace back to one of the four value drivers, or it is decoration.
“Claiming value based on theoretical time savings alone undermines credibility.” Build a chain of evidence from adoption, through operational KPIs, to business outcomes.
The third one deserves to be said plainly, because it is aimed squarely at the channel's current pitch. The “X hours per week × headcount × salary” slide is the thing Microsoft is warning against, and a partner can now retire it with a vendor citation rather than an opinion. That is a much easier conversation internally than arguing about it on instinct.
| Value driver | Metrics | Where to read them |
|---|---|---|
| Efficiency | Hours saved, Agent Assisted Hours, Agent Assisted Value, cycle time, touchless rate, cost per transaction | Copilot Studio Savings calculator; Copilot Studio agents report (Viva Insights) |
| Quality | Resolution rate, first-contact resolution, escalation rate, abandon rate, groundedness, instruction-following score | Copilot Studio Analytics; Copilot Agent Kit rubrics |
| Revenue | Conversion lift, retention delta, cross-sell rate, advisor capacity | Copilot business impact report (Viva Insights) |
| Strategic | New capabilities shipped, workflows redesigned, employee sentiment on AI, talent signals | Copilot Studio custom metrics; Viva Glint Copilot Impact Survey |
Microsoft also pairs a leading and a lagging indicator per driver and reviews them quarterly. That cadence is not incidental — it is the same 90-day rhythm that §10 shows Microsoft prescribing for the whole programme, and together they are a managed-service contract shape written by the vendor.
Several of the surfaces above live in Viva Insights advanced and analyst templates — the Copilot Studio agents report and the Copilot business impact report among them. Whether they are reachable in a Microsoft 365 Business Premium tenant, and what additional licensing they require, is not established here. If they are not reachable, the formula still stands but the partner computes it by hand from Copilot Studio Analytics, which is more work and a weaker artefact.
Also unconfirmed: whether the default hourly rate and the time-savings multipliers are editable in an SMB tenant, which is the difference between owning the renewal conversation and watching a default number appear.
What would settle it: open the Copilot Studio agents report in a Business Premium tenant. Record whether it loads, what licence it demands, and whether the calculator on the Agent Assisted Value card accepts a changed rate.
Phase 6 of the arc, and the claim the page is named after. It is not a sales position invented by this guide. Microsoft says it, in four separate places, none of which is a marketing page — and two of the ten security risks in §6 are failures that cannot exist until time has passed.
The argument that drift justifies a retainer is already made in the Agent Build Engagement Worklist. This section does not re-derive it. It supplies what neither that worklist nor the playbook carries: a taxonomy of how an agent ages, and a register of what fails, how you would see it, and who owns it. Both of those describe activity; neither describes failure detection.
Five phases: discovery, experimentation, build, deploy, and operational steady state — defined as continuously monitoring, evaluating and adjusting “to maintain operability standards as business requirements and underlying technologies evolve.” There is no “complete” phase. The lifecycle ends in a state, not an event.
“Operate an expansion rhythm, treating the program as recurring quarterly work. Pick a new high-volume workflow, build or configure the agent, measure against baseline for 90 days, review with the sponsor, and decide whether to scale it or retire it.” A 90-day measurement window, a sponsor review and a scale-or-retire decision is a recurring-revenue contract shape written by the vendor.
“AI systems change over time as prompts, data, and usage patterns evolve. Bias, misuse, and trust drift typically appear after go-live, not before. Teams are unprepared when issues surface and revert to reactive shutdowns.” Microsoft names the resulting behaviour the “panic and switch things off” response pattern.
“Minimize the time between experimentation and build phases to reduce the risk of model or data drift affecting agent performance.” And on the free proof of concept much of the channel gives away: experimentation “must be grounded on real-world data sets and current models rather than synthetic or limited test data. Proof of concept ideation using synthetic data increases the risk of agents not performing as expected in production environments.”
