Managing agents in Microsoft 365 has officially leveled up. Until now, admins had to hunt through multiple admin centers to find Copilot Studio agents, 3rd Party Agents, SharePoint agents, and the other many types of agents available!
In this interview from PPPC25, I sit down with Zohar Raz, Group Product Manager at Microsoft, to walk through the brand-new Agent Inventory experience — a unified way to discover, govern, and monitor every agent across your organization.
🔎 In this video we cover:
✅ The new Power Platform Admin Center inventory (V3)
✅ How Microsoft loads 1.6M+ agents, flows, and apps in seconds
✅ Where to find Copilot Studio agents, SharePoint agents, Light agents & more
✅ How the Microsoft 365 Admin Center will soon show all agents in one place
✅ Managing agent permissions, versions, models, and lifecycle
✅ New governance controls: environment groups, advanced connector policies, sharing limits, and more
✅ How managed environments unlock enterprise-grade governance for agents
Whether you’re an IT admin, governance lead, or building your Copilot adoption strategy, this is the clearest look yet at how Microsoft plans to bring true enterprise visibility to the AI era.
Want to learn from more pros? Learn from some of the top talent around the world at M365 Community Conference, and get $150 off with discount code VLAD150! Have questions? Check out my M365 Community Conference FAQ!
Watch my 100+ courses on Pluralsight
Video Summary
- One Pane of Glass for Agents Is Coming. Managing agents across Copilot Studio, SharePoint, and Azure AI Foundry has been a challenge—but Microsoft is working hard to bring everything into a single view. Soon, the Microsoft 365 Admin Center will show all published agents, making governance easier than ever.
- Power Platform Admin Center Gets a Big Upgrade. The new green Power Platform Admin Center introduces an Inventory page that loads millions of assets—apps, flows, and agents—in seconds. You can filter, sort, and even export data or connect via API for advanced reporting.
- Governance at Scale with Environment Groups. Admins can now apply policies across thousands of environments in one click. From sharing limits to connector restrictions, advanced connector policies give granular control—even down to specific actions on connectors.
- Managed Environments Are a Must for Serious Admins. If your organization uses agents, you’re entitled to managed environments without extra cost. This unlocks 50+ governance features, saving you hours of manual scripting and giving you enterprise-grade control.
- What’s Next? More Agent Types and Approval Workflows.
Soon, SharePoint agents and Copilot Studio Light agents will appear in the Microsoft 365 Admin Center. Plus, requested agents can now be approved or rejected directly in the same pane—no more jumping between admin centers.
For more information, read the transcript blog below, or watch the video above!
Want to learn how to create Agents for Microsoft 365 Copilot? Watch my series here!
Transcript
We all know that “agents” is the word of the year, but when it comes to managing them, administrators across the enterprise are having a bit of trouble finding all the different types of agents that are available. We have agents made in Copilot Studio, agents made in Copilot Studio Light, SharePoint agents, and for those of you who are more advanced, even stuff in Azure AI Foundry. So today, we’re going to take a look at how we can discover and manage all the different agents that our organization has.
To do this the right way, I’m honored to be joined by Zohar Raz, a Group Product Manager at Microsoft. Thank you so much for being here. You have a unique experience at Microsoft. When you were on the SharePoint team or M365 management, you were hearing me complain about SharePoint stuff. Now you’ve moved over to the Power Platform and made it enterprise-ready. I like to say you’re the one responsible for bringing all the admin and governance stuff, and that has advanced really, really fast.
I’m sure you know, and I’m sure many customers talk to you, that we have so many different admin centers to manage things. But you told me it’s getting better, and you had a few sessions this week at the Power Platform Conference. So, can you show us what’s new and how we can manage agents today?
“Yes, thanks, Vlad, for having me and thanks for the introduction. I think I spent a decade plus in SharePoint and OneDrive helping build the SharePoint Admin Center, and then I moved to the Power Platform side to do pretty much the same on the Power Platform. People call me Mr. Managed Environments. We did a lot of managed environment stuff and then built the new Power Platform Admin Center. We’ve heard loud and clear from customers that apps, flows, and agents—you can only govern what you see. So we’ve heavily invested now and announced in this week’s conference the new inventory experience for agents, apps, and flows. We’re also working really closely with the friends in the Microsoft 365 Admin Center to bring a lot of that visibility to a one pane of glass where you can actually see not just the things that are built on the Power Platform, but also things across SharePoint and things across the Azure Foundry. In fact, every agent that is going to show up inside Copilot, you would be able to see in the Microsoft Admin Center and then route from there to the places where you could do even advanced governance, like the Power Platform Admin Center.”
