MC1472007 High Major change

Manage who can upload advanced agents and plugins

  • User
  • Admin
  • Compliance
  • Copilot License

Summary AI-generated

A new admin control will let admins restrict who can upload advanced Copilot agents and plugins, improving governance and manageability.

Suggested actions AI-generated

  • Review the advanced-package upload setting on September 25th
  • Decide upload permissions for advanced packages before October 25th
  • Update admin/help desk documentation
  • Inform support teams about the new control

Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.

Original post from Microsoft

Updated September 15, 2026: We have updated the content below with additional information.

[What and Why:]

To help organizations manage the deployment of advanced Copilot extensibility scenarios, we are introducing a new admin control that determines who can upload advanced agents and plugins. This enhancement strengthens enterprise governance and manageability by allowing administrators to limit advanced-package uploads to specific users or Microsoft Entra ID groups while maintaining flexibility for organizations that want broader access.

[Rollout Schedule:]

  • General Availability (Worldwide): Rollout begins September 25th
  • Expected completion by the end of October 2026.

[Impact on Your Organization:]

Who is affected:

  • Microsoft 365 administrators responsible for managing Copilot agents and plugins.
  • Organizations that allow users to upload advanced agents or plugins.
  • Users who create or upload advanced agents and plugins after this feature becomes available.

Platforms/Services:

  • Microsoft 365 Copilot and Cowork surfaces, ATK
  • Copilot agents
  • Copilot plugins
  • Microsoft Entra ID

What will happen:

  • On September 25th, the control will be visible in MAC under Copilot Settings and admins will have until October 25th to select their preference of all users, no users or specific users or groups (see Advanced package uploads screenshot).

  • Starting October 25th, Advanced-package uploads will be enabled by default unless the admin has selected no users or specific users or groups.
  • Admins can configure uploads for all users, selected users, Entra ID groups, or no users.
  • Basic package uploads remain allowed and are not impacted.
  • An advanced agent is a package that has either a Declarative Agent with actions or with an MCP server. All other packages are considered basic.
  • This setting is only applicable to user uploaded packages and does not cover 1P or 3P built agents.
  • IT admins can view user uploaded packages as shared in MAC and the details page will show the components of the package.
  • The setting applies only to advanced agents and plugins uploaded after the control becomes available.
  • No action is required to maintain current behavior,

[Action Required/Recommendations:]

  • Review the advanced-package upload setting when it becomes available on September 25th.
  • Determine whether advanced-package uploads should be available to all users, selected users, groups, or no users prior to October 25th.
  • Update internal administrator and help desk documentation as needed.
  • Inform support teams of the new governance control.
  • If no action is taken, advanced-package uploads remain allowed by default.

[Compliance Considerations:]

  • The change introduces new administrative governance controls for advanced agents and plugins.
  • The feature supports administration through Microsoft Entra ID group membership.

Additional details from Microsoft

Summary
Starting September 25, Microsoft 365 admins can control who uploads advanced Copilot agents and plugins, limiting access to specific users or Entra ID groups. This governance feature rolls out worldwide by October 2026, with default uploads enabled unless admins configure restrictions by October 25. Basic uploads remain unaffected.