Alex Fleck, Author at Inside Track Blog http://approjects.co.za/?big=insidetrack/blog/author/alexfleck/ How Microsoft does IT Fri, 17 Jul 2026 22:52:37 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 137088546 Meet DigitalMe: Our AI digital twin that works on our behalf http://approjects.co.za/?big=insidetrack/blog/meet-digitalme-our-ai-digital-twin-that-works-on-our-behalf/ Thu, 11 Jun 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24102 Have you ever wanted a clone to help you keep up with your work? In an always-on business environment, even routine collaboration can be overwhelming. But in an environment of Frontier Transformation, this challenge represents an opportunity for AI. Our employees don’t need to handle all their work alone anymore, because agents can now extend […]

The post Meet DigitalMe: Our AI digital twin that works on our behalf appeared first on Inside Track Blog.

]]>
Have you ever wanted a clone to help you keep up with your work?

In an always-on business environment, even routine collaboration can be overwhelming. But in an environment of Frontier Transformation, this challenge represents an opportunity for AI.

Our employees don’t need to handle all their work alone anymore, because agents can now extend their responsiveness and reach. Here in Microsoft Digital, the company’s IT organization, one of those AI agents is acting as a digital twin for just that purpose. It’s called DigitalMe, a personal virtual proxy designed to keep work moving when our employees are busy with other tasks.

Always-on knowledge without always-on employees

Large meetings generate a constant stream of questions, side conversations, and follow-up items. They’re often more than a single presenter or moderator can manage in real time. Important insights get buried in chat threads, queries go unanswered, and valuable momentum gets lost.

For our teams at Microsoft, this challenge became especially visible during large-scale readiness sessions, where subject matter experts found themselves inundated with requests for clarification and guidance.

A photo of Kerametlian.

“In order for our transformation into a Frontier Firm to be successful, we need to step back and ask what works well for employees, what doesn’t work well, and where agents can help.”

Stephan Kerametlian, senior director, Microsoft Digital

That’s not the only place where employees can use an extra hand. When people are out of the office, that doesn’t mean work stops. Their coworkers often need access to their colleagues’ knowledge to move mission-critical work forward, even when they’re not reachable.

“In order for our transformation into a Frontier Firm to be successful, we need to step back and ask what works well for employees, what doesn’t work well, and where agents can help,” says Stephan Kerametlian, a senior director in Microsoft Digital. “We’re crossing the horizon into human-led, agent-operated patterns of work.”

One team in Microsoft Digital created DigitalMe to explore what that future could look like in practice.

DigitalMe: A personal digital twin for Microsoft employees

For the members of our Employee Experience Success team responsible for adoption efforts around Microsoft 365 Copilot and Microsoft Copilot Studio in the Greater China Region, readiness meetings were becoming unwieldy because of attendee questions.

A photo of Bu.

“Our purpose was to use as little code and as much natural language as possible so people could modify their own personal DigitalMe easily. In Copilot Studio, you can manage agents as a solution. So users can just download and import a zip file, modify an agent like DigitalMe according to their business context and preferences, then use it.”

Ju Bu, business program manager, Microsoft Digital

The team wanted a way to focus on running the meeting while simultaneously providing their knowledge to participants. They decided to create an agent to help deal with the deluge of queries: DigitalMe.

At its core, DigitalMe is a personal, context-aware digital twin with versions that operate in both Microsoft Teams and Microsoft Outlook. It draws on the same knowledge bases and resources that its user can access, for example, SharePoint sites and Teams channels.

The team designed DigitalMe in Microsoft Copilot Studio and prioritized a low-code approach. At most, the creators used code to build 15–20% of the agent and accomplished the rest using natural language prompts.

“Our purpose was to use as little code and as much natural language as possible so people could modify their own personal DigitalMe easily,” says Ju Bu, a business program manager in Microsoft Digital. “In Copilot Studio, you can manage agents as a solution. So users can just download and import a zip file, modify an agent like DigitalMe according to their business context and preferences, then use it.”

Equipped with an employee’s full knowledge base, DigitalMe can respond in Outlook and Teams on its human counterpart’s behalf. To ensure transparency, a label appears at the beginning of each message indicating that it originates from the agent.

DigitalMe also reinforces context for the requester by including their original question in quotations. Finally, the agent @-mentions the recipient to notify them effectively.

The team identified two primary use cases for the agent:

  • Moderating live sessions. In large meetings, DigitalMe acts as an always-on co-moderator, answering questions in real time using scoped, preloaded knowledge. By speaking for them in the meeting chat, it helps presenters stay focused while ensuring attendees receive timely, accurate responses. Surfacing information instantly enhances both the efficiency and quality of the session. DigitalMe has the added advantage of being able to pull from resources the presenter might not recall in the moment. Over time, the agent captures and reuses questions and answers, turning live engagement into a growing knowledge base.
  • Extending employee availability. DigitalMe also provides a way for employees to remain responsive when they’re out of the office. It can monitor Teams chats or incoming emails, generate context-aware replies, and surface relevant knowledge for colleagues without human intervention. In practice, it’s proven especially valuable for teams distributed across widely different time zones and for handling project handoffs during onboarding or time-off scenarios.

A key advantage of DigitalMe is its ability to move beyond simple question-and-answer use cases. In some scenarios, it can also trigger workflows like creating tasks or capturing frequently asked questions.

A photo of Cheng.

“Our vision was that DigitalMe shouldn’t just be an assistant. It should function as our digital twin in the cyber world.”

Kai Cheng, program manager, Microsoft Digital

It was important to incorporate human-in-the-loop capabilities. When DigitalMe encounters gaps in its knowledge, it can flag those moments for follow-up, prompting users to refine and expand their knowledge sources. It represents another way that human-led, agent-operated processes continuously improve outcomes.

“Our vision was that DigitalMe shouldn’t just be an assistant,” says Kai Cheng, a program manager working in change management, digital transformation, and AI in Microsoft Digital. “It should function as our digital twin in the cyber world.”

In live sessions, DigitalMe has helped presenters stay focused while maintaining high levels of engagement, responsiveness, and support for participants. Employees are increasingly using it to bridge time zones, support knowledge transfer, and keep projects moving in their absence.

Key impacts of DigitalMe

Here are a few examples of results from our early experiments with DigitalMe:

  • Questions answered: 158 questions handled in one 60-minute session
  • Presenter time saved: Around 60–90 minutes of manual moderation effort
  • Audience engagement: More than 60 chat messages per session, with increased Q&A participation
  • Response accuracy: Around 90% of questions answered satisfactorily
  • Post-session value: 100% of questions and answers captured for reuse as FAQs
  • Adoption: Expanded use across teams, including learning and readiness programs

Extending the impact of DigitalMe

After seeing DigitalMe’s early success, our global readiness and adoption professionals identified the agent as an opportunity to turn individual innovation into a scalable capability. After templatizing the agent in collaboration with its original creators, we’ve now included it in our Agent Starter Kit. This resource makes it easy for employees to create their own personal versions of several useful agents.

A photo of Jones.

“Employees often think building an agent might be complex and time-consuming, and that limits their willingness to try and turn their ideas into working solutions. But tools like this show them how easy it can be.”

Alexandra Jones, director of business programs, Microsoft Digital

Our Agent Starter Kit walks employees through importing a ready-made agent, connecting it to their knowledge sources, and adapting it to their specific workflows. This approach has shifted DigitalMe from a single solution into a repeatable pattern, helping employees across the company move from curiosity to hands-on adoption. We’ve also incorporated the Agent Starter Kit into our Agent Launchpad skilling program to accelerate our employees’ agentic expertise as part of a Frontier firm

There’s an added benefit as well. By getting tools like DigitalMe into people’s hands through templatized versions they can modify and configure themselves, we’re highlighting how easy it can be for even nontechnical workers to build agents themselves.

“Employees often think building an agent might be complex and time-consuming, and that limits their willingness to try and turn their ideas into working solutions,” says Alexandra Jones, director of business programs in Microsoft Digital. “But tools like this show them how easy it can be.”

For organizations that want to replicate this kind of solution, the path is increasingly straightforward. By lowering the barrier to entry with templatized agents and no-code tools, our team in Microsoft Digital has demonstrated that any employee can build tailored, high-impact assistants without deep technical expertise.

How to get started creating agents like DigitalMe

  • Start with a real problem. Identify where employees feel overwhelmed and a need exists. That could be high-volume meetings, repetitive questions, or delayed responses.
  • Use a working template. Create prebuilt agents to accelerate development instead of starting from scratch.
  • Scope your knowledge sources. Ground your agent in trusted content like SharePoint, documentation, and FAQs to ensure accurate responses.
  • Design for specific triggers. Consider where and when the agent should act: Should it act on your behalf in in Teams, answer emails for you, or take other actions on your behalf.
  • Iterate with feedback. Track gaps in responses and expand your knowledge base over time to improve accuracy and usefulness.

By combining these practices and learning from our experience in Microsoft Digital, you can quickly move from experimentation to impact with agents. To get started at your company, sign up for a trial of Copilot Studio.

A photo of Wooldridge.

“The goal of Frontier Transformation is that AI is just there as you’re working, helping you practically do your job to enhance the experience and add value in real time.”

Kevin Wooldridge, senior director of digital transformation, Microsoft Digital

Looking ahead, we’re exploring ways to deepen these capabilities by adding memory and behavioral context so DigitalMe can better reflect individual working styles. The goal is to evolve it from a helpful assistant into a more complete digital representative.

Together, these advances point toward a future where employees routinely work alongside agents that grow, learn, and contribute more over time.

“DigitalMe is an example of the genuine, practical application of agentic use in the flow of work,” says Kevin Wooldridge, senior director of digital transformation in Microsoft Digital. “The goal of Frontier Transformation is that AI is just there as you’re working, helping you practically do your job to enhance the experience and add value in real time.”

Key takeaways

Follow these tips to start experimenting with agents like DigitalMe.

  • Ease and success bring adoption. Even fearful or resistant employees can become interested in participating when they have an easy onramp like templatized agents.
  • Be brave. Have a bias for building and trying agents. They’re rarely as difficult to build as some workers might imagine.
  • Start by setting your tech people free. They’re likely to demonstrate the art of the possible, become leaders in the space, and bring others along for the ride.
  • Encourage potential agent builders to take a step back and look at the basics. That reflection will help them learn to identify opportunities for agentic help in their roles.

Try it out

Related links

The post Meet DigitalMe: Our AI digital twin that works on our behalf appeared first on Inside Track Blog.

]]>
24102
Governing AI agents at scale: Lessons from our journey at Microsoft http://approjects.co.za/?big=insidetrack/blog/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft/ Thu, 21 May 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23618 Empowering employees and protecting your organization through agent governance Welcome to the agentic frontier Agents are expanding the frontier of enterprise AI. By creating tools that surface knowledge, take actions, and even reinvent workflows, organizations can apply the power of AI to business processes in new and innovative ways. But this shift raises questions for […]

The post Governing AI agents at scale: Lessons from our journey at Microsoft appeared first on Inside Track Blog.

]]>

Empowering employees and protecting your organization through agent governance

Welcome to the agentic frontier

Agents are expanding the frontier of enterprise AI. By creating tools that surface knowledge, take actions, and even reinvent workflows, organizations can apply the power of AI to business processes in new and innovative ways.

But this shift raises questions for business and IT leaders: How do you get the benefits of agents without putting your organization and employees at risk? How do you encourage citizen developers to create agents freely while maintaining control, security, privacy, and compliance?

At Microsoft Digital, the company’s IT organization, we’re putting practical governance structures in place to ensure our internal agents are useful, safe, and properly scoped. Through a deliberate strategy of empowerment with established guardrails, we’re unlocking the potential of agentic transformation while maintaining the trust that defines our work.

The AI maturity model and frontier transformation

Agentic AI has made a new operational model possible, one that blends machine intelligence with human judgment, creating AI-operated, human-led teams.

We call organizations that enact this model Frontier Firms.

As organizations move toward this new operational state, they progress from foundational AI assistance through escalating levels of agentic maturity and complexity. First, humans operate with help from an AI assistant like Microsoft 365 Copilot. Then, human-agent teams work together. But the future lies with humans leading teams of agent users: AI agents that perform core labor with relative autonomy.

Pattern 1: Human with assistant—every employee has an AI assistant that helps them work better and faster.
Pattern 2: Human-agent teams—agents join teams as “digital colleagues,” taking on specific tasks at human direction.
Pattern 3: Human-led, agent-operated—humans set direction, and agents execute business processes and workflows, checking in as needed.

Capturing the benefits of this model relies on many factors, but in our experience as Microsoft Digital, two main tenets are instrumental to a successful transformation:

  1. Empowering employees and teams to create and experiment with their own agents
  2. Properly governing those agents to protect the enterprise

It’s a balance. If you set agent builders free without the proper guardrails, you risk data overexposure, agent sprawl, and security vulnerabilities. However, being too restrictive about governance stifles individual imagination, workflow reinvention, and innovation that can come from agentic AI.

A photo of Fielder.

“At Microsoft, we’ve moved beyond envisioning the agentic future into operating within it every day. Our experience as Customer Zero gives us a unique perspective on what it takes to govern AI agents at scale, turning early lessons into proven practices that help organizations innovate with confidence.”

We’re here to help you find the right balance for your organization.

This guide shares what we’ve learned along the way. As you read, you’ll follow our journey as Customer Zero at Microsoft, and you’ll gain access to tips and resources that we’ve assembled to help you apply our expertise to your own agent governance practice.

Every organization is different, and your experience will differ from ours in terms of risk tolerance, technical capability, resourcing, and more. This guide highlights some principles and best practices you can apply to your own business context, needs, and objectives.

“At Microsoft, we’ve moved beyond envisioning the agentic future into operating within it every day,” says Brian Fielder, vice president of Microsoft Digital. “Our experience as Customer Zero gives us a unique perspective on what it takes to govern AI agents at scale, turning early lessons into proven practices that help organizations innovate with confidence.”

Now is the time to seize this opportunity. Follow along to start your own journey toward frontier transformation and capture the benefits of trusted, connected agentic intelligence.

Learn from our experience governing agents

Within Microsoft Digital, we’ve been acting as Customer Zero for frontier transformation by creating the tools, infrastructure, and processes that power agents at Microsoft.

Our goal is to make it easy for employees to engage with agentic tools freely and adaptably while maintaining safety and responsibility. The path to this objective relies on a three-pronged approach to governance:

  • Embedded governance functionality: Agent creation and publishing tools should incorporate good guidance, governance, and guardrails out of the box, making agents people create essentially self-governing.
  • IT oversight: This is a new space and a new way of working, so it isn’t feasible for all agents to self-govern at this point. As an IT organization, we fill gaps in governance through reviews and oversight. We establish risk-based policies around types of agents, exposure and sharing, and other pivots.
  • User education: It’s almost impossible to predict every governance gap and need, so educating our users helps them avoid accidentally increasing risk. Our Agents at Microsoft team and individual change managers are the guides for these efforts. Employees can also refer to resources like Microsoft Learn courses and the Agent Builders SharePoint hub.

Throughout this journey, we’ve empowered our employees to create all kinds of agents, ranging from simple personal tools built by people working in every function, with every level of technical skill, all the way to AI-powered enterprise tools designed by professional developers for use across lines of business and even the entire company.

As part of the process, we’ve incorporated guardrails to ensure less technical employees are limited to tools that simply retrieve enterprise knowledge, such as SharePoint Agent Builder or Copilot Studio, while software engineers get the full power of any tool they need that can take action or automate workflows, including Microsoft Foundry and Microsoft 365 Agent Toolkit.

SharePoint

  • Lowest level of difficulty
  • For all roles
  • Function: information-retrieval only
  • Microsoft 365 content
  • Light governance
  • Lowest risk

Copilot Studio Agent Builder

  • Low difficulty
  • For all roles
  • Function: information-retrieval only
  • Microsoft 365 content and web sources
  • Light governance
  • Low risk

Copilot Studio (full)

  • Low to moderate difficulty
  • For all roles
  • Function: task completion
  • Microsoft 365 content + connectors to external channels
  • Advanced governance
  • Higher potential for risk

Agent Toolkit, Foundry

  • Highest difficulty
  • For developers
  • Function: workflow automation
  • Multiple internal and external channels
  • Advanced governance
  • Highest potential for risk

Over the course of this journey, we’ve learned valuable lessons about effective agent governance, including:

  • How to build an impactful but flexible governance strategy
  • Strategies for creating an AI-ready data ecosystem
  • Ways to apply appropriate policies and controls for highly diverse agents
  • Approaches for tracking the impact and value of agents

Chapter 1: Building your agent governance strategy

Thinking through your organizational needs and building a framework to govern agents

As we’ve incorporated agents into different aspects of our organization, we’ve also deepened their involvement in employees’ daily workflows and core business processes. Because of this, we’re diligent about the governance guardrails and policies that protect our organization.

We’ve accumulated a wealth of knowledge and insights in this area through our efforts governing Microsoft 365 Copilot. Based on this experience, some of the key priorities that we made sure to adhere to included:

  • Effectively applying controls to ensure users and apps don’t get access to privileged information
  • Preventing employees from creating agents that violate company policies
  • Balancing the freedom for employees to share their creations with the need to prevent agent sprawl
  • Delineating which agents are authoritative and applicable for enterprise functions and which ones are meant for employees’ own personal use.
  • Inventorying agents to provide lifecycle management
  • Securing and protecting confidential data while respecting our responsible AI principles: Fairness, reliability and safety, privacy and security, transparency, accountability, and inclusiveness
  • Unlocking telemetry that enables us to govern agents effectively

By focusing on each of these dimensions, our governance team has centered its efforts on the value these agents provide to the company while also ensuring organizational safety and trust. To realize this value, we emphasize three key principles that help protect both our employees and the organization:

Security

We’ve established standards for data classification, policies for handling confidential information, and other security measures to protect data from unauthorized access, misuse, and disclosures. Microsoft Purview powers these capabilities through data labeling, rights management, and data loss prevention.

Privacy

Privacy compliance measures keep personal data protected and ensure agents adhere to regulatory frameworks in the regions where we operate. We conduct regular privacy assessments for all applications, including high-impact agents.

Regulation

Regulatory compliance assessments ensure agents meet prevailing legal standards. Our legal and compliance teams carefully monitor AI guidelines, regulations, and laws as they evolve so we can understand and incorporate them into these assessments.

We incorporated elements of our tenant’s minimum bar for governance into how we secure agents. Those include Microsoft Purview Information Protection, a functional inventory, activity logging, lifecycle management, and the ability to properly isolate agents so that they don’t cross data boundaries.

Our overarching tenant governance strategy is to govern items like documents and data at the container level. However, within a SharePoint site, for example, the added functionality of agents demands that we introduce further controls like sharing limits, breadth of knowledge sources, agent metadata, and information about an agent’s behaviors.

Turning priorities into principles

To operationalize governance, we developed six principles that guide our approach to agents. They form the governance foundation for a wide matrix of agent creation and usage opportunities.

  1. We ensure a strong data hygiene foundation so we can trust our data estate as employees build and use agents.
  2. We empower employees to build personal agents that can access permitted services and data sources to help automate and accelerate their tasks.
  3. We empower teams and lines of business to build agents with known lower-risk patterns to accelerate impact.
  4. We provide a smooth release path for engineering teams to develop agents designed for enterprise functions so they can access all the services and sources they need. This includes the same software development lifecycle (SDLC) reviews and certifications as other enterprise software, which we outline in Chapter 3.
  5. We accelerate innovation through agent and automation templates while maintaining an AI Center of Excellence (CoE) to help teams think through their opportunities.
  6. We reimagine employee experiences and task execution to simplify and optimize productivity.

Securing control through agent lifecycles

As we strategized to operationalize good governance, agent lifecycles became one of our most crucial tools. We superimposed the enterprise lifecycle on top of these policies, with both user-based and attestation-based lifecycles.

This means we treat agents owned by individual employees like any other user app and delete them when they leave the organization. Meanwhile, we ensure that agents owned by teams have a lifecycle that’s defined by the tenant and tied to attestation, our internal enterprise SDLC, and accountability confirmations.

This approach helps us combat sprawl by eliminating agents that no longer serve a purpose. It provides a solid foundation for more fine-tuned, matrixed policies and practices.

Governing amid real-time technology acceleration

One recent development illustrates how the rapid advancement of AI technology requires us to stay ahead of policy for new features.

Model Context Protocol (MCP) adds new capabilities, but also new risks and challenges. It’s a simple standard that lets AI systems communicate with the right tools and data without custom integration work. Instead of building a new connection or API every time, teams plug into a common pattern.

That standardization delivers speed and flexibility, but it also changes the security equation. We’ve extended our security and governance practices to account for MCP servers.

Our practices and policies help us govern agents effectively in this new environment. First, we assess security across four layers: Applications and agents, the AI platform, data, and infrastructure. We establish a secure-by-default strategy by positioning every remote MCP server behind our API gateway and establishing practices for vetting, identity management, automation that slows agents at the right moments, context trimming, and server isolation.

As you define policies for governing your own agentic ecosystem, you can take inspiration from our process. Start by asking questions about what you want to accomplish and what you want to protect, then move on to establishing your most important priorities. From there, you can cement those priorities into policies.

Learning from our approach to agent governance strategy

Match policies to progress on your AI journey

The complexity of agent governance depends on the maturity of your organization and where you are in your adoption journey. Start slowly to let that maturity grow over time.

A strong policy framework is the foundation

Lean on existing app governance policies, then layer agent-specific structures on top.

Take your cues from established standards

Global regulations around privacy, security, and responsible AI provide a good baseline for establishing governance policies. Assign teams to work through these regulations and incorporate their insights into your agent governance strategy.

Decide on your comfort level with risk

Bring cross-disciplinary experts together from across your organization to determine what level of risk is acceptable for different agents and their use cases. Put guardrails in place for low-risk scenarios and establish processes for supporting more complex or sensitive use cases. Evaluate what data sources agents can extract information from. Establish whether users have shared sensitive data sources.

Change is constant

Plan to reassess and revise your governance structure regularly. Agents are evolving rapidly, as is the tooling surrounding them, so maintaining good governance policies will be an ongoing practice.

Governance is a value driver for employees

Governance isn’t just about protecting your organization. It also provides the right patterns to make sure your employees are getting value from agents. Establish strong measures of business value and a robust methodology for management and assessment of agents through ongoing tracking. This kind of observation and telemetry is foundational and should be a key part of your governance efforts.

Key takeaways

Use these tips based on what we learned here at Microsoft to build your strategy for agent governance at your company:

  • Establish a cross-disciplinary agent Center of Excellence. Bring together stakeholders across the organization to define priorities, goals, and shared practices for agent adoption.
  • Right-size oversight based on risk. Determine your organization’s risk tolerance and define which agents require more or less involvement from IT, security, and compliance teams.
  • Operationalize agent oversight and management. Establish an oversight model and implement tools that help manage agents at scale.
  • Establish change management and adoption. Determine and implement a strategy for driving adoption to educate and empower employees.
  • Create a centralized governance and information hub. Provide employees and agent builders with a single place to find guidance, standards, and governance information.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 2: Establishing a solid data foundation for agent governance

Setting agents up for success using a secure, robust data foundation

Operating according to an escalating maturity model means we’ve done the foundational work to secure and govern our data estate for Microsoft 365 Copilot. Many of the same principles apply to agents, with the added complexity of incorporating additional data sources.

To lead these efforts, we established a cross-functional team of data professionals within our AI CoE. This team is mostly comprised of Microsoft Digital employees who support corporate functions like Corporate, External, and Legal Affairs (CELA) and Global Workplace Services. Together with our AI CoE, this team helped us define what it means to have AI-ready data.

In essence, AI-ready data just means information we’ve certified for AI workloads. We certify those data sources using Microsoft Purview to identify defects in our core data products, and we’ve also built AI-powered assessments to certify which data lakes are AI-ready.

In most ways, governance is tool-agnostic and rooted in basic principles. With robust data labeling, data hygiene, and permissions in place alongside our AI tools, which respect labels by default, we can confidently give every employee the ability to build basic agents and trust in our governance guardrails. For decades, the challenge of data analysts and engineers was maintaining a consistently reliable source of truth despite inconsistent data quality, insufficient governance, and years of collecting data in silos. Microsoft Fabric and Microsoft Purview can help resolve these issues.

We’re embracing a more balanced, federated approach to data management today. We call this approach a data mesh. Rather than allowing unchecked decentralization or forcing all our data into a single centralized system, the data mesh formalizes domain ownership while embedding governance, quality, and interoperability directly into shared platforms.

Graphic shows our data mesh architecture surrounded by the platform services layer and the data management zones layer.
Our data mesh architecture helps us preserve trust and establish a strong governance foundation while preventing data from becoming siloed.

The data mesh connects and distributes, data products across domains, enabling shared data access and compute while scaling beyond centralized architectures.

Platform services are standardized blueprints that embed security, interoperability, policies, standards, and core capabilities — providing guardrails that enable speed without fragmentation.

Data management zones provide centralized governance capabilities for policy enforcement, lineage, observability, compliance, and enterprise-width trust.

With this approach, our domain teams publish data as well-defined, discoverable products, while common standards for security, metadata, and compliance are enforced through automation rather than manual processes. This model preserves enterprise trust and consistency without sacrificing speed or autonomy. By adopting a data mesh mindset, we can scale analytics and AI more effectively across the organization while still keeping ownership closely connected to the business focus.

Confidentiality labels, the practical framework for data protection

To operate according to Zero Trust principles, we needed a coherent system that lets us see, label, and protect data. Otherwise, the burden of data loss prevention would fall solely on employees, who would have to exercise individual discretion whenever they decided how to house and share potentially sensitive content.

With labeling, it’s important to strike a balance between the depth necessary for supporting an array of data governance controls and the simplicity to ensure labeling isn’t burdensome for users.

We decided on four overarching labels for container and file classification, each with its own sub-labels. The highest-level schema looks like this:

  1. Highly confidential: We only share our most critical data with named recipients.
  2. Confidential: Any items crucial to achieving our goals feature limited distribution.
  3. General: Employees can share daily work–like personal settings and postal codes–internally throughout Microsoft.
  4. Public: We share unrestricted data meant for public consumption freely. That includes information like publicly released source code and openly announced financials.

For our risk tolerance and organizational needs, we made the decision to protect data designated confidential or higher. As a result, we contain data flows to their tenants and only trust suitable storage destinations for content. That suitability depends on a storage location’s ability to gate which connectors can work with particular source data and sensitivity labels.

The administrators responsible for workspaces like SharePoint sites set default labels. These labels serve as a foundation for appropriate access and circulation for objects within those containers. It takes the burden of labeling off of employees. The sensitivity labels that administrators apply map to several different categories of policies that can anticipate and help to mitigate data loss and risk.

They communicate four key areas:

  1. Breadth of availability: Labels determine whether the workspace is broadly available internally or is a private site.
  2. External permissions: We administer guest allowance via the group’s classification, allowing specified partners to access teams when appropriate.
  3. Sharing guidelines: We tie important governance policies to the container’s label. For example, can an employee share this workspace outside of Microsoft? Is this group limited to a specific division or team? Is it restricted to specific people? The label establishes these rules.
  4. Conditional access: While we haven’t implemented this policy at Microsoft, tying identity and device verification to container labels can introduce additional governance controls.

Within Microsoft Digital, we’ve put a lot of thought into how each of our labels aligns with relevant policies. You can see more of the logic behind our sensitivity labels and their policies in this graphic:

A chart shows the different types of data container labels and what level of access is given for each one.
Our Microsoft Digital schema clearly lays out what each container sensitivity label means and how it affects content.

If a container owner needs different policies for a set of files to provide greater external access, they can self-service new groups without accidentally violating our governance practices.

At Microsoft, we use Microsoft Purview, which is our suite of data estate management tools, but you can use your tool of choice to apply labels in your environment. Microsoft tools will respect them. Microsoft Purview helps us accomplish three important tasks: mapping our labeling structure onto the relevant policies, verifying them against our standards, and backstopping self-service data loss prevention practices through automation.

Automation is particularly useful. We’ve configured Microsoft Purview Information Protection to scan automatically for wayward credentials, malicious user behaviors, and other sensitive information in items without the proper protections. When Purview detects a violation, our governance team receives alerts that prompt them to contain the risk by upgrading an item’s sensitivity label or requiring employees to remedy the issue.

The result is a system that allows flexibility for employees to self-manage their digital workspaces while providing guardrails that help our governance experts take appropriate actions without overtaxing their time and resources.

Our approach within Microsoft Digital is just one way to create an AI-ready data estate, but aspects of our story will hold true for almost any organization. Consider establishing a body to take over responsibility for AI-ready data, developing your primary goals for AI-ready data, unifying your data estate, and implementing a system of confidentiality labels.

Learning from our approach to agent governance strategy

Define the responsibility for AI-ready data

Identify and assign enterprise data owners to implement and oversee the processes that guarantee data quality.

Create intuitive labels

Your employees will be the ones applying labels, so make those labels intuitive. For example, “highly confidential” is easy to understand, while “business-critical” could be interpreted in many ways from a sensitivity standpoint.

Don’t overwhelm your users

Make labeling simple and intuitive to ensure it isn’t overwhelming. Employees should have a limited set of choices to keep things comprehensible.

Use existing defaults

Identify the security needs and regulatory compliance that are specific to your organization and use built-in governance controls available through Microsoft tools.

Key takeaways

You can use these tips based on what we learned here at Microsoft to tackle agent governance at your company:

  • Establish a cross-functional data council. Form a data council to help promote a culture of AI-ready data with professionals from all relevant disciplines, including human resources, legal, security, IT, and anyone else who can share relevant expertise.
  • Certify datasets for AI workloads. Limit agents to datasets that have been certified as “AI-ready” to minimize hallucinations and reasoning errors.
  • Define your labeling parameters. Keep the number of labels to five main labels with five sub-labels each. The fewer you use, the better.
  • Align your sensitivity labels with policies. Consider how your labels line up with breadth of availability, external permissions, sharing guidelines, and conditional access.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 3: A matrixed approach to agent governance

Governing different types of agents for different contexts, built with different toolsets

Our customers have expressed a strong desire to start building agents, but they’re concerned about where to begin and how to manage those agents once they’re built. They worry about persistent problems such as hallucinations and agent sprawl. These concerns are especially pronounced on IT teams.

During our Customer Zero journey, we’ve learned that the diversity of agent types and creation methods means there’s no one-size-fits-all approach to governance. Generalized approaches will only get you so far.

We’ve found it helpful to think about different kinds of agents along an escalating spectrum of development complexity:

The Microsoft Digital agent controls model, spanning citizen, partnered, and professional development models and their relevant tools.
The agent controls model we’ve developed at Microsoft Digital spans different agent-building methods for different kinds of creators using a spectrum of tools.

There’s an entire matrix of different parameters that apply to an agent at any level of this spectrum, and they all require different policies. Those parameters include:

  • Level of reach: Personal agents, limited sharing (like development environments or team boundaries), or enterprise-wide distribution
  • Agent-building tool: SharePoint agent builder, Agent Builder in Microsoft 365 Copilot, Microsoft Copilot Studio, or tools geared to more professional developers (such as Microsoft Foundry or Microsoft 365 Agent Toolkit)
  • Knowledge sources and content accuracy: Public sites, SharePoint and OneDrive, directly uploaded files, enterprise apps and systems, or third-party knowledge bases
An overview of the range of agent-building tools and our matrixed approach to governing them across different parameters.
Our matrixed approach to agent creation and governance spans a wide array of tools, knowledge sources, actions, channels, and more.

Each of these parameters creates a pivot that we need to govern, and we’ve carefully assembled a set of policies and controls to account for them. As our understanding and use of agents advances, we’re continually updating how we match their characteristics and capabilities with relevant policies and any applicable reviews.

Within Microsoft Digital, we’ve adopted a risk-based approach that helps us establish a matrixed model for agent governance. The foundational idea is that we identify potential harms for each kind of agent, then assign policies for the level of review and oversight they require.

For example, simple agents that can only read and present data tend to be low risk. Because their access is tied to their creators’ identities and access, our data governance structures and guardrails can prevent overexposure. But for agents that have capabilities like writing data, taking action, or creating items, more reviews are necessary.

A matrix of agent governance policies, pivoted by parameter

The following matrix enumerates the factors that determine how we govern different kinds of agents created using different tools. This matrix helps our employees understand the agent creation process and helps us maintain safety and control.

SharePoint agent builder

What users can build: Knowledge-only agents
These agents reason over Microsoft 365 Copilot collaboration data, and they’re gated to the SharePoint environment where they’re created.

Technical proficiency: No-code

Knowledge sources: SharePoint, custom instructions

Capabilities: Not applicable

Actions and plug-ins: Not applicable

Sharing and publishing: Copilot navigation in SharePoint, sharing by link, sharing in Microsoft Teams chat

Custom engine or bring-your-own model: Not applicable

Reviews: No review needed
IT doesn’t gate knowledge-only agents outside of governance tied to SharePoint sites. Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.

Agent Builder in Microsoft 365 Copilot

What users can build: Knowledge-only agents
These agents feature graph connectors from a preapproved catalog to expose additional data.

Technical proficiency: No-code

Knowledge sources: SharePoint, external websites, custom instructions, additional internal knowledge sources via graph connectors

Capabilities: Code interpreter, image generator

Actions and plug-ins: Not applicable

Sharing and publishing: Individual use, sharing by link

Custom engine or bring-your-own model: Not applicable

Reviews: No review necessary
These agents only access graph data available in Copilot. Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.

