There's a moment every IT person will recognise from the last two decades: a technology stops being a feature you enable for users and becomes a system you're responsible for. Email did it. Mobile did it. The cloud did it. In 2026, Microsoft's Copilot did it — and a lot of IT teams haven't noticed yet, because it still looks like a helpful button in Word. It isn't. It's become a class of thing I now have to inventory, permission, monitor and switch off, exactly like a server or a service account. This is a note from that shift, written for the people who'll be answerable for it.

I run a Microsoft-heavy estate and I've spent this year watching Copilot cross the line from novelty to infrastructure. The vendor messaging is all productivity and magic. The administrator's reality is quieter and more consequential: you've just been handed a new category of privileged, autonomous account, and the tools to govern it arrived at roughly the same time as the thing itself.

1. Copilot is an identity now, not a feature

The change that reframes everything is this: Microsoft's newer agents get their own identity. An Entra Agent ID, in some cases an email address, a presence in Teams, even a place in the org chart. The new "autopilot" style of agent can start its own conversations, work on shared files, follow up on action items and collaborate with people over time. Read that again as an administrator, not a user. That is not a feature. That is a non-human account with standing access and initiative, and I have to treat it with the same seriousness I'd treat a new employee or a service account — arguably more, because it acts faster and doesn't get tired.

Everything I already believe about identity being the security perimeter applies here, just with higher stakes. An agent is an identity that can act. The moment you have those in your tenant, "who can access what" stops being a question only about people.

2. Agent 365: the control plane you'll need whether you wanted it or not

To Microsoft's credit, they shipped the governance layer alongside the capability rather than years later. Agent 365 is now generally available as a centralised control plane for agents across the environment — one place to see the agent inventory, their permissions, their behaviour and their activity. If you're running Copilot Studio or Foundry agents, the security capabilities now route through it, and as of this month it's a licensing requirement for those agent security features.

My honest advice: stand this up before you have a sprawl problem, not after. The pattern I've seen with every previous platform shift is that capability arrives first, everyone enables it enthusiastically, and governance gets retrofitted in a panic eighteen months later once nobody can say how many of the things exist or what they can touch. A control plane you adopt on day one is administration. A control plane you adopt after the sprawl is archaeology.

The question that used to define a tidy estate was "how many servers do we have and who owns them?" The 2026 version adds "how many agents do we have, what can each one reach, and who is accountable when one misbehaves?"

3. The permission model is the whole game

Here's the part I cannot say loudly enough, because it's where the real incidents will come from. Copilot and its agents surface whatever the identity running them can technically reach. They don't hack around your permissions; they inherit them, and then they make the consequences of your permissions instantly, effortlessly visible. If your SharePoint and Teams have been a quiet free-for-all for years — and in most organisations they have — Copilot doesn't create a new exposure so much as turn a latent one into a live one at conversational speed. "Technically everyone could open that folder" becomes "the assistant just pasted that folder's contents into a chat for someone who never should have seen it."

So the unglamorous prerequisite for safely adopting AI in a Microsoft estate isn't an AI project at all. It's a permissions and data-governance clean-up: find the sensitive data, label and protect it with Purview, and fix the oversharing before you widen Copilot's reach. I know that's not the exciting part. It's the part that determines whether your AI rollout is a productivity story or an incident report.

4. What breaks first

From watching real rollouts, the failure modes cluster:

  • Oversharing made visible. The number-one issue, every time. Not a Copilot flaw — a permissions debt Copilot collects on.
  • Shadow agents. Someone in a business unit spins up an agent in Copilot Studio to solve a local problem, wires it to real data, and nobody in IT knows it exists. This is the new shadow IT, and it's faster to create and harder to see.
  • Over-trust. Users treat confident output as correct output. That's a training and culture problem, but the incidents land on IT's desk.
  • Cost surprise. Consumption-based AI has a way of producing a bill nobody forecast. Governance tooling now offers per-project token budgets and monitoring; use them from the start.

5. The IT team's new job: agent lifecycle

Put it together and a new operational discipline falls out, one that looks a lot like joiner-mover-leaver for people, applied to agents. An agent should be provisioned deliberately, with a named human owner and a defined, least-privilege scope. It should be inventoried in the control plane. Its activity should be logged somewhere you'd actually look. And — the step everyone forgets — it should be decommissioned when its purpose ends, because an orphaned agent with lingering access is exactly the kind of forgotten privileged account that shows up in a breach report. If you've ever run a proper identity lifecycle for staff, you already know how to do this. You just have a new, faster-moving population to do it for.

6. Where I'd start on Monday

If Copilot is arriving in your estate and you're the one who'll answer for it, here's the order I'd work in. First, fix the foundation you already own: MFA and conditional access solid, permissions cleaned up, sensitive data labelled — the same identity-and-data hygiene I'd insist on before any cloud rollout. Second, stand up the control plane and make agents visible before they proliferate. Third, write the one-page policy: who can create agents, what data they may touch, who owns each, how they're retired. Only then widen the capability to users, with the training that confident output still needs a human check.

None of this is anti-AI. I'm genuinely enthusiastic about what a well-governed Copilot does for a small IT team — it genuinely multiplies a small team. But that only holds on top of the fundamentals, and the fundamentals are the same ones I've been arguing for across twenty years: know your identities, govern your data, own your lifecycle. AI didn't change the rules. It just raised the stakes and shortened the timeline. If you're planning a Copilot rollout and want the governance thought through before the switch flips, get in touch.