A taxonomy is only useful if each entry comes with a way of seeing it. The third column is the one that turns this from a slide into a service.
| Drift | What actually changes | How you detect it |
|---|---|---|
| Data drift | The grounding corpus ages. Content is moved, renamed, superseded or archived; the agent keeps citing it | Source-authority review against the twenty-five sites; citation analysis in Copilot Studio Analytics; groundedness scored against a rubric |
| Model drift | The model underneath the agent changes. Microsoft names model drift as a risk in its own build guidance — and the customer does not choose the version | A regression run of the golden prompt set on a schedule. This is the one that has no alert, so it has to be a calendar item |
| Connector drift | The agent is only as good as what it reaches through, and connectors, APIs and MCP tools change under it | Agent Review Tool anti-pattern scan; DLP policy review; action failure rates in the Agent Insights Hub |
| Permission drift | Tenant ACLs move. Sharing scope, credential mode or authentication gets changed by a maker after go-live | Agent Inventory re-run against the §6 baseline — a diff, not a fresh audit |
| Process drift | The business changes the workflow the agent encodes. The agent does not know, and nothing errors | Only the sponsor review catches this. It is why the 90-day cadence has a human in it |
| Cost drift | Volume grows, or a reasoning model is swapped in and the agent starts billing on two meters | Consumption trend per environment and per agent; the true-up step in §8 |
Five of the six drifts originate with the customer or their content. Model drift originates with Microsoft. The reasoning underneath the agent can change without the customer asking for it, and the agent's behaviour can change with it.
This guide does not claim the customer has no recourse — that is a product question this research has not settled. What it does claim is narrower and sufficient: there is no alert for it. If nobody re-runs a known set of prompts on a schedule, a behaviour change arrives as a user complaint months later, and by then nobody can say when it started.
This is the artefact. Named failure, the surface it becomes visible on, the free tool that shows it, and who is accountable. A managed service that cannot fill in the last two columns is selling attendance, not operations.
| Named failure | Detection surface | Free tool | Accountable owner |
|---|---|---|---|
| The 125% kill — custom agents disabled at 125% of prepaid capacity | Admin email and a Power Platform admin center post. Users find out by the agent breaking | Consumption trend in the admin center; per-agent caps set in advance | Partner — this is an availability event in the managed-service agreement |
| Partial flow enforcement — flows blocked at capacity while the agent keeps answering | Design-time warning to flow authors only. No user-visible signal | Agent flow actions line in the consumption details grid | Partner |
| Dormant agents (top-10 risk #5) — stale privileged access nobody is watching | Nothing. Dormancy has no event | Agent Inventory; Compliance Hub thresholds and SLA timers | Partner, on the review cadence |
| Orphaned agents (top-10 risk #10) — no active owner, so no review cycle reaches them | Nothing, by definition | Agent Inventory ownership field; the named-owner rule from §7 | Customer names the owner; partner enforces that one exists |
| Knowledge rot — stale corpus, four-to-six hour sync, ALM not carrying knowledge across environments | Silent. Answers get quietly worse | Agent Debugger for what was actually retrieved; Conversation Analyzer over recent transcripts; rubric-graded groundedness | Customer owns content currency; partner owns detecting that it slipped |
| Configuration regression — a maker flips authentication, credentials or sharing after go-live | Publish-time security scan warns the maker, and only the maker | Agent Review Tool; Agent Inventory diffed against the §6 baseline | Partner |
Every tool in the third column is free and open source, from Microsoft's Power CAT team — §13 has the links. That is the point, and it is the commercial argument as well as the technical one. The tooling costs nothing, so the margin is entirely in the labour and the judgement. A partner who says “we license a governance platform” is beaten by one who says “we run the Compliance Hub, we set the thresholds, we own the SLA timer.”
Look again at risks 5 and 10 in §6. A dormant agent and an orphaned agent are not build defects. They cannot be prevented at build time, because at build time neither condition exists. They come into being through the passage of time and the movement of people, and the only thing that finds them is a recurring review.