Microsoft Copilot Studio

What users can build: Task and custom agents
These agents connect to more systems through connectors and orchestration logic to handle more complex scenarios. We might publish agents at this level of complexity and utility to our agent catalog for wide organizational use.

Technical proficiency: Low-code or pro-code

Knowledge sources: SharePoint, external websites, custom instructions, additional internal knowledge sources via advanced graph connectors, Power Platform connectors

Capabilities: Not applicable

Actions and plug-ins:
Retrieval and task agents: Read-only actions
Custom agents: Read or write actions using Power Platform connectors

Sharing and publishing:
Retrieval or task agents in a personal developer environment: Sharing by link with up to 10 people
Custom agents: Publishing to 10 people or the agent catalog in Microsoft 365 Copilot Chat
Broad publishing: Requires a review similar to professionally developed apps, including an understanding of the agent’s data implications

Custom engine or bring-your-own model: Custom Azure OpenAI large language models (LLMs)

Reviews: Custom agents for our catalog require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review.

Microsoft Foundry

What users can build: Retrieval, task, and custom agents
These agents may or may not connect to more systems through connectors and orchestration logic to handle more complex scenarios. We might publish agents produced at this level of complexity and utility as Microsoft Teams apps or to our agent catalog for wide organizational use.

Technical proficiency: Pro-code

Knowledge sources: SharePoint, external websites, custom instructions, additional internal knowledge sources via graph connectors

Capabilities: Code interpreter, image generator, Teams chats and channels

Actions and plug-ins: API actions

Sharing and publishing: Publishing as an app in Teams or as an agent in the catalog in Copilot Chat

Custom engine or bring-your-own model: Custom Azure OpenAI large language models (LLMs)

Reviews: Custom agents for publishing as a Teams app or in our catalog require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review.

In addition to mapping out our policies for governing agents, the matrix illustrates how we see their relative utility across the organization. It demonstrates an escalation from personally useful to organizationally useful agents. Their governance policies and controls escalate accordingly.

Regionality is an additional concern. Regulatory compliance might vary, but it’s important to keep in mind that certain kinds of data access and actions might be perfectly permissible in one region, but not in another.

One example is our Employee Self-Service Agent, a central resource employees can turn to for help with IT support, HR questions, and facilities requests. Because it can access potentially sensitive personal information, this agent required additional review from European works councils to ensure it met all relevant workplace standards.

As you facilitate the experimentation and innovation with agents across your workforce from citizen developers to pro developers, consider adopting a similar matrixed approach to agent governance. It starts with understanding your organization’s needs, your risk tolerance, and the different employee populations you want to equip with agent-building capabilities.

Learning from our matrixed approach to agent governance

Figure out your building environment strategy

Decide which scenarios match up with specific environments and make those environments available to the relevant employees.

Design governance structures that scale from low-code to more advanced agentic tools

With the proliferation of AI agents, platform-level approvals similar to the Power Platform model at Microsoft can ensure rapid innovation while requiring review for individual high-impact scenarios.

Build trust through transparency and structure

A clear, well-documented approval process helps internal regulatory advisors understand new AI technologies and establishes the trust needed for productive, long-term collaboration.

Treat regional partners as strategic allies in the agentic future

Early feedback on digital agents from regional partners like works councils helps improve product design, accelerate approvals, and reduce fear or misconceptions about AI in the workplace.

Don’t forget that Copilot Studio is part of Power Platform

You can use what you’ve learned empowering citizen developers in Power Platform to guide your work with agents.

Key takeaways

Use these tips based on what we learned here at Microsoft to tackle agent governance at your company:

  • Establish your tolerance for risk. Determine where the most prevalent risks emerge across different populations and kinds of agents. Remember, you control the guardrails in your environment.
  • Determine what agent-building tools you want to roll out and who can use them. Different populations benefit from different agent-building capabilities. Put thought into what individuals and teams can create and the degree of partnership each level will need from IT.
  • Define your governance parameters for different kinds of agents. Determine the best ways to hedge against risk at every level. For example, you might choose to trust in tenant governance for simple agents and establish reviews for more complex tools.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 4: Tracking, impact, and value

Managing agents and assessing their business impact for the organization

It’s clear that agents bring astonishing capabilities to the enterprise. For many organizations, what remains unclear is exactly how to measure their impact. Without that information, businesses are at a loss for ways to articulate value and drive improvement.

Tracking agents is also a crucial component of preventing sprawl: We need to understand what agents we have, how employees are using them, what critical processes they’re supporting, and if they’re contributing value or need to be retired.

We’re at the beginning of our impact-tracking journey, but our work can provide a starting point for your own efforts to measure the value of AI initiatives at your organization.

Managing our agent catalog through comprehensive tracking

Microsoft Digital partners with other internal organizations to ensure we’re prioritizing the right agents and avoiding agent sprawl. Ideally, these engagements take place before teams start building their agents so we can avoid wasted effort or duplicated work.

Still, ongoing management efforts are crucial to keeping our agent ecosystem healthy. Telemetry is the key to assessing usage and ensuring compliance. We’ve developed our own internal tooling to ensure that:

  • Metadata is complete and available
  • The tooling tells us the right information about our agents
  • The tools connect properly with other compliance tooling, like Microsoft Purview

This telemetry also reveals agent behaviors, shows how agents do their work, and tracks events, actions, and policy baselines.

These capabilities help us gain visibility into policy adherence and violations, and then to conduct enforcement actions. We also track the speed of reaction and mitigation. AI-ready data and robust guardrails mean we head off most violations before they occur.

A robust inventory, an agile policy framework, and an automated workflow for enforcement are cornerstones for successfully governing agents at scale.

The release of Microsoft Agent 365, now in early access, represents the next step in agent observability and management, two key aspects of agent governance and sprawl mitigation. This control pane for agents incorporates many of our learnings as we’ve bridged governance gaps through IT intervention.

Some of the key aspects of the control pane:

The registry

Provides a complete view of agents, and the enterprise agent store makes it easy to find the right agents for each role and business process within familiar workflows in Microsoft 365 Copilot and Teams.

Visualization

Delivers the observability layer, including role-specific oversight, compliance and audit features, and performance measurements that can help organizations track their agents’ impact and see where they contribute value.

Interoperability

Ensures Agent 365 is open to any Microsoft-built or partner ecosystem, while delivering work intelligence through access to data and Microsoft 365 apps.

Security features

Provide crucial confidence through visibility into security posture, detection and response capabilities, and intelligent runtime defense.

As Customer Zero for Agent 365, we’re excited to have a platform for observability and telemetry that encompasses everything from agentic creation through usage.

Tracking governance from agent inception

Professionally developed agents add a new dimension of tracking and governance, because we need standards in place for ensuring compliant agent-building and to remediate any issues.

We use our Azure DevOps instance to catalog apps on our tenant, and we’ve applied this practice to agents created professionally for lines of business and enterprise agents. This tool contains our service tree with product and app log registration, which is tied to our KPI dashboard and scoring system that validates agent data against our policies.

Our expectation is that all new apps and agents start from a place of compliance. Any new agent is registered through this platform, and we expect adherence within the first 14 days. In our experience, the introduction of new metrics, policies, or timeframes as our governance policies evolve is where agents tend to drop out of compliance. The priority is restoring compliant status.

We’ve established a series of metrics to help track and manage these expectations:

  • Enablement velocity
  • Renewal velocity
  • Agents in compliance
  • Time to remediation of noncompliance

Through a DevOps process built on our preexisting software development lifecycle practices, we’ve applied governance not only to agents themselves, but to the process of building them professionally.

Measuring progress and unlocking value

Properly measuring value depends on concrete definitions of success and metrics that support it. Articulating AI’s impact came with several challenges. First, we had to land on a consistent taxonomy for different measurement areas. Then we needed to make the relevant data accessible, ensure its quality, and confirm it made sense.

The Microsoft Digital AI Value Framework is our flexible, modular tool for measuring the impact of our AI initiatives. With tools for measurement firmly in place, we can effectively demonstrate value and guide further decision-making.

Revenue impact

Direct contributions to revenue generation and business growth

Example metrics:

  • Increased sales or customers
  • Improved customer targeting
  • Higher lead quality
  • Deal velocity

Productivity and efficiency

Efficiency gains while completing tasks and processes without a reduction in quality

Example metrics:

  • Increased throughput
  • Process optimization
  • Task automation

Security and risk management

Improvements in identifying, preventing, and managing security vulnerabilities and risks

Example metrics:

  • Vulnerability detection or prevention
  • Reduction in data security incidents
  • Increased compliance with responsible AI standards

Employee and customer experience

The impact of AI initiatives on employee satisfaction, engagement, and productivity

Example metrics:

  • Employee or customer engagement satisfaction with products or services
  • Improved employee health scores

Quality improvement

Enhancements in the quality of deliverables, services, and processes

Example metrics:

  • Higher-quality deliverables
  • Confidence in code quality
  • Accuracy of numbers

Cost savings

Reduction in operational costs and resource allocation efficiencies

Example metrics:

  • Operational efficiencies
  • Improved resource allocation
  • Future cost avoidance

We plan to use the following capabilities to improve the overall ecosystem:

  • Filtering our agent inventory on specific criteria like the type of agent or how it was built
  • Enhancing governance-specific actions we can take with agents in areas like ownership and quarantining
  • Gaining visibility into trends like agent usage
  • Ingesting agent blueprints and defining policy templates

We’re still in the midst of our agentic measurement journey at Microsoft, but the blueprint for tracking already exists. Your organization might be in the early stages of agent readiness and deployment. If that’s the case, it could be helpful for you to internalize the lessons we’ve learned as Customer Zero and apply them as early as possible in your own journey toward AI maturity.

Learning from our agent adoption experience

Think proactively, not retroactively

If you put effort into tracking agentic impact early in your AI maturity journey, you’ll be poised to start capturing insights immediately instead of applying your methodology retroactively.

Involve a wide array of stakeholders

This workstream needs oversight from different kinds of stakeholders, including your leadership team, IT, Microsoft 365 administrators, agent developers and builders, and employee champions. That will provide the sponsorship, expertise, and perspective you need for success.

Different measurements will be appropriate for different phases of your initiatives

These measurements include monthly, weekly, or daily active usage; consider which metrics make sense at each phase of an AI initiative.

Establish a continuum of value

Agents need to tie into real business goals, so it’s important to establish metrics that actually speak to those objectives. Cascade business goals to concrete KPIs with well-defined timelines and track those diligently.

Embrace the red

Try to think of underperformance not as failure, but as data. Performance data over time helps you course correct or pivot, making sure you invest where it matters.

Key takeaways

Here are some important steps to keep in mind as you embark on your own tracking and measurement efforts for agents:

  • Establish priorities and parameters for tracking agents. Consider measurements that relate to sprawl, usage, and coverage, and build them into your telemetry tooling.
  • Pull your stakeholders together to establish measurement parameters. Cascade business priorities into measurable value.
  • Conduct ongoing tracking. Establish a cadence for tracking and reviewing progress with your team.

Learn more

How we did it at Microsoft

Further guidance for you

Governing the frontier to scale innovation

AI agents are rapidly becoming core contributors to how work gets done. As our experience within Microsoft Digital demonstrates, realizing their full potential demands more than powerful tools or enthusiastic builders. It requires thoughtful governance that evolves alongside your AI maturity, protects what matters, and gives employees the confidence to innovate responsibly.

As you consider your own strategy for managing agents, it can be helpful to keep one truth in mind: Governance is a catalyst for progress, not a barrier. By embedding guardrails into tools, grounding agent creation in AI‑ready data, applying risk‑based and matrixed policies, and reinforcing all of it through adoption and education, we’ve been able to expand agentic capability without sacrificing security, privacy, or trust.

From our experience, we’ve learned that governance works best when it’s:

  • Proportional, scaling with risk and agent complexity
  • Embedded, not bolted on after the fact
  • Human‑led, recognizing that accountability and judgment remain essential
  • Iterative, adapting as technology, regulations, and business needs evolve

When you design governance this way, it allows experimentation, learning, and impact at scale. Employees feel empowered to build agents that solve real problems, while IT and compliance teams gain visibility and control without becoming bottlenecks. Crucially, leaders can measure value, manage risk, and make informed decisions about where to invest next.

A photo of Alaparthi.

“At Microsoft, we believe the future of agentic AI depends on governance that empowers people first. The structures should be invisible when they’re working, intentional when they’re needed, and trusted by everyone they serve.”

This is the foundation of the Frontier Firm: Organizations where humans lead and agents operate, guided by clear principles and trusted systems.

As you continue your AI maturity journey, remember that there is no single, correct governance model. Your approach will reflect your risk tolerance, regulatory environment, data maturity, and organizational culture. The practices outlined here provide a proven starting point informed by real-world deployment at enterprise scale.

“At Microsoft, we believe the future of agentic AI depends on governance that empowers people first,” says Vijaya Alaparthi, principal group product manager in Microsoft Digital. “The structures should be invisible when they’re working, intentional when they’re needed, and trusted by everyone they serve.”

Now is the moment to act. Start with strong foundations. Empower your builders. Measure what matters. And treat governance not as a constraint, but as a strategic advantage that allows your organization to move faster, innovate safely, and lead confidently on the agentic frontier.

Key takeaways

Here are the high-level learnings and insights that you need to consider as you embark on your own agent governance journey, based on what we’ve learned here at Microsoft:

  • Treat governance as an enabler of innovation, not a brake. Effective agent governance is what makes large‑scale innovation possible. When you embed guardrails into platforms, data, and processes, employees can build and experiment confidently without exposing the organization to unnecessary risk or slowing progress.
  • Match governance rigor to agent risk and maturity. Not all agents need the same level of oversight. A risk‑based, matrixed approach lets organizations trust lightweight, personal agents while applying deeper reviews to agents that write data, take actions, or operate across business‑critical systems.
  • Start with AI‑ready data and zero‑trust foundations. Strong agent governance rests on secure, well‑labeled, high‑quality data. Clear ownership, intuitive sensitivity labels, default protections, and automation reduce reliance on user judgment and allow agents to operate safely at scale.
  • Embed governance where agents are built and used. The most effective governance is built into tools and workflows, not enforced through manual reviews alone. Defaults, limits, identity‑based access, lifecycle controls, and telemetry should apply automatically so agents are governed by design.
  • Plan for the full agent lifecycle to prevent sprawl. Agent inventories, ownership models, attestation, and retirement processes are essential. Governance needs to account for how you create, share, evolve, audit, and ultimately decommission agents, whether individuals or enterprise teams are responsible for building them.
  • Reinforce governance through adoption and education. Guardrails work best when employees understand them. Targeted adoption programs, clear guidance, prerequisites for advanced tools, and visible leadership sponsorship can help employees build responsibly and recognize their role in protecting the organization.
  • Measure what matters to prove value and drive improvement. Visibility drives trust. Telemetry, observability, and clear metrics that span productivity, quality, risk reduction, and experience allow organizations to track impact, course‑correct early, and continuously improve their agent ecosystem.

Learn more

Try it out

Get started building and managing agents at your company with Microsoft Agent 365.

The post Governing AI agents at scale: Lessons from our journey at Microsoft appeared first on Inside Track Blog.

]]>
23618
How we’re tackling Microsoft 365 Copilot governance internally at Microsoft http://approjects.co.za/?big=insidetrack/blog/how-were-tackling-microsoft-365-copilot-governance-internally-at-microsoft/ Thu, 07 May 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23360 Governance in the age of AI Unlocking the next generation of productivity tools Microsoft 365 Copilot combines the power of large language models (LLMs) with your organization’s data to turn employees’ words into some of the most powerful productivity tools on the planet—all within the flow of work. It suffuses the Microsoft 365 apps your […]

The post How we’re tackling Microsoft 365 Copilot governance internally at Microsoft appeared first on Inside Track Blog.

]]>

Governance in the age of AI

Unlocking the next generation of productivity tools

Microsoft 365 Copilot combines the power of large language models (LLMs) with your organization’s data to turn employees’ words into some of the most powerful productivity tools on the planet—all within the flow of work. It suffuses the Microsoft 365 apps your people use every day—including Word, Excel, PowerPoint, Outlook, Teams, and more—to provide real-time intelligent assistance.

Findings from workplace surveys that we did internally here at Microsoft show that AI tools are having a significant and measurable impact across some of our major business functions:

Text graphic shows the measurable impact of AI tools on different functions at Microsoft with specific data points for marketing, IT, HR, and finance.

Getting governance right

With all the opportunities AI presents, your organization might be in the process of implementing Microsoft 365 Copilot. But it’s important to do that safely.

Copilot combs through your organization’s entire data estate in the blink of an eye, so the old method of security through obscurity doesn’t cut it. You need to assert control over where data flows throughout your tenant, so Copilot knows what it can and can’t access or display.

Learn from our Microsoft 365 Copilot experience

We learned a lot as the first large enterprise to deploy Microsoft 365 Copilot. We used those learnings to create this deployment and adoption guide that you can use at your company—check it out:

To ensure that proper data hygiene extends to AI-powered workflows, Microsoft designed Copilot to respect the sensitivity labels and data loss prevention (DLP) controls that organizations configure in their Microsoft Azure environment. That way, administrators can be confident that the right people and apps have access to the data they need, and that sensitive information doesn’t appear where it shouldn’t.

Our team in Microsoft Digital, the company’s IT organization, created a company-wide governance strategy to address this challenge. In the process, we learned valuable lessons that will be useful to any organization using Copilot.

“We’re entering an age where AI amplifies human capability at unprecedented scale, and the integrity of our data determines the integrity of that transformation. Thoughtful governance ensures that we balance adoption with risk to enable the business.”

 A photo of Fielder.

This guide outlines our process for developing and implementing a governance strategy that delivers the benefits of Copilot to Microsoft employees while minimizing the risks to our data estate. We share our internal learnings so our customers can get up and running quickly while avoiding pitfalls or surprises.

Follow along to find out how you can safely and effectively deploy Copilot at your organization—backed by rock-solid governance.

“We’re entering an age where AI amplifies human capability at unprecedented scale, and the integrity of our data determines the integrity of that transformation,” says Brian Fielder, vice president of Microsoft Digital. “Thoughtful governance ensures that we balance adoption with risk to enable the business. AI accelerates possibility and does so with clarity, confidence, and unwavering trust.”

Principles for effective AI governance

Use this set of tips to ground yourself as you read through this guide:

Enable self-service. Give employees the ability to create new workspaces across your Microsoft 365 applications. By maintaining all data on a unified Microsoft 365 tenant, you ensure that your governance strategy applies to any new workspaces.

Limit the number of information protection labels. Try to limit your taxonomy to a maximum of five parent labels and five sub-labels. That way, employees won’t feel overwhelmed by the volume of different options.

Use intuitive labels that mean what they say. Make your labels simple and legible. For example, a “business-critical” label might imply confidentiality, but every employee’s work feels critical to them. On the other hand, there’s very little doubt about what “highly confidential” or “public” mean.

Capture container labels for groups and sites. Label your data containers for segmentation to ensure your data isn’t overexposed by default. Consider setting your container label defaults to the “Private: no guests” setting.

Derive file labels from parent containers. Classify files according to their parent containers. That consistency boosts security at multiple levels and ensures that deviations from the default are exceptions, not the norm.

Train employees. Train your employees to handle and label sensitive data to increase accuracy and ensure they recognize labeling cues across your productivity suite.

Trust employees, but verify their work. Trust your employees to apply sensitivity labels, but also verify them. Check against DLP standards and use auto-labeling and quarantining through Microsoft Purview automation.

Implement lifecycle management and attestation. Use strong lifecycle management policies that require employees to attest containers, creating a chain of accountability.

Consider your default link-sharing configuration. Limit oversharing at the source by allowing company-shareable links—at least as secondary options—rather than forcing employees to add large groups for access. For highly confidential items, limit sharing to employees on a need-to-know basis.

Extract inventory to detect and report oversharing. Use Microsoft Graph Data Connect extraction in conjunction with Microsoft Purview to catch and report oversharing after the fact. When you find irregularities, contain the vulnerability or require the responsible party to repair it themselves.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 1: Enable self-service

Empowering employees with secure self-service

Applying self-service principles to the way we manage labeling and governance emerged as a crucial step for us. 

Self-service is a core tenet of employee empowerment here at Microsoft. We want to give every employee the independence to create the resources they need without engaging IT. But that level of freedom relies on ensuring our Microsoft Digital governance team identifies and protects valuable data. As a result, our employees can implement and own the containers, workspaces, and content they need to do their work productively. 

A container or workspace is a logical unit of content storage associated with a designated roster of collaborators. Common containers include SharePoint sites, Viva Engage communities, Outlook groups, and Teams channels.

Self-service forms the foundation of our entire governance strategy. Employees can create workspaces and content across many of the Microsoft tools they use for their day-to-day work, including SharePoint, OneDrive, Teams, and Power Platform. That freedom enables a culture of innovation and agility, where people can work together across teams and geographies without encountering “IT gating,” the need for IT to get involved in enabling day-to-day activities.

By encouraging collaboration in place, our tenant structure frees employees from resorting to email attachments or working in overly broad and open workspaces. As an IT team ourselves, we understand the value of eliminating IT gating for minimizing the time and effort our professionals need to invest in keeping employees productive.

This kind of data hygiene isn’t just about Microsoft 365 Copilot. It maintains data security and compliance wherever employees access company content and information. But because Copilot depends on the ability to access an organization’s data estate, good governance is essential for keeping it within bounds—especially in a self-service culture.

Here are the key pillars of our asset governance:

Empower employees
  • Support self-service creation
  • Use lifecycle management
  • Offer user education and awareness/trainings
  • Implement monitoring and auditing
  • Adopt insider risk management
Identify valuable and vulnerable content
  • Require classification for containers
  • Scan with Microsoft Purview Data Loss Prevention and Information Protection services
Protect assets
  • Limit reach
  • Enforce policy
  • Use conditional access or multifactor authentication
  • Apply Microsoft Purview Data Loss Prevention and Information Protection services
Ensure accountability
  • Manage group or site ownership
  • Review external membership
  • Generate reports

Responsible self-service

Self-service container creation has abundant benefits, but it also poses some challenges for content governance and security—things like oversharing, unneeded asset sprawl, and data leakage. To address these challenges, our Microsoft Digital governance team has established self-service principles that balance the needs of employees and the company.

We empower with accountability

Accountability has responsibility. Any full-time employee can create a workspace, but they’re responsible for re-attesting its compliance every six months to ensure it meets our governance requirements. They also need to attest that they still require and maintain the resource. They need to manage their own content and ensure it’s properly classified, labeled, and secured. The content’s accountable owner makes any decisions about the workspace with respect to reach or the desire to maintain it. That removes any guesswork for IT about whether a site is still valued and cared for.

We empower with guardrails

We secure assets by default and expand access based on employee needs.

We trust, but we also verify

Microsoft Information Protection (MIP) sensitivity labels and Purview DLP act as guardrails for employee-led governance efforts.

As we in Microsoft Digital have worked to improve the company’s overall governance posture, we’ve learned several important lessons. When you consider self-service container creation, there are a few questions to ask yourself:

  • Who do you trust to create containers? At Microsoft, we reserve complete self-service capabilities for full-time employees. Then, we configure those privileges in Microsoft Entra ID to define who can create Microsoft 365 Groups. These users need to take relevant trainings, and we hold them accountable for the containers they create.
  • Where does employee self-service make sense? Different employees will require self-service in different environments. Will yours need to operate within SharePoint? Power Platform? Teams?
  • What are your lifecycle rules? Think about your policies and rule sets. Who’s accountable? What does the lifecycle look like?
  • What are your naming rules? A clear taxonomy can act as an extra signpost and organizational driver for your users. It can also be useful to think through what names are explicitly helpful or obscure. At Microsoft, we use a blocked word list, but we don’t prefix or suffix all groups or site names to avoid overloading the employee experience.

When you’ve settled on degrees of autonomy and where to apply it, you can begin your AI governance journey. Find out how to configure containers for self-service.

Key takeaways

Use these tips—which are based on what we learned here at Microsoft—to enable self-service in Copilot governance at your organization:

  • Front-end load on building your strategy. Put thought into your environment and tenant architecture, key personas, and scenarios before adoption.
  • Account for hesitancy. Understand that IT organizations have inherently cautious habits, and self-service might seem like a leap. As you lay out the business value for self-service container creation, illustrate the safety backstops as well. Also consider the risks if you don’t take this step, like employees misusing existing sites or other means not supported by IT.
  • Bring leadership on board. Make the business case and offer reassurances that greater flexibility doesn’t equal greater vulnerability.
  • Assess your current setup. Consider your existing data hygiene and how it needs to extend to accommodate AI.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 2: Establish container labels and set well-scoped, intuitive defaults

Balancing freedom with trust through an easy-to-use labeling taxonomy

Self-service container creation forms the foundation of our employee-centric governance strategy. As part of that freedom, our Microsoft Digital governance team has established baseline protections inherent to all containers, and those protections depend on sensitivity labels. Microsoft 365 Copilot respects labels, so establishing effective labeling practices extends data security into our employees’ AI usage.

Baseline labeling habits

Employees need to label every container or workspace they create using Purview Information Protection (PIP) container labels. It’s a matter of policy at Microsoft: If it isn’t labeled, we delete it. We use container labeling for data delineation and to apply consistent protection and governance policies to containers based on their sensitivity and purpose.

Microsoft labels break out into four different categories:

  • Highly confidential. This is our most critical data. Employees can only share this with specifically designated recipients.
  • Confidential. This is sensitive business data that’s crucial to achieving our goals. Employees should limit distribution to a need-to-know basis.
  • General. The “General” label includes data we use and share throughout Microsoft, like personal settings and postal codes. They’re visible internally throughout Microsoft.
  • Public. Public data is unrestricted and suitable for open, external consumption. It includes open-source code or financials the company has announced. Employees can share this data freely.

Container labels provide two things:

  • First, they drive user awareness over how to handle content. For example, if something is highly confidential, employees shouldn’t talk about it in the café.
  • Second, they illustrate what data is appropriate for which container. In other words, they signal to an employee that they shouldn’t store highly confidential documents on a general site.

Our Microsoft Digital governance team predefines and centrally manages labels to align them with broader MIP sensitivity levels used for email, files, meetings, and containers. Those include the same four categories: “highly confidential,” “confidential,” “general,” and “public,” although we don’t use the last one for containers.

Matching labels with policies and protections

Each label we’ve defined has a set of protection settings that include policies around characteristics like guest allowance and membership openness. They also drive inherited file labeling, which we use for encryption.

At its core, container classification communicates four things:

  • Privacy level: Labels determine whether the workspace is broadly available internally or it’s a private site.
  • External permissions: We administer guest allowance via the group’s classification, allowing specified partners to access teams when appropriate.
  • Sharing guidelines: We tie important governance policies to the container’s label. For example, can employees share this workspace outside Microsoft? Is this group limited to a specific division or team? Or is it restricted to specific people? The label establishes these rules.
  • Conditional access: While not implemented at Microsoft, tying identity and device verification to container labels introduces additional governance controls.

After extensive experimentation, we arrived at our current schema for how container sensitivity labels align with MIP policies. Your organization might make different choices about your labels’ relationships with information protection policies, but this graphic can give you an idea of what a healthy governance ecosystem looks like:

A chart shows the different types of data container labels and what level of access is given for each one.
Our Microsoft Digital schema clearly lays out what each container sensitivity label means and how it affects content.

Building a process around employee ownership

The labeling process works like this: When employees create a new container, they’re responsible for selecting a container label that matches the sensitivity and purpose of the content they intend to store and share. By default, we lock new containers, which means that only the owner and members can access them. Locked containers prevent unauthorized or accidental access to their content.

Container owners can unlock the container if they need to share content with a broader audience within the organization or external partners. Container owners can also change the container label if the sensitivity or purpose of the content changes over time.

At Microsoft, this process provides the right combination of flexibility and protection while empowering employees with effective self-service.

Key takeaways

Here are some of the main insights we’ve gleaned from our own data-labeling practices, which you can apply to your efforts in this area:

  • Use intuitive labels. Your employees will be the ones applying labels, so make those labels intuitive. For example, “highly confidential” is easy to understand, while “business-critical” can be interpreted many ways from a sensitivity standpoint.
  • Make use of existing defaults. Identify the security needs and regulatory compliance that are specific to your organization and use built-in governance controls available through Microsoft tools.
  • Limit the number of labels to 5×5. Keep labels minimal to avoid overtaxing your employees’ understanding. We recommend restricting your labeling schema to no greater than five main labels with five sub-labels each—and the fewer, the better!
  • Pilots are powerful. Experiment with sensitivity labeling through a small group of early champions, then roll these features out alongside an adoption and education initiative.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 3: Derive file labels from parent containers

Using default file-labeling based on container labels

We’re helping our teams stay consistent with how they create and store resources by making sure that default file-labeling happens based on container labels. Here’s how that looks for our employees:

  1. SharePoint and other containers support default library labels, which we configure to align with the container label through mapping we define in Purview.
  2. For instances where we need to define default library labels for tools that don’t have container labels, like OneDrive for Business, we create custom scripts. For OneDrive, we “secure by default” by using a default label like “Confidential\Internal-only,” which means that any file type that supports protection will remain protected–even if it’s accidentally left behind on a device, emailed externally, or purposefully shared externally. Without lowering the label, the default protection will not be decryptable by external actors.
  3. By default, new items that are unlabeled inherit the label of the container that stores them. That helps employees apply the correct label and avoid misclassification. For example, if an employee creates a new document in a SharePoint site labeled “confidential,” the document will automatically receive that label.
  4. Employees can change the item label if the sensitivity or purpose of the content differs from the container label. But that only works in one direction; they can’t store files with higher-confidentiality labels in a lower-confidentiality container. For example, they can downgrade a file in a “highly confidential” container to “general” if it doesn’t require heightened protection, but they can’t upgrade a file in a “general” container to anything above that grade. SharePoint will provide warnings to site owners when it detects label mismatches—for example, when a file label is more sensitive than its container’s.

The following graphic shows how default file-labeling is impacted by container labels and other sharing limitations:

Graphic shows the different levels of protection for different container labels at Microsoft.
By trusting employees and setting good defaults, we’re able to account for 99% of our governance needs.   

By defaulting file labels to their container labels, you can ensure that every item and collaborative space will align with both its context in your organization and your information protection policies. As a result, Copilot will respect those labels and their corresponding information protection policies.

Key takeaways

Here are some key tips for setting up container-file relationships, based on what we’ve learned through our own experience here at Microsoft:

  • Communicate the relationship between files and containers. Employees might not understand the relationship between files and their containers intuitively. When you implement your labeling strategy, be sure to include education about container-file derivation.
  • Guide through correction. Many employees learn best from practice, not instruction. Include automated messages that correct edge-case behaviors like trying to make a file in a confidential container generally available.
  • Ensure you’re comfortable with your label defaults. Employees will more often than not use the default, so ensure your defaults are correct and reflect your organization’s needs.
  • Reinforce the importance of file labels. Because a file can be moved or downloaded from its original container, the only way to protect that information is to ensure its label remains durable. Embed that durability in your object label configurations.
  • Match container and file label defaults. Whenever possible, make the container and file defaults the same from the outset. If you start with different labels or policy sets at the outset, it will be difficult to reconcile those changes later.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 4: Train employees

Empowering our employees: A joint effort between IT and users

Training your employees on how to handle and label sensitive data continues to be a critical step on our governance journey. 

Establishing a robust labeling strategy is only part of good governance. When it comes to getting employees on board, culture is as critical as policy.

At Microsoft, employee learning and development are how we move sensitivity labeling from the administrative sphere into day-to-day practice. It helps us increase the accuracy of how our labels are used and ensures that our employees recognize labeling cues when they appear across our productivity suite.

Every incoming Microsoft employee takes our Standards of Business Conduct and security trainings. As part of that process, we created an internal SharePoint resource dedicated to educating employees about their responsibilities for labeling and adhering to our governance policies. It educates employees about the philosophy behind our policies, shares a simplified overview of our sensitivity label structure, and provides practical, app-specific guidance for self-service labeling.

Text graphic shows the Microsoft labeling taxonomy that determines how employees determine what sensitivity label to use.
This quick-reference guide helps Microsoft employees understand our labeling taxonomy at a glance.

Effective learning and development assets

As you build out your employee education assets, consider emulating our content with the following elements:

1. Overview

It will be much easier for employees to act according to your governance policies if they understand what the policies do and why they’re so important. Our overview illustrates the relevance of sensitivity labeling for security and compliance and reinforces our employees’ role in maintaining them.

2. A quick-reference guide

A visual guide will help employees understand how labels relate to each other and what they accomplish. At Microsoft, we use a helpful flowchart that provides an outline of our labeling taxonomy without overloading employees with details. Placing it near the beginning of your training content grounds employees in the knowledge early, before they dive deeper into the details.

3. Technical education

Our learning material includes a section on how labeling works within our data estate. Then, it proceeds into an in-depth description of how each label or classification interacts with users’ content. Including this section will make labeling more tangible for your employees.

4. App-specific guidance

At this point, our guidance documentation progresses through the most common app-based use cases for sensitivity labeling: Microsoft 365 files, Teams, Power BI, and PDFs, as well as AIP and other file types separate from Microsoft 365. This app-by-app procedural content will help employees home in on their most common scenarios and educate themselves accordingly.

Aside from laying a solid foundation as an IT team, the most effective way to promote good governance is by bringing your workforce on board. Robust learning and development content is a powerful lever for establishing a culture of data security.

Key takeaways

Here are some of the key insights we’ve drawn from our own employee training in Copilot governance, which can guide you as you set up your own trainings.

