Seven phases from the first conversation to the retainer — what must be true in the tenant at each step, what the meter costs, which controls to set before launch, and what you are still being paid for two years later. For the customers you actually have: Business Premium, zero Copilot seats. The agent is never done, and that is the commercial argument.
Sections 2 through 8 are the seven phases in delivery order — each one states what you do, what you do not do, what has to be true in the tenant, and what it produces. Sections 9 through 12 are the reference material you reach for mid-engagement: the limits and silent failures, the Agent 365 trigger logic, and the free toolchain. Nothing here is argued. Where you want the reasoning, the evidence and its weaknesses — the Gartner cancellation data, the margin-trap case, the full source apparatus — the long-form background reference carries all of it, section by section.
Your customer is on Business Premium, has bought zero Copilot seats, and wants an agent. Everything below assumes that as the starting condition.
Start with zero Copilot seats. Copilot Chat is included with any Microsoft 365 or Office 365 subscription, and agents that use the customer's own data are billed on metered consumption. The seat is a capability upgrade you sell later on evidence, not an entry ticket you demand first on faith.
You still assess what you ground in. But an agent's blast radius is 25 named SharePoint sites, not the tenant graph — and every control involved is Power Platform configuration, reachable on Business Premium. No E-SKU, no SharePoint Advanced Management licence wall.
A flat monthly fee over a metered cost base is a margin trap. You do not fix it by pricing around the meter. You fix it by selling the management of the meter — estimate, cap, monitor, true‑up. Section 6.
The build is the part that is project-shaped, easiest to quote, and most competitive. Gartner's three named causes of agentic-project cancellation — escalating costs, unclear business value, inadequate risk controls — are phases 4, 2 and 1 skipped, in that order.
“Sell seats → prove adoption → then talk about agents” puts a per-seat commitment in front of a conversation the customer is already entitled to have. For most SMBs it is the reason the conversation never starts.
The invoice is flat; prompts, actions and background runs are not. This is the most likely way to lose money on an agent that is working perfectly — and it is entirely a phase 4 failure.
Read across, not down. Paper names the shape of the commercial instrument, never a rate — rates live in section 10 of the Frontier Partner Playbook. Week ranges for phases 2–5 are the build-side clock published in section 4 of the Ops Companion; phases 0, 1 and 6 have no equivalent there.
| Phase | Elapsed | Paper | What must be true in the tenant | Detail |
|---|---|---|---|---|
| 0 · Standing and visibility | One conversation, 30–60 min | None. If you are writing paper here you have mistimed it | Any Microsoft 365 or Office 365 subscription. No Copilot seat | §2 |
| 1 · Agent governance baseline | 1–2 weeks | Fixed-fee assessment. Short-form — not the build SOW | Power Platform admin access, plus AI Administrator or Global Reader. Nothing needs buying | §3 |
| 2 · Candidate and baseline | 1–2 weeks · Weeks 1–2 | Assessment, or the first phase of the SOW | Nothing new. The constraint is organisational — somebody has to own the process | §4 |
| 3 · Prerequisites and harness | 2 weeks · Weeks 2–4 | SOW | A Dataverse environment, production or sandbox — trial and developer are not eligible for pay-as-you-go. A DLP policy separating Business from Non-Business connectors | §5, §9 |
| 4 · Economics | 2–3 days, inside phase 3. It gates the quote | None of its own — its output is the number the build SOW is written around | Copilot Credit capacity packs. Per-agent monthly caps configured before launch | §6 |
| 5 · Build and deploy | Weeks 4–8 simple, 4–14 complex | SOW. The retainer is signed here, not later | Capacity live. On the GitHub Copilot harness your own dev and QA consume the customer's credits before publish | §7 |
| 6 · Managed AgentOps | Indefinite. 90-day cycle | Retainer — a managed services agreement, not a renewal of the build | Capacity and caps under active management. Agent 365 only when a trigger fires | §8, §10 |
Every other phase has an obvious owner and an obvious moment. Economics does not: it sits between the design work and the quote, produces no deliverable the customer asked for, and is the easiest thing to defer. So partners defer it — quote build labour, sign, ship, and let the customer meet the monthly run rate on a Microsoft invoice they were never shown a forecast for. The estimate takes days, the tooling is free and published by Microsoft, and the cap that prevents the worst outcome is a setting nobody has to buy.
The first two decide whether phase 1 has a finding in it. The last two decide whether phase 2 has an owner. If neither pair produces a satisfying answer, this is an education conversation, not a deal.
“You do not need to buy a Copilot seat to start this. Microsoft's own documentation says Copilot Chat is included with the subscription you already have, and agents that use your data are billed on usage instead of per person.
What I would like to do first is find out what is already running in here. There are almost certainly agents in this tenant that nobody inventoried, and some of them will be running with their maker's permissions rather than the user's. That is a two-week fixed-fee piece of work, it needs nothing purchased, and what it finds decides whether we build anything at all.”
This is the assessment that earns the rest of the engagement. It audits what already exists. Section 5 prepares to build something new. Collapse the two and you have given away the billable assessment.
Microsoft's framing is that agents are secure by default and makers change those defaults “for valid scenarios without knowing the risk.” Copilot Studio runs an automatic security scan and warns the maker before publishing. It warns. It does not stop them.
| Setting | Secure default | The dangerous value | What it means |
|---|---|---|---|
| Authentication mode | ✓ Authenticate with Microsoft | ✗ No authentication | Anyone who has the link can interact with the agent |
| Credentials to use (connectors and flows) | ✓ End user credentials | ✗ Maker-provided credentials | Every user of the agent operates with the maker's permissions, not their own |
| Sharing scope | ✓ Shared with no one | ✗ Shared with everyone in the organisation | No access boundary |
Permanent privilege escalation for every person who invokes the agent, configured by a single dropdown, with a publish-time warning as the only friction.