Awesome. I know you love to do demos in your sessions.
“Yeah.”
So, let’s go see it in action. Where do we start when it comes to managing agents?
“For folks who are seeing the screen for the first time, this is the Power Platform Admin Center. It’s brand new. We’ve transitioned over to this new green experience from the legacy purple admin center. It was a purple admin center that is now a delight. It’s actually a new navigation, the most modern navigation in our Microsoft design language, which is based on jobs to be done. So, if you’re an admin focused on security, you would come in and see through the security page, and these are what we call hubs. The one I want to take you to—I’m logged into a demo tenant as Nestor, who is the Power Platform admin or a global admin—and then on the homepage, just like other admin centers, you would get all the things you would expect to land on. But the important page that is heavily used is the Manage page. In the Power Platform, we use environments. This is the equivalent, I guess, of sites or teams that you would see in M365. It’s a container where a lot of the policies and security are attached, and then you could put different assets in it, and it would be enforced on all those assets. But the one I want to draw your attention to is this new page called Inventory. This is our V3, Vlad.”
“V3 already?”
“I think our V1 was—some might know—the Center of Excellence toolkit or the CoE.”
“Okay.”
“And that was built outside of the product using flows to collect the data and render them as Power BI reports. It had a scale issue. So for large enterprises, it stopped working, and it was also a supportability thing where, because it was outside the product, many enterprises were not big fans of it not being officially supported.”
“Yes, I agree. And then it gets refreshed every month, and it’s an SDK, but it really helped a lot of companies bootstrap over the last six or seven years.”
“At the same time, we tried to bring all of it into the product and built it in one way. And then this week, we announced something we’re really proud of, which is the inventory service. In our demo this week, we’re showing our close partners from Microsoft IT who are demoing how this page actually renders in seconds. There are 1.6 million assets across apps, flows, and agents.”
“That is crazy.”
“Filters and sorts. And then you can actually see how, in the demo, we update one of the apps, and it shows up in less than 60 seconds. It shows updated.”
“That’s really cool.”
“So in the admin center, there’s the inventory where you could do sorting, filtering, find specific people, and then apply it. It would render the page. We also have a dedicated page with a little bit more metadata. If you go to Apps, you will see all your apps. Automate—you would see all your workflows. And then Copilot is what you’re asking me about, which is here are all the agents. You could see the agents where they’re created across all the environments. It gives you a bird’s-eye view. There’s already a set of columns that we render, and we’re hard at work to add additional things like connectors, models they’re working on, and what the agent is connected to. So you’d be able to see if there’s a model because I think GPT-4.0 is getting retired soon.”
“I wouldn’t say that, but it’s augmented with cloud and other models that you could use.”
“Well, I think that version is getting retired specifically. So if you see the model here, you’re able to quickly see all the agents that you have to go fix whenever a model gets retired.”
“Yeah. And mostly we’re trying to make it a decision support system for agents, for admins. So you can actually find the agents you want to take care of and then act on them relatively easily. You would be able to export it to Excel or see all this data using our Power Platform API. So if you’re using the Power Platform admin connector, you’d be able to connect to this data. Or if you are an Azure fan already using Azure Resource Graph, you can actually run KQL queries and integrate it to any other system that you might have or have been using.”
“That is awesome. And I guess if you’re able to load 1.6 million items in a few seconds, the API shouldn’t have big throttling stuff and things like that. It should be pretty straightforward to get the data refreshed.”
“Yeah, for everyone who has been using Azure Resource Graph, you know Azure can manage billions of items. So that’s why we picked that architecture.”
“And I love that you also have not only the agents and the agent flows. And I know this was a big topic in the keynote, where agents aren’t just chat boxes. You get the value by doing stuff. And I see the agent flow tab over there. So you can also see those. I know right now you don’t have any in the environment, but you’ll be able to see them here. And classic chat box, I guess they’re Power Virtual Agents.”
“Yes.”
“So we did the separation to administer them separately.”
“I’m surprised people still use Power Virtual Agents because Copilot Studio—it’s crazy that it’s just an evolution. For me, it seems like a brand-new product. Okay. So to access all of this, you need to be a Power Platform administrator.”
“That is right. So right now, do you know if there’s a plan—you know, there’s an AI admin role. Do you know if there’s a plan for that AI admin role to have access just to the inventory of agents, to this page only, even if it’s just read, or you want to keep them separate?”