  • Educate from day one. People will only do what they know, so ensure employees know your policies and how to enact them. Build robust education into your labeling and governance strategy, ideally as part of employee onboarding.
  • Don’t neglect in-app education opportunities. Labeling cues are an excellent opportunity for helping employees remember their responsibilities. Make label descriptions brief and tangible during in-app experiences.
  • Provide education on-ramps. Nobody’s memory is perfect. Link out to relevant information as part of label descriptions so curious employees have a chance to reinforce their knowledge.
  • Engage actively and situationally. If breaches occur or certain teams underperform, coordinate with relevant managers to refresh employee knowledge.

Learn more

How we did it at Microsoft

Further guidance for you

  • Learn more about sensitivity labels. This Microsoft Learn content provides an overview of sensitivity labels, including how they help classify, protect, and govern sensitive data across Microsoft 365.

Chapter 5: Trust employees, but verify their work

Self-service with guardrails: Backstopping our employee efforts with technology

Trusting your employees while also verifying that their actions are secure via automation is a crucial step. 

Thanks to our education efforts and intuitive labeling interfaces, we trust employees to apply sensitivity labels. But we also verify their work. It’s how we catch the 1% of edge cases where problems might arise.

We accomplish that by checking files against our data-loss prevention (DLP) standards and using auto-labeling and quarantining when we need them. Swiftly tying up any loose ends eliminates wayward items that Microsoft 365 Copilot might scoop up during the course of its work. Another way we verify employee decisions is by asking them to provide a reason when they downgrade a security label.

Data-loss prevention (DLP) is a set of technologies and practices centered around Microsoft Purview that help detect, monitor, and reduce the risk of sensitive data being inappropriately shared or accessed.

At Microsoft Digital, we use Purview DLP policies to define the rules and actions for detecting and protecting sensitive data across Microsoft 365, SharePoint, OneDrive, and Teams.

DLP policies support vulnerable data types and scenarios that require protection. They include any kind of information that might introduce inappropriate access to company data or intellectual property:

  • Access credentials like keys or tokens
  • Personally identifying information
  • Financial data
  • Non-public source code
  • Sign-in information

Reports and dashboards are available via Purview to help our team monitor and analyze content activity and compliance across the organization. They also provide insights into the volume, location, and usage of sensitive data, as well as any incidents and alerts that indicate potential data breaches or violations.

For example, an employee might label something as “General,” but it contains credentials or other sensitive end-user identification information (EUII). In those instances, Purview will automatically block the file from access beyond its owner or reapply a more appropriate label.

Automation and escalation

We’ve configured Purview to automatically remediate these kinds of issues or escalate them to our Microsoft Digital governance team for resolution when an issue is more complex. DLP remediation and escalation processes can involve several different groups of stakeholders depending on the severity and impact of the incident or alert:

  • Content owners
  • Content champions
  • The MIP team
  • Our legal team
  • Security

We use Microsoft 365 Purview to run DLP remediation operations at scale.

  1. DLP systems acquire telemetry from the Microsoft 365 activity management API. Backend processing cleanses the data to build relevant insights and surface them through Power BI dashboards.
  2. We flag information about files and aggregate it at the file level, then assign it to the last modifier for remediation action.
  3. If users don’t act on the files quickly, the DLP team scopes risky sites to quarantine any files with vulnerabilities.
  4. All activities—including sharing, labeling, and changing labels—get written into the unified audit log and into Sentinel to monitor for possible risks.

Fortunately, all these features and functionalities are available out of the box through Microsoft 365 and Purview. After you’ve established your labeling strategy and policies, it’s just a matter of adding guardrails to your self-service environment. By automating information protection through quarantining content or rightsizing its label, you can keep Copilot from making sensitive information available where it shouldn’t.

Key takeaways

Here’s what we’ve learned from our trust and verification process, which can inform your own process:

  • Consider your key escalation partners. When human intervention is necessary, it’s important to have immediate access to the relevant stakeholders. Assemble your list and build it into your process.
  • Understand DLP’s limitations. Purview DLP is a powerful set of capabilities, but it still relies on automation, which can miss things humans don’t. For example, DLP might not understand the code name for a product and fail to catch it during automated verification.
  • Identify and manage exceptions. There are very few absolutes in IT, so you’ll always need exceptions. For example, finance professionals will often need to include passwords or credit card numbers in working documents, so we exempt them from Purview DLP oversight with that team. At Microsoft, we use exemption groups to exempt certain employees.
  • Involve experts. Your legal, HR, and security teams will be key allies in this process. Engage them early to help you flesh out risk factors and vulnerabilities.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 6: Implement lifecycle management and attestation

Pairing trust with accountability: How we’re maintaining our data hygiene with attestation

We focused on strong lifecycle management policies and employee attestation to help us get our lifecycle management right. 

Attestation and self-service go hand-in-hand. In simple terms, it means employees can create what they need, but they’re accountable for its upkeep. In turn, that chain of accountability makes sure Copilot only accesses clean and appropriate data.

To support this, SharePoint now offers both activity‑based and non‑activity‑based attestations through SharePoint Advanced Management, giving organizations flexible ways to validate that their containers are being properly maintained. Microsoft Entra also provides an inactive group expiration policy that requires renewal of any inactive Microsoft 365 Group (like a team, group-connected site, or Outlook group).

At Microsoft, we follow the principle of data minimization. That means only content that’s necessary and relevant for the company’s operations and objectives should exist in storage. Data minimization reduces the risk of oversharing content that isn’t cared for by employees, minimizes asset sprawl, halts data leakage, and improves quality and usability.

To implement this principle, we require that every existing container has attestation. By extension, we delete information that doesn’t have a full-time employee to care for it or that has become stale or irrelevant.

Attestation is the process of verifying and validating the existence, ownership, and purpose of a container and ensuring it complies with content governance and security policies.

At Microsoft, we require attestation from a full-time employee for all shared workspaces every six months to confirm several aspects of their containers:

  • It’s correctly labeled.
  • Users actually care about its ongoing existence.
  • The roster of people with access is accurate and necessary.
  • Sharing capabilities are appropriately restrictive or permissive.
  • It complies with corporate retention guidelines.

If a container or an item doesn’t have attestation, we consider it orphaned or abandoned, and it’s subject to deletion. Note that we archive deleted items over an extended period, in case our employees decide they need them after the fact.

Managing exceptions

If a container is subject to a retention or hold for our legal team, that supersedes any deletion event. Generally speaking, containers where the legal team is the accountable owner aren’t subject to re-attestation because we handle those lifecycles more granularly based on Purview retention policies.

Ultimately, every organization will have to decide what makes the most sense for them. Applying these principles will help you maintain organization-wide data hygiene, which prevents over-access from Copilot.

Key takeaways

Here are some tips that come from our experience managing the product lifecycle for Microsoft 365 Copilot here at Microsoft.

  • Choose a meaningful attestation interval. The attestation interval should be short enough that it doesn’t introduce risk through neglect and long enough that it isn’t unnecessarily burdensome for employees. Think about what makes the most sense for your people by analyzing their behaviors.
  • Communication is key. Be sure that the attestation requests you create for employees contain both the objective for motivation and simple instructions. That will increase buy-in and smooth the process.
  • Base non-compliance response on severity. The severity of non-compliance will vary based on different files and containers. Some might be more relaxed, and others more strict. Determine a strategy for deciding which is which.
  • Include reasonable resolution and recovery options. Consider your resolution and recovery intervals after a lapse in attestation. You’ll need to balance between items’ sensitivity, employees’ bandwidth, and the infrastructure cost of extended archiving for recoverable items.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 7: Enable company-shareable links

Enabling fluid, secure collaboration: Extending access with company-shareable links

We’re finding that the best way to reduce oversharing is by addressing it at the source.

At Microsoft Digital, we recognize that content sharing is essential for collaboration and productivity. Employees need to share content with both internal and external audiences. But that also poses a risk of content oversharing when employees expose material to more people or for longer than necessary. It might also mean they’ve shared content without proper protection or classification.

In many cases, employees need to share content outside its container. That might include simply sharing a specific file outside of the container’s roster to enable collaboration in place without resorting to making a copy of the file. On the other hand, someone might need to email the file as an attachment.

Using company-shareable links

We limit oversharing at the source by enabling employees to directly share with users or groups, or by using company-shareable links (CSLs) for all SharePoint sites and items (except ones labeled “highly confidential”).

A CSL is a type of link that allows anyone who receives it within our organization to access the content. CSLs are convenient and easy to use, and they promote a culture of openness and transparency.

Before CSLs, employees were forced to share content with large security groups, because they didn’t know which groups contained everyone who needed access and manually adding every unique user was too cumbersome. That behavior leads to oversharing, because anyone with access can stumble on the content in Microsoft Search or via an answer from Copilot. Any Microsoft 365 discovery scenario will security-trim results, so it’s important that users can’t directly access things they don’t need.

While employees can pass a company-shareable link around within the company, it isn’t discoverable in Microsoft Search or Copilot, because only users who received the link directly via email or chat will have pre-granted access. It might seem counterintuitive that a CSL is more secure, but it eliminates the need for standing access to content and provides greater protection.

Finally, we allow content owners to modify or revoke CSLs if their sensitivity or purpose changes, or if sharing is no longer necessary. The content owner can also set an expiration date or a password for their link to enhance security and control.

Note that company-shareable links are no longer the default option, but they are still available as a sharing option for the reasons outlined here.

Extra protection for highly confidential items

Our governance team at Microsoft Digital determined that we should enable CSLs by default for all containers and items labeled “public,” “general,” or “confidential.” As a result, employees can share content with their colleagues without having to grant individual permissions or manage access requests.

There are some kinds of content that employees absolutely shouldn’t share through a company-shareable link. The risk emerges if someone copies the link into an open location like a broadly accessible document or community. You’ll have to decide where to draw that line for your organization. At Microsoft, we’ve elected to disable CSLs for all containers and items that are labeled “highly confidential.”

At Microsoft, highly confidential items require need-to-know access for specific people. For these files, employees use links they designate for specific people, which allows access to only individuals the content creator or owner explicitly identifies. In those situations, large security groups aren’t appropriate in any case.

We also want to drive broad sharing to SharePoint, so we discourage CSL use on OneDrive by automatically implementing expiration policies on OneDrive-created CSLs.

These policies compel employees to think about who needs access to content and to take deliberate action before sharing. In some ways, the policies act as an extra gate or prompt to keep our people security-conscious during the sharing process.

At Microsoft Digital, we tailored our policies to the company’s specific needs, but it provides a blueprint for other organizations to build a CSL strategy. Deciding what should be sharable and how will help you ensure robust information protection that’s still flexible enough to foster collaboration and productivity.

Key takeaways

Here are some key learnings we took from our CSL strategic work at Microsoft, which you can apply to your own efforts in this area:

  • Establish thresholds for company-shareable links or specific-people links. Align your CSL policies with the sensitivity labels that meet your organization’s security needs. Above a certain threshold, it might make sense to require links for specific people.
  • Embed education in the process. Employees will need time to get used to this structure. Create education communications early in the process, and configure your labeling interface to display information about the sharing implications of different labels.
  • Manage expectations for security teams. CSLs are counterintuitive in terms of safety. They might make security professionals uncomfortable because employees are free to share them internally with anyone. Reinforce that CSLs are safer than giant security groups, which will be the other default behavior for employees. And unlike security groups, they won’t show up in Microsoft Search.
  • Build data hygiene on good defaults. Most people will take the simple path, so make the simple path the safe path. Generally speaking, employees leave the defaults intact. If CSLs are your default, that’s the behavior it will drive for your employees.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 8: Extract inventory to detect and report oversharing

Remediating oversharing errors when they occur: Reporting on broad-access files and sites with Microsoft Graph Data Connect

When oversharing does slip through, it’s important to have systems in place to catch it. 

In spite of our Microsoft Digital governance team’s best efforts to limit oversharing at the source, it can still occur. In some ways, it’s inevitable.

Organizations are made up of people, and so will always be vulnerable to human error. Left unchecked, content oversharing can have negative consequences for an organization, including data breaches, compliance violations, or reputational damage. It will also give employees access to content through Copilot that isn’t appropriate.

To detect and mitigate content oversharing, we use Microsoft Graph Data Connect to report on every broad-access file or site with more sensitive labels. It helps us access and analyze data from Microsoft 365, SharePoint, OneDrive, and Teams using Azure Data Factory, Azure Synapse Analytics, or Azure Machine Learning. We then connect those datasets in our data estate using Azure Synapse Spark and track how many SharePoint sites and items are currently overshared based on our business rules.

One of the principal benefits of Microsoft Graph Data Connect is accessing the information we need through each of these technologies in a secure and scalable way, with control governed by our tenant admins.

Flow-chart graphic shows how Microsoft Graph Data Connect analyzes and remediates oversharing instances in our network.
We use Microsoft Graph Data Connect to detect, reveal, and remediate oversharing in the rare cases where it occurs.

Note that there will always be cases where we create exemptions to sharing limits. The policies around these exemptions are laid out as part of our Enterprise Governance, Risk, and Compliance guidelines.

Reporting for accountability

Our tenant’s data team uses Microsoft Graph Data Connect to generate reports on every file or site on the tenant with a broad access level, like a CSL or link that can be shared with anyone. It also monitors any item with a sensitive label like “confidential” or “highly confidential.”

These reports provide information and insights on the content’s owners, recipients, activity, and content protection and compliance status. They also help identify and prioritize potential cases of content oversharing.

At Microsoft, this output is helpful for several groups of stakeholders:

  • We share the reports with the content champions responsible for reviewing and validating any cases of content oversharing.
  • We use the reports to contact and educate the content owners on how to resolve oversharing issues and comply with our governance and security policies.
  • We share the reports with the legal and security teams responsible for investigating and responding to cases of content oversharing that involve legal or security risks and incidents.
  • We track our improvement over time as we enforce policies on our assets.

To help customers benefit from this kind of visibility, we’ve created a freely available reporting template. We encourage you to use this tool to track oversharing.

Beyond weaving your Microsoft Graph data connect and data export into your own data estate, you can now also use SharePoint Advanced Management in SharePoint Premium to get a list of sites that meet a set of criteria that you select. We use this capability to find all of our sites that share Highly Confidential data to more than 5,000 users. We then use the same capabilities to selectively require our site owners to fix any anomalies we discover.

Get more information on this data access functionality in SharePoint from Microsoft Learn.   

With the right controls and policies in place, you can minimize the number of oversharing errors your employees commit. But when errors do occur, a proactive detection strategy quarantines the risk from Copilot, even as your staff stays connected and collaborating.

Key takeaways

Some of the things we learned about setting up an oversharing detection and reporting system included:

  • Select the tools that work best for you. Between Microsoft 365 and Azure, it’s likely you already have access to the tools you need to set up your reporting apparatus. Explore out-of-the-box functionality before building your own solution.
  • Get reports to the right people. Collaborate with stakeholder teams to nominate point people who will receive oversharing reports and take action or communicate findings.
  • Put thought into your communication strategy. Work with internal comms professionals to determine the best communication strategy when you detect oversharing, especially when speaking with content owners.
  • Consider the content of your reports. Different stakeholders will require different information. Work with individual teams to determine what their reports should look like.

Learn more

How we did it at Microsoft

Further guidance for you

“As AI becomes woven into the fabric of how we work, governance is no longer just an operational requirement—it’s a strategic imperative.”

The way forward

Getting governance right in the age of AI

The advent of AI tools like Microsoft 365 Copilot is a once-in-a-generation development. At this point, we’re still learning all the ways that these tools can be used to unlock creativity, productivity, collaboration, and innovation.

But we can be sure of one thing: implementing them securely and effectively should be priority one.

“As AI becomes woven into the fabric of how we work, governance is no longer just an operational requirement—it’s a strategic imperative,” says David Johnson, a principal architect in Microsoft Digital. “When we pair powerful tools like Copilot with thoughtful oversight, we ensure that innovation accelerates our mission without compromising our security or our values.”

If you’re deploying Copilot to your organization, the lessons we’ve learned at Microsoft Digital can act as a roadmap for your own journey.

Ultimately, the most important thing is to consider the data implications of AI assistance and plan accordingly. Diligence and forethought will make sure your employees get all the benefits of next-generation AI technology while your organization stays protected.

Welcome to the age of AI.

Key takeaways

This guide reflects what we learned as we set up and implemented our governance processes during our internal rollout of Microsoft 365 Copilot. Here are some overall insights to keep in mind when establishing governance controls at your own organization.

  • Build governance on intentional design, not inherited habits. Thoughtfully define your tenant architecture, sensitivity labels, lifecycle policies, and container defaults to create a governance environment that is both secure and scalable.
  • Empower secure self‑service. Give employees the freedom to create the workspaces they need, backed by intuitive labeling and clear accountability for the content they manage.
  • Keep labeling simple, consistent, and enforced by defaults. Use a minimal, intuitive sensitivity label taxonomy and rely on container‑based default labeling to ensure that files stay consistently protected wherever they go.
  • Trust users—but verify with automation. Use Purview DLP, auto‑labeling, quarantining, and escalation workflows to catch exceptions and prevent sensitive data from being exposed through Copilot.
  • Maintain data hygiene with lifecycle management and attestation. Require regular re‑attestation, remove stale or unowned content, and use SharePoint Advanced Management to support both activity‑based and non‑activity‑based attestations.
  • Make collaboration safer with thoughtful sharing defaults. Use company‑shareable links (CSLs) and clear link‑sharing policies to reduce oversharing while still enabling fluid, secure collaboration.
  • Detect oversharing proactively and remediate quickly. Use Microsoft Graph Data Connect and SharePoint Advanced Management reporting to surface broad‑access content, notify owners, and correct issues before Copilot surfaces inappropriate data.

Learn more

Try it out

Get your organization and data ready for Microsoft 365 Copilot.

The post How we’re tackling Microsoft 365 Copilot governance internally at Microsoft appeared first on Inside Track Blog.

]]>
23360
Becoming a Frontier Firm: A guide for deploying AI agents based on our experience at Microsoft http://approjects.co.za/?big=insidetrack/blog/becoming-a-frontier-firm-a-guide-for-deploying-ai-agents-based-on-our-experience-at-microsoft/ Thu, 16 Apr 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=22868 A how-to guide for governing, implementing, adopting, supporting, and measuring the impact of AI agents from Microsoft Digital, the company’s IT organization. The agentic future: Our journey to becoming a Frontier Firm at Microsoft A new way of working, a modern way to achieve more The rate of change for AI tools and technology continues […]

The post Becoming a Frontier Firm: A guide for deploying AI agents based on our experience at Microsoft appeared first on Inside Track Blog.

]]>

A how-to guide for governing, implementing, adopting, supporting, and measuring the impact of AI agents from Microsoft Digital, the company’s IT organization.

The agentic future: Our journey to becoming a Frontier Firm at Microsoft

A new way of working, a modern way to achieve more

The rate of change for AI tools and technology continues to accelerate, and new opportunities to reimagine business processes and employees’ day-to-day workflows are emerging. Agents are the driving force behind this next leap forward.

As a result of this technological shift, a new organizational blueprint is emerging. It blends machine intelligence with human judgment to create systems that are AI-operated but human-led.

We have a name for an organization that enacts this model: The Frontier Firm.

As organizations progress toward this goal, they move from foundational AI assistance through escalating levels of agentic maturity and complexity. First, humans operate with help from an AI assistant like Microsoft 365 Copilot. Then, human-agent teams work together. But the future lies in humans leading teams of agent users: AI agents that perform core labor with relative autonomy.

Pattern 1: Human with assistant—every employee has an AI assistant that helps them work better and faster.
Pattern 2: Human-agent teams—agents join teams as “digital colleagues,” taking on specific tasks at human direction.
Pattern 3: Human-led, agent-operated—humans set direction, and agents execute business processes and workflows, checking in as needed.

This has been a three-year process for us at Microsoft, and throughout our journey, we’ve had to allow adequate time for deliberate planning and careful execution. Just as importantly, we invested early in clear, consistent internal communications to help employees understand what agents are, why they matter, and how they could safely participate in building them. That shared understanding created the confidence and momentum required to scale agent creation across a global workforce.

“It’s a truly transformative time,” Brian Fielder, vice president of Microsoft Digital. “What we’ve learned from embracing the agentic future at Microsoft is only making us more eager to see organizations empower their employees to take the lead in a world where human judgment and machine intelligence work in harmony.”

Our Frontier Firm journey so far

Within Microsoft Digital, the company’s IT organization, we’re taking a leadership role in reimagining core processes and workflows. These efforts rest on four pillars of practice:

  • We envision and implement the AI-first workplace of the future.
  • We empower our employees to build their own agents that help supercharge their productivity by providing the training, resources, and inspiration they need.
  • We define guardrails and safeguard our environment so our employees can maximize the power of AI while keeping our enterprise safe and secure.
  • We’re the voice of company’s internal AI transformation, and we provide the blueprint for our customers to accelerate their own AI journeys.

To guide our steps, we’ve established a cross-disciplinary initiative we call Agents at Microsoft. We’re looking at agentic transformation from an end-to-end perspective that reaches into every aspect of building, publishing, governing, managing, and getting the most value out of agents.

Six pillars of the workstreams involved with the Agents at Microsoft initiative: Strategy and value realization, analytics, accelerators, change management, governance, and publish and lifecycle.
Our Agents at Microsoft initiative represents part of a 360-degree approach to agentic maturity. These six pillars each represent a distinct workstream, each with its own accountable team.

As we’ve incorporated agents into more and more aspects of our organization, key questions have surfaced:

  • How do we balance freedom for employees to create agents against the need to manage sprawl?
  • How do we put guardrails around agentic capabilities so they can be useful, without introducing undue risks?
  • How do we differentiate between agents of different complexity and capability, and how do we adjust our strategies around them accordingly?
  • Where can we use agents to fill enterprise functions, and who should be responsible for creating those crucial tools?
  • How can we adapt existing software development standards to AI tools?
  • How can we minimize the risk of data over-exposure through AI?

It’s possible you’re also considering where agents fit into your organization. If so, it’s likely that you’re wrestling with many of the same questions. We’re here to help.

This guide shares our experience as Customer Zero for agents at Microsoft. As you read, you’ll be able to follow our journey to defining what it means to govern agents safely, implement them effectively, guide their adoption by employees, build a foundation for support, and track their impact through effective measurement.

We’ll share some of the most important lessons we’ve learned so far, along with readiness checklists and resources that can help you advance agentic maturity at your organization. With this guide in your toolkit, you’ll have a framework for building a strategy that incorporates agents into your business goals safely, responsibly, empathetically, and impactfully.

“As we harness the transformative power of AI agents, it’s our responsibility in IT to ensure that technology not only enhances decision making but also fosters a culture of innovation and collaboration across the organization,” says Stephan Kerametlian, a business program management senior director in Microsoft Digital.

The agentic future is here. We’ve explored the path forward, and we’ve seen the exciting places it leads. This guide can help you take your first steps and start realizing those possibilities today.


Expert insights

A photo of Fielder.

“It’s a truly transformative time. What we’ve learned from embracing the agentic future at Microsoft is only making us more eager to see organizations empower their employees to take the lead in a world where human judgment and machine intelligence work in harmony.”

Brian Fielder, vice president, Microsoft Digital

A photo of Kerametlian.

“As we harness the transformative power of AI agents, it’s our responsibility in IT to ensure that technology not only enhances decision-making but also fosters a culture of innovation and collaboration across the organization.”

Stephan Kerametlian, business program management senior director, Microsoft Digital


Chapter 1: Advancing good governance to meet the agentic moment

Maintaining privacy, security, and compliance while respecting regulatory frameworks

Agents offer powerful opportunities to enhance employee productivity, but they also introduce concerns. For example, how do we keep privileged information where it belongs? And how do we keep employees from building agents that violate company policies?

In answering these questions, Microsoft Digital’s governance team focused on the value the company is trying to derive from agents.

We wanted to give employees and teams the freedom to build without risk to the business or introducing agent duplication and sprawl. We wanted to weave robust, reliable agentic experiences into enterprise workflows. We also needed to secure and protect confidential data while respecting responsible AI principles.

“Our principles haven’t changed, but they’ve evolved,” says David Johnson, a tenant and compliance architect at Microsoft Digital. “With AI, the need for proactive governance is far greater than ever before, so we’re putting structures in place that take some of the labor around managing agents off of IT.”

There are some cornerstone constructs that underpin our agent governance strategy. There’s a tenant that holds employees accountable, a reasonably clean data estate, a lifecycle for the agents users-they disappear when the employee leaves. 

We’ve developed six core principles to guide our approach to governing agents:

  1. We ensure a strong data hygiene foundation so we can trust our data estate as employees build and use agents.
  2. We empower employees to build personal agents that can access services and data sources those users can already access to help automate and accelerate their tasks.
  3. We empower teams and lines of business to build agents with known lower risk patterns to accelerate impact.
  4. We provide a smooth release path for engineering teams to develop agents designed for enterprise functions so they can access all of the services and sources they need.
  5. We accelerate innovation through agent and automation templates while maintaining an AI Center of Excellence (CoE) to help teams think through their opportunities.
  6. We reimagine employee experiences and task execution to simplify and optimize productivity.

As a result of our experience establishing strong governance for Microsoft 365 Copilot, we’d already laid a firm foundation for an agent-ready data estate. In some ways, governance is tool-agnostic, rooted in basic principles. With appropriate data labeling, data hygiene, and well-managed permissions in place alongside tools that respect labels by default, we can confidently give every employee the ability to build basic agents and trust in our governance guardrails.

A matrixed approach to agent governance

The sheer diversity of agents and their use cases means we need a multifaceted approach to governance. A matrix of different parameters applies to any agent, and each of those elements requires its own approach to policy.

In practice, agent governance structures echo our overall maturity approach. Simple, personal, lower-risk agents with built-in guardrails act as a starting point for employee experimentation and require very little oversight. As a result of our robust data hygiene foundation, if an employee has access to the grounding content, these agents are low-risk accelerators for things they can already do on their own. Meanwhile, higher-impact agents demand greater attention that echoes our security development lifecycle (SDLC) for internal apps, which include more extensive, cross-disciplinary reviews.

SharePoint, Agent Builder in Microsoft 365, Copilot Studio, and Copilot Studio + Microsoft 365 Agents Toolkit and the level of agent governance required for each.
Our matrixed model for agent governance spans low-complexity, low-risk agents as well as more advanced tools created by professional developers.

To accommodate agent-creation experiences across this spectrum, we’ve enabled several different building platforms and processes employees and teams can use to create the AI tools they need.

  1. We opened up Agent Builder in Microsoft 365 Copilot for all employees to create read-only declarative agents.
  2. We created an environment strategy and governance in Power Platform to manage personal environments featuring data connectors with lower risk but high value.
  3. We enabled a process to flow the data that teams need into production Power Platform environments featuring data connectors. These agents initially come with sharing limits until the agent receives risk approval.

This structure provides the ability to safely create agents of increasing complexity while ensuring they remain secure and contained until they get the necessary reviews for wider sharing and data exposure.

Our governance guardrails, review policies, and publishing scope varies based on the tool used to create an agent, the level of technical proficiency it requires, its grounding in knowledge sources, its capabilities, the actions it can take, the plug-ins it requires, and whether it includes a custom engine or a bring-your-own model.

The following examples illustrate two different agent scenarios:

An employee builds a knowledge-only agent using Agent Builder in Microsoft 365 Copilot.

This agent features graph connectors from a pre-approved catalog for exposing additional data, easily created using no-code tools. Its knowledge sources are limited to SharePoint and OneDrive sites accessible to the employee, along with external websites, custom instructions, and additional internal sources through graph connectors. As a result, the risk of data overexposure is limited. These agents can’t take action, they don’t rely on plug-ins, and they’re tied to our data hygiene foundation. The employee can only use the agent personally or share it through a link.

No review necessary: Our team in Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.

Professional developers build an agent to manage enterprise workflows.

Agents created using pro-code tools can include custom connectors and orchestration logic to handle more complex scenarios, and their builders typically intend them to become Microsoft Teams apps or part of our agent catalog for wide organizational use. Their knowledge sources can be almost anything, from internal SharePoint sites to third-party apps, so they’ll often need to make use of APIs. For these apps, knowledgeable builders can create custom Azure OpenAI large language models (LLMs).

Reviews: These agents require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review. This review stage is essential because these agents can potentially transform or write data outside their places of origin. These capabilities represent both the power of agents and the risk we need to evaluate.

As you consider your own governance structures and policies, think about where agents and the ability to create them fit your needs and risk tolerance. Then learn from the different parameters of our governance matrix to access a working model for your own agentic transformation.


Expert insights

A photo of Johnson.

“Our principles haven’t changed, but they’ve evolved. With AI, the need for proactive governance is far greater than ever before, so we’re putting structures in place that take some of the labor around managing agents off of IT.”

David Johnson, tenant and compliance architect, Microsoft Digital

A photo of Hasan.

As you consider your own governance structures and policies, think about where agents and the ability to create them fit your needs and risk tolerance. Then learn from the different parameters of our governance matrix to access a working model for your own agentic transformation.

Aisha Hasan, Power Platform and Copilot Studio product manager, Microsoft Digital


Balancing utility and manageability in our agent ecosystem

Empowering employees and teams to simply and securely create agents has been a top priority as we move toward AI maturity at Microsoft, but we also want to eliminate agent sprawl.

Aside from complicating agent management, sprawl has several user-side disadvantages. For example, if more than one team were to create an agent that points to HR information, the employee experience would suffer, because our users wouldn’t be sure which agent serves as the authoritative source of truth.

Our team in Microsoft Digital partners with other internal organizations to ensure we’re prioritizing the right agent development projects and avoiding agent sprawl. Ideally, these engagements take place before teams start building their agents so we can avoid wasted effort or duplicate work.

If a pre-existing agent fits the target scenario, we encourage a team to use that agent instead of creating a redundant solution. For employees who want to create their own agents, we recommend that they first search for an existing tool in our agent catalog to avoid duplication.

User-based lifecycles and periodic attestation are also key pieces of the puzzle. Requiring attestation helps ensure that agents cease to exist once they’re no longer useful or their owner leaves the company.

The release of Microsoft Agent 365, now in early access, represents the next step forward in agent observability and management, two key aspects of agent governance and sprawl mitigation. This control pane for agents incorporates many of Microsoft’s Digital’s learnings as we’ve bridged governance gaps through IT intervention.

  • The registry provides a complete view of agents. The enterprise agent store makes it easy to find the right agents for each role and business process within familiar workflows in Microsoft 365 Copilot and Teams.
  • Visualization provides the observability layer, including role-specific oversight, compliance and audit features, and performance measurement that can help organizations track their agents’ impact and see where they contribute value.
  • Interoperability ensures Agent 365 is open to any Microsoft-built or partner ecosystem, while also delivering work intelligence through access to data and Microsoft 365 apps.
  • Security features provide crucial confidence through visibility into security posture, detection and response capabilities, and intelligent runtime defense.

“The next step in our governance journey will be using AI to help us govern AI,” says Aisha Hasan, Power Platform and Copilot Studio product manager at Microsoft Digital. “We’re looking at ways AI can help us manage this new space, and we believe Agent 365 will be the foundation for our deterministic approach to governance.”

As you strategize to deepen AI maturity at your organization, our experience will help you operationalize many of the aspects of governance we’ve pioneered as Customer Zero for agentic AI, especially with the wide release of Agent 365. By adopting the principles we’ve illustrated in this chapter, you can accelerate your transformation and advance your maturity rapidly and securely.

Learning from our experience with agent governance

A strong data foundation is crucial

We’ve built respect for labeling and data governance policies into the tooling for AI assistants and agents, but it’s dependent on a well-governed data estate. Invest time and effort in establishing that foundation.

Decide on your comfort level with risk

Bring cross-disciplinary experts together from across your organization to determine what level of risk is acceptable for different agents and their use cases. Put guardrails in place for low-risk scenarios and establish processes for supporting more complex or sensitive use cases. Evaluate what data sources agents can extract information from. Do you have confidence that users haven’t over-shared data access?

Agents aren’t always like applications—adjust your processes accordingly

We quickly learned that reasonable processes, approvals, and workflows for internal application development didn’t scale well with agents. Consider a risk-based assessment model.

Change is constant

Plan to reassess and revise your governance structure regularly. This technology is evolving rapidly, as is the tooling surrounding it, so maintaining good governance will be an ongoing practice.

Governance is a value driver for employees

Governance isn’t just about protecting your organization. It also provides the right patterns to make sure your employees are getting value from agentic technology. Establish strong measures of value and a robust pane for management and assessment. Observability and telemetry will be foundational, so ensure you build that into your governance efforts.

Continue non-agentic workstreams

Enterprise technology environments are additive and incremental. Don’t cease your efforts to create and govern other internal technologies. Instead, maintain a holistic ecosystem.

Key takeaways

Use these tips based on what we learned here at Microsoft to tackle agent governance at your company:

  • Establish a cross-disciplinary agent center of excellence: Bring together stakeholders across the organization to define priorities, goals, and shared practices for agent adoption.
  • Put strong data and information protection policies in place: Establish clear governance for your data estate, including labeling and information protection, to support responsible agent use.
  • Right-size oversight based on risk: Determine your organization’s risk tolerance and define which agents require more or less involvement from IT, security, and compliance teams.
  • Define a clear agent building tool strategy: Decide which tools employees and teams can use to create agents, balancing empowerment with governance.
  • Operationalize agent oversight and management: Establish an oversight model and implement tools like Agent 365 that help manage agents at scale.
  • Create a centralized governance and information hub: Provide employees and agent builders with a single place to find guidance, standards, and governance information.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 2: The Microsoft roadmap for implementing agents

Developing a plan to advance AI maturity while unlocking agentic value at every level of our organization

Implementing agents across your organization is intertwined with your larger AI transformation efforts. At Microsoft, we’ve adopted an escalating maturity model that unfolds across five stages.