And it is invisible to every Copilot readiness report the channel currently sells. Data Access Governance does not see it. SharePoint Advanced Management does not see it. It lives in Power Platform — and it is the exact setting that inverts the 25-site containment argument in section 1. Flip it, and every invoker inherits the maker's permissions across the whole tenant.
Published by Microsoft's security organisation in February 2026. This is the phase 1 checklist and nobody in the channel had to invent it.
| # | Misconfiguration | Consequence |
|---|---|---|
| 1 | Broad organisational sharing | Unintended access, expanded attack surface |
| 2 | Missing authentication | Public exposure, unauthorised access |
| 3 | Risky HTTP request actions | Governance bypass, insecure communications |
| 4 | Email-based data exfiltration | Data leakage via prompt injection |
| 5 | Dormant agents and connections | Hidden attack surface, stale privileged access |
| 6 | Author (maker) authentication | Privilege escalation, separation-of-duties bypass |
| 7 | Hardcoded credentials | Credential leakage, unauthorised system access |
| 8 | Model Context Protocol (MCP) tools | Undocumented access paths, unintended interactions |
| 9 | Generative orchestration lacking instructions | Prompt abuse, behaviour drift, unintended actions |
| 10 | Orphaned agents | Lack of governance, outdated logic, unmanaged access |
Items 5 and 10 are the argument for the retainer, and they come from Microsoft's security organisation rather than its marketing. A dormant agent and an orphaned agent are not build defects — at build time neither condition exists. They come into being through the passage of time and the movement of people, and the only thing that finds them is a recurring review. Section 8.
The February blog directs readers to Advanced Hunting community queries in the AI Agents folder of the security portal. On 1 July 2026 that path moved behind a Microsoft Agent 365 licence — Microsoft published the risk list in February and licensed its recommended detection method five months later. Section 10 covers the transition.
The checklist is still free to read and still free to run — just not Microsoft's way. The no-licence path is the Copilot Agent Kit: Agent Inventory for the registry, Agent Review Tool for the anti-pattern scan. Both free and open source, from Microsoft's Power CAT team. Section 11 has the links.
The tenant-wide Copilot readiness path needs an E-SKU base that Business Premium does not provide — Copilot Readiness Engagement, section 9. This needs Power Platform admin access and a Global Reader role.
An oversharing report describes what could happen. An agent running on maker credentials with no authentication is something that is happening, today, with a name attached to it.
No Copilot seats, no capacity packs, no governance licence. It is sellable into the tenant at its current licensing, which is what makes it phase 1 rather than a post-sale activity.
This phase sits before the build sections for one reason: the baseline cannot be captured retroactively. A partner who reaches the end of a build and then starts thinking about measurement has already lost the argument they will need at renewal.
You do not have to defend a home-made ROI model in front of a sceptical finance person. The model is Microsoft's, the defaults are sourced, and the report computes it.
| Value driver | What it measures | How to price it |
|---|---|---|
| Efficiency | Productive hours your team gets back, reinvested in higher-value work | Productive hours returned × fully loaded productive-hour value |
| Quality | Error reduction, consistency and compliance | (Error rate before − error rate after) × volume × cost per error |
| Revenue | Top-line lift from retained, expanded or new business | Conversion or deflection delta × volume × unit revenue × attribution discount |
| Strategic | Decision velocity, employee confidence, optionality and resilience | Option premium on capability + retention value of talent + resilience value |
Agent Assisted Hours = (Knowledge references + Weighted sessions without knowledge references) × Time savings multiplier ÷ 60Microsoft Learn — Measure the impact of your agents
1.0, escalated or abandoned as 0.7.Whoever configures the hourly rate and the multipliers decides what number appears on the sponsor's slide every quarter. That is not administrative trivia — it is defensible, recurring, billable judgement work performed inside Microsoft's own report, not a spreadsheet you have to defend line by line.
The same logic applies to the attribution discount in the revenue formula. It is Microsoft conceding, in its own published method, that attribution is contestable. Agreeing the discount with the sponsor up front converts the hardest conversation at renewal into a parameter that was settled in phase 2.
| Value driver | Metrics | Where to read them |
|---|---|---|
| Efficiency | Hours saved, Agent Assisted Hours, Agent Assisted Value, cycle time, touchless rate, cost per transaction | Copilot Studio Savings calculator; Copilot Studio agents report (Viva Insights) |
| Quality | Resolution rate, first-contact resolution, escalation rate, abandon rate, groundedness, instruction-following score | Copilot Studio Analytics; Copilot Agent Kit rubrics |
| Revenue | Conversion lift, retention delta, cross-sell rate, advisor capacity | Copilot business impact report (Viva Insights) |
| Strategic | New capabilities shipped, workflows redesigned, employee sentiment on AI, talent signals | Copilot Studio custom metrics; Viva Glint Copilot Impact Survey |
Several of those surfaces live in Viva Insights advanced and analyst templates. Whether they are reachable in a Business Premium tenant, and what licensing they demand, is not established. If they are not reachable the formula still stands, but you compute it by hand from Copilot Studio Analytics — more work, weaker artefact.
Also unconfirmed: whether the hourly rate and multipliers are editable in an SMB tenant. That is the difference between owning the renewal conversation and watching a default number appear. Section 13.