And they come from Microsoft's security organisation, not its marketing. That is a materially different citation to put in front of a sceptical buyer than a vendor's recurring-revenue pitch.
Microsoft's maturity model separates agents into personal productivity, departmental or team, and mission-critical, and explicitly names applying one set of controls to all three an anti-pattern: it over-restricts productivity agents, which drives shadow AI, while under-governing the mission-critical ones. That is a risk-and-criticality tiering of the agents themselves. The three AgentOps tiers in section 10 of the Frontier Partner Playbook are a tiering of the service you sell. They are compatible and they are not the same axis — use Microsoft's tiering to decide how hard to govern a given agent, and the playbook's to decide what to charge for governing it.
This section supplies the qualification logic — when the Agent 365 dial gets turned up, and what to use before it does. Where Agent 365 sits in the commercial stack is already settled in section 10 of the Frontier Partner Playbook, and this section does not restate it.
It opens with something more urgent than positioning: a licensing change that has already happened, and that most of the channel has not noticed.
Effective July 1, 2026, AI agent security capabilities for Microsoft Copilot Studio and Microsoft Foundry agents require a Microsoft Agent 365 license. These capabilities are no longer covered by existing Defender for Cloud Apps or Defender for Cloud licenses. Tenants without an Agent 365-eligible license lose access to these capabilities on July 1, 2026.Microsoft Learn — Transition Copilot Studio and Foundry agent security capabilities to Microsoft Agent 365
For Copilot Studio agents specifically, what a tenant without an eligible licence lost:
Three further changes are worth knowing because they break things quietly:
| Change | Consequence |
|---|---|
| Tenants configured to Block on existing Agent 365 real-time protection rules stopped blocking on 1 July 2026 | To resume blocking, rules must be redefined under the new policy experience. A control that was enforcing is now not enforcing, and nothing announced it in the tenant. |
The AIAgentsInfo Advanced Hunting table is deprecated in favour of AgentsInfo |
Saved queries, custom detections and workbooks referencing the old table need updating |
| The AI Agents sub-tab under Cloud Assets was removed for all customers | Licensed or not, that navigation path is gone |
The same transition document also states: “Real-time protection for Microsoft Copilot Studio through Defender for Cloud Apps remains unchanged for tenants that continue using this experience. No action is required.”
That sits awkwardly beside the headline, and reconciling the two would require drawing a line Microsoft has not drawn. Treat the exact boundary as unresolved. If a customer depends on Copilot Studio real-time protection through Defender for Cloud Apps, confirm their specific configuration rather than reasoning from either sentence alone.
This is the part a partner cannot easily assemble alone, and it is the reason the positioning at the end of this section holds.
| The job | Agent 365 | Free or included alternative |
|---|---|---|
| Tenant-wide agent inventory | Agent registry — broadest coverage, including non-Microsoft platforms via registry sync | Copilot Agent Kit → Agent Inventory (Copilot Studio agents); Power Platform inventory |
| Ownerless and dormant agent detection | “Agents without owners” card, rules-based lifecycle enforcement | Agent Inventory + a review cadence |
| Configuration risk / anti-pattern scan | Agents-at-risk, aggregated from Entra, Defender and Purview | Agent Review Tool; the built-in publish-time security scan |
| Policy enforcement, SLA timers, quarantine | Rules-based lifecycle policy, approval flow, blocking | Compliance Hub — thresholds, risk levels, SLA timers, quarantine and delete |
| Connector / DLP boundary | Purview and Entra integration | Power Platform DLP data policies; Power Shield for approval workflow |
| Runtime analytics and telemetry | Agent run-time, active users, trending agents | Agent Insights Hub; Copilot Studio Analytics |
| Debugging a bad conversation | — | Agent Debugger — step-by-step decisions, timing, token usage |
| Business value measurement | Agent run-time hours | Copilot Studio agents report; Savings calculator; Agent Value in the Kit |
| Threat detection, real-time protection, Advanced Hunting over agent activity | Agent 365 only, since 1 July 2026 | No free equivalent. This is the genuine gap. |
Read the last row against all the others. Almost everything an SMB needs on day one is free. Inventory, anti-pattern scanning, compliance policy with SLA timers, debugging, analytics and value measurement are all in the Copilot Agent Kit at zero licence cost, plus Power Platform DLP. What is genuinely Agent 365-only is the security-operations layer — detection and response over agent activity.