Graphic showing the five stages of the Microsoft AI maturity model: awareness and foundation, active pilots and skill building, operationalize and govern, enterprise-wide adoption, and transformation with agentic AI.
AI maturity starts with simple awareness and foundational usage, then progresses to more complex patterns of interaction between humans and agents.

Putting the Microsoft AI maturity model into practice

Whatever stage you’re at in your AI journey, you’ll likely experience many of the same challenges and opportunities we do at Microsoft.

Stage 1: Awareness and foundation

Building a foundation means setting a bold vision for your AI journey, anchored in clear business outcomes. At this stage, it’s important to engage your executive sponsors early to foster cross-functional collaboration and empower experimentation.

At Microsoft, we established our AI Center of Excellence (CoE) to help guide and drive adoption of Microsoft 365 Copilot, as well as a Data Council that powers our AI-ready data strategy. As we’ve moved into the agentic future, these teams have been instrumental in maintaining forward momentum.

The company also established the Office of Responsible AI (ORA) to advance AI development, deployment, and secure and trustworthy innovation through governance, legal expertise, internal practice, public policy, and guidance on sensitive uses and emerging technology. ORA partners closely with product and engineering teams alongside other trust domains like privacy, digital safety, security, and accessibility to align our work with Microsoft’s six responsible AI principles:

  • Fairness
  • Reliability and safety
  • Privacy and security
  • Transparency
  • Accountability
  • Inclusiveness

Target outcomes include

A foundational strategy, governance principles, and leadership buy-in to kickstart AI projects.

Stage 2: Active pilot programs and skill building

We started by launching targeted pilot projects across different areas of the company. This process encouraged experimentation and used hackathons to surface a broad range of ideas. From there, we selected the most promising initiatives by evaluating business value against implementation effort and focused resources on a select group of high-impact projects.

To establish early-stage governance, we required all pilots to undergo responsible AI and architectural reviews.

Target outcomes include

The first tangible benefits of AI, including efficiency gains, time and cost savings, quality improvements, and an emerging internal talent pool that paves the way to scale successful solutions.

Stage 3: Operationalize and govern

At this point, we worked to scale and integrate AI solutions across the company. We strengthened our data and AI infrastructure to support this transition by formalizing enterprise governance with clearly defined steering teams. Our AI CoE, Data Council, and Office of Responsible AI helped accelerate implementation, ensure the ongoing quality of structured data, and oversee ethical AI use and compliance. Collaboration among these groups was crucial for ensuring our AI initiatives remained within acceptable bounds while delivering tangible business impacts.

Target outcomes include

Multiple AI use cases running at enterprise scale under robust oversight, with cross-functional alignment on AI objectives and the business value they’re delivering.

Stage 4: Enterprise-wide adoption

To consolidate our gains and achieve AI adoption across the enterprise, we prioritized making AI a core consideration in every new project and process by asking where AI-driven intelligence could deliver real impact. That could be by boosting efficiency, enhancing user experiences, or unlocking new business value. From there, we aligned our AI initiatives with our organization’s strategic goals by empowering business leads to synchronize efforts and continuously update our AI roadmap.

We also cultivated a data-driven culture through ongoing, large-scale training while making AI tools a natural part of everyday work. To accomplish that, we established rigorous impact tracking with clear measurement of the amount of value delivered. Key metrics include time savings, cost reduction, and quality improvements. We reviewed these outcomes regularly at the leadership level to maintain accountability.

Our Continuous Improvement CoE has been instrumental in the process of aligning AI initiatives with our organizational goals and providing a framework for progress. It operates according to four principles:

  1. A clear definition of winning, based on expectations
  2. Disciplined execution
  3. Constrained problem-solving with urgency
  4. Sustained replication and acceleration

Target outcomes include

Measurable, data-driven monitoring of AI for your business that’s powered by a continuous improvement mindset.

Stage 5: Transforming your business with agentic AI

At stage five, we’ve been working to embed AI into every aspect of our operations and culture. We started by leveraging the expertise of our AI CoE to foster innovation, drive continuous improvement, and keep our AI initiatives evolving using structured mechanisms like a Kaizen funnel to crowdsource, prioritize, and advance ideas that extend the impact of AI across the enterprise.

We also further strengthened governance to address the advanced challenges of agentic applications, including responsible scaling of generative AI and effective mitigation of AI hallucinations. Finally, we focused on refining human-AI collaboration so our teams can offload routine tasks to AI agents and concentrate on higher-value work.

One tactic that’s been highly successful here at Microsoft Digital is conducting “Fix, Hack, Learn” weeks, where we encourage employees to identify opportunities for improving our services. So far, these initiatives have yielded multiple AI-powered breakthroughs that are already in production.

Target outcomes include

Significant efficiency gains and innovations from AI, including recognition as a leader in enterprise AI adoption.

As you advance along the AI maturity curve at your organization, keep these essential ingredients in mind:

  1. Executive sponsorship and governance
  2. Responsible AI by design
  3. Data foundations, architecture reviews, and technical readiness
  4. Talent, skills, and culture
  5. Impact tracking and accountability
  6. Change management and communication
  7. Continuous improvement, innovation, and partnerships

It’s important to remember that these elements aren’t static, but iterative. You’ll need to continue to evolve them over time as your enterprise AI transformation continues. But the five stages of enterprise AI maturity we’ve outlined in this chapter form an overarching framework to keep you moving forward.

Learning from our agent implementation experience

Invest in data infrastructure and AI platforms

Building robust data infrastructure ensures your organization is prepared to leverage AI, supporting scalable, innovative, and secure AI-driven solutions.

Foster a culture of innovation and collaboration

Champion an AI-forward culture where innovation and collaboration drive the adoption of agentic AI.

Align AI initiatives with strategic business goals

Ensuring AI initiatives align with business goals maximizes impact and positions your organization to succeed in the rapidly evolving world of agentic AI.

Implement ethical practices based on our responsible AI principles

Adopting ethical AI practices builds trust, ensures responsible innovation, and prepares your organization to navigate the evolving landscape as AI becomes central to business operations and decision-making.

Position IT to facilitate the transition to a Frontier Firm

At a minimum, your IT leaders and practitioners need to prepare your data estate for agentic workloads, partner to identify and enable prioritized business scenarios, and then actively participate in enterprise transformation through skilling, change management, and measurement activities.

Evolve your enterprise IT infrastructure to embrace dynamic and adaptive agent-based systems

Moving from traditional deterministic systems to agentic systems that introduce probabilistic behaviors, autonomous decision-making, and continuous learning requires new architectural thinking, audit capabilities, and governance models.

Key takeaways

Here are some key tips for implementing agents at your organization, based on what we’ve learned through our own experience here at Microsoft:

  • Align agent efforts with business priorities: Partner with leadership to establish clear business priorities that guide agent adoption and investment.
  • Define success and how you’ll measure it: Determine business goals and metrics of success that allow you to track impact and value over time.
  • Put the right governance structures in place: Establish steering committees across implementation, data, responsible AI, and continuous improvement to guide decision-making.
  • Start with early adopters and focused pilots: Identify enthusiastic users and promising pilot programs to validate value and refine your approach.
  • Scale what works across the enterprise: Determine which initiatives deliver the greatest value and are ready for broader, enterprise-wide adoption.
  • Support change through targeted skilling and enablement: Develop skilling and change management strategies that address the needs of both technical and nontechnical employees.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 3: Driving adoption to capture value across the organization

Readying our workforce for the agentic future through targeted enablement, skilling, and cross-company collaboration

Change management is an important part of our AI maturity journey. All the technical readiness in the world means nothing if we don’t build a transformative culture. The spectrum of agents, use cases, and creation methods is wide, but enabling them all requires one thing: an AI-first mindset.

“An important part of agentic adoption is telling stories to help people understand where AI’s value comes alive or why they should build agents. Examples from peers and real-world use cases are two of our most effective methods for getting people into the AI-first mindset.”

Driving adoption for agents represents a fundamental shift from an AI assistant like Microsoft 365 Copilot, which delivers a comparable experience for every employee. With the agentic mindset, the point is for individuals to be selective about the agents they choose to use—and more significantly, the agents they choose to create.

We also structure our enablement efforts to channel employees into different behaviors based on what’s available and what they might need to build:

  • First, we enable employees to discover and use agents that are already published and available.
  • If an agent that serves their use case doesn’t exist, employees can build their own, starting with simple no-code agents.
  • For complex agents, we channel employees, teams, and lines of business into using Copilot Studio and other, more full-featured pro-code tools.

Regardless of the behavior we’re trying to enable, we follow a four-phase strategy that takes inspiration from Prosci’s ADKAR model, which progresses through awareness, desire, knowledge, ability, and reinforcement. Our adoption efforts align with the Microsoft Engagement Framework, which we’ve developed specially for driving adoption of our products. You can learn more about our overarching approach in our Microsoft 365 Copilot readiness guide.

“An important part of agentic adoption is telling stories to help people understand where AI’s value comes alive or why they should build agents,” says Amy Rosenkranz, a principal product manager on the Copilot Extensibility team within Microsoft Digital. “Examples from peers and real-world use cases are two of our most effective methods for getting people into the AI-first mindset.”

We’re applying several tried-and-tested change management techniques to our organization-wide adoption efforts. These are relevant to both non-developer employees who want to create simple agents and professional developers working on tools for their teams, lines of business, and the entire enterprise.

Cohort-based coordination

We divide our adoption campaigns along two pivots: Internal organizations like legal or sales and marketing, and regions like North America or Europe. Different cohorts have different focuses, but the strategy is similar. Our company-wide adoption leads spearhead our efforts, and we identify members of target cohorts who can support the adoption, including change managers, leadership sponsors, and employee champions.

Adoption communications

We treat internal communications as a primary driver of agent adoption and creation, not just a distribution channel for training. Our initial communications focused on building confidence, reducing fear, and reinforcing clear norms for responsible agent building. We used consistent messaging across leadership communications, learning content, and employee channels to normalize experimentation and help employees understand when to create an agent, when to reuse one, and where to go for guidance.

AI Agent Launchpad

During our deployment of Microsoft 365 Copilot, we experimented with event-driven skilling in the form of Camp Copilot and Copilot Expo. Now, we’ve adapted these kinds of skilling events to agents as well. AI Agent Launchpad takes employees on a learning path through five modules to help them discover, use, and build agents confidently:

  1. AI mindset in motion: Employees learn about the concept of the Frontier Firm.
  2. Introduction to agents: This module covers the basic principles and definitions of AI agents to establish a foundation of understanding for agent creation and usage.
  3. Explore existing agents: Participants build the new habit of discovering available agents to see if any existing tools meet their needs.
  4. Build agents with ease: Employees polish their agent building skills in Copilot Chat and SharePoint with an expert in a hands-on lab environment.
  5. Build with Copilot Studio: This module goes deeper into designing, connecting, testing, and publishing more powerful agents.

Each module features self-learning readiness, live sessions, gamification, and Credly badges. Instead of a global, centralized event, we’ve modularized the experience so local or organization-level leaders can adapt it to their particular cohort’s needs, while still providing support from centralized adoption leads. We’ve also created a freely available resource organizations can use to plan and run their own virtual skilling events around AI adoption.

Copilot builder champs

Our initial AI rollout showed us first-hand the power of peer leadership in driving adoption, so we adapted the strategy behind our highly successful Copilot Champs Community into our Copilot builder champs program. This initiative makes use of peer connections, success stories, and a Viva Engage community, and we refocused it on enabling employees to create the agentic solutions they need.

These champions represent some of our strongest adoption evangelists on their respective teams. We also created a Microsoft SharePoint hub with resources, best practices, agent publishing information, and more.

Integration and incentivization

We collaborate with managers to integrate AI into their teams’ routines. Often, we’ll use mini-challenges or gamification strategies to encourage agent usage. We recognize top contributors with shout-outs or small awards. We’ve also found that it makes these efforts more engaging to blend work tasks with personal interests.

Formalizing change management for professional developers

We apply more focused adoption initiatives for the professional developers who create team, line-of-business, and enterprise agents. Because their efforts are reimagining how work gets done across the organization, we need to ensure these agents are aligned with business goals, built securely and responsibly, and drive the impact the company needs. The process unfolds across five steps.

1. Driving product adoption

This step echoes our broader adoption initiatives. We cultivate leadership alignment and sponsorship, comprehensive communication plans, training and upskilling programs, champion-led peer support, and integration into daily work with incentives.

2. Agent ideation and development

Here, we capture high-value use cases by mapping out processes and pain points we could improve with agents. Then we prioritize and select pilots and empower small interdisciplinary teams to build, test, and refine those agents.

3. Agent discovery and advocacy

Once we’ve completed our pilot programs, we identify the agents with the most potential impact, broaden their development, establish a catalog for observability and discoverability, and showcase success stories.

4. Workforce transformation

At this point, we’re ready to map workflows for human-AI optimization, capture scenarios that are especially useful for key roles, commit to wider AI skills training, develop our workforce into “agent bosses,” and work to measure and communicate impact.

5. Feedback and listening

Tracking the impact of your efforts is crucial. We established a feedback loop to drive further success through telemetry and analytics, employee feedback, and insights from our support channels and FAQs. Then we analyze and triage those insights and close the loop with users by communicating how their feedback drives change.

Whatever your goals and whichever segment of your workforce you target, it’s important to understand that adoption doesn’t happen by accident. True workforce transformation won’t take place without appropriate adoption activities.

As you launch your own adoption initiatives, consider who your audience is, what they need to build confidence and competence, and how you can unlock agentic value for them across your organization.

Learning from our agent adoption experience

Be thoughtful about your audience

Vary your efforts between non-developer and developer audiences, different geographies and internal organizations, and specific goals. Put together a methodology for thinking about what agents you want and what benefits they’ll provide, then determine who the best builder is.

Don’t just enable agents—empower the enterprise

Your goal isn’t just to activate agents for agents’ sake. Think carefully about what workflows and value you’re trying to unlock, and how agents can get you there. Break down aspects of roles and workflows, and see how agents fit in.

Establish multiple vectors for skilling

Different modalities work for different employees. Use every tool at your disposal, from live events to peer leadership to self-guided learning, and communicate them across all available channels.

In many ways, this is a reset

Your employees may have just become comfortable with Copilot, and agents might feel like a whole new horizon. That’s true. Have patience and understand that this is an entirely separate adoption path.

Showcase and celebrate success

People need to see value and possibilities for agents in their own work. When pilots or personal agents create results, socialize them widely and encourage employees to try them out. Nothing encourages experimentation with agents like successful usage.

Leadership sponsorship is absolutely crucial

Leaders both set expectations and bear the standard of your organization’s culture. They can be the figureheads of transformation by setting priorities, participating in communications, and leading by example.

Key takeaways

Here are some important steps to keep in mind as you embark on your own adoption and change management efforts for agents:

  • Establish strong adoption leadership early: Assign a dedicated adoption lead, form a cross-functional adoption team, and align change managers, executive sponsors, and employee champions around clear ownership and cadence.
  • Design adoption around real work and real people: Identify priority cohorts, personas, and usage scenarios, then tailor messaging, enablement, and communications to how each group works and learns.
  • Define success before you deploy: Set clear KPIs and success criteria likefeature usage, scenario adoption, and employee sentiment, and put a measurement and feedback plan in place from day one.
  • Enable employees through structured onboarding and learning: Combine readiness communications, live learning, self-service resources, and a centralized enablement asset library to help employees build confidence and momentum.
  • Activate champions and leadership to amplify adoption: Launch champion communities, empower leaders to model usage, and use internal channels to reinforce behaviors and share progress.
  • Continuously listen, learn, and iterate: Gather feedback through surveys and listening sessions, surface success stories, and apply insights to refine adoption, reinforcement, and resistance management plans.
  • Extend and optimize for professional developer teams: Support advanced agent ideation, development, discovery, and advocacy while using ongoing feedback to drive workforce transformation at scale.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 4: Providing support at the agentic frontier

Bolstering agentic transformation through solid groundwork, human oversight, and AI-driven support

With many forms of technology, support is fairly simple. You identify pain points and common issues with a relatively static technology, create self-service tools to help users with those challenges, and make subject matter experts available in the form of a dedicated support team.

But AI is evolving too quickly for that model, and agents are too diverse and individualized for a static approach. As a result, our support apparatus for agents needs to be much more flexible. Within Microsoft Digital, our goal is to make it easy for employees to engage with agentic tools freely and adaptably while maintaining safety and responsibility.

The path to this objective relies on a three-pronged approach to governance:

  • Embedded governance functionality: The ideal state is that our agent creation and publishing tools should incorporate good guidance, governance, and guardrails out of the box so the agents people create are essentially self-governing.
  • IT oversight: This is a new space and a new way of working, so it isn’t feasible for all agents to self-govern at this point. As an IT organization, Microsoft Digital fills gaps in governance through reviews and oversight. We do this by establishing risk-based policies around types of agents, exposure and sharing, and other pivots we addressed in our governance chapter.
  • User education: It’s almost impossible to predict every governance gap and need, so educating our users helps them avoid accidentally stepping out of bounds. Our Agents at Microsoft team and change managers are the linchpins of these efforts, and employees can lean on resources like Microsoft Learn courses and the Agent Builders SharePoint hub.

Of course, we do have a support team of AI subject matter experts available to employees for any questions they can’t answer themselves. Our HelpDesk support team operates independently from other enablement vehicles, but human support representatives can only accomplish so much. It’s important not to create bottlenecks by relying on conventional support. After all, the promise of AI is to reduce the burden on humans, and that’s no different for our support teams.

A photo of Sydorchuk.

“On our journey to Frontier Firm, we’re working really hard to accelerate processes and remove roadblocks so people can get to value much faster. This is crucial for agentic scenarios because we’re using these iterations to polish and improve the tools we create.”

AI itself is becoming a cornerstone solution for this challenge. An AI-driven approach aligns with the idea of the Frontier Firm, where humans lead and agents operate, in this case by supporting other humans as they explore AI more deeply.

This is a relatively new approach, but we’re already using agents to provide support in several ways:

  • We operate an agent called Ask MICA (Microsoft Intelligent Compliance Agent). This tool provides information and support for compliance issues.
  • Agents help us evaluate the risk profiles of other agents. Automating risk assessment accelerates publishing by minimizing human reviews or questions to support specialists.
  • We use an agent to perform checks against standards for responsible AI, security, privacy, and access to sensitive information.
  • We’re also partnering with our product groups to develop automated agent-building enablers and accelerators that can support ideation and evaluation for new ideas instead of relying on groups like the AI CoE to step in for that kind of support.

In reimagining the support experience this way, we’re focused on maximizing efficiency so that humans remain in the loop, but only for edge cases where AI can’t help. That’s the best use of their time and unique human talent. Meanwhile, we’re continuing to develop and implement agents to support employees for increasing numbers of non-edge cases.

Continuous improvement practices help propel this work forward. Much of that work comes from targeted conversations around pain points. For example, an agent builder might share that it’s taking too long to get security reviews for their projects. To us, that signifies that a security review agent may be useful.

“On our journey to Frontier Firm, we’re working really hard to accelerate processes and remove roadblocks so people can get to value much faster,” says Mykhailo Sydorchuk, a Customer Zero lead for Microsoft 365 integrated experiences at Microsoft Digital. “This is crucial for agentic scenarios because we’re using these iterations to polish and improve the tools we create.”

It’s important to remember that humans will always need to be involved in supporting other humans. But the more assistance agents can provide your support specialists, the more they can focus on tasks that absolutely require human attention. As you consider where AI might fit into your support efforts, our journey can shed some light on the possibilities agents represent.

Learning from our experience with providing support around agents

Emphasize proven agents to minimize the need for support

If you’ve built dedicated first-party agents within your organization, encourage employees to favor those through internal communications. They’re less likely to require support in the first place.

Identify opportunities for AI-driven support

Listen to employees’ pain points and concerns. Recurring themes and issues probably mean there’s an opportunity for agentic support.

Meld adoption and support

Education and skilling initiatives build employee competency to minimize their need for support. If people understand standard use cases thoroughly or know where they can find the right information, they’re more likely to reach out to support specialists only on real edge cases.

Backstop support as much as possible

Microsoft is working to make our tools as self-service as possible. Where gaps appear for your organization’s specific use cases, fill those with IT backstops and employee enablement resources. Hopefully, your support team can be your final resort.

Key takeaways

Here are some key things to remember as you develop your support plan for agents at your company:

  • Build agent expertise within support teams early: Provide targeted training, skilling, and early access so support teams can become trusted agent subject matter experts.
  • Reduce support demand through proactive enablement: Identify IT backstops and employee enablement opportunities that prevent common issues before they require support intervention.
  • Operationalize agentic support at scale: Identify recurring issues across non-developers and professional developers, select high-value opportunities for agentic support, build and test support agents, and actively promote them to drive adoption.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 5: Tracking the impact of your agents

Building the apparatus for effective measurement to ensure our agentic ecosystem drives business value

Effective governance, implementation, adoption, and support don’t mean anything if your agents aren’t driving the impact your organization wants. But how do you understand that impact if you can’t track and measure it? And what should your measurement criteria be?

Within Microsoft Digital and the company’s leadership team, we’re currently thinking through these ideas to ensure we’re capturing all the value agents have to offer. We’re still developing our approach, but the questions we’ve asked and our measurement parameters will be helpful to consider as you track your own agents’ impact.

First, there’s a difference between tracking agent volume, agent usage, and agent value. Employees creating massive numbers of agents that never get used don’t drive impact. Agent usage is closer to the mark, and it can be a good indicator of which tools are meaningful to employees or might deserve potential promotion for use throughout your organization. Still, usage doesn’t necessarily correlate to business value.

To really articulate value, you need to dive into the specifics of what you intend your agents to do. There are several dimensions to consider:

  • Types of agents: First-party enterprise agents, third-party agents, line-of-business or team-based tools and individually created agents all have different purposes and capabilities. They need different measurement strategies.
  • Personas: Who is creating the agent, and what are their maturity and needs? What value does a user get compared with a developer or administrator? There’s also team versus individual value. For teams, we tend to measure impact in terms of workflows automated or pain points relieved. For individual users, it’s all about satisfaction, productivity, quality, and efficiency gains.
  • Data: Different agents access varying degrees of data. How do you assess the ways they provide access and deliver insights?
  • Creation versus discovery and usage: We want to encourage both agent creation when it meets a unique need and agent discovery when a useful agent already exists. Each requires its own measurement parameters.

Our roadmap to agentic impact tracking

We aren’t starting from scratch when it comes to tracking agentic impact. Our Continuous Improvement CoE has already done extensive work aligning targeted and sanctioned AI initiatives with greater business value and tracking them over time. The concept is based on defining top-level value, cascading that value into operational drivers that deliver results, creating action plans and delivering AI solutions to achieve those goals, and then tracking them over time.

We’re currently progressing along a roadmap to a more holistic impact tracking methodology we can use to identify, consolidate, and build agent analytics for all makers, developers, administrators, and Microsoft Digital teams. As time goes on, this approach will accelerate product improvements, improve the builder experience, and cater to reporting and analysis requirements.

Our journey has three main goals:

  1. Authoritative, clean, deduplicated data
  2. A baseline for creation and usage, and well-defined key performance indicator (KPI) targets
  3. Advanced insights to accelerate the agentic ecosystem at Microsoft

In service of these goals, we’re progressing through a five-phase process:

Our five steps for setting up our agent analytics: Set requirements, partner with product teams, establish methodologies, set KPIs, and report and analyze findings.
We’re currently in phases three and four of our five-phase plan for holistic agentic analytics methodology.

As this methodological structure for tracking agentic impact has come together, we’ve used various tools to help us gain visibility. These include Viva Insights, Microsoft 365 admin center, and an internally built declarative agent tracker, with visibility typically provided by Microsoft Power BI. With the release of Microsoft Agent 365, now available through the Frontier program, we’ve gained a more streamlined vehicle for observability and telemetry.

Three feature sets will be especially useful for tracking value:

  • Registry provides a complete view of agents to give us maximum visibility and trackability across our entire agentic ecosystem.
  • Visualization includes measurement features to track agent performance, speed, and quality so we can assess ROI and make informed deployment decisions.
  • Interoperability ensures we can connect to an open ecosystem of both Microsoft and partner tools.

As Customer Zero for Agent 365, we’re excited to have a platform for observability and telemetry that encompasses everything from agentic creation through usage.

We plan to use the following capabilities to improve the overall ecosystem:

  • Filtering our agent inventory on specific criteria like the type of agent or how it was built
  • Enhancing governance-specific actions we can take with agents in areas like ownership and quarantining
  • Gaining visibility into trends like agent usage
  • Ingesting agent blueprints and defining policy templates

We’re still in the midst of our agentic measurement journey at Microsoft, but the blueprint for tracking already exists. Your organization may be in the early stages of agent readiness and deployment. If that’s the case, it will be helpful for you to internalize the lessons we’ve learned as Customer Zero and apply them as early as possible in your own journey to AI maturity.

Learning from our approach to tracking agentic impact

Think proactively, not retroactively

If you put effort into tracking agentic impact early in your AI maturity journey, you’ll be poised to start capturing insights immediately instead of applying your methodology after the fact.

Involve a wide array of stakeholders

This workstream needs oversight from different kinds of stakeholders, including your leadership team, IT, Microsoft 365 administrators, agent developers and builds, and employee champions. That will provide the sponsorship, expertise, and perspective you need for success.

Establish a continuum of value

Agents need to tie into real business goals, so it’s important to establish metrics that actually speak to those objectives. Cascade business goals to concrete KPIs with well-defined timelines and track those diligently.

Embrace the red

Try to think of underperformance not as failure, but as data. Performance data over time helps you course correct or pivot, making sure you invest where it matters.

Key takeaways

Here are some tips as you develop a strategy for measuring the impact of agents at your organization:

  • Assemble a cross-functional analytics and adoption team: Bring leadership, IT, Microsoft 365 administrators, agent builders, and employee champions together to ensure shared ownership and accountability.
  • Clarify analytics and insight requirements up front: Identify, source, and clearly articulate the data and insights needed to measure agent adoption and impact.
  • Build an analytics foundation and iterate over time: Consolidate data sources, establish baselines, and develop initial analytics that can evolve as usage grows.
  • Define and standardize agent KPIs: Finalize a clear, consistent set of metrics aligned to business outcomes and adoption goals.
  • Turn insights into action through reporting: Apply analytics and reporting to inform decisions, optimize adoption efforts, and drive continuous improvement.

Learn more

How we did it at Microsoft

Further guidance for you

Applying lessons from our agent deployment at your organization

You’ve learned from our AI maturity journey. It’s time to get started on yours.

Becoming a Frontier Firm might seem daunting. But the agent-building and agent-adoption practices we’ve articulated in this guide can help you gradually and thoughtfully progress toward a new organizational blueprint, one that blends machine intelligence with human judgment. It can help you build systems that are AI-operated but human-led.

By capitalizing on the lessons we’ve learned during our internal deployment, you can both speed up the process of building and deploying agents at your company while avoiding frustrating pitfalls. If you anchor your work in careful planning and use the steps and resources we’ve provided here, you’ll be on the path toward true business transformation through agentic workflows.

A photo of Alaparthi.

“Embracing AI transformation is an opportunity for IT leaders to take part in defining the future of their organizations. Our role as technical professionals has never been more revolutionary, and our team can support yours as you reimagine workflows to make AI part of your everyday reality.”

You’re not in this alone. If you’re looking for support or knowledge on any aspect of your deployment, reach out to our customer success team.

“Embracing AI transformation is an opportunity for IT leaders to take part in defining the future of their organizations,” says Vijaya Alaparthi, a principal group product manager at Microsoft Digital. “Our role as technical professionals has never been more revolutionary, and our team can support yours as you reimagine workflows to make AI part of your everyday reality.”

Frontier opportunities are present across every aspect of your organization today. Partner with us and take your first steps toward this exciting agentic future.

Key takeaways

This guide captures what we’ve learned as we’ve deployed agents across our entire global organization. Here are the key things to remember as your company moves from early AI adoption to a large and thriving agentic ecosystem:

  • Advance governance early: Establish a strong and trusted data foundation that includes labeling, protections, and a risk-based governance model before enabling broad agent creation. Establishing your governance foundations for Microsoft 365 provides the confidence to open up Copilot without hiding data. Clear guardrails, differentiated oversight, and lifecycle management help ensure safe innovation without sprawl.
  • Follow a maturity roadmap: Use an escalating AI maturity model that progresses from awareness to enterprise-wide adoption and agentic transformation to sequence your rollout. This staged approach aligns AI investments with business goals while building the culture, skills, and infrastructure you need to scale.
  • Drive targeted adoption: Treat agent adoption as its own transformation journey, distinct from assistant-based tools like Microsoft 365 Copilot. Cohort-driven skilling, champion communities, localized learning, and leader-led communications accelerate confidence and empower both makers and users.
  • Empower builders at all levels: Support no-code creators and professional developers with tailored enablement, clear publishing workflows, and accessible resources. This ensures individuals can create personal agents while teams can safely build enterprise-grade tools that unlock high-value scenarios.
  • Reimagine support with AI: Blend embedded governance, flexible IT backstops, and AI-driven support agents to reduce friction and scale help resources. As employees experiment with agents, automated checks, accelerators, and intelligent support tools keep humans focused on true edge cases.
  • Track impact holistically: Distinguish between agent creation, usage, and value by establishing KPIs that map directly to real business outcomes. A unified telemetry and observability layer powered by tools like Microsoft Agent 365 enables clear measurement, optimization, and proof of return on investment.
  • Continuously evolve toward becoming a Frontier Firm: Advance your culture, architecture, governance, and workforce practices iteratively as agentic capabilities grow. By combining human judgment with autonomous agentic operations, your organization can unlock transformational efficiency, innovation, and scale.

Learn more

How we did it at Microsoft

Further guidance for you

Try it out

Get started with Microsoft Agent 365 at your company.

The post Becoming a Frontier Firm: A guide for deploying AI agents based on our experience at Microsoft appeared first on Inside Track Blog.

]]>
22868
Transforming the marketing function at Microsoft with AI http://approjects.co.za/?big=insidetrack/blog/transforming-the-marketing-function-at-microsoft-with-ai/ Thu, 16 Apr 2026 14:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23127 The AI revolution is reaching everyone. As AI agents become more mainstream, we’ve seen the powerful impact they can have on all kinds of work and a wide variety of roles. At Microsoft, we’re leading the way in exploring how workers can use AI agents to help them save time, automate workflows, and amplify human […]

The post Transforming the marketing function at Microsoft with AI appeared first on Inside Track Blog.

]]>
The AI revolution is reaching everyone. As AI agents become more mainstream, we’ve seen the powerful impact they can have on all kinds of work and a wide variety of roles.

At Microsoft, we’re leading the way in exploring how workers can use AI agents to help them save time, automate workflows, and amplify human impact. It’s all part of our journey to becoming an AI-first Frontier Firm.

As part of this AI transformation, the Microsoft Azure AI marketing team is modernizing its work through intelligence on tap. Together with a group of Microsoft Foundry developers, the team has been using Foundry to create agent-based tools that are changing the way the marketers work and accelerating their impact.

Microsoft Foundry is our unified, enterprise‑grade Azure platform for building, deploying, and governing AI models and agents—bringing development, operations, security, and governance together in one place.

Marketing: Human challenges, AI opportunities

Marketers today face a challenging work landscape. They’re responsible for reaching diverse and dynamic audiences, adjusting to rapidly shifting market conditions, and promoting ever-expanding product portfolios with tight branding and messaging control—all under intense time pressure at an escalating scale.

At Microsoft, our marketing organization is no exception. It has experienced a 40% year-over-year increase in product launches. This job function is also highly multi-disciplinary, with many marketing professionals wearing different hats and adapting to new capabilities, often involving an array of disparate tools.

It can be an overwhelming space, which makes it easy to overlook outdated content and terminology, produce incomplete materials, or misalign messaging. All of that pressure doesn’t just lead to poor performance, but also employee burnout. It’s not surprising that plenty of marketers feel overtaxed.

“Frontier marketing is about helping our team navigate the AI transition to thrive in their roles. Contrary to people’s fears about AI, this technology is tremendously helpful for amplifying marketers’ ability to connect products and services to their audiences.”

Don Scott, general manager, Azure AI Marketing

Leaders on our Azure AI marketing team recognized these challenges, so they started exploring ways that AI could make their workers’ jobs easier. Two new AI-driven projects have come out of this effort:

  • MarThrive: A marketing platform featuring a suite of complementary agents and grounded data designed to improve blog quality, assist with product launches, and deliver competitive intelligence on demand.
  • AI Messaging Assistant: A generative AI application grounded in 100,000-plus proprietary customer voices that embeds this intelligence directly into marketing workflows, influencing business decisions in real time.

These tools benefit from the power of AI agents while keeping human creativity firmly at the center of our marketers’ work. Both represent function-aligned agentic design aimed specifically to meet the needs of our marketing team.

These aren’t generic AI platforms. They’re tools built by marketers, for marketers. And they’re a big part of equipping our marketing team to embrace the world of the Frontier Firm.