Instrumentation is strong during the pilot, then drifts as the agent moves to production. Microsoft's fix: embed measurement in the deployment workflow itself, so every production agent keeps emitting the signals the review depends on.
Sessions and user counts show usage; they are not value. Every KPI has to trace back to one of the four value drivers, or it is decoration.
“Claiming value based on theoretical time savings alone undermines credibility.” Build a chain of evidence from adoption, through operational KPIs, to business outcomes.
Pattern 3 is aimed squarely at the channel's current pitch. The “X hours per week × headcount × salary” slide is the thing Microsoft is warning against — and you can now retire it internally with a vendor citation rather than an opinion.
Section 3 audited what exists. This is what has to be in place before anything new is published — five layers in dependency order, and one choice that sets the price of everything after it.
A harness is the runtime between your agent design and the model: it decides when to call the model, what to send it, how to interpret the answer, and which tools to call. Microsoft lists four things it determines. Three are capability questions a maker cares about. The fourth is how your usage is billed — and that one is the partner's problem, not the maker's.
| Consideration | GitHub Copilot harness | Standard harness | Copilot chat harness |
|---|---|---|---|
| Best for | Complex, multi-step business processes | Rule-based agents and structured conversations | Extending M365 Copilot Chat with enterprise knowledge |
| How it works | Reasons through a goal on its own, step by step | Follows the topics and rules you define | Connects enterprise knowledge to M365 Copilot Chat |
| Recovers from problems | Retries and finds alternative paths automatically | Follows the paths you've built | Not a focus |
| Works with files | Creates, edits and reasons over Word, Excel, PowerPoint and PDF | Not a focus | Not a focus |
| Skills and memory | Yes | Not a focus | Not a focus |
| Publishing | Internal teams or external customers | Internal teams or external customers | Internal teams only |
| Billing | Usage-based — starts when you start building | Copilot Credits per the rate card, after publish | Consumption, or included in Microsoft 365 Copilot licences |
Copilot chat harness. Knowledge grounding, internal only, billed as consumption or covered by a Copilot licence. Narrow reach, no file creation, no retry.
GitHub Copilot harness. Different capability set, different failure modes, and a meter that runs during your own development. Needs a build-burn clause — section 6.
A partner who quotes without naming the harness has not scoped the work. Name it in design, write it into the SOW, and treat a request to change it mid-build as the scope change it is — because it moves both the capability and the invoice.
This is the spine of the guide. It resolves the margin trap, it takes two to three days, and it is the phase that turns a metered cost base from a risk into the recurring service.
The billing unit is the Copilot Credit. Capacity is pooled at the tenant and allocable per environment. Channel material still talking about “messages” is working from pre-rename documentation — though the older vocabulary survives inside Microsoft's own tables, where the tenant billing capability column still reads “prepaid message packs.” The terms map; the material around them usually does not.
A pooled tenant allocation, allocable per environment, managed in the Power Platform admin center.
Subject to overage enforcement — see 6.3. This is where the 125% kill switch lives.
Enabled by linking an Azure subscription billing plan to the environment. Overage bills to the Azure subscription instead.
Enforcement does not apply. A genuine architectural choice with a commercial consequence — decide it here, not after the first outage.
| Agent feature | Billing rate | Used by a Microsoft 365 Copilot licensed user |
|---|---|---|
| Classic answer | 1 Copilot Credit | No charge |
| Generative answer | 2 Copilot Credits | No charge |
| Agent action | 5 Copilot Credits | No charge (Computer-Using Agents excluded) |
| Tenant graph grounding for messages | 10 Copilot Credits | No charge |
| Agent flow actions, per 100 actions | 13 Copilot Credits | No charge, only via the “When an agent calls the flow” trigger |
| Text and generative AI tools — basic, per 10 responses | 1 Copilot Credit | No charge |
| Text and generative AI tools — standard, per 10 responses | 15 Copilot Credits | No charge |
| Text and generative AI tools — premium, per 10 responses | 100 Copilot Credits | No charge |
| Content processing tools, per page | 8 Copilot Credits | No charge |
One interaction can bill on several meters at once. Microsoft's own example: a tenant-graph-grounded agent may spend 12 credits on a single complex prompt — 10 for the grounding, 2 for the generative answer. Nobody quoting per-conversation gets this right by intuition.
Reasoning models bill twice. Copilot Studio bills the feature rate for the operation plus the premium text-and-generative-AI-tools rate for the reasoning model's token usage. Swapping in a reasoning model is a pricing decision disguised as a quality decision — the single biggest silent cost driver in the platform.
This is not a billing footnote. It is a service-availability event with no user-facing warning, and it belongs in the managed-service agreement.
| Custom agents | Agent flows | |
|---|---|---|
| Trigger | 125% of prepaid capacity | Prepaid capacity fully consumed (100%) |
| What happens | Custom agents are disabled. An ongoing conversation is not interrupted; every subsequent attempt to invoke the agent is rejected | New flow runs cannot start. Runs already in progress complete. The agent remains available for everything else |
| Who is told | Email to the tenant's designated administrator, plus a post in the Power Platform admin center | Flow authors see a design-time warning in the Copilot Studio designer |
| What the user sees | “There is a billing issue.” or “This agent is currently unavailable. It has reached its usage limit.” | Nothing obvious. The agent still answers — it just stops doing things |
| Reset | When capacity is increased or reset | Monthly, when prepaid credits renew |
The admin gets an email; nobody is watching that mailbox at the moment it matters. If you are selling a managed service over this platform, detecting the 125% event before the customer does is a large part of what you are actually being paid for.
