Copilot governance is 9 tenant decisions, not one permissions project. Your license tier decides which of them you can actually enforce. Every Microsoft 365 Business and Enterprise plan already includes an agent registry with block, delete and reassign rights. Policy enforcement, agent telemetry and agent audit logs need Microsoft 365 E7 or the Agent 365 add-on at $15.00 per user per month.
The first Copilot governance conversation I have with a client almost never starts with Copilot. It starts with a spreadsheet of licenses somebody already bought. Sometimes hundreds. By then the question is no longer whether to govern the rollout. It’s how much of the governance they wrote down they can actually enforce with what they own. Usually less than they think.
That gap is the whole subject of this guide. If you’re earlier on, the managed AI services hub explains where governance sits in the wider program, and our Copilot readiness checklist covers the technical prerequisites. This piece assumes something different. The licenses are coming, and the rollout date is real.
One number frames it. Deloitte surveyed 3,235 business and IT leaders across 24 countries for the 2026 edition of The State of AI in the Enterprise and found that only 21% report having a mature model for agent governance, while close to three-quarters plan to deploy agentic AI within 2 years. The gap isn’t awareness. It’s enforcement.
What Copilot governance actually covers
Copilot governance is the set of tenant decisions that control who can use Copilot, what it’s allowed to read, which agents can run inside your organization, and how prompts and responses are logged. Microsoft groups those controls into the Copilot Control System.
Microsoft splits the Copilot Control System into 3 pillars, and the split matters because the pillars live in different admin centers with different license requirements. Security and governance covers data protection, AI threat detection and compliance. Management covers licensing, the agent lifecycle and customization. Measurement covers adoption reporting. Different teams own each. Three pillars, three admin centers. Almost every governance document I review covers the first one and stops there.
Microsoft’s own security and governance documentation draws a line through that first pillar too. It calls controls in the Microsoft 365 admin center, SharePoint Advanced Management and Purview with an A3, E3 or G3 license “foundational.” It calls controls in Purview and Defender for Cloud Apps with an A5, E5 or G5 license “optimized.” Read that again. Those are licensing words dressed up as maturity words.

Worth being direct about the bias here. Uprite sells managed IT and Copilot deployment work, so of course a governance guide from us ends with more things to govern. The threshold I’d use is this. If you have a full-time Microsoft 365 administrator who already opens Purview every week and can name your tenant’s sensitivity labels without looking, you can run this yourself from the links below. Genuinely. If your admin is a network engineer who inherited the tenant, the decisions are still yours but the execution is where teams like ours earn the fee.
The 9 decisions, and who actually owns each one
Governance fails in small businesses for a boring reason. Nobody writes down who decides. The IT manager assumes leadership will rule on retention. Leadership assumes IT already handled it. Then a license activates and the defaults decide for everyone. That’s the failure mode.
Here’s the register I build with clients before a rollout date gets set. Nine rows. Each one has a name next to it before we go live. No blanks.
| Decision | Who should own it | Where it’s set | Easy to reverse? |
|---|---|---|---|
| Who gets a paid Copilot license | Finance with IT | Microsoft 365 admin center, Billing | Yes |
| Whether Copilot Chat stays available to unlicensed staff | IT | Microsoft 365 admin center, Copilot settings | Yes |
| Whether Copilot may ground answers in the public web | Security lead | Microsoft 365 admin center, Copilot settings | Yes |
| Which SharePoint sites Copilot may read | Site and data owners | SharePoint admin, restricted content discovery | Slow, propagation takes time |
| Which sensitivity labels block Copilot processing | Compliance or the owner | Purview DLP, Copilot location | Yes, with a lag |
| Who is allowed to build agents | IT | Copilot Studio, Power Platform admin center | Yes |
| Which agents reach everyone in the Agent Store | AI Administrator | Microsoft 365 admin center, Agents, Requests | Yes |
| Who owns each agent that ships | The requesting department | Microsoft 365 admin center, Agent Registry | Yes, but the old owner loses all access |
| How long prompts and responses are retained | Legal or the owner | Purview Data Lifecycle Management | No, deletion is permanent |
Two rows on that list are the ones people get wrong. Row 2 is the one nobody thinks about, because Copilot Chat is already on for staff who never got a paid seat, and it’s the surface where shadow AI habits quietly become sanctioned ones. Row 9 is the expensive one. A retention policy only governs forward, so the months you spend deciding are months of prompts and responses that policy will never reach.