Frontier marketing is about helping our team navigate the AI transition to thrive in their roles,” says Don Scott, general manager for Azure AI Marketing. “Contrary to people’s fears about AI, this technology is tremendously helpful for amplifying marketers’ ability to connect products and services to their audiences.”

But these capabilities don’t happen by accident. Before either tool could come to fruition, we first needed to ensure we had a tightly unified, AI-ready marketing data ecosystem.

“If you feed your agents the right data, they’ll be so much more useful,” says Brett Mills-Meiner, a director of AI intake and platform strategy for Microsoft Foundry. “Agent development isn’t the hard part—it’s getting the data in the right place.”

MarThrive: An agentic toolkit built for marketers

After a months-long effort to build secure, scalable integrations across core systems, the marketing team had an agentic toolkit they could use to accelerate product launches. They dubbed it MarThrive.

The creation process relied on a strong strategic vision and close alignment between marketers and AI agent developers.

A photo of Mills-Meiner.

“AI allows the people who do the work to be a lot closer to the technology they’re using.”

Brett Mills-Meiner, director of AI intake and platform strategy, Microsoft Foundry

The process for developing MarThrive started with getting a handle on the tasks and human needs that AI can fulfill. In many ways, the platform acted as an internal proving ground for agentic patterns by making use of Microsoft Foundry’s platform capabilities.

It was also a way to establish closer collaboration between employees who have specific business needs and Microsoft Foundry developers who can build more complex agents.

“We knew we wanted to use Microsoft Foundry to empower our own organization,” Mills-Meiner says. “AI allows the people who do the work to be a lot closer to the technology they’re using.”

The Azure AI marketing team began by establishing what it wanted to accomplish, the ideal capabilities for the necessary tools, and what their functional requirements would be. One major step was defining the specifications and workflows the tool needed to support. Another was getting the live data connections set up, which helped them properly contextualize and ground the agents (with FoundryIQ playing a big role in getting the most from the organizational data).

The main goal was to improve the consistency of the many blogs and messaging surfaces the team oversees, while also minimizing the need for review. From there, it was a matter of experimenting with how individual agents could accomplish those goals.

The results were astounding, as the tool enabled a small team to generate a host of agents on a very tight timeline. In just three weeks, the agent-builder team created 12 agents and released them over 12 days: Azure AI marketing’s so-called “12 Days of Shipmas.” The agents covered a wide variety of functions, as shown here:

  • Blog Tree Explorer
  • Edit Suggester
  • Voice Profiler
  • Social Copy Generator
  • Calibration Studio
  • Field Alert Generator
  • Blog Q&A
  • Microsoft Learn Docs Quality Tester
  • Launch Readiness
  • Shipmas Agent
  • Blog Draft Writer
  • BOM Generator

MarThrive users in action

Sharmila Chockalingam and Jenn Cockrell are both senior product marketing managers on the Microsoft Foundry team. The agents they access through MarThrive have become instrumental to their work and productivity.

A photo of Chockalingam.

“We typically don’t get all the information about a model until a few days before its launch on Foundry; the MarThrive tool has made rapid iteration and review possible.”

Sharmila Chockalingam, product marketing director, Microsoft Foundry Models

One of Chockalingam’s greatest challenges has been working with partner contributors to launch third-party models as they get added to Foundry. Model releases vary in scope, so they require a spectrum of marketing assets like blog posts, social copy, pitch decks, sizzle videos, product demos, and FAQs.

For Chockalingam, MarThrive provides the greatest value through the Social Copy Generator and Edit Suggester. These agents help her get incoming copy from model partners into consistent shape quickly. Meanwhile, the BOM Generator agent helps her team rapidly spool up full complements of assets to support launches properly.

“On one of our major, late-breaking model launches, MarThrive really proved how crucial it could be,” Chockalingam says. “We typically don’t get all the information about a model until a few days before its launch on Foundry; the MarThrive tool has made rapid iteration and review possible.”

One of Cockrell’s areas of responsibility is managing one of our Tech Community blogs. This blog relies heavily on multiple internal and community contributors, so it can be a challenge to review output and ensure quality at scale.

A photo of Cockrell.

“The main benefit is the single pane of glass that gives marketers access to the agents they need.”

Jenn Cockrell, senior product marketing manager, Microsoft Foundry

The Blog Grader agent provides an initial scrub of a contributor’s work, giving immediate feedback and a grade for aspects like technical depth and visuals. From there, Cockrell can provide contributors with specific, actionable feedback so they can improve their submissions.

At a more strategic level, the Blog Tree Explorer helps her position different blog posts within our overall approach to content. It also gives her team the comprehensive visibility it needs to establish baseline standards around branding, quality, and best practices.

“MarThrive really only rolled out in December of last year, and we’ve already seen immediate value and better output, as well as improvements to the AI tool,” Cockrell says. “The main benefit is the single pane of glass that gives marketers access to the agents they need.”

To keep our blog quality standards fresh and evolving, the team uses an agent that connects to the rest of the MarThrive ecosystem: Calibration Studio.

When a blog post performs particularly well, the team works with this agent to apply its learnings to other tools like the Edit Suggester and Blog Grader. This produces a multi-agent workflow that relies on human judgment to make adjustments that align with our priorities as a business.

Thanks to these tools, the team has seen the conventional product marketing cycle shrink from 18 months to as low as 18 hours. We’ve also boosted our blog post engagement metrics by 10–12 points.

On the popular Microsoft Tech Community site, publishing a blog post used to involve at least a week of reviews and communication back-and-forth between the author and our marketers. With an average of 250 posts a year by our marketing team, that was no small commitment.

Today, writers submit their work, and a product marketing manager can run the draft through the Blog Grader agent. If their post gets a high enough score, the marketer will proceed with publication. That translates to at least four hours of time saved per post for our product marketing managers.

The overall result is a substantial reduction in human effort while quality improves, velocity increases, and our marketers can spend more time on strategy and big-picture guidance.

The AI Messaging Assistant: An audience marketing ally

As the discipline of marketing has modernized, the possibilities for reaching highly tailored and targeted segments have only increased. But to be truly effective, this requires greater granularity and deeper insights, all in the context of accelerating market changes. That analysis takes time—time that marketers don’t usually have.

With that pressure in mind, the Azure AI market research team set out to augment its ability to flow audience insights directly into their work. The result was the AI Messaging Assistant.

At the outset of this project, there were questions about whether to use Microsoft Copilot Studio or Microsoft Foundry to create the AI Messaging Assistant tool. The team eventually decided that Foundry offered the end-to-end capabilities it needed—from building, deploying, and governing the agent to iterating and updating it as time went on.

Research is a very specific discipline, so creating this tool relied on close collaboration between the Microsoft Foundry team, data scientists, and researchers. The core goal was to help the research team scale their skills by extending their work through AI agents.

In defining the solution, the teams mapped the process from research to marketing output, identifying processes that often get left by the wayside in day-to-day workflows because of time pressure and resourcing.

The AI Messaging Assistant was built to bridge those gaps. It accesses our rich store of customer intelligence and builds models on top of it, then applies that data to produce outputs grounded in what real audiences actually think, feel, and prioritize.

Marketers select their audience and parameters and the tool generates or refines content accordingly, including messaging, naming, and feature prioritization. Because every output is rooted in real customer intelligence, the result is marketing content that is more personalized, engaging, and relevant to the audiences that matter most.

A photo of Graves.

“As the speed of marketing increases, the AI Messaging Assistant makes sure we can still represent the voice of the customer. We’re closing the gap between marketer intent and marketing output.”

Robert Graves, senior director, Data Management and Science

A simple user interface was crucial to keeping the process streamlined. Users access the AI Messaging Assistant through an easy-to-manage web portal, then select from 12 different audiences. Examples include gamers and Microsoft 365 users on the consumer side, or IT decision-makers and developers in the commercial space.

Then the user chooses a pre-made output type to guide their messaging. While marketers mostly use the tool for last-mile naming and messaging support, researchers have more flexibility to pore over data through a blank workbook.

The AMA user interface, displaying the various outputs available to users.
The AI Messaging Assistant gives marketers access to research insights and generates flexible outputs, helping marketers understand their audiences and tailor messaging more quickly and effectively.

The AI Messaging Assistant is not designed to replace humans. Instead, it expands what our human researchers and marketers can do, extending customer intelligence into decisions and moments that would otherwise be out of reach. The process remains human-led. Marketers set the parameters, assess the output, and make the final decisions before deploying.

“A lot of use cases are things we normally wouldn’t have time to research,” says Robert Graves, senior director with Data Management and Science. “As the speed of marketing increases, the AI Messaging Assistant makes sure we can still represent the voice of the customer. We’re closing the gap between marketer intent and marketing output.”

AI Messaging Assistant user in action

Ben Loeb is a product marketing manager on the Microsoft Edge team. His work focuses on ways we’re bringing AI into the browsing experience.

Perceptions of AI, habits around using it, and even the nature of engaging with the internet all mean that the browser marketplace is in a constant state of change. Agile intelligence is key.

“This is a highly competitive space, so we need to adapt quickly,” Loeb says. “We’re always thinking with an audience lens to create messaging that resonates.”

In the course of Loeb’s day-to-day tasks, he tends to use the AI Messaging Assistant to work with pre-built prompts for research projects he’s conducting and populate them with elements specific to a particular initiative. Typically, he’ll specify the product he’s working on, identify the perceptions or attributes he wants to work with, and give the agent the context it needs to craft messaging or naming. He’ll then test the outputs against different audiences, like IT decision makers versus employee users.

A photo of Loeb.

“Now we don’t feel like we have to make a trade-off between research and velocity.”

Ben Loeb, product marketing manager, Microsoft Edge

For example, he might suggest that a feature name needs to combine the concept of innovation with objective descriptions of its functionality. The AI Messaging Assistant will deliver options based on the parameters he provides, and he can then take those suggestions through the final, human mile of refining and decision making.

Of course, any product or feature name will still need oversight from our product and branding teams. But the tool provides a starting point grounded in audience insights.

The Microsoft research team is a strategic asset. And like any high-value resource, its impact is greatest when focused on the decisions that most benefit from deep human expertise.

The AI Messaging Assistant expands what’s possible by providing initial intelligence that marketers can act on with confidence, backed by data rather than instinct alone. Teams no longer have to be selective about where customer voice enters the conversation—the tool ensures it’s present across a much broader range of decisions.

The immediate outcome for Loeb and his peers is that they save time and increase output, all while operating with greater confidence.

“Now we don’t feel like we have to make a trade-off between research and velocity,” Loeb says.

The impact has been quite dramatic. Thanks to the AI Messaging Assistant, message testing cycles have accelerated by up to 90%. We estimate the tool has generated at least $10 million in value to date; in one Windows 11 campaign, AI Messaging Assistant marketing enhancements contributed to sales that were 25% above target.

From a confidence standpoint, it’s clear that the Azure AI marketing team trusts and values this tool. So far, the AI Messaging Assistant has informed more than 250 significant business decisions.

Exploring opportunities for AI across the enterprise

The benefits of AI-driven tools like MarThrive and the AI Messaging Assistant aren’t unique to Microsoft. Our experience is just one part of a new approach to work, one where anyone can build the agents they need to make their jobs and lives easier.

This is true whether it’s simple agents that employees create through Copilot Studio Agent Builder or more advanced tools tailored to lines of business, created in partnership with professional developers using Copilot Studio or Microsoft Foundry. It’s clear there are opportunities everywhere for highly personalized, human-centered workflow reinvention.

With the right data foundations, a responsible outlook, a focus on human problems, and a process of experimentation and iteration, you can follow in our footsteps to seek out frontier transformation.

It’s important to note that in the case of both MarThrive and the AI Messaging Assistant, the end product isn’t static. Keeping these tools relevant and effective relies on regular evaluation, feedback loops, and continual calibration to ensure consistent quality.

“What we’ve discovered as we’ve enabled different disciplines to create agents is that there’s tremendous innovation waiting in all of these pockets,” Scott says.

Ultimately, these tools are about reducing cognitive load, not adding process. They’re about helping marketers thrive, not replacing them. And by accomplishing those goals, we’re driving greater impact in marketing: improved quality signals, more consistent application of standards, the ability for small teams to have an outsized impact, and faster experimentation without sacrificing trust.

Key takeaways

If you’re ready to start creating agents that support work in any discipline, consider taking these steps:

  • You can use agents for every function. You may not be part of a technical team, but that doesn’t mean agents don’t have a place in your discipline. With simplified tools for agent creation, it’s important for all different parts of your organization to experiment with these initiatives.
  • Assess challenges before building solutions. Identify problems where AI solutions could apply, then triage those use cases according to the greatest potential impact.
  • These tools need iteration by users to ensure effectiveness. AI tools won’t get things right the first time. You need a good feedback loop to ensure they grow and evolve to fully meet your needs.
  • Agentic tools represent a fundamental change in what humans focus on. Human oversight is the key component of Frontier Firm transformation. Think of the human’s role as creating the notion of what a good outcome will be, identifying the data sources needed to get there, and experimenting with AI solutions.
  • Managing agents will require resources. Consider explicitly creating a role to manage the strategic planning of agent processes: identifying goals, setting targets, and managing feedback and iteration.

The post Transforming the marketing function at Microsoft with AI appeared first on Inside Track Blog.

]]>
23127
Responsible AI: Why it matters and how we’re infusing it into our internal AI projects at Microsoft http://approjects.co.za/?big=insidetrack/blog/responsible-ai-why-it-matters-and-how-were-infusing-it-into-our-internal-ai-projects-at-microsoft/ Thu, 26 Mar 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=19289 Like the computer itself and electricity before it, AI is a transformational technology. It’s providing never-before-seen opportunities to reimagine productivity, address major social challenges, and democratize access to technology and knowledge. As AI reshapes how we work and live, it brings with it both transformative potential and complex challenges. Across the industry, concerns about bias, […]

The post Responsible AI: Why it matters and how we’re infusing it into our internal AI projects at Microsoft appeared first on Inside Track Blog.

]]>
Like the computer itself and electricity before it, AI is a transformational technology. It’s providing never-before-seen opportunities to reimagine productivity, address major social challenges, and democratize access to technology and knowledge.

As AI reshapes how we work and live, it brings with it both transformative potential and complex challenges. Across the industry, concerns about bias, safety, and transparency are growing.

At Microsoft, we believe that realizing AI’s benefits requires a shared commitment to responsibility—one we take seriously. As a result, we aren’t just creating AI solutions. We’re taking the lead on infusing responsible AI principles into our technology and organizational practices.

Prioritizing responsible AI across Microsoft

The most impressive AI-powered capabilities in the world mean nothing if people don’t trust the technology. Microsoft and many of our customers across all industries are working to strike the right balance between innovation and responsibility.

“We’re on a multi-year journey born out of the need to support innovation—and do it in a way that builds trust. Along the way, we’ve continued to iterate and evolve the program through a series of building blocks.”

Mike Jackson, head of AI Governance, Enablement, and Legal, Microsoft Office of Responsible AI

IT leaders and CXOs aren’t just deploying AI tools. They’re also thinking of the right guardrails to implement around those tools as their organizations mature. Meanwhile, developers and deployers want to be sure they’re building and implementing AI solutions within the bounds of responsibility.

As an organization that’s mapping the frontier of AI while creating business-ready tools for our customers, Microsoft is shaping the global conversation on responsible AI. We don’t only accomplish that through policy and governance, but also by embedding responsibility into the ways we build, deploy, and scale AI.

Laying the foundation for this work is the duty of our Office of Responsible AI (ORA). This team brings policy and governance expertise to the responsible AI ecosystem at Microsoft.

“We’re on a multi-year journey born out of the need to support innovation—and do it in a way that builds trust,” says Mike Jackson, head of AI Governance, Enablement, and Legal for the Office of Responsible AI. “Along the way, we’ve continued to iterate and evolve the program through a series of building blocks.”

ORA advances AI development, deployment, and secure and trustworthy innovation through governance, legal expertise, internal practice, public policy, and guidance on sensitive uses and emerging technology. The team focuses on empowering innovation while ensuring it falls within Microsoft’s governance, compliance, and policy guardrails.

ORA also partners closely with product and engineering teams as well as other trust domains like privacy, digital safety, security, and accessibility. The team created our Microsoft Responsible AI Standard, the cornerstone of our governance framework, and ensures internal AI initiatives align with it.

The Responsible AI Standard translates our six principles into actionable requirements for every AI project across Microsoft:

Fairness

AI systems should treat all people equitably. They should allocate opportunities, resources, and information in ways that are fair to the humans who use them.

Privacy and security

AI systems should be secure and respect privacy by design.

Reliability and safety

AI systems should perform reliably and safely, functioning well for people across different use conditions and contexts, including ones they weren’t originally intended for.

Inclusiveness

AI systems should empower and engage everyone, regardless of their background, striving to be inclusive of people of all abilities.

Transparency

AI systems should ensure people correctly understand their capabilities.

Accountability

People should be accountable for AI systems with oversight in place so humans can maintain accountability and remain in control.

ORA reports into the Microsoft Board of Directors and collaborates with stakeholders and teams across the company to operationalize these principles, implementing policies and practices that apply to AI applications. They determined that every AI initiative should undergo an impact assessment to ensure it aligns with the standard.

If ORA is our compass for responsible AI, our companywide Responsible AI Council has its hands on the steering wheel.

The council, led by Chief Technology Officer Kevin Scott and Vice Chair and President Brad Smith, was formed at the senior leadership level as a forum and source of representation across research, policy, and engineering. It provides leadership, strategic guidance, and executive support and sponsorship to advance strategic objectives around innovation and responsible AI.

A photo of Tripathi.

“ORA has established clear principles and a step-by-step assessment framework and tool. Our responsibility is to rigorously follow this process and ensure compliance across our products and initiatives.”

Naval Tripathi, principal engineering manager and co-lead, Microsoft Digital Responsible AI team

Under the council’s guidance, responsible AI CVPs, division leaders, and a network of responsible AI champions across the company operationalize the implementation of our Responsible AI Standard and compliance with our policies.

The structure of these teams is straightforward.

Every division has a designated CVP and division lead to steer the work and connect their team to the overarching Responsible AI Council. Within those divisions, each organization has a lead responsible AI champion or a set of co-leads to steer their team of champions. Those champions act as subject matter experts, reviewers for the impact assessment process, and points of contact for the teams developing AI initiatives.

Implementing AI governance within Microsoft IT

As members of the company’s IT organization, Microsoft Digital’s responsible AI division lead and champion team have a special role to play. They helped develop a critical internal workflow tool, which has now become a mandatory part of our responsible AI assessment process.

“The key is to ensure full alignment of responsible AI practices with ORA,” says Naval Tripathi, principal engineering manager and co-lead for Microsoft Digital’s Responsible AI Team. “ORA has established clear principles and a step-by-step assessment framework and tool. Our responsibility is to rigorously follow this process and ensure compliance across our products and initiatives.”

This tool logs every project, guides AI developers through initial impact assessments all the way to final reviews, and facilitates those workflows for champions.

A photo of Po.

“As organizations develop a diverse ecosystem of AI agents, often created by multiple engineering teams, it becomes essential to establish a standardized evaluation process. This ensures every agent adheres to enterprise-level standards before we deploy and distribute it to end users.”

Thomas Po, senior product manager, Microsoft Digital

By streamlining the process through a unified portal, the tool increases efficiency and minimizes errors that can arise from manual processes. It also encourages teams to make responsible AI part of the software development lifecycle (SDL) itself, not a hurdle or an afterthought.

“As organizations develop a diverse ecosystem of AI agents, often created by multiple engineering teams, it becomes essential to establish a standardized evaluation process,” says Thomas Po, a senior product manager working on Campus Services agents. “This ensures every agent adheres to enterprise-level standards before we deploy and distribute it to end users. That makes it more manageable in the long term, and having it all in one tool gives us more transparency.”

Our unified internal workflow looks like this:

  • Project initiation and system registration: During the design phase for an AI initiative, the engineering team accesses the portal and registers a new AI system. From there, they fill out fields with crucial information, including a title, description, the developer team’s division, whether the project will include internal or external resources, the relevant champion who should review their initiative, and other details. Within this initial form, different scenarios will trigger different review parameters and requirements, for example, when a team intends to publish a tool externally or engage with sensitive use cases.
  • Release assessment: After the system registration is complete, the team initiates the release assessment, a much more thorough review designed to ensure the AI-powered solution is ready to go live. At this point, the engineering team needs to provide detailed documentation. That includes the volume and kinds of data the system will use, potential harms and mitigations, and more. A release assessment includes experts in our Office of Responsible AI, Security, Privacy, and other teams, who review sensitive use cases or initiatives that include generative AI.

If the project clears all the requirements and reviews, it’s ready to go live. Crucially, we don’t think of these stages as a set of hurdles teams need to clear to complete their projects. Instead, the process guides engineering teams through the design elements they need to consider and provides opportunities for feedback from subject matter experts.

“The tool captures all the requirements from ORA and incorporates them into a developer-friendly workflow,” says Padmanabha Reddy Madhu, principal software engineer and responsible AI champion for Employee Productivity Engineering in Microsoft Digital. “It’s also a great way to pull AI champions into the design phase so we can support our colleagues’ work.”

With more than 80 AI projects currently underway across Microsoft Digital, logging and streamlining are essential. Teams are working on all kinds of ways to boost enterprise processes and employee experiences, like the following examples from Campus Services that users can access through our Employee Self-Service Agent:

  • A facilities agent helps employees take action when they discover an issue at one of our buildings, like a burnt-out light, a spill, or physical damage. The agent creates a ticket to alert a Facilities team so they can resolve it and allows the submitter to follow up on progress.
  • A campus event agent makes onsite gatherings like talks and Microsoft Garage build-a-thons more discoverable through simple queries. Using this agent, employees can more easily discover and plan around events that interest them, adding value to the in-person experience and incentivizing community.
  • A dining agent addresses the challenges of multiple on-campus restaurants featuring menu options that shift daily. Employees can use natural language queries like “Where can I get teriyaki today?” The agent does the rest. This kind of agent can be especially helpful for employees with allergies or dietary restrictions, providing a boost to accessibility for the on-campus dining experience.
A photo of Wu.

“AI is rapidly becoming a standard part of how we build and operate. As adoption accelerates, Responsible AI becomes imperative and enables teams to innovate at speed while maintaining safety and accountability at scale.”

Qingsu Wu, principal group product manager, Microsoft Digital

Our policies and practices have embedded a culture of responsibility and trust into our internal AI development processes. With that trust comes the confidence to experiment.

“AI is rapidly becoming a standard part of how we build and operate,” says Qingsu Wu, principal group product manager in Microsoft Digital. “As adoption accelerates, Responsible AI becomes imperative and enables teams to innovate at speed while maintaining safety and accountability at scale. By embedding Responsible AI into our engineering practices, teams have the clarity and confidence they need to manage risk proactively and deliver value without compromising safety or trust.”

Far from thinking of responsible AI assessments as an administrative or policy burden that creates additional work, teams now recognize their benefits. They look at the process as an extra set of eyes from a trusted partner. By minimizing legal and compliance risks through our Responsible AI Council’s expertise, our teams save time and stress, and we avoid problems like delayed releases or rollbacks.

A photo of Smith.

“What we’re doing is entirely novel in the tech world. Microsoft is really the lead learner here, and we have a passion for corporate citizenship that we’re embedding in our tools.”

Jamian Smith, principal product manager and co-lead, Microsoft Digital Responsible AI team, Microsoft Digital

Lessons learned: Embedding responsible AI into our development efforts

Throughout this process, we’ve learned lessons that will be helpful for other organizations just beginning their AI journeys:

  • We empowered early adopters and enthusiasts as responsible AI champions. They act as anchors and resources for developers who use AI, so we made sure they had the knowledge and training they needed to unlock downstream value.
  • Culture has been crucial to our success, especially our growth mindset and our focus on trust. Emphasizing these aspects of our company culture helped us embed responsible AI into core SDL processes and naturalize it on our engineering teams.
  • Processes are one thing, and tooling is another. If your responsible AI assessment workflow isn’t attuned to your needs, simply building a review portal tool won’t get you the rest of the way. First, we thought about the process we needed to put in place to solidify responsible AI practices and support our teams’ work. Then we built a tool that supports those workflows as easily and seamlessly as possible.
  • Accuracy is reliant on data, and data has a tendency to reflect the biases of the humans who organize it. It’s necessary to correct bias actively through introspection and testing.

“What we’re doing is entirely novel in the tech world,” says Jamian Smith, principal product manager and co-lead for Microsoft Digital’s Responsible AI team. “Microsoft is really the lead learner here, and we have a passion for corporate citizenship that we’re embedding in our tools.”

As your organization begins to experiment with its own AI projects, take these concrete steps to infuse responsibility into the solutions you create:

  1. Establish a strong foundation based on core principles and standards that align with your organizational culture. The Microsoft Responsible AI Standard is a great place to start because it reflects our experience and the expertise we’ve built as AI technology leaders and providers.
  2. Seek out the activators across your organization: people with a passion for AI, security, transparency, and other challenge areas, along with a willingness to learn and the ability to lead. Think about how to place them in both centralized and distributed positions.
  3. With the rapidly evolving regulatory climate around AI, it’s crucial to have a broad understanding of compliance and continue to follow its developments. Involve dedicated regulatory, compliance, and legal professionals in researching and monitoring global standards while communicating that information to your organization, particularly through training and updates that help teams adapt new regulations into their core processes.
  4. Create a process for responsible AI assessment. Consider ways to break it into stages that propel projects forward rather than hindering them. Enlist the right people to assess projects, and consider tooling that streamlines actions for both creators and assessors. Our AI Impact Assessment Guide can help you get started.
  5. Benefit from pioneers in the space, including our experts at Microsoft. Our journey has produced ready-to-use resources that can accelerate your progress. Examples include our Responsible AI Toolbox for GitHub, hands-on tools for building effective human-AI experiences, and our AI Impact Assessment Template.

“It’s not about how fast you can move, but how prepared you are. Responsible AI processes might seem like speed bumps, but ultimately they’re accelerators.”

Naval Tripathi, principal engineering manager and co-lead, Microsoft Digital Responsible AI Team

Building your capacity to create AI tools responsibly won’t happen without careful planning and strategy. As part of that process, embed responsible AI into your development workflows by emulating the practices we’ve pioneered at Microsoft.

“It’s not about how fast you can move, but how prepared you are,” Tripathi says. “Responsible AI processes might seem like speed bumps, but ultimately they’re accelerators.”

By prioritizing responsible AI, businesses of all kinds, all over the world, can ensure that the AI revolution is a truly human movement.

Key takeaways

These insights can help you as you begin your own journey through responsible AI:

  • Realize that this isn’t just a technical transition. It’s also a gradual evolution and an ongoing journey.
  • Work with people across your organization to establish goals and standards, because different disciplines bring different expertise and insights to the table. This will also align your responsible AI standards with your organizational values.
  • Start with the basics and build from there. Establish principles, create processes, and construct tooling around those structures.
  • A wide array of tooling is readily available in the world of AI. Seek out providers that model responsible values.
  • Lean on your existing experts across privacy, security, accountability, and compliance. Their skills will be crucial in this new technological landscape.
  • Conducting your own responsible AI groundwork is crucial, but you can also partner with Microsoft. We run on trust, and we’ve thought about these issues to pave the way for your success. Follow our lead, consider the best ways to adapt our lessons to your organization, and come to us with questions.

The post Responsible AI: Why it matters and how we’re infusing it into our internal AI projects at Microsoft appeared first on Inside Track Blog.

]]>
19289
Accelerating transformation: How we’re reshaping Microsoft with continuous improvement and AI http://approjects.co.za/?big=insidetrack/blog/accelerating-transformation-how-were-reshaping-microsoft-with-continuous-improvement-and-ai/ Thu, 26 Mar 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=20297 Technology companies are really people companies. In an age of rapidly advancing AI, losing sight of this reality leads to an overemphasis on new tools while neglecting opportunities for the transformational change that AI offers. Moving forward, the winners will be the companies that prioritize technological and operational excellence. Microsoft Digital, our company’s IT organization, […]

The post Accelerating transformation: How we’re reshaping Microsoft with continuous improvement and AI appeared first on Inside Track Blog.

]]>
Technology companies are really people companies. In an age of rapidly advancing AI, losing sight of this reality leads to an overemphasis on new tools while neglecting opportunities for the transformational change that AI offers.

Moving forward, the winners will be the companies that prioritize technological and operational excellence. Microsoft Digital, our company’s IT organization, is seizing this moment by reinventing processes for agentic workflows powered by continuous improvement (CI).

We believe that AI-powered agents, Microsoft 365 Copilot, and human ambition are the key ingredients for unlocking opportunity across every industry.

A photo of Laves.

“Continuous improvement is a natural, formal extension of our culture that applies rigor, structure, and methodology to enacting a growth mindset through understanding waste and opportunities for optimization.”

David Laves, director of business programs, Microsoft Digital

By combining our AI capabilities with continuous improvement, we’re executing initiatives that increase our productivity and improve our performance. We’re forging a new path for how companies operate in the era of AI.

Welcome to the age of AI-empowered continuous improvement.

Our vision for continuous improvement, turbo-charged by AI

At Microsoft Digital, we’re embracing continuous improvement to unlock greater operational excellence and better employee experiences.

“One of the main tenets of our culture at Microsoft is a growth mindset, and that involves experimentation and curiosity,” says David Laves, director of business programs within Microsoft Digital. “Continuous improvement is a natural, formal extension of our culture that applies rigor, structure, and methodology to enacting a growth mindset through understanding waste and opportunities for optimization.”

Our capacity to drive process improvements has been crucial to our AI transformation as a company. We’ve adopted a “CI before AI” approach to ensure that we don’t end up automating inefficient processes. By engaging in activities that focus on continuous improvement, our teams can better identify which problems to address with AI and prioritize meeting customer needs.

“Continuous improvement is really about understanding your business, its needs, and where you can find value,” says Matt Hansen, a director of continuous improvement at Microsoft. “It gives us the language to scale our efforts out across everything we do.”

This process isn’t just another way to enable AI. In fact, AI is essential to enabling continuous improvement itself.

A photo of Campbell.

“When leaders stay actively engaged and partner through these Centers of Excellence, we can create alignment, accelerate decisions, and ensure both CI and AI help to deliver measurable business outcomes.”

Don Campbell, senior director, Microsoft Digital

Operationalizing continuous improvement and AI

Operationalizing continuous improvement and AI enablement is a leadership imperative at Microsoft, and one that doesn’t just happen organically. As an organization, we are deliberate about turning business strategy into measurable outcomes through clear sponsorship, disciplined prioritization, the right resourcing, and sustained investment in change management and employee skilling.

“The difference between strategy and real business impact is execution,” says Don Campbell, a senior director in Microsoft Digital. “That execution requires strong leadership sponsorship and clearly designed continuous improvement efforts and AI Centers of Excellence (CoEs), which translate business strategy into operational reality. When leaders stay actively engaged and partner through these CoEs, we can create alignment, accelerate decisions, and ensure both CI and AI help to deliver measurable business outcomes.”

To support leadership’s vision, we’ve put organizational resources in place to manage our continuous improvement investments, guide practices, and support teams. There’s an overarching continuous improvement CoE within Microsoft Digital, which works in close partnership with the AI CoEs, forming an integrated model which connects enterprise priorities with frontline execution.

Together, these CoEs establish shared standards, provide clarity on where to invest, and help us move faster with confidence, turning ambition into sustained business impact.

A photo of West.

“Continuous improvement is about process, but it’s also about people.”

Becky West, lead, Continuous Improvement Center of Excellence, Microsoft Digital

Continuous improvement and people

As we build out the organizational structures that underpin our investment in continuous improvement, we’re approaching the people side of change with intention.

Currently, we’re undertaking skilling efforts and communicating with every employee about how their role fits into core continuous improvement tools, including bowler cards, Gemba walks, Kaizen events, and monthly business reviews. We’re also demonstrating how “CI + AI” is a powerful combination.

The roadmap is there, the structure is in place, and we’re already seeing progress.

“Continuous improvement is about process, but it’s also about people,” says Becky West, lead for the Continuous Improvement CoE within Microsoft Digital. “A guiding hand like the Continuous Improvement CoE is how you make sure those two components align.”

Three Microsoft Digital continuous improvement initiatives

As we negotiate the early days of the company’s continuous improvement journey, Microsoft Digital is becoming a proving ground for the larger CI framework we want to deploy across the company. Our teams are spearheading projects to bring this framework to diverse functions like asset management, incident response (with a designated responsible individual), and third-party software licensing.

Enterprise IT asset management

Microsoft Digital’s Enterprise IT Asset Management team oversees the 1.6 million devices that power the company, from servers and IoT devices to labs, networks, and 800,000 employee endpoints. Safeguarding this vast landscape is critical to enterprise cybersecurity.

Three security pillars form the foundation of our security efforts: protect, detect, and respond. All of these depend on a complete, accurate device inventory.

Unified visibility enables proactive protection through enforced security controls, improves detection by spotting anomalies and misconfigurations, and accelerates responses by reducing investigation and remediation time. Without this foundation, security teams lack the precision to execute effectively.

To reach the goal of a unified inventory, the team initiated a continuous improvement initiative to build a consolidated source of truth for Microsoft Digital IT assets. Grounded in the principle of “progress over perfection,” the team initially narrowed its focus to Microsoft Lab Services (MLS) and IoT devices, with a vision to eventually expand to networks, employee devices, conference rooms, and printers. The ultimate goal is to move toward a truly comprehensive inventory.