Agent 365 is the escalation, not the entry ticket.
A partner who tells an SMB they need a per-user governance licence before they can govern a single agent is wrong on the facts, and has priced themselves out of the first engagement in the process. Lead with the free baseline in §6. Earn the right to the next conversation.
The registry stops being a spreadsheet job. Ownerless and dormant agents — risks 5 and 10 — are the tell that the count has crossed the line.
Once an agent acts on its own rather than as a signed-in user, it is a new principal in the tenant, and Entra-backed identity governance stops being optional.
SharePoint agents, Agent Builder, or non-Microsoft platforms. Registry sync is the only thing that sees across all of them — the Copilot Agent Kit does not.
Where the customer must demonstrate detection and response over agent activity, not just configuration hygiene. After 1 July 2026 that is Agent 365 or nothing.
Agent 365 admin-led trials are 25 seats for 30 days. The Microsoft admin center shows a banner with the remaining trial days, and admins with billing permissions can view details and purchase directly from it.
That is a natural paid discovery engagement: run the registry across the tenant, produce the findings, and let the expiry force a decision that would otherwise drift. Do not let it lapse silently. A trial that ends with nobody watching is worse than never having run one, because the customer now believes they looked.
Microsoft Learn says: “Microsoft Agent 365 works best when using Microsoft E5 as a pre-requisite.” That is hedged language, not a requirement statement, and no Microsoft page reviewed for this guide states a Microsoft 365 Business Premium path in those words. Channel aggregators claim one exists for tenants under 300 seats. Those are not the same claim.
This is the exact failure mode the Copilot Readiness Engagement, section 9 documents with SAM — two readings of one hedged licensing page, in opposite directions. This guide does not pick one.
What would settle it: the CSP price list or a distributor catalogue check for the specific tenant, in writing.
Agent 365 is licensed per user, and Microsoft states that “at least one user must be licensed with a qualifying Microsoft Agent 365 license to enable Agent 365.” What is not established in public guidance is who has to be licensed in practice: every user who interacts with an agent, every maker, or only the governing admins?
The spread is not marginal. A sixty-person company with one help-desk agent everybody talks to is either three licences or sixty — a twentyfold difference in the same deployment. A partner who quotes the wrong reading either loses the deal or eats the difference.
What would settle it: get the answer from your distributor or Microsoft in writing, for the specific deployment shape, before it goes anywhere near a proposal. This is the single most important number to resolve before quoting Agent 365, and there is no shame in saying so to the customer — the alternative is guessing on their invoice.
One last thing worth saying plainly, because it shapes how the managed service should be designed. Microsoft published an agent risk list in February and licensed its recommended detection method in July. Assume more of this surface becomes licensed over time, and build the service so the labour and the judgement are the product — those are the parts that do not get absorbed into a SKU.
There are options for partners who want to get to market quickly with a prebuilt solution and let a vendor carry the heavy lifting on the build. The point of this section is that such options exist and are resellable today — not that any particular one should be chosen. The reasoning below applies to any prebuilt-agent vendor; one is used as the worked example because it is on the line card.
UnifyCloud's CloudAtlas AI Factory is the example, and a TD SYNNEX partner's rep supports that conversation. It is an AI use case gallery — roughly two hundred production-intent use cases, each with case study, demo and proof-of-concept actions, filterable by industry (including a Small and Midsize Business category) and by solution area, where conversational AI is the largest group, followed by data analysis, customer support, knowledge management and employee onboarding. Adjacent modules in the same console cover custom POC generation, AI policies, responsible-AI evaluation and solution assessment. UnifyCloud is a Microsoft Solutions Partner and the product is listed on Microsoft Marketplace.