The flow column is worse in one specific way: a partial failure is harder to detect than a dead one. The agent answers normally and silently stops completing actions. Nobody raises a ticket for an agent that is still talking.
Per-agent monthly consumption limits. They cost nothing, take minutes, and convert an uncontrolled tenant-wide kill switch into a per-agent budget. Microsoft's own framing is that they cap usage before enforcement is triggered. Set them during phase 4, on every agent, before launch.
Run the estimator against the actual design — harness, orchestration mode, knowledge sources, tools. Produce a forecast the customer has seen and signed off, not a number they discover later.
Set the per-agent monthly limit in the admin center. This is the control that turns a possible outage into a known ceiling, and the one most partners never touch.
Consumption details per environment in the admin center; per-agent consumption on the agent's Monitor page. Watch the trend, not the total — the 125% event is a slope, and it is visible weeks before it lands.
Reconcile forecast against actual, reallocate capacity between environments, adjust the caps, and tell the customer what changed and why.
Four steps, recurring, tool-supported, and every one of them is labour and judgement rather than a licence resale. That is the answer to the margin trap: you do not fix a metered cost base by pricing around it, you fix it by selling the management of the meter. What to charge is settled in section 10 of the Frontier Partner Playbook, not here.
Billing starts when you start building. Unlike the standard harness, which starts billing after publish, the GitHub Copilot harness charges credits from the moment you start building. Experiences such as creating an automated solution with natural language, previewing and testing the agent, and generating and creating agent evaluations all consume credits.Microsoft Learn — Overview of usage-based billing (GitHub Copilot harness)
Read that as a partner. On this harness your own development, testing and QA consume the customer's credits, before anything is published and before anything works. Every SOW that selects the GitHub Copilot harness needs a clause naming who funds development consumption, and a cap on it. Almost none in the channel currently have one.
How big is the burn? Nobody has published a number — which makes the clause a warning rather than a negotiating position. One afternoon of testing would convert it into a figure; see TT-2 in section 13.
The part that looks like the project, and the part most at risk of commoditisation. Prebuilt agent galleries already do a large share of it. That is an argument for this engagement shape, not a threat to it.
A prebuilt agent gallery is an AI use case gallery: production-intent use cases with case study, demo and proof-of-concept actions, filterable by industry and solution area. The reasoning below applies to any such vendor. ExampleUnifyCloud's CloudAtlas AI Factory is on the TD SYNNEX line card and resellable today — stated on the line card's authority, not a public source. Confirm current availability with your rep before quoting it.
Tested logic for a recognisable business problem. A demo you can put in front of a customer this week, and POC scaffolding behind it. Someone else's solved version of the hard design questions.
This is real value and it compresses weeks. A partner who dismisses it is competing on labour against someone who is not.
None of it transfers, because none of it is about the agent — it is about the customer.
And every item on that list is a section of this guide. The last mile is not an afterthought to the build. It is the engagement.
| What the gallery cannot know | Where it is handled |
|---|---|
| The customer's SharePoint permissions state, and which 25 sites the agent should ground in | §5 |
| Sensitivity labels that make knowledge silently unreadable, and password-protected files that index as Ready | §9 |
| Which harness it targets, and therefore when billing starts | §5, §6 |
| Capacity, rate limits, and whether the pilot environment can carry launch-day traffic | §9 |
| Credit run rate, per-agent caps, and who is watching for the 125% event | §6 |
| The baseline, and who configures the measurement constants | §4 |
| Existing ungoverned agents already in the tenant | §3 |
| The process the agent encodes, and who owns it when the business changes it | §8 |
“80% of the way there is 80% of the build, not 80% of the engagement. The gallery gets you a working demo. The last mile is what makes it survive contact with your tenant, and what keeps it alive afterwards.”
It was built against someone else's data, someone else's process and someone else's permissions model. All six ageing sources in section 8 start running the moment it lands.
And one question has no published answer for any vendor: when the vendor updates a gallery template, what happens to an instance already deployed in a customer tenant? That is the versioning question the entire never-done thesis turns on. Ask it before the first deployment, not after.
A proof of concept in days wins the room. It becomes a trap the moment it turns into the production agent without being regrounded in real data — and this is Microsoft's own warning: proof-of-concept ideation on synthetic data “increases the risk of agents not performing as expected in production environments.”
Use the gallery to win the room. Reground it before it goes live.
None of the five have publicly documented answers for any vendor reviewed here. Asking them is a five-minute call that changes what you can safely commit to.
AvePoint AgentPulse serves readiness and steady state — discovery, inventory, policy enforcement, cost insight, backup and recovery for Copilot Studio agents — where a gallery accelerates the build. They compose; they do not compete.
A productised 80% collapses build labour as a revenue line. You cannot bill hours for work a gallery already did, and pretending otherwise loses to whoever stops pretending first. What is left to charge for is the assessment ahead of the build, the last mile through it, and the operations after it — phases 1, 2, 3, 4 and 6. The gallery compresses phase 5, and phase 5 was always the most competitive part.
Where it stops being a project. The claim is not a sales position invented here — Microsoft says it in four places, none of them a marketing page, and two of the ten security risks in section 3 are failures that cannot exist until time has passed.