This foundation will not only enhance security but also deliver enterprise-wide value through consistent policy enforcement, more resilient infrastructure, and comprehensive lifecycle management. By applying continuous improvement processes to help prioritize high-impact opportunities and using AI to accelerate outcomes, the program is enhancing Microsoft’s operational excellence and security posture.

“It’s better to do step A than wait until you’re ready to do steps A, B, C, and D,” says Aniruddha Das, a principal PM in Microsoft Digital.

As the team progressed from Gemba walks to Kaizen events under the guidance of the Continuous Improvement CoE, they dug deeper into areas of waste. Then they identified potential actions, breaking them down into “value-add,” “non-value-add-but-essential,” and “non-value-add.”

A photo of Ashwin Kaul

“For every action item, we were always asking ourselves how we could make these things better through AI. We’re looking for ways to expedite our core outcomes with minimal human involvement.”

Ashwin Kaul, senior product manager, Microsoft Digital

This exercise helped them prioritize their activities and land on a starting point: A device security index that would provide an overview of our hardware environment’s security posture. Essentially, it would represent a list of device security statuses.

The team identified distinct improvement areas for IoT and Microsoft Lab Services (MLS) devices. For IoT devices, they needed to build the inventory from the ground up. MLS already had a fairly complete inventory of devices, so the team set a goal to improve data quality. Although each of these challenges is different, they’re excellent opportunities for AI-empowered continuous improvement.

Now that the project is underway, the team plans to use an AI agent to automate device registration for IoT devices, which currently relies on manually uploaded spreadsheets. It’s a prime example how streamlining a process with continuous improvement enables AI to automate and accelerate our work.

On the MLS side, the team is creating an AI-driven normalization tool to automate the de-duplication and correction of inaccuracies in device data. The goal is to get from less than 50% data quality to 100%, dramatically improving our security posture through greater accuracy.

“For every action item, we’re always asking ourselves how we can make these things better through AI,” says Ashwin Kaul, a senior product manager within Microsoft Digital. “We’re looking for ways to expedite our core outcomes with minimal human involvement.”

Continuously improving the designated responsible individual experience

On the Digital Workspace team, designated responsible individuals (DRIs) are in charge of maintaining the health of our production systems. When technical emergencies arise, they’re the rapid-response point people who take the lead.

A photo of Ajeya Kumar

“We asked ourselves, ‘How can AI elevate the designated responsible individual (DRI) experience to the next level?’”

Ajeya Kumar, principal software engineer, Microsoft Digital

That process itself can be incredibly stressful, and time is of the essence. When every moment counts, efficiency is key. Meanwhile, a big part of a DRI’s work is just finding out what’s gone wrong so they can fix the incident.

But their job isn’t just about crisis management. When there are no active incidents, they work on engineering enhancements to improve the efficiency of production systems and clear backlog projects.

There’s also a handover process that takes place when one DRI finishes their rotation and another goes on-call. That involves a report about any incidents that have occurred, active issues, actions taken, key metrics, and other important information.

With these two priorities in mind, our Digital Workspace team initiated a continuous improvement process review. Their Gemba walk provided a crucial starting point.

“The planning stage is all about figuring out what the process is, what it should be, and what we can do to improve it,” says Ajeya Kumar, a principal software engineer on the Digital Workspace team within Microsoft Digital. “We asked ourselves, ‘How can AI elevate the designated responsible individual (DRI) experience to the next level?’”

Collectively, the team decided to tackle these challenges with a multifunctional AI agent they call the Smart DRI Agent. This agent’s primary role would be synthesizing and presenting information to its human counterparts to help them save time in context-heavy situations.

The AI elements that the team has planned can be broken out into the following capabilities:

  • Text summarization: Going through logs and identifying key insights.
  • Data correlation: Tracking and collating error logs.
  • Automation: Updating the status of issues, keeping abreast of communications, and providing point-in-time, daily, and weekly summaries of system health.
  • Identifying patterns: Building troubleshooting guides based on frequency patterns.

The Smart DRI Agent is already in its pilot phase and producing results. It conducts four main activities:

  • AI-generated summaries of DRI actions.
  • Proactive notifications with AI-generated insights.
  • Chat support to assist with all kinds of DRI queries.
  • AI-generated handover reports.

“The continuous improvement framework that enables these pieces is the key to unlocking value,” says Aizaz Mohammad, principal software engineering manager on the Digital Workspace team. “It may seem process-heavy, but once you work through it, you’ll see the value.”

That value is apparent in their results.

In the first 30 days of the Smart DRI Agent’s pilot, there were 301 incidents, and the agent provided insights on 101 of them. That led to an approximate 100 hours of time savings for DRIs and a 40% improvement in our key network performance metric.

Third-party software license audits

Within Microsoft Digital, the Tenant Integration and Management team is responsible for a range of services, including third-party software licensing. This space is all about managing liability from both a security operations and an auditing perspective.

A photo of Hovhannisyan.

“It takes a tremendous amount of data and traversals through multiple sources to get us to the actionable data we need. The goal for this project is to reduce that time to increase operational efficiencies.”

Anahit Hovhannisyan, principal group product manager, Microsoft Digital

Without the proper security insights, the company could find itself with risks associated with third-party software vulnerabilities. And without thorough auditing, we might experience license overuse and contractual issues that can lead to waste or expensive license reconciliations.

“It takes a tremendous amount of data and traversals through multiple sources to get us to the actionable data we need,” says Anahit Hovhannisyan, a principal group product manager within Microsoft Digital. “The goal for this project is to reduce that time to increase operational efficiencies.”

A photo of Kathren Korsky

“It’s tough to be honest about what isn’t working, because it ties into people’s personal value and worth, but it’s essential to the process.”

Kathren Korsky, team lead, Software Licensing, Microsoft Digital

The team decided to target the auditing process first. Currently, the software licensing team performs audits manually by looking at entitlements, contracts, purchase orders, and more while liaising with suppliers and our Compliance and Legal teams. That’s incredibly time-consuming.

During the software licensing team’s planning phase, they developed an ambitious goal of reducing the time to insights on third-party software license data from 154 days down to 15 minutes. During their continuous improvement Kaizen event, the team uncovered opportunities for AI-powered process improvements that eliminate waste.

“It required a lot of courage as we were identifying waste,” says Kathren Korsky, Software Licensing team lead within Microsoft Digital. “People are very invested. It’s tough to be honest about what isn’t working, because it ties into people’s personal value and worth, but it’s essential to the process.”

Now, they’re building and implementing solutions, including an AI and data platform that provides business intelligence with custom reporting abilities, an AI agent that provides audit support and ticket creation, and another that automatically generates audit reports. The team has been using Azure Foundry and Azure AI services to create their agents because these tools have the flexibility to switch between different models and fine-tune their parameters.

As these agents emerge, they’ll take the most tedious and error-prone aspects of the process out of human auditors’ hands, freeing them up to focus on solving problems, not endlessly searching for them.

Realizing continuous improvement at scale

These are just a small selection of the many continuous improvement initiatives underway within Microsoft Digital and the company as a whole.

“What continuous improvement gives us is the macro vision and the micro actions we can do to accomplish our goals.”

Kirkland Barret, senior principal PM manager, Microsoft Digital

At Microsoft, most of our continuous improvement initiatives are in their initial stages. As they progress through the measurement and adjustment phases, two benefits will emerge.

First, we’ll iterate and improve the value that each individual initiative provides. Second, we’ll continue to build our discipline and cultural maturity around a growth mindset we’re operationalizing through continuous improvement.

“What continuous improvement gives us is the macro vision and the micro actions we can do to accomplish our goals,” says Kirkland Barrett, senior principal PM manager for Employee Experience in Microsoft Digital. “It’s about knowing our objectives, identifying upstream root causes, and rippling them throughout a mechanism of progress.”

Key takeaways

These tips for implementing a continuous improvement framework come from our own experiences at Microsoft Digital:

  • Be inclusive: Have the right subject matter experts at the table from the start. Sponsors need to be present as well.
  • Cultivate maturity and transparency: Objective analysis about how things are going requires honesty.
  • Sponsorship matters: Make sure you have sponsorship at the highest levels. This is a cultural change, and leadership is the core of culture.
  • No half-measures: If you’re going to identify opportunities for continuous improvement, commit to having budget and resources in place.
  • Process, then technology: Focus on what you need to simplify processes first, then apply AI. This will keep you from automating waste and inefficiency into your operations.

The post Accelerating transformation: How we’re reshaping Microsoft with continuous improvement and AI appeared first on Inside Track Blog.

]]>
20297
Deploying Microsoft 365 Copilot in five chapters http://approjects.co.za/?big=insidetrack/blog/deploying-microsoft-365-copilot-in-five-chapters/ Thu, 29 Jan 2026 17:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=21913 Deploying Microsoft 365 Copilot: A next-generation business tool Welcome to the new era of productivity Generative AI has captured the world’s attention, and businesses are taking notice. According to our Work Trends Annual Report, 70% of people would delegate as much work as possible to AI to lessen their workloads. “I’m inspired by the transformative […]

The post Deploying Microsoft 365 Copilot in five chapters appeared first on Inside Track Blog.

]]>

Deploying Microsoft 365 Copilot: A next-generation business tool

Welcome to the new era of productivity

Generative AI has captured the world’s attention, and businesses are taking notice.

According to our Work Trends Annual Report, 70% of people would delegate as much work as possible to AI to lessen their workloads.

A photo of Osten

“I’m inspired by the transformative power of AI. I’ve been impressed with how quickly our employees have put it to work for them.”

Capitalizing on this trend will mean the difference between surging ahead or getting left behind, including here at Microsoft, where we’re the first enterprise to deploy Microsoft 365 Copilot fully.

“I’m inspired by the transformative power of AI,” says Andrew Osten, general manager of Business Operations and Programs in Microsoft Digital, the company’s IT organization. “I’ve been impressed with how quickly our employees have put it to work for them.”

He would know. His team is responsible for driving usage and adoption of Copilot and any new features to more than 300,000 employees and vendors across the world.

“Customers are looking to us to share what we’ve learned as the first enterprise to deploy Copilot,” Osten says. “Our team has a unique opportunity to help them deploy and get to value as quickly as possible.”

Meet Microsoft 365 Copilot

Copilot combines the power of large language models (LLMs) with your organization’s data to turn your employees’ words into some of the most powerful productivity tools on the planet—all within the flow of work. Employees can access intelligent assistance through Microsoft 365 Copilot Chat or the apps they use every day, including Word, Excel, PowerPoint, Outlook, Teams, and more, to provide real-time intelligent assistance. It also forms the foundation for new, agentic capabilities that apply the power of Copilot orchestration to more specific knowledge sources and tasks.

According to our Work Trends annual report, employees who use AI are seeing significant benefits.

Organizations like ours that are unlocking AI assistance within employees’ everyday workflows are poised to gain a distinct advantage in terms of productivity, engagement, and innovation.

“We’re using it to reduce our IT expenses and enhance our productivity,” Osten says. “We’re also excited by its potential to create a lasting competitive advantage for us here at Microsoft and for our customers.”

Our mission in Microsoft Digital is to empower, enable, and transform the company’s digital employee experience across devices, applications, and infrastructure. We also provide a blueprint for our customers to follow in the form of this guide for deploying and adopting Copilot.

“The contents of this guide are based on the lessons we’ve learned deploying Copilot,” Osten says. “The tips and ideas you’ll read here will help you accelerate your own time to value with Copilot so you can realize the same benefits as our employees.”

Chapter 1: Getting governance right

Maintaining privacy, security, and compliance while respecting regulatory frameworks.

Before you begin your Microsoft 365 Copilot implementation, you’ll want to consider how this tool impacts your data. Copilot employs LLMs that interact with data and content across your organization. It uses information your employees can access to transform user prompts into personalized, relevant, and actionable responses throughout Microsoft 365 apps.

Giving your employees this level of access means proper data hygiene is essential. At Microsoft Digital, we use sensitivity labeling to empower our employees with access while also protecting our data. Our colleagues on the product side designed Copilot to respect labels, permissions, and rights management service (RMS) protections that block content extraction on relevant file labels. By implementing effective sensitivity labeling practices, you can rest assured that anything you intend to remain private or confidential will stay that way.

Pick the governance path that’s right for you

This chapter outlines the highly robust, best-case scenario we created at Microsoft, but we know not every organization has a fully deployed data governance system and strategy. If you’re in that position, don’t worry! You can use techniques like Restricted SharePoint Search that provide value and protection without exposing Copilot to your internal resources.

Laying the groundwork with proper labeling

Throughout our internal governance efforts within Microsoft Digital, we’ve developed four labeling practices that make up our foundation for appropriate policies and settings.

Responsible self-service

Support and enable your employees to create new workspaces like SharePoint sites, ensuring your company data is on your Microsoft 365 tenant and employees don’t simply re-use and overload existing spaces with mismatching permissions. That enables your employees to take full advantage of Copilot in ways that align with your organizational data hygiene while you keep your company’s information safe.

Top-down defaults

Label containers for data segmentation by default to ensure your information isn’t overexposed. At Microsoft, we default our container labels to “Confidential\Internal Only.” That ensures alignment with our policies and settings that limit external sharing. We use Microsoft Purview to manage this process.

Consistency within containers

Derive file labels from their parent containers. Being consistent here boosts security across every layer and reduces the administrative burden on your employees to label every file they create. Copilot will reflect file labels in chat responses, so employees know the level of confidentiality behind each portion of AI-created responses.

Employee awareness

We train our employees to understand how to handle and label sensitive data. By making your workers active participants in your data hygiene strategy, you increase accuracy and your overall security posture.

Self-service with guardrails

The data hygiene practices we outlined above form a foundation for compliance and security, but backstopping those efforts through Microsoft 365 features adds an extra layer of protection. That’s a core principle of Zero Trust.

At Microsoft Digital, we use Microsoft Purview Data Loss Prevention (DLP) policies to define the rules and actions for detecting and protecting sensitive data across Microsoft 365, SharePoint, OneDrive, and Teams. DLP policies support vulnerable data types and scenarios that require protection. Those include any kind of information that might introduce inappropriate access to company data or intellectual property. Examples include access to credentials like keys or tokens, personally identifying information, financial data, or non-public source code.

Sign-in information, reports, and dashboards are available via Purview to help our team monitor and analyze content activity and compliance across the organization. They also provide insights into the volume, location, and usage of sensitive data, as well as any incidents and alerts that indicate potential data breaches or violations.

For example, an employee might label something as “General,” but it contains credentials or other sensitive end-user identification information (EUII). In those instances, Purview will automatically block the file from access beyond its owner or reapply a more appropriate label.

Between proper labeling and backstopping self-service through DLP guardrails, we’re able to keep Copilot Chat from surfacing documents it shouldn’t share in the wrong context or to the wrong people. Using Purview and other tools at our disposal, the five practices below help us keep our employees and our company’s data safe.

Trust, but verify

Empower self-service with sensitivity labels, but verify them by checking against DLP standards, then use auto-labeling and quarantining when necessary. Internally, we’ve configured Microsoft Purview DLP to detect and control sensitive content automatically.

Expiry and attestation

Put strong lifecycle management protocols in place that require your employees to attest containers to keep them from expiring. We don’t keep items that don’t have an accountable employee or that might not be necessary for our work.

Controlling the flow

Limit oversharing at the source by enabling company-shareable links instead of forcing employees to grant access to large groups. At Microsoft, we add an extra layer of highly confidential items that users can only share with specific people on a need-to-know basis. To enforce these behaviors, you can set default link types based on labels through Purview.

Oversharing detection

Even under the best circumstances, accidents happen. When one of our employees does overshare sensitive data, we use Microsoft Graph Data Connect extraction in conjunction with Microsoft Purview to catch and report oversharing.

International compliance: No size fits all

Europe has extra requirements in the form of EU Data Boundary regulations and works councils, internal organizations that provide employee co-determination on workers’ rights or regulatory issues, including performance management or monitoring. Our Copilot deployment meant we needed to partner closely with our Microsoft works councils when launching AI technology with complex data and privacy implications.

Your experience will vary depending on your industry and where you operate, but we’ve learned that it’s best to work closely with local subsidiaries to ensure you have a complete picture of a region’s regulatory situation. Local insiders are poised to liaise with their works councils, as we’ve done at Microsoft, or other bodies through direct relationships. Start the process early so you can manage feedback cycles effectively, make adjustments, synthesize any answers that works councils need, and resolve any concerns through configurations that make sense for your employees.

Learning from Microsoft’s governance, security, and compliance practices

Bring the right people into the conversation

Don’t keep this conversation in the IT sphere alone. Bring in all the relevant security, legal, and compliance professionals.

Build a foundation for automation

Microsoft Purview DLP has powerful intelligent detection, but it relies on establishing good defaults.

Think about how your employees will use Copilot

Determine the primary use cases for Copilot. The kinds of collaboration and access employees need will affect your default labeling architecture.

Take this opportunity to train employees

If you’ve been looking for an excuse to refresh employee knowledge around data privacy, let this moment be your milestone. It will be far easier to start with a clean data estate.

Don’t overwhelm your users

Make labeling simple and intuitive and ensure it isn’t overwhelming. Employees should have a limited set of choices to keep things comprehensible. It’s also valid for different employees to see different choices.

Balance good governance with time to value

Because of the scope and complexity of our deployment, we took a very thorough approach to governance. If speed is your priority, you might consider a faster deployment with a less comprehensive governance approach, for example, using Restricted SharePoint Search to constrain both Enterprise Search and Copilot experiences to a curated set of SharePoint sites of your choice.

Key takeaways

Use these tips to tackle governance, security, and compliance at your company. It’s based on what we learned deploying Copilot internally here at Microsoft.

1) Labeling

  • Develop a labeling taxonomy. This should include:
    • Classification levels, not exceeding five primary labels and five sub-labels
    • Descriptions clearly outlining a label’s meaning for employees
    • Examples to clarify usage for employees
  • Determine policies and settings that correspond with labels. Consider the following:
    • Storage type and location
    • External allowance
    • Encryption
    • Access control
    • Data destruction
    • Data loss prevention
    • Public disclosure
    • Logging and tracking access
  • Establish container defaults
  • Configure container labels to set the default file label in document libraries
  • Initiate an employee education initiative

2) Data loss prevention

  • Configure Microsoft Purview DLP standards and quarantining protocols
  • Establish lifecycle management and attestation protocols
  • Configure Microsoft Graph Data Connect to discover where you’re oversharing

3) International compliance

  • Initiate conversations with local subsidiaries
  • Engage works councils or other advocacy bodies
  • Address concerns
  • Determine the feasibility of regional deployment and segment if necessary

Key actions:

How we did it at Microsoft

Further guidance for you

Chapter 2: Implementation with intention

Building a strategy for licensing, administration, and rolling Microsoft Copilot out to different groups within your organization.

Implementing Microsoft 365 Copilot isn’t as easy as just turning on licenses and alerting your users. It takes organizational partnerships, early assessments of your concrete business needs, and careful planning.

Design for the “who”

Copilot is a new concept in business software. At the time of our implementation, we were the first company to roll it out anywhere in the world, and our Microsoft Digital implementation team had to choose from countless ways to approach a licensing strategy—different mechanisms of licensing, automation, management, and the list goes on. Regardless of your overall approach, we’ve learned from experience that it almost always makes sense to start with pilot groups who can validate the tool and enable the rest of your organization.

For us, that looked like this:

Scaling out your licenses

After you decide on the general shape of your rollout, you can begin building your licensing strategy. Fortunately, if your organization uses Microsoft 365, you’ll already have access to most of the apparatus you need. The inherent flexibility of Microsoft 365 licensing means you can easily adjust your strategy as you progress based on scale, organization changes, or any other factors.

At Microsoft Digital, we started with individual licenses at the single-user level. As our implementation scaled, we tied licensing automation to Microsoft 365 security groups to implement targeted licensing changes at scale. Those groups could include tailor-made subsets of employees or entire organizations within Microsoft, and we keyed our automation logic to their expanding and contracting eligibility.

We highly recommend defining a phased rollout strategy and structuring your groups accordingly. That creates accountability and gives your IT admins a crucial point of contact for understanding the licensing needs of different groups within your organization.

Based on our implementation experience, there are three main benefits to using security groups:

Optimize licensing costs: Create groups that reflect your business needs and goals that align with your respective business sponsors. Sync your licensing status changes with group membership changes. That way, you can assign the right licenses to the right users and adjust easily if you require frequent changes, for example, in your early initial validation phase, to avoid paying for licenses you don’t need or use.

Refine admin costs: Group-based licensing lets your admins assign one or more product licenses to a group. This depends on your rollout strategy and progress. Your admins will be able to streamline your group setup at scale, reducing your admin overhead. This strategy is helpful, considering all the licenses you likely need to manage.

Enhance compliance and security: This ensures that only authorized users receive licenses and get access to resources, enhancing your security and compliance. Your admins can use audit logs and other Microsoft Entra services to monitor and manage your group-based licensing activities.

Pre-adoption communications

Given the excitement around AI tools, one of the biggest challenges during our phased implementation was support requests from employees outside our initial pilot groups. Most of our support requests at this stage were essentially asking, “Where’s my license?” It was a key learning for our Microsoft Digital implementation team.

You can easily avoid the issue through clear and honest communication. For example, when you alert your initial implementation groups about their Copilot access, you could simultaneously deploy “Coming soon” emails to the rest of your organization. That will help you avoid any confusion while simultaneously generating excitement and boosting general adoption when the time comes.

In the end, what’s most important is building a strategy for getting all users access to Copilot, structuring your rollout, and helping people build the daily habit of using AI. While leadership sponsorship is especially important in later phases of adoption, it’s also crucial here as a way of identifying who should be part of pilots and subsequent cohorts. Leaders can help communicate those decisions.

The bottom line is that your IT implementation team can’t work in isolation. Communication—especially from organizational leadership—will be a key part of your licensing and implementation strategy.

Learning from our implementation 

Design for the “who”

When you determine your initial cohorts, base your decisions on which roles have the largest coverage and will provide the most relevant feedback.

Get your groups in place

Be thoughtful about your Microsoft 365 groups and make sure everyone knows who owns them and who’s responsible.

Engage your support team from the start

This is a new technology, so your support teams will receive requests. Ensure they’re ready by giving them early access.

Manage expectations to minimize blowback

Proactively help users understand why they have licenses or don’t. Note that your rollout strategy might be subject to change.

Bring leadership on board early

Executive sponsorship isn’t just useful for adoption. Leaders will also help you identify the key use cases within their organizations to determine if they belong in early rollout phases.

Product feedback at every level

Encourage feedback for employees in your early implementation phases, because that will guide your wider adoption efforts.

Key takeaways

Use these tips to help you with your internal implementation and admin process. They are based on our experience here at Microsoft.

1) Get ready

  • Perform the Microsoft 365 Copilot optimization assessment
  • Identify key implementation phases and groups
  • Secure leadership involvement
  • Build out your implementation plan and map it to a licensing strategy

2) Onboard and engage

  • Assemble security groups and assign responsibilities
  • Build an automated Microsoft 365 licensing management workflow
  • Enable roles for Copilot reports and the Copilot dashboard
  • Assign licenses and configure them using the setup guide
  • Analyze pilot data:
    • Access in-app feedback
    • Facilitate feedback sessions
    • Analyze usage reports
  • Deploy communications: For strategy around this element, see the next section

Key actions

How we did it at Microsoft

Further guidance for you

Chapter 3: Driving adoption to capture value

Effective adoption: From readiness to empowerment

The fact that your employees are excited to try out a powerful new technology platform isn’t enough. We found that you need strategic, coordinated change management efforts to drive Microsoft 365 Copilot adoption.

That way, you can be sure to get your employees onboard at the right time in the ways that you want. The idea is to give them the freedom to be themselves with proper guardrails.

Consider breaking your company-wide adoption into cohorts, for example, subsidiaries or business groups. We divided our adoption along two vectors: internal organizations like legal or sales and marketing, and regions like North America or Europe. Different cohorts have different focuses, but the strategy is similar.

Microsoft 365 Copilot change management

Illustration showing four steps of change management: Getting ready, onboarding and employee engagement, delivering impact, and extending and optimizing.
Focusing on change management is key when you deploy Microsoft 365 Copilot.

Effective change management needs careful planning. Our adoption efforts took inspiration from the Microsoft Engagement Framework, which we’ve developed specially for driving adoption of our products. If you’re an adoption specialist or change manager, you might notice similarities with Prosci’s ADKAR model, which progresses through awareness, desire, knowledge, ability, and reinforcement.

Whichever framework you choose, the techniques we use here at Microsoft will apply. Either way, the process starts with your people.

Get ready

Begin by working with your company-wide adoption leads, then identify members of your target cohorts who will support the adoption, including change managers, leadership sponsors, and employee champions.

Champions boost adoption by filling several important roles:

  • Pinpointing key usage scenarios for Copilot based on their cohort’s culture or processes.
  • Deciding on the best methods of communication.
  • Providing insights that help adoption leaders build out their rollout plans.
  • Extending the reach of our adoption team through peer-to-peer support and guidance.
  • Most importantly, demonstrating the value of Copilot and showing their peers how powerful this tool can be in their day-to-day work.

When champions socialize their tips and tricks, our experience at Microsoft Digital has revealed that it’s best to share specific prompts and the value they provide as a concrete entry point for users. For example, a champion could say, “I saved three hours drafting this sales script in Microsoft Word using this prompt,” then share their Copilot prompt as a place for peers to start. You’ll find advice below for how you can effectively incorporate champs into your adoption efforts.

Works councils also play a key role at this stage. They offer the benefit of local cultural expertise and can help you identify challenges employees face in their jurisdictions. Even something as simple as understanding proper modes of address helps smooth the road to adoption through effective communication.

Each of these sets of stakeholders has a role to play in your rollout. We recommend using Microsoft Copilot adoption resources to build out your adoption plan.

Onboard and engage

At Microsoft, we implemented this phase across each adoption cohort. Because every group will have its own champions and leadership sponsors, it’s important to treat each of them as its own organization, with its own unique adoption needs.

In advance of our general rollout, we deployed jump-start communications with links to learning opportunities:

  • Localized training took the form of Power Hours in different languages and time zones. These training sessions demonstrated key Copilot scenarios across Microsoft 365 apps.
  • Self-learn assets included user quick-start guides, demo videos, and the Microsoft Copilot Academy to accommodate different learning styles and preferences.

From our experience at Microsoft Digital, pre-rollout communications fulfill two needs. First, this messaging is a great opportunity to launch your champion communities because early access to Copilot licenses and learning material helps peer leaders build their expertise. Second, these communications build your general adoption population’s desire and excitement for their incoming Copilot licenses, then prepare them to hit the ground running when they finally get access. Clear messaging also helps ward off questions from eager employees asking why they don’t have licenses yet.

After your Copilot licenses are live, your launch-day welcome communications are relatively simple. Just invite employees to access Copilot, play with this new tool, and start to experiment with how it can fit into their daily workflows. It’s also helpful to include information about where employees can get support. There are many possible vectors for deploying these communications, but a multi-pronged effort that includes Microsoft Viva Amplify will deliver the maximum impact.

For support in building out your own communication plan, our adoption team has created a user onboarding kit for Copilot. These ready-to-send emails and community posts can help you onboard and engage your users.

Deliver impact

After everyone has access, it’s time to promote Copilot usage and ensure your employees are getting the best possible experience and the most value. For Microsoft’s cohorts, employee champions and leadership sponsors were essential levers.

It’s important to remember that Copilot isn’t just another tool. It introduces a whole new way of working within employees’ trusted apps. At Microsoft Digital, we took great care to encourage employees to be adventurous and lean into a mindset shift to see it as part of their daily work—not just something they play with when there’s time.

Microsoft Viva Engage or a similar employee communication platform is a helpful forum for peer community support. In our case, it provided an organic space for champions to share their expertise and change managers to provide further recommendations and adoption content. For employees who explore best on their own, Copilot Lab provides in-the-flow learning opportunities to build their prompt skills.

Meanwhile, leadership sponsors diversified our communications strategy by deploying and amplifying messaging through executive channels like org-wide emails or Microsoft Viva Amplify. Because we broke our adoption out by both organization and region, employees benefited from two sets of communications, each focusing on the scenarios that are most relevant to them.

Extend and optimize

Finally, successful adoption depends on measurement, feedback, and listening.

Understanding overall usage patterns and impact is crucial to optimizing adoption. Our Microsoft Digital team employed a combination of controlled feature rollout (CFR) technology while tracking usage through Microsoft 365 Admin Center, the Copilot Dashboard, and Viva Insights. Together, these tools gave us the visibility and tracking we needed to establish and communicate adoption patterns. Meanwhile, IT admins and user experience success managers accessed simple in-app feedback through Microsoft 365 admin center. But to really maximize value, our Microsoft Digital employee experience teams conducted listening sessions and satisfaction surveys.

All of these insights are helping us establish a virtuous cycle to drive further value and better adoption for future rollouts, extend usage to new and high-value scenarios, incorporate Copilot into business process transformation, and understand custom line-of-business opportunities.

Driving user enablement with Microsoft Viva 

We used Microsoft Viva to help enable our 300,000+ global users. Microsoft Viva is an Employee Experience Platform that brings communication and feedback, analytics, goals, and learning into one unified solution. Our team in Microsoft Digital used Viva across a range of change management scenarios, including building awareness, communicating with our employees, providing access to readiness and learning resources, and measuring the impact of our deployment. 

Accelerating Microsoft 365 Copilot with Viva

Viva Connections

Sharing key news related to deployment and enablement, generating “buzz,” and tying Copilot to Microsoft culture.

Viva Amplify

Producing and efficiently distributing employee communications to build awareness and excitement.

Viva Learning

Courses and training for our employees on how to maximize value from Copilot, inclusive of building effective prompts.

Viva Engage

Actively engaging employees, providing leader updates, listening to feedback, and enabling Champs community.

Viva Insights

Using the Microsoft 365 Copilot Dashboard beta to identity actionable insights and usage trends.

Viva Pulse

Instant feedback from employees on their Copilot experience to fine-tune our landing and adoption approach.

Viva Glint

Understanding employee sentiment and gauging the overall effectiveness of our Copilot deployment effort.

Consider these examples:

  • A human resources professional might use Copilot to create job descriptions by prompting it to suggest essential skills, qualifications, and responsibilities for a prospective role.
  • A salesperson could ask Copilot to generate a table comparing their company’s flagship product with a competitor’s to address customer questions more efficiently.
  • A finance professional might prompt Copilot to review and summarize a new contract to reduce the time it takes to search for key data.

Any single approach would never be adequate to address every different discipline and use case. With the rise of agents, specialized AI-powered assistants that customize and focus the capabilities of Copilot, certain roles derive the most value from tailored assistance for specific tasks.

So, we created a playbook that our employees can use to construct their own role-based scenarios according to their individual teams’ unique needs.

We designed it to help adoption professionals accomplish the following objectives:

  1. Understand the top responsibilities, challenges, needs, and wants of prioritized roles.
  2. Articulate and communicate hero scenarios by clearly depicting how Copilot can enable them.
  3. Share deliverables that include roles, scenarios, and prompts with the wider organization to drive awareness, adoption, engagement, and value.

Through internal testing and scenario crafting, we developed a four-part framework for creating, delivering, and socializing hero scenarios across any organization. These are the steps you can follow to create Copilot support content for adoption efforts tailored to specific roles.

Phase 1: Ready

This phase will help your organization, department, or team prepare for the process. It involves aligning with leadership and sponsors who will be accountable for driving value using Copilot. It’s also where you’ll select the priority roles, draft outlines of those roles so you can clarify your understanding of their needs and wants, and seek out feedback from leaders, managers, and subject matter experts.

Phase 2: Engage

Engaging with employees is the key to uncovering Copilot’s core value. In this phase, you’ll identify participants from your priority roles who demonstrate enthusiasm and early aptitude with the tool. From there, you can choose an approach, which might include in-person group sessions, virtual Microsoft Whiteboard sessions, one-on-one interviews, Microsoft 365 Loop collaboration, or whatever modality works best, then communicate the process to participants. Whatever you choose, the final step in this phase is conducting your employee engagements to document existing and aspirational Copilot usage scenarios.

Phase 3: Deliver

Ideating hero scenarios is how you discover value. The delivery phase defines that value and organizes it into a useful, consumable format. It starts with reviewing and analyzing the outcomes of your sessions to gain insights and identify themes. Now is the time to document your hero scenarios and the value they add, as well as blockers and accelerators. Finally, you’ll provide your output: a comprehensive deck that includes your priority roles, hero scenarios, next steps, and more.

Phase 4: Share

The final phase of this process involves socializing your scenarios across your team or organization to realize value. If you’re part of a large organization, it’s helpful to radiate these outputs beyond the target group as an opportunity for further Copilot momentum. This stage includes diving deeper into blockers and accelerators that can help your organization as a whole speed time to value.

Learning from our adoption of Copilot

Cascade adoption efforts through localization

Regional differences, priorities, even time zones—they can all block your centralization efforts. Your insider adoption leaders within each adoption cohort can help.

Empower your employee champions with trust

Monitor your user-led adoption communities at the start to provide support. As this community of power users becomes product experts, they’ll take over.

Empower employees as innovators

You’ll be surprised by what your employees dream up. Provide every opportunity for them to share their favorite tips and usage scenarios.

Create excitement, but set expectations

Encourage a healthy mindset around what Copilot can accomplish and where it fits. Don’t overpromise.

Gamify learning to build engagement and experience

Friendly competitions or cooperative challenges like prompt-a-thons generate excitement and invite creativity.

Understand that for many, AI is emotional

Overcome AI hesitancy by encouraging employees to tackle easy tasks with Copilot assistance. That will help minimize reluctance through practice.

