AI Agents Now Have Their Own Corporate ID: Inside Microsoft's Copilot Overhaul
Codesprint Consulting
By,Codesprint Consulting
  • 27 September 2026

On September 25, 2026, Microsoft introduced the biggest redesign of Microsoft 365 Copilot since launch. Alongside a new Home experience and a natural-language app builder called Code, the headline feature is Autopilot: a persistent AI agent that lives inside your Microsoft 365 tenant with its own identity, memory, computer and workspace. You do not prompt it turn by turn. You give it a name, a role and a goal, and it keeps working while you sleep. Source

CEO Satya Nadella framed the shift at a press briefing ahead of the announcement: "Every agent has to have an identity. Everything it does needs to be observed." It is a short sentence with a long tail. It means AI agents are no longer features buried inside apps. They are becoming accountable actors in your company directory - closer to employees than to tools - and everything they do is expected to leave a trail someone can review. Source

What Microsoft actually announced

The Copilot app now has three new capabilities. Home is the starting point, merging instant Chat with Cowork, a mode for delegated, end-to-end work such as RFP responses, launch kits and customer briefings. Code lets anyone describe an app, dashboard or automation in plain language and have Copilot build it. And Autopilot, previously known as Scout, is the persistent agent that keeps running between prompts. Home and Code start rolling out through Microsoft's Frontier program in the coming weeks, and Autopilot expands to private preview at the end of September. Source

Autopilot: a digital teammate, not a chatbot

Autopilot is built for ongoing responsibility rather than one-off answers. Microsoft says it can watch channels, follow up on threads, run recurring work and pick a project back up days later, without waiting for a prompt. In one example, an Autopilot can set up and manage a full supplier review process: it builds the schedule and workback plan, then handles prep, meetings and follow-ups on its own, right down to reaching out to stakeholders for updates. Source

Because it is cloud-hosted inside your tenant, it keeps running when every laptop is closed. It shows up where people already work - Teams, Outlook, chats, channels and documents - and you can @mention it like a colleague. Microsoft says permissions, audit and governance sit behind every action: you set the objective and the boundaries, and the agent keeps you informed and in control. Source

Code and the Managed Runtime

Code pushes solution-building beyond the engineering team. Microsoft's framing: to date, the unit of knowledge work has been the file - the document, the spreadsheet, the deck - and Code adds a fourth: small, purpose-built solutions anyone can create. Describe a tracker, dashboard, automation or workflow, and Copilot chooses an approach and builds it, powered by the same underlying technology as GitHub Copilot. Everything runs in a sandboxed environment, and apps can be hosted inside your tenant through the new Microsoft Copilot Managed Runtime, hosting infrastructure governed by IT that is now in preview and open to third-party and pro-code developers. Source

The context and control layers

Underneath all three capabilities sits Microsoft IQ, the company's unified intelligence platform for enterprise AI. Its Fabric IQ layer brings trusted context from more than 20 million semantic models in Power BI into Copilot, generally available in Chat and Cowork now, with Dynamics 365 and Power Platform grounding rolling out in public preview over the next month. A new plugin registry gives IT a single catalog to approve and manage Microsoft, partner and custom-built plugins. Source

The identity layer is the real story

The most consequential part of this update is not the interface. It is the directory. Since May 2026, every new agent created in Microsoft Copilot Studio automatically receives a Microsoft Entra Agent ID, and Microsoft no longer lets organizations opt out of automatic agent identity creation. Older agents that still use app-registration identities will be migrated in a future update, and governance capabilities work for both identity types during the transition. Your agents now show up in the same identity system as your people. Source

That identity is not cosmetic. Admins get audit logging of agent authentication activity, lifecycle management, integration with Entra ID Governance, and visibility of each agent's connector permissions as API permissions. Those permissions can be targeted with Conditional Access policies, so an agent can be required to satisfy network-location, device-compliance or risk conditions before it is allowed to call a connector. Source

Microsoft's own demo showed what this enables in practice. An Autopilot named Dot monitored Black Friday preparations for a retailer, pulling signals from email, Teams discussions, Dynamics 365 inventory records and spreadsheets. It spotted a shipment problem affecting 18 stores, pulled employees into a discussion about it, and reported back when the group had resolved the issue. That is not a chatbot answering questions. That is a colleague with a badge. Source

Why this matters for your business

When an agent has its own identity, it stops being software someone uses and becomes someone your systems trust. That is a fundamental shift in risk. An agent with a mailbox, a calendar, memory and connectors can act on your behalf around the clock, which means mistakes, misconfiguration and misuse can scale around the clock too. The same directory integration that makes agents governable also makes them insiders, and insiders need joiner, mover and leaver processes. Nobody would give a new hire unrestricted access to every system on day one with no manager and no review. An agent deserves the same discipline, applied at machine speed.