A taxonomy is only useful if each entry comes with a way of seeing it. The third column is what turns this from a slide into a service.
| Drift | What actually changes | How you detect it |
|---|---|---|
| Data drift | The grounding corpus ages. Content is moved, renamed, superseded or archived; the agent keeps citing it | Source-authority review against the 25 sites; citation analysis in Copilot Studio Analytics; groundedness scored against a rubric |
| Model drift | The model underneath the agent changes. Microsoft names model drift as a risk in its own build guidance — and the customer does not choose the version | A regression run of the golden prompt set on a schedule. This is the one with no alert, so it has to be a calendar item |
| Connector drift | The agent is only as good as what it reaches through, and connectors, APIs and MCP tools change under it | Agent Review Tool anti-pattern scan; DLP policy review; action failure rates in the Agent Insights Hub |
| Permission drift | Tenant ACLs move. Sharing scope, credential mode or authentication gets changed by a maker after go-live | Agent Inventory re-run against the phase 1 baseline — a diff, not a fresh audit |
| Process drift | The business changes the workflow the agent encodes. The agent does not know, and nothing errors | Only the sponsor review catches this. It is why the 90-day cadence has a human in it |
| Cost drift | Volume grows, or a reasoning model is swapped in and the agent starts billing on two meters | Consumption trend per environment and per agent; the true-up step in §6 |
Five of the six originate with the customer or their content. Model drift originates with Microsoft. The reasoning underneath the agent can change without the customer asking for it, and the agent's behaviour can change with it.
Whether the customer has recourse is a product question this research has not settled. The narrower claim is sufficient: there is no alert for it. If nobody re-runs a known set of prompts on a schedule, a behaviour change arrives as a user complaint months later, and by then nobody can say when it started.
This is the artefact. Named failure, the surface it becomes visible on, the free tool that shows it, and who is accountable. Fill in the fourth column for a live customer; every row you cannot fill is the retainer.
| Named failure | Detection surface | Free tool | Accountable owner |
|---|---|---|---|
| The 125% kill — custom agents disabled at 125% of prepaid capacity | Admin email and an admin center post. Users find out by the agent breaking | Consumption trend in the admin center; per-agent caps set in advance | Partner — this is an availability event in the managed-service agreement |
| Partial flow enforcement — flows blocked at capacity while the agent keeps answering | Design-time warning to flow authors only. No user-visible signal | Agent flow actions line in the consumption details grid | Partner |
| Dormant agents (top-10 risk #5) — stale privileged access nobody is watching | Nothing. Dormancy has no event | Agent Inventory; Compliance Hub thresholds and SLA timers | Partner, on the review cadence |
| Orphaned agents (top-10 risk #10) — no active owner, so no review cycle reaches them | Nothing, by definition | Agent Inventory ownership field; the named-owner rule from §5 | Customer names the owner; partner enforces that one exists |
| Knowledge rot — stale corpus, 4–6 hour sync, ALM not carrying knowledge across environments | Silent. Answers get quietly worse | Agent Debugger for what was actually retrieved; Conversation Analyzer; rubric-graded groundedness | Customer owns content currency; partner owns detecting that it slipped |
| Configuration regression — a maker flips authentication, credentials or sharing after go-live | Publish-time security scan warns the maker, and only the maker | Agent Review Tool; Agent Inventory diffed against the baseline | Partner |
Every tool in the third column is free and open source, from Microsoft's Power CAT team. That is the commercial argument as well as the technical one: the tooling costs nothing, so the margin is entirely in the labour and the judgement. A partner who says “we license a governance platform” is beaten by one who says “we run the Compliance Hub, we set the thresholds, we own the SLA timer.”
| Where | What it says |
|---|---|
| Agent development lifecycle | Five phases: discovery, experimentation, build, deploy, and operational steady state — continuously monitoring, evaluating and adjusting. There is no “complete” phase. The lifecycle ends in a state, not an event. |
| Measure the impact of your agents | “Operate an expansion rhythm, treating the program as recurring quarterly work” — pick a workflow, build, measure against baseline for 90 days, review with the sponsor, scale or retire. A recurring-revenue contract shape written by the vendor. |
| Agentic AI maturity model | Treating Responsible AI as a one-time review is a named anti-pattern: “Bias, misuse, and trust drift typically appear after go-live, not before.” Microsoft names the resulting behaviour the “panic and switch things off” response pattern. |
| Agent development lifecycle | Drift named in the build guidance itself: minimise the time between experimentation and build “to reduce the risk of model or data drift.” And POC ideation on synthetic data “increases the risk of agents not performing as expected in production environments.” |
Microsoft's maturity model separates agents into personal productivity, departmental or team, and mission-critical, and names applying one set of controls to all three an anti-pattern — it over-restricts productivity agents, driving shadow AI, while under-governing the mission-critical ones. That is a tiering of the agents. The three AgentOps tiers in section 10 of the Frontier Partner Playbook are a tiering of the service you sell. Use Microsoft's to decide how hard to govern a given agent; use the playbook's to decide what to charge for governing it.
Reference material for phase 3 and phase 5. The traps have one property in common: nothing errors. The status says Ready. The agent answers. The answer is just missing something.
Microsoft's wording is unambiguous: you cannot index documents that use sensitivity labels of confidential or highly confidential, or that are password protected. If you add them, “they show as ready for use but don't provide responses.”
A customer who has done classification well — exactly the mature customer you want — gets an agent that answers nothing about its most important content, with no error anywhere to explain why.
The inverse is a genuinely useful control. Labelling is a cheap, reliable way to hold content out of an agent, it needs no extra tooling, and it works on Business Premium. Used deliberately it is a feature; discovered accidentally it is a failed pilot.
Microsoft states it for every unstructured knowledge source type: ALM “isn't supported for this feature. Importing agents doesn't result in automated knowledge source processing.”