Key takeaways

Use these tips as your guide as you build out and implement your adoption plan. They are based on our own experience internally at Microsoft.

1) Get ready

  • Identify and ramp up the person who will lead adoption for your organization
  • Create an adoption team and identify who will lead each workstream within each cohort, including:
    • Change managers
    • Executive sponsors
    • Employee champions
  • Conduct a kickoff meeting with your adoption team and set up a meeting cadence and workflow
  • Identify users and usage within your cohorts:
    • Pinpoint key usage scenarios, for example, CRM-connected email communication for salespeople or customer-facing copy support for marketers
    • Identify cohort-specific personas, for example, software engineers, customer support specialists, and business operations project managers
  • Determine communication preferences for each cohort and their personas and optimize messaging for each
  • Define success criteria with KPIs and a success measurement plan
    • Examples include usage by app or feature and user sentiment
  • Complete user enablement strategy training
  • Define a user experience and feedback strategy
  • Build deployment communications and an enablement asset library
    • Localize for international audiences

2) Onboard and engage

  • Deploy readiness communications with onboarding content:
    • Led by cohort adoption team
    • Led and amplified by leadership sponsors
  • Launch champion communities
  • Deploy launch communications
    • Led by cohort adoption team
    • Led and amplified by leadership sponsors
  • Socialize employee engagement communities
  • Run live learning sessions
  • Provide self-learning opportunities
  • Upscale the working environment with digital banners, posters, and other promotional materials to help employees visualize Copilot

3) Deliver impact

  • Promote usage through internal cohort channels
    • Follow-up communications
    • Viva Engage champion posts
  • Report on KPI success at predetermined intervals
  • Facilitate listening
    • Satisfaction surveys
    • Listening sessions
  • Gather and amplify success stories
  • Apply learnings to further adoption activities
  • Nurture existing champions through a technical training track
  • Develop reinforcement, resistance, and maintenance plans

4) Extend and optimize

  • Explore new high-value scenarios
  • Investigate business process transformation via agents, Copilot Studio, plugins, and connectors
  • Source custom line-of-business opportunities

Key actions

How we did it at Microsoft

Further guidance for you

Support for adoption leaders

Resources for IT practitioners

Chapter 4: Building a foundation for support

Setting your Support team up for success

Empowering employees means making sure they have access to the right support channels, especially if they have concerns with a new technology. The fact that Microsoft 365 Copilot operates across a wide spectrum of Microsoft 365 apps adds complexity to your support apparatus.

As a result, it’s important to give your support teams early access along with your earliest pilot implementations. For Microsoft Digital, that included members of our internal support teams who help Microsoft employees when they run into technical issues, as well as our Customer Experience and Support team that engages with external customers to troubleshoot problems with new Microsoft products. We also invited subject matter experts for Microsoft 365 apps featuring Copilot experiences, including Teams, Outlook, and more.

A small group of users across both internal and external support teams, as well as our Microsoft 365 subject matter experts, gained access at first, and we encouraged them to experiment and try to break features. This was a crucial learning phase for Microsoft Digital because it surfaced interesting issues that wouldn’t come up if our teams didn’t have access and an opportunity to experiment.

Building insights and product experience was step one, but we needed to collect that knowledge so it would be actionable in real situations. To accomplish that, we created a special Teams channel where our support team members collaborate with pilot users of Copilot and representatives of the product group. From there, we worked with marketing and communications professionals to start building our support team’s knowledge base, which would also serve as the foundation for our user-facing content.

Eventually, the time came to provide access to our wider support team. At that point, our support pilot members operated as learning leaders. When it came time to share their knowledge, it took the form of informal brown-bag sessions. We also engaged in shadow/reverse-shadow role-playing exercises so our support agents could practice addressing common issues.

Principles of good support

Strategizing for support

Building experience and knowledge is one thing, but coming up with your approach to support requires planning and a strong idea of your users’ ideal experience. At Microsoft Digital, we take a “shift-left” approach. That means we save our human support staff time by attempting to create excellent self-service options for our users. As a result, they won’t need to access a human agent unless they’re at a genuine impasse.

Shift-left principles can apply to many different support contexts, but with Copilot, we’ve found that the most important upfront action is ensuring your employees have accessible self-service support channels and communicating their availability. That might come through in-app support or access to knowledge bases.

Work with your adoption teams to ensure they include those self-service support vectors in their rollout communications. For us, self-service was able to answer many of our users’ questions, and for any extra-tricky issues, we had them access human-led support.

Seven things we learned preparing our Microsoft 365 Copilot support

Preliminary access

Select your initial support specialists. Include people with different Microsoft 365 app focuses, support tiers, and service audiences.

Communication hub

Establish a community space where your support team can connect and collaborate on issues. Invite non-support professionals as needed.

Knowledge base

Start a collaborative document and add learnings. This will eventually evolve into your knowledge base for internal support.

Widen access

Host information sessions with the wider support team and extend access so all relevant support professionals can ramp up.

Rehearse

Conduct role-playing and shadowing sessions so support teams can build practical knowledge and confidence.

Support go-live

Get your support resources and processes ready and push them live in advance of your Copilot deployment. Consider a dry run.

Track

Determine a tracking cadence and gather data on Copilot issues that arise so support teams can identify trending issues and tickets.

Common questions, issues, and resolutions

As the first enterprise organization to go through the Copilot deployment process, we’ve identified a few challenges and questions you might have. Feel free to add these to your support knowledge base and employee-facing communications.

We’re getting questions about why particular employees don’t have licenses.

Ideally, your adoption communication waves solve this issue by alerting employees when to expect their licenses and when they receive them. Otherwise, consider having a readily available link that answers licensing questions for users or directs them to their relevant managers or admins. You can also automate this process.

Users are coming to us with questions that would be better served by adoption and employee material, and that isn’t our role as support.

Work with your adoption team to preempt these issues with proactive communications. Update your self-help content and provide your support agents with ready access to different employee education resources, including your user-facing knowledge base, self-help videos, and Viva Engage communities focused on Copilot.

Teams are looking for integration support. Where do I send them?

Share this list of pre-built connectors to help your users integrate various data sources into your Microsoft Graph. This list shares the types of content supported.

Can employees put confidential information into Copilot?

As long as your employees are signed in to Copilot with their Entra ID, they can enter confidential information.

My organization has concerns about who owns the IP that Copilot generates. Does the Microsoft Customer Copyright Commitment apply to Copilot?

Microsoft does not own the IP generated by Copilot. Our universal terms state, “Microsoft does not own customers’ output content.” Those terms also include our Customer Copyright Commitment.

What’s the best way to verify the accuracy of the information Copilot provides?

Where possible, Copilot is transparent about where it sources responses from. It answers complex questions by distilling information from multiple web sources into a single response. Copilot provides linked citations to these answers so the user can verify further. 

Key takeaways

Use these tips as your guide as you build out and implement your adoption plan. They are based on our own experience internally at Microsoft.

1) Onboard and engage your support team

  • Start with a small set of support leaders:
  • General support
  • Microsoft 365 product specialists
  • Establish a Teams channel for communication and knowledge sharing
  • Create a collaborative knowledge base foundation
  • Widen access to the full Copilot support team
  • Train your full support team:
    • Conduct information sessions
    • Conduct role-playing exercises
  • Establish your escalation process
  • Engage your internal communications team:
    • Finalize your user-facing knowledge base
    • Discuss the inclusion of knowledge base material and the support process in rollout communications

2) Deliver impact for your users

  • Signal support availability in user communities on Viva Engage and other platforms
  • Publish your user-facing knowledge base
  • Establish self-service automations if applicable

3) Extend and optimize your services

  • Review support issues and product feedback
  • Calibrate the optimization of your support workflows

Key actions

How we did it at Microsoft

Further guidance for you

Chapter 5: Extending Copilot through agents

Unlocking more tailored experiences by enabling employees and teams to create agents

As organizations and employees have matured with respect to AI, agentic extensibility is expanding the frontiers of this technology. By using and even creating agents that surface knowledge, take actions, and reinvent workflows, employees can personalize AI’s capabilities to fulfill more specific needs.

What is an agent?

Agents are specialized AI-powered assistants that automate and execute business processes, working alongside or on behalf of a person, team, or organization. They range from simple prompt-and-response agents to more advanced, fully autonomous agents. Through specific instructions, grounding, connectors, APIs, and custom orchestration, creators can tailor agents to more focused workflows than a comprehensive AI solution like Microsoft 365 Copilot.

At Microsoft, we’re leaning into the agentic future by empowering employees and teams to create agents of their own. Agents and their capabilities are incredibly varied. They range from pre-made out-of-the-box agents in Microsoft 365 embedded directly into Copilot Chat; to straightforward agents that employees create themselves using a simplified process also available through Copilot Chat; to Copilot Studio agent builder or SharePoint agent builder; all the way up to complex agents that can take action on behalf of users, designed using tools like Microsoft Copilot Studio and Azure AI Foundry.

Our goal has been to provide access and enable their use at appropriate levels for our employees and the company as a whole. To make that happen, we’ve adopted a maturity model for agentic AI deployment. Early phases focus on using Copilot, grounded in enterprise data, to enhance knowledge discovery and retrieval. Later phases will enable our employees to act on that knowledge and even fully automate business workflows.

Phases of maturity

Agentic AI agent types: retrieval, action, and automation.
Our levels of agentic capability.

Each of these levels of agentic capability requires different tools to create and depends on different policies to govern. In the simplest terms, this involves three levels of agent, each of which can handle progressively more complex tasks:

Retrieval agents

Employees use low-code solutions like Copilot Chat or Copilot Studio agent builder, or they can access ready-made agents in Microsoft 365 or SharePoint to quickly train models and retrieve knowledge for specialized scenarios.

Knowledge and action

Powered by built-in connectors in Copilot Studio, agents go beyond simple knowledge retrieval, offering next steps and actions that help employees defragment their day-to-day experience.

Workflow reinvention

Human-led, agent-operated teams perform fully autonomous actions to complete end-to-end workflows, enabling employees to focus on the highest value work while agents take care of repetitive tasks.

While the third level of maturity is still in its initial stages, our employees and teams are already creating retrieval agents and knowledge and action agents. Because retrieval agents don’t require special tooling, we allow employees to create them at will through Copilot Chat and simplified agent builders in Copilot Studio and SharePoint.

For more complex agents intended to meet enterprise needs across lines of business or the company as a whole, our developers use more full-featured tools like Copilot Studio or Azure AI Foundry. For these kinds of agents, we apply the same rigor, reviews, and software development lifecycle (SDL) we use as part of our standard internal app development.

As you explore the different kinds of agents available to your users and decide how and where to enable them, adoption.microsoft.com provides an excellent place to start. It provides three different approaches to creating agents: Microsoft 365 Copilot, Azure AI Foundry, and Copilot Studio. Once you determine who should have access to each of these creation methods, you can follow our advice on driving adoption for this new practice.

Of course, all of this choice adds complexity, so maintaining visibility and control over the agents your employees create can be a challenge. As a result, we take a matrixed approach to creating and governing agents based on different parameters. They include the type of agent, how the user creates it, its knowledge sources, the need for custom tooling, sharing and publishing permissions, and more. It will be helpful to review our strategy in full to help you think through the different parameters behind your agents, in addition to the processes and policies you’ll need to put in place to govern them.

Keeping agents safe and effective through good governance

As you enable your employees and teams to create and use agents, you’ll need structures in place to govern these tools. At Microsoft, we incorporated elements of our tenant’s minimum bar for governance into our policies for managing agents. These measures include Microsoft Information Protection, a functional inventory, activity logging, lifecycle management, and the ability to properly isolate agents against crossing data boundaries.

Our general governance strategy operates at the container level, but agents bring extra functionality to the table. To govern these capabilities, we introduced further controls like sharing limits, breadth of knowledge sources, agent metadata, and information about an agent’s behaviors. The result is a proactive approach to governance backstopped by reactive structures that catch any issues.

As you think about governing your own agents, consider the four core principles we’ve established at Microsoft Digital.

We empower employees to create and share simple, low-risk agents

We provide a safe space and personal flexibility that allows individual employees to experiment without implicating company data or content users don’t own.

We capture and vet sensitive data flows at the enterprise level

More complex or far-reaching agents owned by teams or lines of business need enterprise documentation to account for external audits or security and privacy validation. Builders need to demonstrate that they’ve thought through the security and privacy implications of their agents, so these projects go through approval process flows similar to other professionally developed apps before we trust them with potentially sensitive data.

We protect data designated confidential or higher

We contain data flows to tenant mandates and only trust suitable storage destinations for content. That depends on the ability to gate which connectors can work with particular source data and sensitivity labels.

We honor the enterprise lifecycle 

Both user-based and attestation-based lifecycles come into play. We treat agents that individual employees own like any other user-created app and delete them when that individual leaves the organization. Agents owned by teams have a lifecycle defined by the tenant and tied to attestation, the SDL, and accountability confirmations.

Once you have your governance policies and procedures in place, you can begin your rollout to users through many of the same strategies and processes we’ve discussed in this guide.

Learning from our experience with agents

Connect with relevant stakeholders

Establish early communication and collaboration with members of your security, legal, compliance, IT, and other teams who can help you define ways to configure Copilot Studio agent builder safely.

Trust and empower

Provide safe spaces with appropriate guardrails for individual employees to experiment with simple agents. Copilot Studio agent builder is a great place to start.

Expand enterprise capabilities

Empower a small number of trusted creators to experiment with more powerful agent-building tools under the close watch of IT, Governance, Security, Privacy, Data, and HR teams. This will reveal gaps in process and policy and inform future reviews.

Solidify labeling and data

Revisit your labeling structures and data flows. It will be important to have these structures in place to support this new agentic environment. Start by learning from our experience governing Copilot at Microsoft.

Extend your review process

Adapt any review processes you already have in place to agents, including security, privacy, and accessibility. Embed those reviews into your publishing workflow for agents operating above the individual level. Consider adding reviews for Responsible AI.

Prevent agent sprawl

Establish a reasonable enterprise lifecycle for agents that includes attestation. That will keep agents from sprawling or remaining in place after employees have left your organization or simply no longer need a particular agent.

Key takeaways

Use these tips as your guide as you build out and implement your adoption plan. They are based on our own experience internally at Microsoft.

1) Plan and adapt

  • Connect with stakeholders on relevant teams, including Security, Legal, Compliance, HR, and IT.
  • Revisit your overall governance and labeling policies and procedures and update them to reflect the needs of agents.
  • Plan and document your intended review process.
  • Build your matrix of agent capabilities and parameters and map governance policies and procedures to each aspect of agents.
  • Decide how your SDL procedures will map to agents.

2) Run pilots with select teams

  • Determine your pilot teams. IT and other teams who will be responsible for determining policy are good places to start, for example, Security and HR.
  • Establish a feedback and monitoring pipeline.
  • Fine-tune your review and remediation procedures based on your learnings.

3) Enable agents across your organization

  • Ensure Purview DLP, Microsoft Information Protection, and other backstops are in place before widely enabling agents for users.
  • Deploy adoption communications and change management efforts.
  • Enable simple agent builder capabilities for your general workforce.
  • Enable more complex agent creation for developers on IT and line of business teams.

Key actions

How we did it at Microsoft

Further guidance for you

Applying our deployment lessons at your company

You’ve learned from our Copilot deployment. It’s time to get started on yours.

Embarking on your Microsoft 365 Copilot deployment journey might seem daunting, but by capitalizing on the lessons that we’ve learned during our internal deployment, you can both speed up the process and avoid any pitfalls.

A photo of Kerametlian

“Deploying Copilot internally has inspired us to dive deeper into the power of AI assistance, which is enabling us to enhance our employee experience.”

By anchoring your work in careful planning and using the steps and resources provided in this guide, you can unleash a new era of productivity through Copilot.

You’re not in this alone. If you’re looking for support or knowledge on any aspect of your deployment, reach out to our customer success team.

For inspiration around ways that Copilot can become your employees’ AI assistant at work, read stories about how we’re using AI within Microsoft Digital and Microsoft as a whole.

“Deploying Copilot internally has inspired us to dive deeper into the power of AI assistance, which is enabling us to enhance our employee experience,” says Stephan Kerametlian, a business program management senior director within Microsoft Digital. “With the lessons we learned from our deployment, we’re confident that we can support businesses around the world as they achieve more through the next generation of intelligent experiences.”

Key takeaways

This guide reflects our learnings and the processes we followed during our internal rollout of Microsoft 365 Copilot. This last set of tips summarizes the major actions you can take to get started with Copilot at your company.  

  • Start with strong governance: Build a clear labeling and data protection strategy before deploying Copilot to safeguard sensitive information and meet compliance needs.
  • Pilot, then scale: Roll out Copilot in phases, beginning with pilot groups to gather feedback and refine your approach before expanding companywide.
  • Communicate early and often: Proactive communication and leadership sponsorship are essential for managing expectations and driving successful adoption.
  • Empower champions: Identify and enable employee champions to share best practices, tips, and real-world scenarios that help others get value from Copilot.
  • Invest in training: Provide tailored learning resources and support to help users build confidence and skills with Copilot in their daily workflows.
  • Measure and optimize: Track usage, collect feedback, and continuously refine your deployment to maximize impact and uncover new opportunities.
  • Plan for support: Set up self-service and human support channels early so employees can get help quickly and keep momentum going.
  • Extend with agents: As your organization matures, explore agentic AI to automate workflows and unlock even greater productivity gains.

Key actions

How we did it at Microsoft

Further guidance for you

Try it out

The post Deploying Microsoft 365 Copilot in five chapters appeared first on Inside Track Blog.

]]>
21913
Keeping our content fresh, findable, and governed at Microsoft with AI-powered SharePoint http://approjects.co.za/?big=insidetrack/blog/keeping-our-content-fresh-findable-and-governed-at-microsoft-with-ai-powered-sharepoint/ Thu, 15 Jan 2026 17:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=21811 Microsoft SharePoint is where business knowledge lives. As AI-driven capabilities, assistants, and agents have exploded onto the scene, new possibilities for managing that knowledge and presenting it to our employees are emerging. At Microsoft Digital, the company’s IT organization, we’ve been using the latest AI-enabled features in SharePoint to unlock more flexible, branded, and enjoyable […]

The post Keeping our content fresh, findable, and governed at Microsoft with AI-powered SharePoint appeared first on Inside Track Blog.

]]>
Microsoft SharePoint is where business knowledge lives. As AI-driven capabilities, assistants, and agents have exploded onto the scene, new possibilities for managing that knowledge and presenting it to our employees are emerging.

At Microsoft Digital, the company’s IT organization, we’ve been using the latest AI-enabled features in SharePoint to unlock more flexible, branded, and enjoyable experiences for employees while making SharePoint page creators’ jobs easier.

The modern vision for AI-enabled enterprise knowledge sharing

Since the widespread emergence and adoption of generative AI, new ways of approaching everyday work are springing up across the Microsoft 365 ecosystem. SharePoint is no exception, and AI-powered features are already enabling innovative enterprise content sharing experiences.

It’s all part of our vision for a modern SharePoint.

“We’re investing in making SharePoint the best place to publish stories and pages, the fastest way to build compelling content,” says Sam Crewdson, a principal program manager within Microsoft Digital. “New AI features are making those goals even more attainable.”

The goal is to deliver simplicity, speed, and savings for site owners and page creators while enhancing engagement and discovery for employees.

“SharePoint is the number one source for authoritative content in the enterprise, which is critical for getting high-trust, attributable and verifiable answers from Copilot and agents,” says Kripal Kavi, a principal GPM for SharePoint and OneDrive. “We are investing in making it easier than ever to create this authoritative content that also looks great for human consumption with AI. Our goal is to take the drudgery and toil out of creating awesome high-value content on SharePoint.”

AI-driven SharePoint features in action

The latest AI-powered enhancements in SharePoint provide opportunities for advanced site management and page creation. They deliver intelligent support for maintaining organizational knowledge, automating workflows, and building engaging pages. The result is that site owners, content managers, and content creators can offer more dynamic experiences while offloading manual effort onto agents and AI features.

Knowledge Agent in SharePoint

Knowledge Agent, currently available in public preview, streamlines content management and boosts Copilot capabilities. These new features appear as a persistent, floating button to keep them top-of-mind and accessible in one place.

Knowledge Agent blends curated organizational knowledge with advanced AI to accomplish three goals:

  • Improve AI answers: Knowledge Agent gives AI the context it needs with intelligent tagging, classification, and metadata automation and reasoning. It also helps maintain metadata hygiene and policy alignment through smart suggestions, labeling, and admin controls.
  • Drive business processes: The agent suggests fields to autofill based on content and user input, creates AI-generated views grounded in metadata, and enables searches and workflows through natural language queries.
  • Keep content fresh: The tool analyzes search behavior to detect gaps in content and unmet user needs, fix broken links across the site, and recommend inactive pages for retirement. It also boosts content creation for the web through natural language prompts, templates, and intelligent suggestions.

Curating content with Knowledge Agent

A SharePoint page for a company called Zava, featuring the Knowledge Agent pane along the right-hand side.
Knowledge Agent in SharePoint helps site owners and page creators better manage and curate content for employees.

Jon Norris is the senior product manager responsible for the TechWeb Hub, our internal company resource for technical support and the primary vector for people to access our helpdesk organization. For him, the benefits of Knowledge Agent start with taking the manual effort out of existing processes.

He’s built Knowledge Agent into his regular maintenance workflows. For example, he now uses the tool to scan through sites every six months and identify sites and pages in need of retirement or a refresh.

“As site owners at Microsoft, we can now do almost everything we need in terms of content health without a third-party tool,” Norris says. “Of course, we’ve always had workflows in place to ensure the health of our sites, but the agent puts all of those key capabilities in one place while adding AI assistance into the equation.”

Create page from meeting

Anyone who’s tried to coordinate projects after a team meeting understands the grind of taking notes, assembling resources, and sending follow-up communications. The ability to create a SharePoint page from a Microsoft Teams meeting helps people capture next steps and takeaways.

This feature follows a similar process for creating a SharePoint page from a file. When meeting recordings and transcripts are enabled, users can access SharePoint’s “Create a page from AI” feature and select a meeting as their content source. The tool then reviews the transcript and generates a news page based on the meeting.

A photo of Kavi.

“Having key takeaways and next steps captured in a central durable place that you can point new and existing team members to is extremely valuable. It serves not just as a record of decisions made, but also as a great tool for onboarding new team members.”

Kripal Kavi, principal GPM, OneDrive and SharePoint

This feature uses any relevant materials from the meeting for context, including links to content shared in the meeting itself. Page owners can also prompt the tool to include material from other sources and augment the page as the team’s needs evolve.

Finally, this feature integrates with SharePoint News, so page creators can publish these resources through any vector that will engage their colleagues, like email, a Teams channel, or a Viva Amplify post.

“Having key takeaways and next steps captured in a central durable place that you can point new and existing team members to is extremely valuable,” Kavi says. “It serves not just as a record of decisions made, but also as a great tool for onboarding new team members.”

Different personas will find different aspects of Knowledge Agent helpful. For example, site managers will primarily be concerned with outdated content, while content managers often feel overburdened by creating AI-ready metadata. And content creators are always looking for inspiration on tight timelines.

Wrapping a layer of agentic support around these back-end SharePoint tasks helps make a variety of scenarios easier to tackle, ultimately with better results for content consumers.

Sections with AI

Sections with AI is a new SharePoint authoring tool that allows users to create full-fidelity SharePoint sections with just a prompt. It looks at the context of your page to offer suggested prompts to surface the content the page creator needs.

From there, they can write their own sections and ground them in relevant files to give the AI more context. When the creator clicks “Generate,” Sections with AI uses those sources, the knowledge and material already within the organization, and content already on the page to create rich sections. Creating content with Sections with AI

Creating content with Sections with AI

A SharePoint Page under construction, featuring a pane where the creator is selecting content sources for the page.
Sections with AI helps users build contextually relevant sections of the SharePoint pages through intelligent suggestions and iteration.

Within Microsoft, Norris has seen program managers and other professionals whose roles aren’t explicitly based around communications using this feature extensively. Their professional expertise isn’t necessarily in creating beautiful sites or effective text, so the AI provides a much-needed boost.

And for communications managers, it’s a way to accelerate and supplement their work.

“Page creation is great, but the majority of users spend their time updating and curating their content,” Norris says. “This feature doesn’t just help with page creation—it makes your existing content better and updating it easier.”

Sections with AI generates recommendations and prompts for the user and takes wider content into account, so it’s grounded and contextually aware. As a result, crafting a site with this tool represents collaborative iteration with an AI helper.

A photo of Norris.

“This is enabling our program managers to spend more time creating the kind of content that that they want to work on and that our users want to consume. It’s having a real impact across the board.”  

Jon Norris, senior product manager, Microsoft Digital

It’s a step forward into the agentic future in service of enterprise knowledge management and sharing.

The impact is that it’s taking toil off the plate our program managers who own our SharePoint sites, which is freeing them up to do more of what matters to them.

“This is enabling our program managers to spend more time creating the kind of content that that they want to work on and that our users want to consume,” Norris says. “It’s having a real impact across the board.”   

Driving better experiences and greater engagement

SharePoint site owners and page creators are already experiencing the benefits of a more modern, AI-enabled experience. Within Microsoft Digital, they’ve shared that they’re already saving budget and time and creating more engaging sites.

There’s also a bigger picture than individual AI-powered features. Part of SharePoint’s modernization is about making knowledge and content accessible not just through pages themselves, but across the Microsoft 365 ecosystem, especially by publishing them to Microsoft Teams.

“By making SharePoint pages first-class experiences in Teams, site owners no longer have to push users to load a webpage,” Crewdson says. “Instead, they can reach their colleagues without interrupting the flow of work.”

“The initial feedback we are seeing from internal and external customers is super exciting. Our users clearly see the value in how these capabilities help reduce the painful manual work needed today while still maintaining human control of the final output and decision.” 

Kripal Kavi, principal GPM, OneDrive and SharePoint

These AI-driven innovations are transforming SharePoint and empowering organizations to manage and share knowledge more efficiently and effectively than ever. At Microsoft Digital, we’ve already experienced their benefits. As AI-powered features in SharePoint continue to evolve, employees and site owners alike can look forward to even more engaging, productive, and streamlined experiences across Microsoft 365.

“The initial feedback we are seeing from internal and external customers is super exciting,” Kavi says. “Our users clearly see the value in how these capabilities help reduce the painful manual work needed today while still maintaining human control of the final output and decision.

Key takeaways

Try out these tips based on our experience at Microsoft Digital to start using SharePoint’s AI-driven features effectively.

  • Rethink knowledge management: Discover how AI agents can leverage your organization’s knowledge as context to deliver engaging experiences using sources ranging from legacy content to yesterday’s team meeting.
  • Promote peer-to-peer support: Enable your site owners to build a consistent community of practice through tools like Microsoft Viva Engage and Microsoft Teams channels.
  • Encourage experimentation: Provide these features to your SharePoint site owners and page creators, and deliver concerted change management efforts so they can build experience and start to see their effects.
  • Consider your users: Think about the business personas and scenarios where these features will be most useful, and highlight them in your change management efforts.

Try it out

Want to explore AI-powered features in SharePoint? Get started with a free trial of Microsoft 365.

The post Keeping our content fresh, findable, and governed at Microsoft with AI-powered SharePoint appeared first on Inside Track Blog.

]]>
21811
The agentic future: How we’re becoming an AI-first Frontier Firm at Microsoft http://approjects.co.za/?big=insidetrack/blog/the-agentic-future-how-were-becoming-an-ai-first-frontier-firm-at-microsoft/ Thu, 13 Nov 2025 18:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=20918 The rate of change for AI tools and technology continues to accelerate, and new opportunities to reimagine business processes and employees’ day-to-day work are emerging. Agents are the force driving this evolution forward. Agents are specialized AI tools built to handle specific processes or solve business challenges. Within Microsoft Digital, the company’s IT organization, we’re […]

The post The agentic future: How we’re becoming an AI-first Frontier Firm at Microsoft appeared first on Inside Track Blog.

]]>
The rate of change for AI tools and technology continues to accelerate, and new opportunities to reimagine business processes and employees’ day-to-day work are emerging. Agents are the force driving this evolution forward.

Agents are specialized AI tools built to handle specific processes or solve business challenges. Within Microsoft Digital, the company’s IT organization, we’re responsible for unlocking their potential internally at Microsoft.

A photo of Fielder.

“This is a generational opportunity. The pace of change is only increasing, and we’re committed to experimenting, learning, and leading the way to the deeper possibilities that agentic AI represents.”

Brian Fielder, vice president, Microsoft Digital

As Customer Zero, we serve as the company’s first and best users of new technologies. It’s our role to confirm that they’re business-ready and establish best practices that others can follow.

We’re doing that by empowering our team here in Microsoft Digital to supercharge their work with AI agents. At the same time, we’re the custodians of the employee experience of employees at Microsoft, so we’re actively guiding deployment and adoption efforts for AI tools across the business.

“This is a generational opportunity,” says Brian Fielder, vice president of Microsoft Digital. “The pace of change is only increasing, and we’re committed to experimenting, learning, and leading the way to the deeper possibilities agents represent.”

By following our lead, you can chart your own course to the agentic future, where employees and agents work as teams to achieve more together.

Our vision for agents and the AI-first future of IT

A new organizational blueprint is emerging. It blends machine intelligence with human judgment to create systems that are AI-operated but human-led.

We call it becoming an AI-first Frontier Firm.

Enterprise IT maturity

Explore our series that walks through how to become a Frontier Firm IT organization in the era of agents.

  1. Becoming a Frontier Firm: Our IT playbook for the AI era
  2. Enterprise AI maturity in five steps: Our guide for IT leaders
  3. The agentic future: How we’re becoming an AI-first Frontier Firm at Microsoft (this story)
  4. AI at scale: How we’re transforming our enterprise IT operations at Microsoft

The path to the frontier is starting to reveal itself already. As organizations progress through different phases of AI maturity, they move from foundational Microsoft 365 Copilot capabilities through escalating levels of agentic complexity.

First, humans operate with an assistant like Copilot. Then, human-agent teams work together. But the future lies in humans leading teams of digital workers: AI agents that perform core labor with relative autonomy.

Becoming a Frontier Firm

AI maturity starts at simple AI assistance, then progresses to more complex patterns between humans and agents.

This progression reflects the levels of agentic complexity represented by simple retrieval agents, then knowledge and action agents, and finally workflow reinvention through agents that can perform fully autonomous actions to complete end-to-end business processes. The human-led, agent-operated teams that will drive Frontier Firms forward depend on this advanced stage of agentic maturity.

As the tools used to build agents rapidly mature, we’ve observed that teams can experience these patterns simultaneously. In this rapidly changing environment, it makes sense to think of these as processes that can be targeted to specific business outcomes.

Soon, Frontier Firms will have employees experiencing each of these patterns daily, leveraging the best pattern to complete the task at optimal quality and in the least amount of time. Every business challenge or opportunity is unique, so it makes sense to choose the right tool for the job.  

At Microsoft, we’ve been unlocking opportunities throughout this Frontier Firm curve. At the simpler end of the spectrum, we’re empowering our employees to create their own custom retrieval agents and boosting enterprise knowledge sharing using simple SharePoint agents.

A photo of Heath

“AI agents are an entirely new kind of tool that presents possibilities we’re only beginning to realize. We capture that potential through a disciplined, rigorous, repeatable process of continuous improvement.”

Tom Heath, senior business program manager, Microsoft Digital

We’re also creating more complex agents that affect processes at the team, division, or even company-wide level. They include our autonomous Employee Self-Service Agent designed to enable modern support on key HR IT, and real estate issues, delivering operational excellence through AIOps, and supporting engineers as they manage complex network environments.

In our role as Customer Zero for the company’s agentic solutions, we in Microsoft Digital work closely with Microsoft’s product groups to ensure that our internal usage insights are helping to shape our products to make them more effective for our customers. This is something we do, so our customers don’t have to.

They also ensure we implement these new tools safely and effectively. That’s important, because AI isn’t without its challenges.

We need to minimize risk by using AI responsibly and securely according to our Responsible AI Principles. We need to assuage AI hesitancy among employees and equip them with the skills they need to succeed. Most importantly, we need to use intentional continuous improvement practices to ensure we apply AI’s potential to processes that drive genuine value.

“AI agents are an entirely new kind of tool that presents possibilities we’re only beginning to realize,” says Tom Heath, senior business program manager for Microsoft Digital.  “We capture that potential through a disciplined, rigorous, repeatable process of continuous improvement.”

The opportunities are worth the effort.

As a company, we surveyed leaders working at Frontier Firms. We found that they’re more likely to say their company is thriving, they’re able to take on more work, and they’re more optimistic about future opportunities than the global average.

All those benefits depend on moving toward agentic maturity.

Lessons learned deploying agents at Microsoft

As Customer Zero, our team within Microsoft Digital is already making progress on agent-based workflows, and the patterns and strategies we’re using can help you on your own journey. Like other digital investments, deploying agents depends on the critical pillars of governance, implementation, change management, measurement, and support.

Culture is also a crucial factor.

AI transformation is about unlocking human potential, not replacing it. So, meeting human needs while reaping the benefits of more intelligent tools is paramount.

Agents’ disruptive potential makes getting these elements right even more important.

Governance and AI-ready data

Our Microsoft 365 Copilot deployment acted as proving ground for governing AI and ensuring our data estate is ready for intelligent tools. We’ve applied our learnings from that experience to agents.