Permissions, the thing every governance article leads with, is row 4. One of nine. Not the spine. It’s genuinely important and we’ve written a whole piece on fixing Copilot permissions before rollout. It is not the program.
Which Copilot governance controls does your license already cover?
This is the part that changed in 2026, and it’s the reason this guide exists.
Microsoft Agent 365 went generally available on 1 May 2026 as the control plane for agents, priced at $15.00 per user per month on an annual commitment, and included in Microsoft 365 E7 at $99.00 per user per month. Those figures come off Microsoft’s own Agent 365 plans page. Look at $99.00 and the reasonable conclusion is that agent governance is an enterprise product and smaller companies are locked out of it entirely.
That conclusion is wrong. The correction is sitting in a licensing table almost nobody reads. Microsoft’s Agent 365 service description lists 4 capabilities as included with Microsoft 365 Enterprise, Business, Education and Front Line Worker plans. Not as an add-on. Included.
| Agent 365 capability | Included with Microsoft 365 Business and Enterprise plans | Needs E7 or the Agent 365 add-on |
|---|---|---|
| Inventory of every agent in the Agent Registry | Yes | |
| Publish, deploy, block, delete, approve, assign to groups, reassign owner | Yes | |
| Rules-based automation of agent lifecycle actions | Yes | |
| Sync agents from outside platforms into the registry | Yes | |
| Policy templates applied to agents | No | Yes |
| Agent activity telemetry and observability | No | Yes |
| Control which tools and MCP servers agents can reach tenant-wide | No | Yes |
| Graph API access to the registry and governance actions | No | Yes |
| Conditional access and identity protection for agents | No | Yes |
| Audit logs and eDiscovery of agent interactions | No | Yes |
| Data loss prevention blocking agents from sensitive content | No | Yes |
| Insider risk detection applied to agent activity | No | Yes |
Read the top 4 rows again. Inventory and the kill switch are free with the plan you already pay for. That’s the difference between knowing what’s running in your tenant and guessing. Nobody sells you that upgrade, because there’s nothing to sell, which is probably why the reseller blogs covering Agent 365 pricing all led with the $15.00 figure and none of them mentioned that the registry itself arrives with the plan you bought two years ago.
The bottom 8 rows are where the money goes, and they share a theme. Everything you’d need to prove governance to an auditor, an insurer or a client sits behind E7 or the add-on. Everything you need to exercise governance is already yours. So write the policy against the top 4 today. Put the bottom 8 in next year’s budget conversation with a real number attached. Our breakdown of what Copilot actually costs a Texas SMB walks through how these add up per seat.

Agents are the part your policy doesn’t cover yet
Almost every Copilot acceptable use policy I see was written for a world where Copilot summarized documents. Agents broke that. Completely. An agent has an owner, a set of knowledge sources, permissions of its own, and a lifespan that outlasts the person who built it.
Microsoft’s admin center now recognizes 10 agent types, which tells you how fragmented this got. Copilot Studio declarative agents, Copilot Studio custom engine agents, business process agents, Foundry line-of-business agents, Foundry non-LOB agents, Foundry hosted agents, Agent Builder agents, SharePoint agents, Agents Toolkit agents, and agent instances extended with the Agent 365 SDK. Ten. A SharePoint agent gets created by a department head clicking a button on a document library, which means the person who just published something that reads a folder of contracts and answers questions about them on behalf of anyone with access didn’t think of themselves as deploying software and would be genuinely puzzled to hear it described that way. Nobody files a ticket. Nobody would think to.
Four things about the registry are worth knowing before you rely on it.
- Only 2 roles can act. Approving an agent request or assigning an owner requires AI Administrator or Global Administrator. Every other role can see the governance gap and do nothing about it, which is a support ticket waiting to happen.
- Draft agents are mostly invisible. The registry currently shows drafts from Copilot Studio only. Drafts built in Agent Builder, Foundry and SharePoint aren’t listed, and those are exactly the tools your non-technical staff reach for.
- Blocking doesn’t mean the same thing everywhere. Block an Agent Builder or Copilot Studio agent and it stops working in Copilot, Outlook, Teams and the rest. Block a SharePoint or Foundry agent and, per Microsoft’s agent actions documentation, it only stops appearing in Copilot Chat. It keeps running where it was built.
- Deleting is final and slow. Deleting an agent removes it from inventory, deletes all associated files and deletes the underlying SharePoint Embedded container. Microsoft states the process is irreversible and can take up to 24 hours to reach every user who had access.