This breaks the clean dev → test → prod story every governance conversation depends on. Say it out loud in the design phase rather than discovering it on promotion day. Plan for knowledge sources to be reconfigured per environment, and budget for it.
Across OneDrive, SharePoint upload, Salesforce, Confluence, ServiceNow and Zendesk sources, Microsoft gives the same figure. Whatever the demo implied, the agent is answering from a corpus that is up to six hours stale.
Fine for policy documents, wrong for anything with a deadline attached. If the workflow needs current data it needs an action against a live system, not a knowledge source — which is a different harness conversation and a different price.
Generative AI rate limits are set per Dataverse environment and scale with how much capacity the tenant owns.
| Quota per Dataverse environment | Tenant billing capability |
|---|---|
| 50 RPM / 1,000 RPH | 1–10 prepaid packs |
| 80 RPM / 1,600 RPH | 11–50 prepaid packs |
| 100 RPM / 2,000 RPH | 51–150 prepaid packs |
| 10 RPM / 200 RPH | Trial or developer environments |
| 100 RPM / 2,000 RPH | Pay-as-you-go environments |
| 100 RPM / 2,000 RPH | Microsoft 365 Copilot users |
And it passes anyway, because six testers never approach ten requests a minute. Launch day puts a hundred people on it inside an hour, and the user-visible symptom is a failure notice when they send a message.
Estimate peak traffic windows, not monthly averages. Monthly volume can look entirely comfortable while a Monday-morning spike breaks the agent. Rate-limit increases can be requested, but the path runs through support and is not guaranteed.
None of these are traps — they are documented, findable and hard. They are here because a partner who meets one mid-build is having a scope conversation instead of a design one.
| Limit | Value |
|---|---|
| Knowledge sources per agent | 500 across all types |
| SharePoint site URLs per agent, generative orchestration | 25 |
| Instructions for a Copilot agent | 8,000 characters |
| Topics per agent (Dataverse environments) | 1,000 |
| Trigger phrases per topic | 200 |
| Skills per agent | 100 |
| SharePoint lists | 15 lists, up to 35,000 rows across them |
| SharePoint list query depth | First 2,048 rows only |
| Maximum file size | 512 MB — but 7 MB for generative answers without a Copilot licence in tenant (200 MB with one, and tenant graph grounding with semantic search on) |
Without a Microsoft 365 Copilot licence in the same tenant, generative answers can only use SharePoint files under 7 MB. Nothing errors. The agent simply does not know things. This is the first appearance of the pattern that runs through this whole page: the failures that matter in Copilot Studio are usually silent.
Agent 365 is the escalation, not the entry ticket. This section is the qualification logic — what to use before it, and the four conditions that turn the dial up. Where it sits commercially is settled in section 10 of the Frontier Partner Playbook.
Effective July 1, 2026, AI agent security capabilities for Microsoft Copilot Studio and Microsoft Foundry agents require a Microsoft Agent 365 license. These capabilities are no longer covered by existing Defender for Cloud Apps or Defender for Cloud licenses.Microsoft Learn — Transition Copilot Studio and Foundry agent security capabilities to Microsoft Agent 365
For Copilot Studio agents, a tenant without an eligible licence lost agent discovery and posture, agent threat detection and real-time protection, and investigation of agent activity in Advanced Hunting.
Three further changes break things quietly:
| Change | Consequence |
|---|---|
| Tenants configured to Block on existing Agent 365 real-time protection rules stopped blocking on 1 July 2026 | To resume blocking, rules must be redefined under the new policy experience. A control that was enforcing is now not enforcing, and nothing announced it in the tenant. |
The AIAgentsInfo Advanced Hunting table is deprecated in favour of AgentsInfo | Saved queries, custom detections and workbooks referencing the old table need updating |
| The AI Agents sub-tab under Cloud Assets was removed for all customers | Licensed or not, that navigation path is gone |
The same transition document also states: “Real-time protection for Microsoft Copilot Studio through Defender for Cloud Apps remains unchanged for tenants that continue using this experience. No action is required.”
That sits awkwardly beside the headline, and reconciling the two would require drawing a line Microsoft has not drawn. Treat the exact boundary as unresolved. If a customer depends on Copilot Studio real-time protection through Defender for Cloud Apps, confirm their specific configuration rather than reasoning from either sentence alone.
| The job | Agent 365 | Free or included alternative |
|---|---|---|
| Tenant-wide agent inventory | Agent registry — broadest coverage, including non-Microsoft platforms via registry sync | Copilot Agent Kit → Agent Inventory; Power Platform inventory |
| Ownerless and dormant agent detection | “Agents without owners” card, rules-based lifecycle enforcement | Agent Inventory + a review cadence |
| Configuration risk / anti-pattern scan | Agents-at-risk, aggregated from Entra, Defender and Purview | Agent Review Tool; the built-in publish-time security scan |
| Policy enforcement, SLA timers, quarantine | Rules-based lifecycle policy, approval flow, blocking | Compliance Hub — thresholds, risk levels, SLA timers, quarantine and delete |
| Connector / DLP boundary | Purview and Entra integration | Power Platform DLP data policies; Power Shield for approval workflow |
| Runtime analytics and telemetry | Agent run-time, active users, trending agents | Agent Insights Hub; Copilot Studio Analytics |
| Debugging a bad conversation | — | Agent Debugger — step-by-step decisions, timing, token usage |
| Business value measurement | Agent run-time hours | Copilot Studio agents report; Savings calculator; Agent Value in the Kit |
| Threat detection, real-time protection, Advanced Hunting over agent activity | Agent 365 only, since 1 July 2026 | No free equivalent. This is the genuine gap. |
Read the last row against all the others. Almost everything an SMB needs on day one is free — inventory, anti-pattern scanning, compliance policy with SLA timers, debugging, analytics and value measurement are all in the Copilot Agent Kit at zero licence cost, plus Power Platform DLP. What is genuinely Agent 365-only is the security-operations layer.
