Microsoft Copilot Studio: Share Autonomous Agents to End Users (Run-Only)
🚨 The Signal: Autonomous agents in Copilot Studio can now be shared with end users in a run-only mode. This expands agent access, increasing potential for unmanaged automation and data exposure if not properly governed, requiring immediate security review.
The Impact
All users are affected, with a high security risk due to expanded access to autonomous agents and potential for data exfiltration or unapproved automation.
- Security Teams: Increased risk of data exfiltration and unapproved automation via shared agents.
- Admins: New governance challenges for agent usage and data access permissions.
- End Users: Potential for misuse or accidental exposure of sensitive data through agent interactions.
- Compliance Teams: Difficulty in auditing and demonstrating control over agent-driven processes.
The Action
- Review existing Copilot Studio Data Loss Prevention (DLP) policies to ensure they cover autonomous agent interactions and data flows.
- Implement or update Copilot Studio tenant-level settings to restrict agent sharing capabilities to approved security groups.
- Establish a clear policy for autonomous agent development, sharing, and lifecycle management, including mandatory security reviews.
- Conduct an audit of currently deployed autonomous agents to identify any that could be shared and assess their data access and potential impact.
- Educate makers and end users on secure agent usage, data handling, and reporting suspicious agent behavior.
Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges, User Application Hardening · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1412, ISM-1485, ISM-1486, ISM-1507, ISM-1508, ISM-1509, ISM-1542, ISM-1585, ISM-1647, ISM-1648, ISM-1650, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1686, ISM-1688, ISM-1689, ISM-1823, ISM-1824, ISM-1859, ISM-1860, ISM-1883, ISM-1897, ISM-1898