The first and most important lesson is ensuring you have a strong data hygiene foundation for employees to build and use agents. AI-ready data rests on five pillars: Unification, connection, quality and governance, accessibility to all, and the ability to accelerate time to value.

A photo of Hasan

“Thanks to our early experiences with Copilot Studio, we’ve been able to develop gates and controls based on the type of agents that creators want to build.”

Aisha Hasan, Power Platform and Copilot Studio product manager, Microsoft Digital

Agents offer powerful opportunities to enhance employee productivity, but they also introduce risks. For example, how do we keep privileged information where it belongs? How do we keep employees from building agents that violate company policies? And how can we balance the freedom to create agents with the need to prevent sprawl?

Our response has been a matrixed approach to governing agents, where we apply policies and procedures based on an array of attributes.

Examples of agentic attributes that require different governance policies

Method of creation

Microsoft365 Copilot Chat, SharePoint agent builder, Copilot Studio lite experience, Copilot Studio, or other pro-code tools

What users can build

Knowledge-only, retrieval, task, or custom agents

Technical proficiency

No-code, low-code, or pro-code

Knowledge sources

These include SharePoint, external websites, and internal sources via graph connectors.

Sharing and publishing

Personal networks via link, SharePoint, Microsoft Teams, the Copilot Chat catalog, or broad publishing for lines of business or the company as a whole

Reviews

Ranging from no reviews for knowledge-only agents to thorough reviews around security, privacy, accessibility, and responsible AI for custom agents published as Teams apps.

Fortunately, we have tools—many of which we built ourselves—that are helping us keep the company safe as we navigate our agentic transformation. We’re using them to establish and manage our data, keep our confidential information confidential, and protect our data from unauthorized access, misuse, or disclosures. Microsoft Purview is our primary vehicle for handling data governance.

Finally, rules and a lifecycle for agents are helping us combat sprawl and the risks associated with ownership, access, and identity. The enterprise lifecycle is the model for this work, and attestation is essential for accountability. These structures also include an agent catalog to track these tools and help determine what kinds of AI agents our employees can “hire” as digital workers to help them get their work done.

Structuring your implementation

Implementing AI tools and agents is largely about who, what, and how. For us, it comes down to creating policies that manage which employees can use or create certain agents and how we permit those agents to work within the company.

Our matrixed approach to agent creation

Employees

Personal agents with access to services and data sources they already use

Teams

Quickly building agents with known lower-risk patterns to accelerate business processes

Line-of-business and enterprise agent creators

A smooth release path for engineering teams based on our review structure for other professionally developed internal applications

To land on these policies, we considered what out-of-the-box agents in Microsoft 365 can accomplish, what employees in non-engineering roles can safely and easily create for themselves using no-code or low-code tools, and what agents demand the greater experience of AI developers using pro-code applications. Options include simple agents created in Microsoft SharePoint agent builder or Copilot Studio experience lite, then more complex tools like Microsoft Power Platform, Copilot Studio, Azure AI Foundry, and more—each governed, protected, and overseen by its own policies and procedures.

With these policies in place, implementing agents at scale depends on determining the best opportunities for value.

“Thanks to our early experiences with Copilot Studio, we’ve been able to develop gates and controls based on the type of agents that creators want to build,” says Aisha Hasan, Power Platform and Copilot Studio product manager for Microsoft Digital. “Through predetermined groups and rules, we can allow freedom and experimentation at different scales without putting our internal tenant at risk.”

At Microsoft, continuous improvement provides us with a mechanism for discovering which processes to optimize through agentic workflows, then implementing and tracking those changes. This framework helps us reimagine processes as deterministic state machines to enable digital colleagues that complete workflows on employees’ behalf.

Driving adoption through change management

Change doesn’t happen automatically, especially when a new technology fundamentally alters ways of working. At Microsoft, the message is clear: Regardless of your role, there’s an agent for every task.

We have a global change team operating according to Prosci’s ADKAR model combined with the Microsoft 365 Adoption Guide. At the same time, we recognize that there is no one-size-fits-all adoption campaign, so we take efforts to tailor adoption to specific regions and internal organizations.

We’ve taken a multi-pronged approach to adoption, communications, community, and skilling that relies heavily on Microsoft Viva. Communications center on raising awareness, driving engagement, and encouraging feedback while tracking adoption.

Each Microsoft Viva app has a role to play, but Viva Engage has been the most impactful. It provides opportunities for organic connections that enhance employees’ knowledge and ability while providing opportunities to share successes and inspiration.

Adoption communications focus both on encouraging usage of ready-made agents and encouraging employees to create their own using the right tools for their level of technical capability. Campaigns include an ongoing “Agent of the month” series, spotlighting experimental agent releases, how-to content for agent builders, and promotional efforts for enterprise agents that occupy central places in business processes.

The Analyst and Researcher agents built into Copilot are ideal ways to introduce your employees to the power of agents, and “Agent Mode” in Word and Excel can make agentic workflows more intuitive through integration into the tools your employees are already using every day.

  • Analyst uses chain-of-thought reasoning like a skilled data scientist to progress through problems iteratively, taking as many steps as necessary to refine its reasoning and provide a high-quality answer.
  • Researcher helps employees tackle multi-step research at work—delivering insights with greater quality and accuracy than previously possible. It combines OpenAI’s deep research model with Microsoft 365 Copilot’s advanced orchestration and deep search capabilities.
  • Agent Mode in Microsoft Word and Excel transforms how users create documents or spreadsheets by enabling a more interactive and collaborative experience with AI. Instead of just generating responses to single prompts, Agent Mode allows users to engage in a multi-step process where they can guide the AI through various tasks, making document creation or data analysis more intuitive and efficient.

Building the AI habit takes time, but encouraging usage of these pre-built AI agents is the perfect way to accelerate your journey to the frontier.

At every stage of our AI transformation so far, we’ve experienced the power of peer-led adoption efforts.

Our Copilot Champs Community, a team of AI enthusiasts, early adopters, and eager learners, has been incredibly effective both at providing examples of AI usage and supporting change management initiatives run by our Microsoft Digital organization.

Camp Copilot represented our first runaway success in grassroots, peer-led AI skilling. This three-week learning event gave our Copilot Champs an opportunity to showcase emerging best practices in a structured, gamified setting and reached thousands of employees. We’ve recently followed that with a Copilot Expo, which expanded on Camp Copilot with more learning around agents and a templatized format we deployed to different regions and divisions.

As we shift our focus from Copilot adoption to agentic innovation, we’re also evolving our community strategy.

Our Copilot Champs Community is still a vital source of leadership and guidance, but now we’ve augmented its role with the Builders Community, a new group tailored to sharing knowledge and inspiration around creating agents.

It’s also important to have mechanisms in place that guide employees as our company’s agentic maturity increases.

We are accelerating innovation through agent and automation templates that employees and teams are applying to their own scenarios. On top of those resources, our AI Center of Excellence and a dedicated continuous improvement function are helping our teams think through their opportunities, ensure they capture value, and maintain security.

Measuring impact to demonstrate value

Measuring the impact of AI tools has been a unique challenge, and we’re only at the beginning of our journey. That’s especially true for agents.

The Experience Insights dashboard for Microsoft 365 admin center helps our technology decision makers gather information about product usage, feedback, and employee views of help articles. Crucially, this tool allows people outside of our IT apparatus to gain limited, compliant access to adoption data, which supports more effective change management efforts within their scope.

We’ve also devised several measurement areas and key metrics we can track using the Microsoft Digital AI Value Framework. They include:

  • Revenue impact: Direct contributions to revenue generation and business growth.
  • Productivity and efficiency: Efficiency gains while completing tasks and processes without a reduction in quality.
  • Security and risk management: Improvements in identifying, preventing, and managing security vulnerabilities and risks.
  • Employee and customer experience: The impact of AI initiatives on employee satisfaction, engagement, and productivity.
  • Quality improvement: Enhancements in the quality of deliverables, services, and processes.
  • Cost savings: Reduction in operational costs and resource allocation efficiencies.

As our company has dedicated more attention and resources to an AI and continuous improvement framework, these value drivers have become guiding lights for ideating and executing AI initiatives—and most importantly, tracking them. Methodologies like Bowler scorecards and monthly operating reviews align perfectly with our learn-it-all culture to help us measure and adjust AI projects to align them with our business goals more effectively.

Enabling effective support for agents

When you enter an unprecedented new phase of technology, anticipating the support employees need can be difficult. Our role as Customer Zero has been essential for making sure we have enough experience to properly understand the issues that arise from implementing agents.

Our employees in Microsoft Digital have been some of the company’s first movers on agentic AI initiatives. Through our initial experience, we’ve gradually built up our knowledge and widened access to equip support professionals with everything they need to enable employees.

Within Microsoft Digital, we established a solid support base by progressing through seven steps:

  1. Preliminary access: We selected our initial support specialists, including people with different Microsoft 365 app focuses, support tiers, and service audiences.
  2. Communication hub: We created a community space where our support team could connect and collaborate on issues and invited non-support professionals as needed.
  3. Knowledge base: We created a collaborative document where we added learnings, which eventually evolved into our knowledge base for internal support.
  4. Widening access: We hosted information sessions with the wider support team and extended access so all relevant support professionals could ramp up.
  5. Rehearsal: Role-playing and shadowing sessions helped teams build practical knowledge and confidence.
  6. Go-live support: We prepared our support resources and processes and pushed them live in advance of our deployment.
  7. Tracking: A pre-determined tracking cadence for gathering data on incidents helps support teams identify trending issues and tickets.

Pushing the frontier forward with agentic AI

It’s clear that agents will be the major driving force behind modern workflows. The AI-first Frontier Firm will be the defining blueprint of this next era.

“The future of IT is increasingly about experimentation and adaptation to accelerating AI technologies. We take our role as Customer Zero seriously, and that means boldly experimenting with agentic AI and leading this next transformation for our company and our customers.”

Brian Fielder, vice president, Microsoft Digital

Knowing the future that awaits, our Microsoft Digital team will continue to explore, experiment, and share what we’ve learned. We want to discover pathways to greater human potential, powered by AI agents.

“The future of IT is increasingly about experimentation and adaptation to accelerating AI technologies,” Fielder says. “We take our role as Customer Zero seriously, and that means boldly experimenting with agentic AI and leading this next transformation for our company and our customers.”

Key takeaways

The lessons we’ve learned throughout our unfolding agentic AI transformation can help you start your own journey:

  • Build a solid foundation for governance: Take stock of your data hygiene and ensure your general governance policies are sufficiently robust before deploying agents widely.
  • Consider the who, what, and how: Think carefully about how to structure agent creation across different toolsets, levels of complexity, sharing options, and more.
  • Find and engage your peer leaders: Create a community tailored to agent exploration and peer-led adoption support and promote their work among your employees.
  • Use a multi-pronged adoption strategy: A good strategy will include a mix of centralized communications, peer-driven leadership, learning events, and asynchronous opportunities. Don’t forget measurement and opportunities for feedback.
  • Determine your metrics for success: Identify the impact you want to drive with agents, isolate them into primary value drivers, and cascade those down into key metrics.
  • Build toward successful support: Use your technical team’s experience during pilots and early implementation to build a base for effective support material.

The post The agentic future: How we’re becoming an AI-first Frontier Firm at Microsoft appeared first on Inside Track Blog.

]]>
20918
Keeping our in-house optical network safe with a Zero Trust mentality http://approjects.co.za/?big=insidetrack/blog/keeping-our-in-house-optical-network-safe-with-a-zero-trust-mentality/ Thu, 16 Oct 2025 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=20611 When it comes to corporate connectivity at Microsoft, a minute of lost connection can lead to catastrophic disruptions for our product teams, sleepless nights for our network engineers, and millions of dollars of lost value for the company. That’s why we built our own optical network at our headquarters in Washington state, and that’s why […]

The post Keeping our in-house optical network safe with a Zero Trust mentality appeared first on Inside Track Blog.

]]>
When it comes to corporate connectivity at Microsoft, a minute of lost connection can lead to catastrophic disruptions for our product teams, sleepless nights for our network engineers, and millions of dollars of lost value for the company.

That’s why we built our own optical network at our headquarters in Washington state, and that’s why we’re building similar networks at other regional campuses around the United States and the rest of the world.

With so much on the line, we need to make sure these in-house networks never go down.

But how are we doing that?

We’re applying the same robust Zero Trust approach we take to security and identity. While our optical networks are extremely reliable, any complex system can be knocked offline. In alignment with the Zero Trust mentality we have as a company, we trusted the integrity of what we’ve built, but we needed a resilient backup system that went beyond redundancy to provide true resilience.

Driven by this goal, we created a Zero Trust Optical Business Continuity Disaster Recovery (BCDR) network that combines two fully independent optical systems designed to sustain uninterrupted services, even during systemic failures. The result is more confidence for our employees and vendors, less pressure on our network engineers, and comprehensive network resilience that will protect us against a major outage.

The urgency of resilience

In 2021, our team in Microsoft Digital, the company’s IT organization, deployed our first next-generation optical network to serve the exclusive network needs of our Puget Sound metro campuses. It offers more bandwidth on less fiber for a lower operational cost than leasing from traditional carriers.

“Puget Sound is a highly concentrated developer network where we need to provide very high throughput,” says Patrick Alverio, principal group software engineering manager for Infrastructure and Engineering Services within Microsoft Digital. “Our optical system is the backbone of all that traffic.”

Our state-of-the-art optical network fulfills our need for fast and reliable connectivity at up to 400 Gbps between core sites, labs, data centers, and the internet edge. We built this network on the Reconfigurable Optical Add/Drop Multiplexer (ROADM) technology, delivering dynamic reconfiguration, colorless, directionless, contentionless (CDC) capabilities, flexible grid support, remote provisioning, and automation. It also features a full-mesh topology that provides a layer of redundancy.

But what if the entire ROADM-based system fails?

There are plenty of operational risks that can derail even the most robust network. Anything from misconfigured automation scripts to policy changes to misaligned software versioning to simple human error can cause outages.

A photo of Elangovan

“We don’t want even a second of downtime. We needed a life raft for when failures occur that could also function as a standby network for core site migrations or platform upgrades.”

Vinoth Elangovan, senior network engineer, Hybrid Core Network Services, Microsoft Digital

To some degree, those kinds of minor disruptions are inevitable. But catastrophic events like fiber cuts, failures in the ROADM operating system, or even natural disasters have the potential for even more wide-ranging disruption.

During a catastrophic outage, thousands of engineers, developers, researchers, and other technical employees who need access to crucial lab environments and data centers could lose connectivity. That can sabotage feature delivery, disrupt product patches, interrupt updates, and halt all kinds of core product functions.

On top of normal software development operations, new AI tools demand massive bandwidth and consistent uptime. Finally, our hybrid networks feature paths integrated with Microsoft Azure that consume on-premises resources, so they also stand to benefit from increased resilience.

A catastrophic network outage can cause incredible damage to all of these business functions. In fact, we experienced exactly that in 2022.

A fiber cut combined with a ROADM system hardware reboot caused a five-minute outage at our Puget Sound metro region. In this environment, every minute of lost connectivity can result in significant financial impact, making network resilience absolutely essential.

“We don’t want even a second of downtime,” says Vinoth Elangovan, senior network engineer, who designed and implemented the Zero Trust Optical BCDR network for Microsoft. “We needed a life raft for when failures occur that could also function as a standby network for core site migrations or platform upgrades.”

Delivering greater network resilience

To ensure we could deliver uninterrupted network connectivity even in the midst of a catastrophic outage, we needed to consider the technical demands of a truly resilient system. Five design pillars helped us assemble our architectural criteria:

  1. Independent optical systems: To provide true resilience, our primary and BCDR platforms needed to operate autonomously.
  2. Physically independent paths: Circuits should avoid shared conduits, fibers, and splices to operate completely independently.
  3. Separate control software: The primary and backup networks should operate through dedicated network management systems (NMSs), automation, and provisioning domains.
  4. Unified client interface: Both systems needed to terminate into the same interface to unify service for clients and applications.
  5. Survivability by design: We couldn’t assume that any system would be immune to failure. Instead, we built for the best possible outcomes.

The result was the Zero Trust Optical BCDR architecture, a layered approach to optical networking. It consists of our primary, ROADM-based transport layer and a secondary, MUX-based transport layer, both terminating into a single logical port channel.

“Our core responsibility is the employee experience, so our main design thrust was making sure service is seamless and uninterrupted—even during an outage.”

Vinoth Elangovan, senior network engineer, Hybrid Core Network Services, Microsoft Digital

Both systems are live and active, which means they deliver production services through their own independent fibers, power supplies, and software stacks. By layering fully independent optical domains and logically unifying them at the Ethernet edge, the network can sustain a complete failure of one system and maintain continuity.

That physical and operational independence is the difference between simple redundancy and robust resilience.

“Our core responsibility is the employee experience, so our main design thrust was making sure it’s seamless and uninterrupted—even during an outage,” Elangovan says.

Optical network backed by a BCDR network

A schematic of an optical network running between different nodes and backed up by a BCDR network.
The optical network in our Puget Sound region connects core sites to labs, datacenters, and the internet edge, while the BCDR network provides backup connections to deliver resilience in case of a catastrophic network failure.

A typical ROADM optical network connects campus and data center sites to the internet edge. Our design features three interconnected optical rings, with two internet edges as multi-directional nodes, while other sites operate as dual-degree nodes with bidirectional redundancy. Meanwhile, our campuses and datacenters are designated as critical sites and equipped with Optical BCDR links to ensure enhanced resiliency. In the event of a complete Optical ROADM line failure, these critical sites retain connectivity.

In the event of an outage on the primary network, the port channel handles forward continuity automatically, shifting WAN traffic between optical paths in real time.

The transition occurs seamlessly and transparently, with no noticeable impact to clients.

A photo of Martin

“Our initial goal was to provide high-throughput connectivity for major labs, with less than six minutes of downtime per year. That represents a service level of 99.999% network continuity, and we’re aiming for even better moving forward.”

Blaine Martin, principal engineering manager, Hybrid Core Network Services, Microsoft Digital

Coupling at the Ethernet layer provides clients and applications with one logical interface, automatic load balancing and traffic distribution, and seamless failover, regardless of which optical domain is providing service.

“Our initial goal was to provide high-throughput connectivity for major labs, with less than six minutes of downtime per year,” says Blaine Martin, principal engineering manager for Hybrid Core Network Services in Microsoft Digital. “That represents a service level of 99.999% network continuity, and we’re aiming for even better moving forward.”

A new era of confidence for network engineers

For the network engineers who keep Microsoft employees and resources connected, the Zero Trust Optical BCDR network relieves much of the pressure that comes from resolving outages.

“Before, we were dependent on a single system, even with redundancies, so the human experience was like firefighting. Now, if the primary optical network is having a problem, I don’t even see it.”

Kevin Bullard, principal cloud network engineering manager, Microsoft Digital

When a network goes down, engineers have an enormous set of responsibilities to manage: processing the incident report, assigning severity, performing checks, notifying internal teams, providing updates, and engaging with physical support teams—all with a profound urgency to restore productivity.

Dialing those pressures back has been a huge benefit.

“Before, we were dependent on a single system, even with redundancies, so the human experience was like firefighting,” says Kevin Bullard, Microsoft Digital principal cloud network engineering manager responsible for maintaining WAN interconnectivity between labs. “Now, if the primary optical network is having a problem, I don’t even see it.”

There will always be pressure on network engineers to restore connectivity during an outage, but they can breathe easier knowing it won’t cost the company millions of dollars as the time to resolve ticks away. And in non-emergency situations like core site migrations, the BCDR network provides a much easier way to shunt services while the main network is offline.

“Our internal users have become more confident that they can stay connected, no matter what,” says Chakri Thammineni, principal cloud network engineer for Infrastructure and Engineering Services in Microsoft Digital. “That gives the people responsible for maintaining our enterprise networks incredible peace of mind.”

Fortunately, there hasn’t been a substantial network outage in the Puget Sound metro area since 2022. But our network engineering teams know that if and when it happens, the BCDR network will be ready to maintain service continuity.

A photo of Alverio.

“We’re always looking ahead into industry trends to stay at the bleeding edge, whether that’s in the technology we provide for our customers or the networks we use to do our own work.”

Patrick Alverio, principal group software engineering manager, Infrastructure and Engineering Services, Microsoft Digital

With our Puget Sound network protected, we have plans in place to extend this model to other metro areas. Naturally, we have to balance population, criticality, and the knowledge that elevated reliability and availability come with a cost.

Our selection criteria for new BCDR networks have largely centered around two factors: expansions of AI-critical infrastructure and concentrations of secure access workspaces (SAWs) for technical employees. With these criteria in mind, we’re planning new BCDR networks first in the Bay Area and Dublin, then in Virginia, Atlanta, and London.

Zero Trust optical BCDR architecture represents a paradigm shift in enterprise network resilience, and we’re committed to expanding the model to benefit both conventional workloads and the expanding infrastructure demands of AI.

“We’re always looking ahead into industry trends to stay at the bleeding edge, whether that’s in the technology we provide for our customers or the networks we use to do our own work,” Alverio says. “We refuse to accept the status quo, and we’re elevating the experience for employees across Puget Sound and Microsoft as a whole.”

Driving AI innovation in optical network resilience

Our journey towards an AI-driven optical network is gaining momentum.

As part of our Secure Future initiative, we’ve automated our Optical Management Platform credential rotation and are actively developing intelligent incident management ticket enrichment, auto-remediation, link provisioning, deployment validation, and capacity planning.

AI plays a central role in this transformation.

With Microsoft 365 Copilot and GitHub Copilot integrated into our engineering workflows, we’re accelerating development cycles, improving code accuracy, and uncovering optimization opportunities that would otherwise take hours of manual effort.

These Copilots are also helping our engineers analyze network patterns, simulate outcomes, and validate deployment logic before execution, reducing human error and strengthening our Zero Trust posture. Over time, we’re evolving toward a system where AI not only assists but proactively predicts potential disruptions, recommends remediations, and continuously learns from operational telemetry.

These advancements are paving the way for a future where our optical infrastructure can anticipate issues, recover faster, and operate with the agility and assurance expected in a Zero Trust environment.

Key takeaways

If you’re considering implementing your own optical and BCDR networks, consider these tips:

  • Understand the technical components of resilience: Independent optical systems, physically independent paths, separate control software, a unified client interface, and survivability by design are the key technical components of true resilience.
  • Plan from a preparedness and value perspective: Evaluate the critical points in your infrastructure and determine where you can get the most value out of resilient connectivity.
  • Ensure your teams have the right skillset: Carefully consider the right workforce to run those systems and be accountable for their operation.

The post Keeping our in-house optical network safe with a Zero Trust mentality appeared first on Inside Track Blog.

]]>
20611
Enabling meaningful AI adoption at Microsoft with a Microsoft 365 Copilot Expo http://approjects.co.za/?big=insidetrack/blog/enabling-meaningful-ai-adoption-at-microsoft-with-a-microsoft-365-copilot-expo/ Thu, 09 Oct 2025 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=20562 As our employees incorporate AI into their day-to-day routines, new ways of working are emerging at Microsoft. People are using Microsoft 365 Copilot as their personal AI assistant and employing agents to power new workflows. Meanwhile, our teams are building and deploying AI-powered solutions to meet our enterprise needs. But advancing along the AI maturity […]

The post Enabling meaningful AI adoption at Microsoft with a Microsoft 365 Copilot Expo appeared first on Inside Track Blog.

]]>
As our employees incorporate AI into their day-to-day routines, new ways of working are emerging at Microsoft.

People are using Microsoft 365 Copilot as their personal AI assistant and employing agents to power new workflows. Meanwhile, our teams are building and deploying AI-powered solutions to meet our enterprise needs.

But advancing along the AI maturity curve means more than just adoption. It’s about fundamentally reworking our daily habits to boost productivity and empower our AI assistants to help us accomplish meaningful work.

At Microsoft, we’re dedicated to helping our employees weave Copilot and other AI tools into the fabric of their workdays. To get there, we’ve used the lessons from our early skilling efforts and our experience with peer-to-peer adoption leadership as the foundation for a new learning path.

This is the story of Copilot Expo.

A new approach to skilling

Thanks to the success of our Camp Copilot adoption efforts, we learned valuable lessons about rolling AI out across a company like ours.

We took what we learned working with our champ community and turned it into a more formal Microsoft 365 Copilot adoption program that evolved into an extended company-wide event called Copilot Expo. Our change leaders within Microsoft Digital, the company’s IT organization, drove this three-week online skilling path with the support of our dedicated community of AI peer leaders, the Copilot Champs.

A photo of Kerametlian.

“We saw daily adoption move a lot more when we were presenting content that was bespoke to people’s roles and organizations.”

Stephan Kerametlian, business program management senior director, Microsoft Digital

As AI technology matured, we knew we needed to update our skilling offerings along with it. Some key lessons helped us make that a reality:

  • AI adoption is about more than monthly active usage (MAU) and daily active usage (DAU). It’s about depth of engagement with the tools.
  • Peer leadership is a must. Seeing people you know use a tool makes it much more accessible and attainable.
  • Gamification was one of the most successful features of our early efforts, so we knew we needed to deepen those elements.
  • Making content on-demand extends the life of an event like this, leading to easier knowledge discovery and further engagement.
  • Company-wide initiatives are powerful, but divisions crave events tailored to their work, on their teams, in their disciplines.

“We saw daily adoption move a lot more when we were presenting content that was bespoke to people’s roles and organizations,” says Stephan Kerametlian, a business program management senior director within Microsoft Digital. “Copilot Expo was able to go a lot deeper into different roles and processes to make Copilot more real in people’s day-to-day jobs.”

Copilot Expo: Advancing along the AI maturity curve

Copilot Expo extended throughout three weeks, with plenty of opportunities for learning at different levels of AI maturity.

Our curriculum included three main sessions for the week. To accommodate different time zones with live presentations instead of recordings, each of those sessions took place three times across 12 hours. After each main session, breakouts expanded on their themes, highlighting different areas of Microsoft 365 Copilot.

Some breakouts covered day-in-the-life scenarios that resonated with a wide cross-section of employees, but we also tailored use cases to more specific disciplines and tasks. As a result, the learning path included more role-specific breakouts like “Copilot for Product Managers,” more technical topics outside Copilot like GitHub and Azure DevOps, and more advanced learning like deep dives on prompting.

To help land the lessons for the week, we offered gamified experiences on Microsoft Viva Engage. These activities typically involved a creative prompting exercise, which participants would then share with their Viva Engage communities. As an added bonus, the social aspect helped drive further groundswell for Copilot Expo.

A photo of Kneip.

“Peer influence can scale further and faster than policy alone. Employees show a lot more interest in content their colleagues create than material handed down from IT or adoption professionals.”

Cadie Kneip, readiness business program manager, Microsoft Digital

The sheer number of sessions meant we needed to expand the involvement of Microsoft Digital subject matter experts and change leaders, but it was absolutely essential that we involve our Copilot Champs and maintain the peer-to-peer aspect that made Camp Copilot such a success.

Why?

Because we find that our employees respond well when a respected colleague shows them how to do something or shares why they are excited to try something new.

“Peer influence can scale further and faster than policy alone,” says Cadie Kneip, a readiness business program manager within Microsoft Digital. “Employees show a lot more interest in content their colleagues create than material handed down from IT or adoption professionals.”

When participants completed the learning path, we handed out awards, shared resources, and provided opportunities for feedback. All of these elements helped employees feel a sense of accomplishment while providing our adoption team with valuable insights.

We also updated our key metrics around Copilot usage and sentiment. To make sure these metrics demonstrated meaningful change, we tracked them for comparable periods both before and after Copilot Expo.

Gamification drives deeper engagement

When we developed the plan for Copilot Expo, we knew gamification was one of the most powerful levers we could pull. Not only does it provide a fun way for participants to practice the skills they’ve learned, but it boosts retention and uptake.

Our internal research suggests that fun and gamification amplify engagement by 24% and increase productivity by 50%. They also reduce the time it takes to form habits by 40%.

A photo of Hausfelder.

“You need to think about the activities you can do to inspire your employees to recognize the value AI can hold for their work.”

Sandra Hausfelder, global adoption lead, Microsoft Digital

One of the most exciting components was a live leaderboard featuring participants’ avatars and gamertags created using Microsoft 365 Copilot. The dashboard assigned people points when they completed different components of the curriculum, and the friendly competition boosted engagement through a sense of pride.

We also increased the number of gamified activities that took place throughout the learning path. Yet again, our presenters and peer-to-peer leaders provided essential support, and we were able to crowd-source many of these gamification ideas.

Gamified activities included:

  • Creating a new digital avatar by prompting Microsoft 365 Copilot.
  • Building a unique superhero.
  • Writing a song with Copilot’s assistance.
  • Creating digital swag by designing an enamel pin.
  • Going on a scavenger hunt by trying out 10 Copilot scenarios.

“You need to think about the activities you can do to inspire your employees to recognize the value AI can hold for their work,” says Sandra Hausfelder, a global adoption lead for Copilot in Microsoft Digital.

At the end of Copilot Expo, we offered MVP badges designed using Credly for everyone who completed all the necessary steps. In addition to solidifying the learning with a final motivator, providing a badge encouraged participants to share their journey with their networks, further promoting Copilot Expo as an opportunity for professional growth.

Decentralization and on-demand learning

One of the most important aspects of Copilot Expo is its capacity for extending learning opportunities beyond our centralized event series. We’re accomplishing that in two ways.

First, we make all of our Copilot Expo content available on demand as part of a persistent SharePoint page accessible to both participants and non-participants. These resources aren’t just for passive discovery. We also use them for active adoption efforts like our “Copilot Daily Discoveries” campaign on Microsoft Viva Engage.

Since the end of Copilot Expo, employees have accessed these resources thousands of times—even people who didn’t participate in the event series itself. That demonstrates a real hunger for opportunities to learn about AI.

The greatest potential impact may come from decentralizing this learning model. Company-wide events can only do so much to bridge time zones, languages, and discipline-specific scenarios.

As a result, we’ve designed a system for enabling more tailored events within individual regions and Microsoft divisions. Essentially, we’ve templatized the Copilot Expo experience, and leaders can reach out to the Microsoft Digital team to help assemble and run their own events with more customized learning paths.

Building momentum with activities

A graph of the 2025 Copilot Expo Timeline, Pre-Expo, Master Copilot basics, Champs week, Build your daily habits, Make it real.
We generated interest and enthusiasm for trying Copilot with this cadence of activities.

We start by conducting discovery sessions and interviews that uncover how employees might use Microsoft 365 Copilot in their roles. We also look at existing usage metrics and identify Copilot Champs who can act as advisors and ambassadors.

“We have a baseline package of material, and then we partner with organizational executives and change leaders who want to bring it to their own teams,” Kneip says. “Then we work with Copilot Champs to tailor it to their organizations.”

These focused events typically take shape as three-day learning paths. They tend to cover similar elements to the company-wide expo across the basics, leveling up, and building daily habits. The difference is that they’re highly scenario-specific.

For example, we might provide example scenarios for the Cloud + AI team, like “Give me suggestions for optimizing our next datacenter.” On engineering-heavy teams, we might focus on opportunities for AI in the software development lifecycle.

“Every mini-expo looks a little bit different because we customize it to the organization,” Hausfelder says. “We work hard to create a span of customization by looking into the details of what the organizations need us to land for their employees.”

Continuous impact through more effective adoption

Whether they’re division-based or specific to a region, these learning paths have been highly effective. In one instance, we ran a three-day event specific to Central America and the Caribbean. That led to a 15% increase in DAU and a 17% increase in week-over-week Microsoft 365 Copilot usage.

A photo of Alexandra Jones

“Copilot Expo sets us up for success in the future, because it’s a delivery mechanism for employees, by employees, scaled through Copilot Champs.”

Alexandra Jones, director of business programs, Microsoft Digital

Our company-wide Copilot Expo also demonstrated substantial impact. Before-and-after tracking of key metrics over equivalent testing periods revealed substantial boosts:

  • Average DAU increased substantially.
  • Copilot-assisted hours climbed sharply.
  • Copilot actions taken jumped significantly.
  • Copilot-assisted value nearly doubled.
  • The perception of the quality work done with Copilot measurably increased.

It’s a testament to the power of coordinated efforts that reach across the company as a whole and resonate with individual organizations.

“We’ve created this persistent platform as a recognizable brand for skilling, and it enables us to continue driving change,” says Alexandra Jones, a director of business programs within Microsoft Digital. “Copilot Expo sets us up for success in the future, because it’s a delivery mechanism for employees, by employees, scaled through Copilot Champs.”

Key takeaways

Adopt the lessons we’ve learned during the Microsoft Copilot Expo to successfully run your own AI skilling event.

  • Listen to stakeholders: Collaborate with organizational insiders to think about the gaps they see and the content that will be relevant to their teams.
  • Design your content for discovery: Evolve your offerings to be more self-serve and self-directed while maintaining crucial opportunities for connection.
  • Start small and apply the lessons you learn: Begin with a pilot. Bring eager adopters together and run a small and focused expo.
  • Gamification gets results: People take delight in demonstrating progress and participation. Incorporate badges, certifications, leaderboards, and other elements of fun.
  • Identify your key metrics: Don’t just think about usage percentage. Focus on metrics that really demonstrate value. Examples include the number of actions, Copilot-assisted hours, and sentiment.

Try it out

Get step-by-step instructions for creating an engaging Microsoft 365 Copilot training series with our Copilot Virtual Skilling Event Framework.

The post Enabling meaningful AI adoption at Microsoft with a Microsoft 365 Copilot Expo appeared first on Inside Track Blog.

]]>
20562