“Now granular admin roles are something that is on our roadmap and something we want to invest in, and we keep trying to decide if it’s urgent or just important at this moment, and there’s a lot of other urgent stuff before that.”
“Okay. So for all of you watching, if you think that would be awesome, let me know in the comments, and I will forward them along. But yeah, if you think this is something your company needs and would make you adopt this more, please write in the comments, and this way I can bug him with proof. And those are only your Copilot Studio agents. So full Copilot Studio—what about the other types of agents?”
“It’s a great question. So one is we’re extending this very soon to show all the Microsoft Copilot Studio full agents. So if they’re built, and then the next step would be to also list here all the agents that are light. So Copilot Studio Light—this admin center would include those two agent types. When it comes to one pane of glass to see all your agents in the company, including the ones from SharePoint, the ones from Azure Foundry, the ones from the agent toolkit, then you would be going to the Microsoft Admin Center under Agents in the agent inventory. This is what I call the finished goods—all the agents that got published to Copilot Studio. So it’s hiding a little bit of the sausage factory that I showed earlier. Like everything that is being built by people, either a draft or never published or published to a website and an app, they won’t necessarily show up here initially, but we are working on a plan to try and collect all the agents in the company under one pane of glass, and it would be this Microsoft Admin Center that would show it.”
“Wow. And here you see not only the ones that your company made, but you also see the ones from the store, let’s say. And you can also manage them. If—and I’ll pick on a random one here, I’m sorry, Certify, you’re just the first one on the list—if you don’t want that, you can block it from here.”
“That is right. We would bring in all the most basic, very popular actions, and you would be able to take them here and not need to go to the other admin centers. And in the other admin center, there will be additional capabilities like moving across environments or defining what the data loss prevention—or I should have said data policies—that you want for the agency, and then that would be done in the other advanced admin centers like the Power Platform Admin Center.”
“Awesome. So just to double-check, just so it’s clear for everyone here: today you only see Copilot Studio agents that have been deployed to Microsoft 365 Chat and Teams—I think that’s the name of the channel. But even if it’s a published agent that’s deployed to a public website, to an app, to things like that, for today, they are only in the Power Platform Admin Center.”
“That is true. And that is changing really soon.”
“Okay. So it will be here, find it here, filter, sort it, and then if you need to take advanced actions, that’s when you go to the platform.”
“Awesome. Great. So, from here, can you also see permissions and things like that today or not yet? Or I guess here it’s just deployed to the company.”
“So if you click on one of these, it would give you additional metadata on what the agent is. This is what we call the agent card, and there will be additional things that you could do at the agent level, and then depending on where that agent was built, this card would be slightly different.”
“Okay. Awesome. And I know there’s something that I told you was not possible, and then a few minutes ago, in just two minutes, you showed me, ‘Vlad, you need to keep up to date more,’ because I said no. But before, I think a month or two months ago, if you published an agent from Copilot Studio, you needed to go to the Teams Admin Center in the app management to actually approve it. But now you have the requested agents as well in this single pane of glass, right?”
“Which is pretty cool. If I, as a maker, go and publish the agent to Teams, Microsoft 365 Copilot, and I ask it to be shown to the entire company or the entire organization, then back here in Agents, you would go to Requested Agents. It would show up here as a pending review, and this would allow you, right in the Microsoft Admin Center, to decide if you want to reject it or if you want to publish it. The same panel would open up if you need to make a decision. So it gives you metadata and information about what’s going on.”
“That is awesome. Something else we talked about before, which I think is very valuable: you’ve shown Copilot Studio agents. You also told me that SharePoint agents are going to come here in the very near future.”
“Yes. So the Admin Center—the Microsoft 365 Admin Center—the agent inventory is going to be populated with SharePoint agents as well.”
“That will be amazing. It will really become that single pane of glass. And I think most admins by now are used to how it works, where different teams ship stuff, but eventually it all comes together. So we are almost at that point where we have everything in one single pane of glass. What else is cool that you’re working on for admins today? I know you’re working on probably a hundred things at the same time, but if you had to pick a few favorite ones.”