A partner who tells an SMB they need a per-user governance licence before they can govern a single agent is wrong on the facts, and has priced themselves out of the first engagement. Lead with the free baseline in section 3. Earn the right to the next conversation.
The registry stops being a spreadsheet job. Ownerless and dormant agents — risks 5 and 10 — are the tell that the count has crossed the line.
Once an agent acts on its own rather than as a signed-in user it is a new principal in the tenant, and Entra-backed identity governance stops being optional.
SharePoint agents, Agent Builder, or non-Microsoft platforms. Registry sync is the only thing that sees across all of them — the Copilot Agent Kit does not.
Where the customer must demonstrate detection and response over agent activity, not just configuration hygiene. After 1 July 2026 that is Agent 365 or nothing.
Agent 365 admin-led trials are 25 seats for 30 days. The admin center shows a banner with remaining trial days, and admins with billing permissions can view details and purchase directly from it. That is a natural paid discovery engagement: run the registry across the tenant, produce the findings, and let the expiry force a decision that would otherwise drift. Do not let it lapse silently — a trial that ends with nobody watching is worse than never having run one, because the customer now believes they looked.
Is it purchasable on Business Premium? Microsoft Learn says Agent 365 “works best when using Microsoft E5 as a pre-requisite.” That is hedged language, not a requirement statement. Channel aggregators claim an SMB path under 300 seats. Those are not the same claim — and this is the exact failure mode the Copilot Readiness Engagement, section 9 documents with SAM: two readings of one hedged licensing page, in opposite directions, both wrong to act on.
Who counts as a licensed user? Microsoft states at least one user must hold a qualifying licence to enable Agent 365. What is not established is whether that means every user who interacts, every maker, or only the governing admins. A sixty-person company with one help-desk agent everybody talks to is either three licences or sixty — a twentyfold difference in the same deployment. Get it from your distributor or Microsoft in writing, for the specific deployment shape. There is no shame in telling the customer you are confirming it; the alternative is guessing on their invoice.
Microsoft published an agent risk list in February and licensed its recommended detection method in July. Assume more of this surface becomes licensed over time, and build the service so the labour and the judgement are the product — those are the parts that do not get absorbed into a SKU.
Everything below already exists, most of it is free, and almost all of it is published by Microsoft. This is tools you use; the long-form guide's reference library is sources cited. They overlap and they are not the same list.
“Copilot Chat is included with the Microsoft 365 subscription you already have. If you want an agent that uses your own data, that is billed on usage rather than per person — so you do not need to buy a Copilot seat to start.
What that costs is a real number and I am going to forecast it for you before you sign anything, and cap it before we launch. The seat is a capability upgrade we can look at later, on evidence, once we know what the agent is actually worth to you.”
| Objection | The answer |
|---|---|
| “Don't we need Copilot licences first?” | No. Copilot Chat is included with any Microsoft 365 or Office 365 subscription and agents are billed on metered consumption. Read Microsoft's sentence aloud — it lands better verbatim than paraphrased. |
| “We can't afford the readiness work.” | You are thinking of the tenant-wide Copilot readiness programme, which you cannot license on Business Premium anyway. An agent's blast radius is 25 named sites and three Power Platform settings — a task, not a programme. But be honest about the limit: oversharing inside those 25 sites is not fixed by scoping the agent. What shrinks is amplification. |
| “Why am I still paying you after it's built?” | Three answers, in order of strength. One: the meter — nobody is watching for the 125% event, and your users find out by the agent breaking. Two: Microsoft's own security list names two failures (dormant and orphaned agents) that cannot exist at build time and are only found by a recurring review. Three: the model underneath your agent can change without you asking, and there is no alert for it. |
| “Can't we just buy a prebuilt agent?” | Yes, and you probably should — it compresses weeks. 80% of the way there is 80% of the build, not 80% of the engagement. Then walk the last-mile table in section 7. |
With end-user credentials — the secure default — the agent resolves the signed-in user's own permissions. A genuinely overshared site inside those 25 remains reachable by exactly the people who could already reach it. The oversharing defect is not fixed by scoping the agent.
What shrinks is amplification: a machine surfacing something a user could technically open but would never have found. That shrinks from tenant-wide to 25 named sites — the difference between a programme and a task.
And it shrinks only while the credential setting holds. Flip it to maker-provided credentials and the whole argument inverts. That setting is the first thing section 3 audits, and it is the reason section 3 exists.
None was located for this guide. What exists is a Microsoft enterprise self-reference and a set of unattributed channel numbers. The honest version is more useful in front of a partner than a borrowed number would be:
“There is no audited SMB case study yet. That is exactly why you instrument the baseline before you build — because you are going to be it.”
