Microsoft Copilot Studio: Share Autonomous Agents to End Users (Run-Only)

🚨 The Signal: Autonomous agents in Copilot Studio can now be shared with end users in a run-only mode. This expands agent access, increasing potential for unmanaged automation and data exposure if not properly governed, requiring immediate security review.

The Impact

All users are affected, with a high security risk due to expanded access to autonomous agents and potential for data exfiltration or unapproved automation.

  • Security Teams: Increased risk of data exfiltration and unapproved automation via shared agents.
  • Admins: New governance challenges for agent usage and data access permissions.
  • End Users: Potential for misuse or accidental exposure of sensitive data through agent interactions.
  • Compliance Teams: Difficulty in auditing and demonstrating control over agent-driven processes.

The Action

  1. Review existing Copilot Studio Data Loss Prevention (DLP) policies to ensure they cover autonomous agent interactions and data flows.
  2. Implement or update Copilot Studio tenant-level settings to restrict agent sharing capabilities to approved security groups.
  3. Establish a clear policy for autonomous agent development, sharing, and lifecycle management, including mandatory security reviews.
  4. Conduct an audit of currently deployed autonomous agents to identify any that could be shared and assess their data access and potential impact.
  5. Educate makers and end users on secure agent usage, data handling, and reporting suspicious agent behavior.

Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges, User Application Hardening · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1412, ISM-1485, ISM-1486, ISM-1507, ISM-1508, ISM-1509, ISM-1542, ISM-1585, ISM-1647, ISM-1648, ISM-1650, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1686, ISM-1688, ISM-1689, ISM-1823, ISM-1824, ISM-1859, ISM-1860, ISM-1883, ISM-1897, ISM-1898