“So our life right now is all into making agents easier to govern at scale. We have a concept called an environment group. This would give you a list of containers of containers. In SharePoint, there used to be this site collection. It always reminds me of this thing. So people work in environments, and you could set policy at the environment level, and that’s settings. And then MSIT—Microsoft IT, for example, has an environment group with 130,000 environments. It’s really hard to go one by one 130,000 times and then change a setting to say, ‘I want to block sharing.’ This allows you to do that in one click. So you go to the environment, and there’s a concept called rules. And if you want to search for sharing, this is a growing list of controls. And you could say, ‘I want to allow or not allow co-authoring of agents. I want to say how many people this agent should be shared with.’ You could say, ‘I want to set a limit to 20,’ whatever number you pick.”
“Yeah.”
“And you could say with security groups, without security groups. So it gives you a lot of controls. The nice thing about this, which is unique to the Power Platform, is that if you go to the advanced connector policy, you can set it either at the environment or environment group. You could say the makers that are building in this environment group—so those 130,000 makers—they would only be able to use these connectors. You could add connectors from the 1,500 connectors that we have and allow them to use Salesforce or ServiceNow. Or you could say, ‘I want to remove these.’ And another last thing I would say that is unique about the Power Platform is you can actually go one step deeper and say not just the connector, but I don’t want them to delete, or I don’t want them to do something specific. You can control the actions on the connector, and then once you publish that, within less than 24 hours, the 130,000 people will not be able to build with those things that you took away or will be able to build with the ones you allowed. And that’s how we recommend—in our session, we talked about zone governance. You create a green zone for all your employees to be able to start with something, get excited, ask you for more, and then you move them to the yellow zone or the red zone, where that’s where people build the enterprise-ready ones like the Ask HR agents or whatever.”
“Okay.”
“And so the advanced connector policies, for those of you who are not aware, are a bit of an evolution of data policies or DLP policies, but they add a bunch of cool new features. Like, I think you can block the Dataverse connector if you want to, which is not available in DLP policy, so you have a lot more control.”
“Yeah. So if I go to exactly that, you go to data policies. So I mentioned that the security owners of the platform would go to the security page, and here we split it nicely into data policies and threat protection, and you would see what you just said. So data policies are the legacy thing, and then advanced connector policy is the new upcoming, and we will eventually transition people off the legacy into this new, much easier-to-govern capability. So from here, you pick your environment group or your environment, and then you just set the policy just like I showed you from Manage.”
“So I have a licensing question for you.”
“Yes.”
“I remember that a while ago, advanced connector policies were only for managed environments. Is that changing to where it will be available for all environments, like data policies?”
“We always love licensing questions. So I’ll simplify and say that agents—if you are using agents of Microsoft 365 either because you bought the message packages or because you’ve got the per-user $30 license—it entitles you to use managed environments from the get-go. So if all your company is doing is agents, you could take all your environments and make them all enabled as managed environments right now. If they are using apps and flows, it becomes a little bit more complicated with licensing for apps and flows.”
“So that’s really interesting because I didn’t know that. So if you have an environment just for agents and everybody is licensed to use agents, whether it’s paid or licensed, then you can do managed environments as long as you keep it to agent flows, I suppose that would also be counted in there right now.”
“That’s exactly what people should do.”
“That’s amazing. That will really allow more people to use managed environments that have been holding off because of the other licenses.”
“So please start, because managed environments are just giving you a rich set of 50-plus capabilities that are unique to allow you to get more visibility and more control with a lot less effort. So if you are agent-focused, this is the thing for you. If you’ve got apps and flows, the E3 or E5 don’t entitle you fully to use these things. You would need dedicated licenses for the users who are using those apps in managed environments.”
“If I’m honest, if you’re serious about Power Platform management—and I’m sure you cannot say it like that—you need managed environments. So all of the features that we have been asking for to make it are there, and you, you’re either going to spend hundreds of hours doing PowerShell scripts and API calls and things like that to do it all by hand, but at the end of the day, you’re probably going to save more money if you have the licenses and use managed environments because Microsoft built it, it’s there, and it’s supported versus you doing PowerShell scripts and maintaining them to do the exact same thing. So that’s just my opinion.
“That is totally true. So thank you so much. I know you have another session coming up, so thank you so much for showing me this and for teaching the community how we can manage agents. I’m super excited about how easy it’s becoming and seeing more people adopt it. Any final words?”
“No. Awesome. Thank you for inviting me to this amazing show, and then just keep watching Vlad. Thank you, Vlad, for helping us get the word out.”
“Thank you, everyone, for watching. Again, if you have any questions, please let me know in the comments below. I’ll try to answer them. If not, I know an expert who can help me out. And if you enjoyed this video, please like it and subscribe to the channel. And on the screen right now, you’ll see other interviews with more experts from PPPC25.