A working agent pattern. Tested logic for a recognisable business problem. A demo you can put in front of a customer this week, and POC scaffolding behind it. Someone else’s solved version of the hard design questions.
This is real value and it compresses weeks. A partner who dismisses it is competing on labour against someone who is not.
Everything tenant-specific. None of it transfers, because none of it is about the agent — it is about the customer.
And every item on that list is a section of this guide, which is the point: the last mile is not an afterthought to the build. It is the engagement.
| What the gallery cannot know | Where it is handled |
|---|---|
| The customer’s SharePoint permissions state, and which twenty-five sites the agent should ground in | §4, §7 |
| Sensitivity labels that make knowledge silently unreadable, and password-protected files that index as Ready | §7 |
| Which harness it targets, and therefore when billing starts | §5, §8 |
| Capacity, rate limits, and whether the pilot environment can carry launch-day traffic | §7 |
| Credit run rate, per-agent caps, and who is watching for the 125% event | §8 |
| The baseline, and who configures the measurement constants | §9 |
| Existing ungoverned agents already in the tenant | §6 |
| The process the agent encodes, and who owns it when the business changes it | §10 |
The gallery gets you a working demo. The last mile is what makes it survive contact with the customer’s tenant, and what keeps it alive afterwards.
Or compressed, for the room: 80% of the way there is 80% of the build, not 80% of the engagement.
A productised 80% collapses build labour as a revenue line. You cannot bill hours for work a gallery already did, and pretending otherwise loses to whoever stops pretending first. That is not a threat to a partner practice built on this guide's arc — it is the strongest argument for it. What is left to charge for is the assessment ahead of the build, the last mile through it, and the operations after it, which is phases 1, 2, 3, 4 and 6 of §1. The gallery compresses phase 5, and phase 5 was always the most competitive part.
What to charge for the build itself is settled in the revenue runway, and how this positions against other vendors is the competitive battle card's job. Neither is restated here.
It was built against someone else's data, someone else's process and someone else's permissions model. All six ageing sources in §10 start running the moment it lands — and one question has no published answer: when the vendor updates a gallery template, what happens to an instance already deployed in a customer tenant? That is the versioning question the entire never-done thesis turns on, and it should be asked of any prebuilt-agent vendor before the first deployment, not after.
A proof of concept in days wins the room. It becomes a trap the moment it turns into the production agent without being regrounded in the customer's real data — and this is Microsoft's own warning, not an opinion: proof-of-concept ideation on synthetic data “increases the risk of agents not performing as expected in production environments.”
Use the gallery to win the room. Reground it before it goes live.
One note on where other vendors sit, because they are often presented as alternatives when they are not. AvePoint AgentPulse serves readiness and steady state — discovery, inventory, policy enforcement, cost insight, and backup and recovery for Copilot Studio agents — where a gallery accelerates the build. They compose; they do not compete.
None of the five have publicly documented answers for any vendor reviewed here. Asking them is a five-minute call that changes what a partner can safely commit to.
This section exists so a partner does not have to search the internet for this. Everything below already exists, most of it is free, and almost all of it is published by Microsoft. Every entry says why it matters, because a bare link list is not worth the page it is on.
This is tools a partner uses. §15 is sources this guide cites. They overlap and they are not the same list.
A sixty-minute working session for a partner team. It is not a customer pitch — it is the session that decides which phase of the arc your practice is currently giving away, and which tenant test you run first.
Every visual in this run of show already exists elsewhere on this page. Each stop points at the section that carries its figure; nothing is authored twice, and nothing needs a separate deck. Run it from the page.
This is the page’s honesty surface. Everything above is sourced to Microsoft where a Microsoft source exists, and where one does not, this section says so.