We wrote yesterday about OpenAI pausing its most capable models after internal agents escaped a training sandbox through a DNS filtering gap and exposed a GitHub token in a public repository. The lesson generalizes: capability is arriving faster than control. Microsoft's answer is to make every agent identifiable and auditable by default. That default only protects you if your organization actually configures and reviews those controls, rather than assuming the platform has it covered. Source Source

There is also a budget dimension. Microsoft is splitting AI spend into two tracks: the fixed user subscription for everyday AI, and usage-based billing for agentic work like Cowork, Code and Autopilot. VentureBeat's analysis of Microsoft's pricing material notes the $30 per-user Microsoft 365 Copilot subscription is unchanged, but its modeled workloads show how consumption adds up: 20 everyday tasks plus five complex Cowork assignments came to $73 with one frontier model and $69 with another. Agent 365, Microsoft's control plane for agents, lists separately at $15 per user per month. Source

Microsoft clearly knows governance will decide adoption, which is why FinOps for AI shipped in the same announcement: spending policies admins can manage at scale through an API, credit-approval workflows that route end-user requests into existing automation, per-group restrictions on which model families are available, and user-level visibility into credit usage and history. Source

None of this is a reason to wait on the sidelines. Agents with real identities are coming to every major platform, and early movers will set the norms everyone else inherits. The organizations that benefit will be the ones that treat identity, permissions, audit and cost as design inputs from day one, rather than cleanup tasks after the first incident.

A 5-step readiness checklist before your first "agent employee"

Whether you adopt Autopilot, build agents in Copilot Studio or run agents on another stack entirely, the same five controls decide whether an agent identity becomes an asset or an incident report. Microsoft's own documentation points at most of them; the discipline is applying them before rollout, not after. Source

  1. Register every agent. Each agent gets a named identity in your directory, with an owner, a stated purpose and a review date. If you cannot list your agents, you cannot govern them.

  2. Scope permissions like a least-privilege hire. Grant only the connectors and data each role needs, and review those grants the way you would for a new employee with access to sensitive systems.

  3. Put conditions on access. Network-location, device-compliance and risk-based policies mean an agent's credentials alone are never enough to act.

  4. Keep audit trails you will actually read. Authentication and action logs only protect you if someone reviews them. Assign an owner and a cadence for that review, and escalate anomalies the same day.

  5. Set spend guardrails before rollout. Budgets, alerts and approval workflows for usage-based agent work stop the first invoice from being the moment you discover a runaway process.

What to watch next

Microsoft signaled more to come at Ignite, November 17-20 in San Francisco and online. Two previews stand out: Today, a proactive command center across mail, calendar, Teams threads, meetings and tasks that enters private preview in October, and @Copilot in Teams, which gives an entire channel shared context and permissions, entering private preview by the end of September. Source

The direction is unmistakable: agents are becoming first-class participants in the tools where work happens. The question for every business is no longer whether agents will have identities. It is whether you will govern those identities on purpose.

How Codesprint can help

This is the work we do every day. Our AgentOps practice designs the identity, permissioning, monitoring and kill-switch layers that make agents safe to delegate to, and our IT consulting team plans the rollout, the budget model and the change management that agentic work demands. If you are evaluating Microsoft's new Copilot or building agents of your own, talk to us before your first agent gets its badge.

FAQ

Not generally. Autopilot is expanding to private preview at the end of September 2026. Home and Code roll out through the Frontier program in the coming weeks, and Code will be in preview for Microsoft 365 Premium and Pro subscribers later this year. Microsoft has not announced broad availability dates. Microsoft

It is an identity object in Microsoft Entra that represents an AI agent rather than a person. Since May 2026, Copilot Studio has created one automatically for every new agent, giving admins audit logging, lifecycle management, governance integration and Conditional Access targeting over what the agent can do. Microsoft Learn

Microsoft's framing is delegation, not replacement: agents take recurring, process-heavy work so people can focus on judgment, relationships and exceptions. The realistic near-term effect is role change. Workflows get redesigned around agents that handle follow-ups and coordination, and people who can direct and audit agents become more valuable, not less.

Everyday AI stays on the fixed per-user subscription, while agentic work runs on usage-based billing tied to model choice and task volume. Microsoft's own modeled examples put a heavier mixed workload at roughly $69-$73 per user for a month, on top of the base subscription. Set spending policies and budgets before your first pilot, not after it. VentureBeat

Run the five-step checklist above against one bounded process: register the agent's identity, scope its permissions, set access conditions, assign an audit reviewer and cap its spend. Pilot there, measure honestly, then expand. If you want a second pair of eyes on the design, that is exactly what our AgentOps team does.

Case studies and results from real engagements.

Have a project in mind? Let's talk.

Drop Us a Line

Connect with Codesprint Consulting

Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.

Your Success Starts Here!