None of these has been tested for this guide. Each is cheap. A section resting on an open test ships with the uncertainty stated, or it does not ship — it never ships with a guess.
| # | What is unknown | What it gates | What would settle it |
|---|---|---|---|
| TT-1 | Can you buy Copilot Credit capacity and publish a working agent to Copilot Chat in a Business Premium tenant with zero Copilot seats, without hitting an undocumented licensing wall? | §1 — the page's central claim | Run it once end to end and record every point a licence is requested |
| TT-2 | How many credits does a trivial agent consume on the GitHub Copilot harness before publish? | §6 — turns the build-burn clause from a warning into a number | Build one, preview and test normally, read the Monitor page before publishing |
| TT-3 | When a Confidential-labelled document fails to index, does any signal reach the maker, the user, or the debugger? | §9 — the trap list | Add one, wait for Ready, ask a question only it can answer, record all three surfaces |
| TT-4 | Is the Copilot Studio agents report reachable in an SMB tenant, and is the default hourly rate editable there? | §4 — the measurement argument | Open it in a Business Premium tenant; record the licence demanded and whether the calculator accepts a change |
| TT-5 | Do Managed Environments — needed for sharing limits and pipelines — require premium per-user licensing across the tenant, and does a Copilot Studio standalone licence qualify? | §5 — the most likely wall on the no-seat path | Current Power Platform Licensing Guide, read against a distributor quote, in writing |
| TT-6 | How many agents already exist in a real SMB tenant, and how many use maker credentials, no authentication, or have no owner? | §3 — whether the wedge is real or theoretical | Run Agent Inventory across three tenants; tabulate auth mode, credential mode, sharing scope, owner |
| TT-7 | Is Agent 365 purchasable on Business Premium? | §10 | CSP price list or distributor catalogue, for the specific tenant |
| TT-8 | Who needs an Agent 365 licence — every user who interacts, every maker, or only governing admins? A twentyfold spread on the same deployment | §10 — the most important number to resolve before quoting | Distributor or Microsoft, in writing, for the specific deployment shape |
| TT-9 | Does one Agent 365 licence enable tenant-wide observe and govern, given Microsoft states at least one licensed user enables it? | §10 | Run the 25-seat trial and check what registry coverage a single assigned licence produces |
TT-1, TT-7 and TT-8 are the three most likely to repeat a known failure. The Copilot Readiness Engagement, section 9 documents what happens when one hedged Microsoft licensing page gets read two ways: two internally consistent conclusions, in opposite directions, both wrong to act on.
This page carries one currency figure — Microsoft's default $72 hourly rate in the Agent Assisted Value formula. Everything else about consumption is expressed in Copilot Credits, which are a unit of usage rather than money and need no provenance tag.
A working session for a partner team, not a customer pitch. It decides which phase of the arc your practice is currently giving away, and which open test you run first. Every visual it needs is already on this page — run it from the page, no deck.
Say: “Before we talk about anything we build, here is a complete engagement from the first conversation to the retainer. Seven phases. I want to know which of these we currently do and which we give away.”
Show: the seven-phase table in §1.2. Walk it across, not down. Spend the time on the Paper and What must be true columns — everyone in the room already understands the build.
Do: have each person privately mark the phases they have personally delivered and been paid for in the last year. Do not collect them yet.
Say: “Phases 0 and 1 happen before the build worklist even starts, and both are billable. If our engagements begin at Discover, we have handed the assessment away and started at the most competitive part.”
Show: the three blast-radius settings and Microsoft's ten misconfigurations — §3. The point to land: maker-provided credentials is invisible to every Copilot readiness report we currently sell.
Do: collect the marks from stop 1. Count how many people have been paid for phase 1. In most rooms the answer is nobody.
Say: “We have been gating the agent conversation behind a Copilot seat purchase. Microsoft's own documentation says we don't have to.” Read the line in §12.1 aloud — verbatim beats paraphrase.
Show: the licensing strip in §1, then immediately the limit in §12.3: amplification shrinks, oversharing does not, and the whole argument inverts on one credential setting.
Do: name a real customer in the room who is on Business Premium with no Copilot seats. Ask what has been stopping the agent conversation with them. That is the test case.
Say: “We sell a flat monthly fee over a cost base that moves. That is the trap. Phase 4 is how we get out of it, and phase 4 is the one we skip.”
Show: the rate card and the overage table — §6.2 and §6.3. Land three things: an agent action is 5 credits and not the 25 the blogs say; a single prompt can bill on three meters; at 125% the customer's users find out by the agent breaking.
Do: open the Power Platform admin center on screen and navigate to Licensing → Copilot Studio → Manage Agents. Ask who in the room has ever set a per-agent cap. Then walk the four-step loop in §6.5 as the recurring deliverable.
Say: “This is not our recurring-revenue pitch. It is Microsoft's lifecycle, Microsoft's ninety-day rhythm, and Microsoft's security organisation naming two failures that cannot exist until time has passed.”
Show: the six drifts and the failure register — §8.1 and §8.2. Dwell on model drift: the one change that originates with Microsoft, and the one with no alert.
Do: take the failure register and fill in the fourth column for one live customer. If the room cannot name an accountable owner for each row, that gap is the retainer.
Say: “Two things get decided before we leave. Which phase we stop giving away, and which tenant test we run this month.”
Decision one: pick a single phase from §1.2 to productise first. Phase 1 is the usual answer, because it needs no purchase from the customer. Name the owner and the first customer.
Decision two: pick one open test from §13.2 and put a date on it. TT-1 validates whether we can start at all; TT-6 tells us whether phase 1 is a real wedge; TT-8 changes what we tell customers about Agent 365. All three are cheap.
You are the first tenant. Run phase 1 against your own Power Platform environments before you sell it — Agent Inventory takes an afternoon, and the findings from your own tenant are the only ones you can show without a customer's permission. That is also the honest answer to the missing case study in section 13.