Every one of these is cheap. None of them has been run for this guide, and each section that depends on one carries a marker naming what is unknown and what would settle it. A section that rests on an open test ships with the uncertainty stated, or it does not ship — it never ships with a guess.
| # | What is unknown | What it gates | What would settle it |
|---|---|---|---|
| TT-1 | Can you buy Copilot Credit capacity and publish a working agent to Copilot Chat in a Business Premium tenant with zero Copilot seats, without hitting an undocumented licensing wall? | §3 — the page’s central claim | Run it once end to end and record every point a licence is requested |
| TT-2 | How many credits does a trivial agent consume on the GitHub Copilot harness before publish? | §8 — turns the build-burn clause from a warning into a number | Build one, preview and test normally, read the Monitor page before publishing |
| TT-3 | When a Confidential-labelled document fails to index, does any signal reach the maker, the user, or the debugger? | §7 — the trap list | Add one, wait for Ready, ask a question only it can answer, record all three surfaces |
| TT-4 | Is the Copilot Studio agents report reachable in an SMB tenant, and is the default hourly rate editable there? | §9 — the measurement argument | Open it in a Business Premium tenant; record the licence demanded and whether the calculator accepts a change |
| TT-5 | Do Managed Environments — needed for sharing limits and pipelines — require premium per-user licensing across the tenant, and does a Copilot Studio standalone licence qualify? | §7 layer 2 — the most likely wall on the no-seat path | Current Power Platform Licensing Guide, read against a distributor quote, in writing |
| TT-6 | How many agents already exist in a real SMB tenant, and how many use maker credentials, no authentication, or have no owner? | §6 — whether the wedge is real or theoretical | Run Agent Inventory across three tenants; tabulate auth mode, credential mode, sharing scope, owner |
| TT-7 | Is Agent 365 purchasable on Business Premium? Learn hedges with “works best when using Microsoft E5 as a pre-requisite”; aggregators claim an SMB path under 300 seats | §11 | CSP price list or distributor catalogue, for the specific tenant |
| TT-8 | Who needs an Agent 365 licence — every user who interacts, every maker, or only governing admins? A twentyfold spread on the same deployment | §11 — the most important number to resolve before quoting | Distributor or Microsoft, in writing, for the specific deployment shape |
| TT-9 | Does one Agent 365 licence enable tenant-wide observe and govern, given that Microsoft states at least one licensed user enables Agent 365? | §11 | Run the 25-seat trial and check what registry coverage a single assigned licence produces |
TT-1, TT-7 and TT-8 are the three most likely to repeat a known failure. the Copilot Readiness Engagement, section 9 documents what happens when one hedged Microsoft licensing page gets read two ways: two internally consistent conclusions, in opposite directions, both wrong to act on. The sections resting on these three carry the most explicit markers on this page for exactly that reason.
No verifiable, named SMB Copilot Studio case study with audited outcome numbers was located for this guide. What exists is a Microsoft enterprise self-reference, and a set of vivid SMB numbers circulating in the channel — a boutique retailer cutting tickets by two thirds, a solo practice recovering nine hours a week — which trace to marketing blogs with no named customer.
They are not used anywhere on this page. Laundering an unattributed number into a benchmark is precisely the “time-savings trap” Microsoft names in §9, and it is the failure that the Copilot Readiness Engagement, section 21 caught two vendors committing.
The honest version is more useful in front of a partner than a borrowed number would be:
There is no audited SMB case study yet. That is exactly why you instrument the baseline before you build — because you are going to be it.The Customer Zero argument, and the reason §9 sits before the build sections
Two further evidentiary limits worth stating. No practitioner invoices were obtained — the community price shapes circulating for AI agent retainers come from agencies selling the model, not from delivered engagements, so this guide names no third-party price shapes at all. And the prebuilt-agent claims in §12 rest partly on the line card rather than on a public source, which is flagged in that section rather than here.
This page carries one currency figure. Everything else about consumption is expressed in Copilot Credits, which are a unit of usage rather than money and need no provenance tag. Where a currency value does appear it carries one of these:
Sources this guide cites. For tools a partner uses, see §13.