Ownership has a sharp edge too. Reassigning an agent to a new owner gives that person full edit and delete rights plus access to files the previous owner uploaded, and the previous owner loses all access including read. Including read. If your governance rule is “reassign agents when someone leaves,” write down who checks the files first.
Our AI acceptable use policy template handles the employee-facing side of this. Agents need the operator-facing half. That means an owner, a review date and a documented reason to exist.
What the audit log will and won’t prove
Auditing for Microsoft Copilot is part of Audit Standard, which means it’s on by default for new tenants and you don’t configure anything extra. That’s the good news. The detail underneath is better than most people expect and worse in 2 specific places.
Each interaction record carries a lot more than a timestamp. Microsoft’s audit documentation for Copilot and AI applications lists the fields. These are the 7 that matter for governance.
| Audit field | What it lets you prove |
|---|---|
| AccessedResources | Every file, email or site Copilot read for that answer, with the name, SharePoint URL and SensitivityLabelId |
| XPIADetected | A cross prompt injection attempt arrived inside a document Copilot was reading |
| JailbreakDetected | A user tried to talk Copilot past its guardrails on that prompt |
| AISystemPlugin.Id set to BingWebSearch | That answer was grounded in the public web, not just your tenant |
| ModelProvider and ModelName | Which model vendor and model version processed the request |
| AgentId, AgentName, AgentVersion | Which agent handled it, and which build of that agent |
| DLPEvaluationDeferred | Your DLP policy did not finish evaluating that interaction |
Two of those rows deserve a second look.
The ModelProvider field exists because Microsoft 365 Copilot is no longer single-model. Audit records can show values like OpenAI with a GPT model, or Anthropic with a Claude model, when a user picks a specific model instead of leaving the selector on Auto. That surprises people. Every time. If your AI policy promises the board that prompts stay inside Microsoft’s stack, that sentence now needs a footnote, and the audit log is where you check it rather than assume it. Microsoft also notes that with Auto selected, provider and model name might not be recorded for every request.
DLPEvaluationDeferred is the one that keeps me honest. It’s a bitmask, and the values tell you which stage got skipped. 1 means the prompt wasn’t evaluated, 2 the response, 4 the grounding content, 8 the web grounding content. A policy that is switched on is not the same thing as a policy that ran. Those are different claims. Timeouts and service errors are both listed as reasons. If you’re relying on DLP to keep regulated data out of Copilot answers, query this field before you tell anyone the control is working. Check it quarterly after that.
Retention deserves its own decision, which is why it sits at row 9 of the register. Purview Data Lifecycle Management can enforce retention and deletion on Copilot and agent interactions, and eDiscovery can put a user’s prompts and responses on legal hold and search them for an investigation, but every one of those capabilities only reaches the records that exist by the time you switch the policy on. Set it early. It costs nothing to decide.
One budget note. Audit records for non-Microsoft AI applications aren’t covered by your subscription. Those fall under pay-as-you-go billing, retained for 180 days, charged by the number of records ingested. That’s the shadow AI bill nobody forecasts. Budget for it.

Four traps that make a governance program look finished
These are the ones I’ve watched teams walk into. All four produce a green dashboard. That’s what makes them dangerous.
| What looks fine | What’s actually happening | How to check it |
|---|---|---|
| The agent is blocked | Blocking a SharePoint or Foundry agent only removes it from Copilot Chat, so it still runs in its own host | Test the agent where it lives, not only in Copilot |
| The admin action went through | Power Platform Firewall in active enforcement rejects actions from the admin center, because the request arrives from the upstream service IP | Power Platform admin center, Security, Identity and access, IP firewall, Advanced tab |
| The registry is empty, so there are no agents | Drafts outside Copilot Studio aren’t listed yet | Ask department heads directly what they’ve built in SharePoint and Agent Builder |
| Usage looks clean across the last 30 days | Agent metrics start collecting at license activation, with no backfill | Treat the first month as a baseline, not an all-clear |
The firewall one is nasty because it fails quietly. In audit-only mode the same action succeeds and simply raises an alert in Purview. In active enforcement mode the action fails and doesn’t apply. Same click, same confirmation flow, different outcome, and the difference is a toggle sitting in a different admin center that your Copilot admin probably doesn’t have access to. Go look at it now.
What does a 30-day governance start look like at 50 people?
You don’t need a committee. Uprite runs with a team of 42 and we didn’t form one. What you need is a named owner per decision and 4 hours a week for a month. That’s it.
- Open the Agent Registry in the Microsoft 365 admin center and export the list. This is free with your plan. Do it before anything else, because the rest of the month depends on knowing what’s already running.
- Assign an owner to every ownerless agent. Anything nobody claims gets blocked, not deleted, until someone does.
- Confirm who holds AI Administrator. If the answer is “the Global Admin, I think,” that’s your first fix.
- Decide row 2 of the register. Copilot Chat is already live for unlicensed staff, so make that a decision instead of a default.
- Run a Purview audit search for CopilotInteraction and read 20 records end to end. You’re looking for AccessedResources entries that surprise you.
- Set a retention policy for Copilot interactions before volume builds. Retention only governs forward.
- Write the one-page policy. Who can build agents, who approves them, what the review date is, and what happens when an owner leaves.
- Put the E7 or Agent 365 decision on the budget calendar with the $15.00 per user figure attached, so it’s a choice rather than a surprise.
Notice what isn’t on that list. No labeling project, no tenant-wide permissions remediation, no 90-day readiness sprint. Those matter, and the AI readiness assessment is where they belong. They’re also the reason governance programs stall at step 1 and never reach the agent inventory. Sequence matters more than scope. Start small.
Where Texas rules fit into this
Governance and compliance overlap here but they aren’t the same work. The Texas Responsible Artificial Intelligence Governance Act sets obligations around intent, disclosure and documented risk management, and we’ve covered what TRAIGA requires of Texas SMBs separately, along with the broader AI governance and compliance program that sits around it.
The connection worth making is evidence. A documented risk management process is only as good as the records behind it, and for Copilot those records are the audit log, the agent registry export and the retention policy. Every item in this guide produces one of those. That’s the argument for doing the free parts now, even if the paid tier waits until next year.

What teams ask before they switch Copilot on
Do we need Microsoft 365 E7 to govern Copilot properly?
No, agent inventory, blocking, deleting, approving and owner reassignment are all included with Microsoft 365 Business and Enterprise plans. E7 or the Agent 365 add-on buys enforcement and evidence, meaning policy templates, agent telemetry, conditional access for agents, DLP and agent audit logs. Start with what’s included. Budget the rest deliberately.
Who should own Copilot governance in a company without a CISO?
Split it between 2 people, with one named person holding AI Administrator to execute and the business owner or a department head signing off on retention, web grounding and which agents ship. Governance breaks when one person holds both. The admin ends up making business risk calls at 4pm on a Friday, usually while a department head waits on an agent approval, and the answer that gets given in that moment becomes the policy nobody wrote down. Separating the two roles costs nothing. It just means naming the second person before the first one needs them.
Is Copilot Chat governed the same way as a paid Copilot license?
Not quite, because Copilot Chat reaches staff who never got a paid seat and comes with web data agents, even though the same admin center controls apply to both. A lot of teams govern only the licensed population and leave the larger unlicensed one sitting on defaults. Check that population before rollout. Not after.
How do I find agents somebody already built without telling IT?
Export the Agent Registry, then ask people. It lists published agents well, but drafts only from Copilot Studio, so the conversation catches what the dashboard misses.
Can we prove to an auditor that Copilot never touched regulated data?
You can prove which resources Copilot accessed, because audit records carry file names, SharePoint URLs and sensitivity label IDs for every interaction. Proving a negative is harder. Check the DLPEvaluationDeferred field before making that claim, since a deferred evaluation means the policy did not finish running on that interaction.
What happens to agents when the person who built one leaves?
Nothing happens automatically, so the agent keeps running and shows as ownerless in the registry until somebody acts. An admin can reassign it, but the previous owner then loses all access including read, so check the uploaded files first. Build that step into offboarding now.
How often should a governance review actually happen?
Monthly for the first quarter, then quarterly. The monthly cadence exists because agent counts move fast early and the registry gives you a number you can compare month over month. After that the review is 3 questions. What’s new, what’s ownerless, and what hasn’t been used in 60 days.
Getting this set up without stalling the rollout
Nearly all of the first month costs you nothing but attention. The registry, the ownership pass, the audit search and the policy page are available on the plan you already hold, and they answer the question a board or an insurer is going to ask, which is whether you know what’s running.
If you’d rather not run that month yourself, our Microsoft Copilot deployment team does this as a fixed scope of work across Houston, San Antonio, Dallas and Fort Worth. We’ll do the registry export, name the owners with you, set retention and hand back the one-page policy your staff will actually read. Call us at (866) 570-3065 or send the tenant details and we’ll tell you which of the 9 decisions are still on defaults.









