Inside Track Blog http://approjects.co.za/?big=insidetrack/blog/ How Microsoft does IT Fri, 21 Aug 2026 23:57:24 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.4 137088546 Enhancing Microsoft network reliability with AIOps and Network Infrastructure Copilot http://approjects.co.za/?big=insidetrack/blog/enhancing-microsoft-network-reliability-with-aiops-and-network-infrastructure-copilot/ Thu, 20 Aug 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25154 In today’s rapidly evolving technology landscape, maintaining network reliability is paramount. Our team in Microsoft Digital, the company’s IT organization, keeps the company connected and maintains foundational network services for all our employees and guests. With an environment comprising 100,000 network devices (including access points) and over 900 buildings (including data centers), which supports 350,000 […]

The post Enhancing Microsoft network reliability with AIOps and Network Infrastructure Copilot appeared first on Inside Track Blog.

]]>
In today’s rapidly evolving technology landscape, maintaining network reliability is paramount. Our team in Microsoft Digital, the company’s IT organization, keeps the company connected and maintains foundational network services for all our employees and guests.

With an environment comprising 100,000 network devices (including access points) and over 900 buildings (including data centers), which supports 350,000 users and over 1 million connected devices generating 300,000 incidents per year, traditional methods of network management can often be insufficient.  

To operate at this scale, we’re building and deploying AI solutions that help us manage our network more efficiently, respond to issues faster, and reduce manual work. This is a critical part of our role as the team that’s responsible for powering, protecting, and transforming our digital employee experience across devices, applications, and hybrid infrastructure at Microsoft.

A photo of Fielder.

“As the organization that acts as Customer Zero for the company, we are leading with AI to help power Microsoft and keep things like our network infrastructure secure and reliable. We must aggressively experiment and adopt AI agents to foster innovation and model the future of service engineering.”

Brian Fielder, vice president, Microsoft Digital

Within Microsoft Digital, our AIOps and Network Infrastructure Copilot (NiC) AI solutions have emerged as transformative new tools for enhancing network performance. These tools take advantage of AI-powered capabilities by turning data and knowledge into powerful insights and, eventually, meaningful actions to run the industry’s most secure and reliable enterprise network. They also share a common data architecture comprised of millions of telemetry points but perform unique AI functions in both running and supporting the network.

AIOps is an automation solution that uses data insights to prevent and resolve network issues before they become impactful. NiC is an interactive experience that helps network practitioners, and a variety of other personas more easily interact in natural language with complex network services to get rapid answers and intelligent suggestions.  

“As the organization that acts as Customer Zero for the company, we are leading with AI to help power Microsoft and keep things like our network infrastructure secure and reliable,” says Brian Fielder, vice president of Microsoft Digital. “We must aggressively experiment and adopt AI agents to foster innovation and model the future of service engineering.”

AIOps: Transforming how we deliver operational excellence 

AIOps integrates AI into our IT operations by automating and enhancing various aspects of network management. This approach significantly reduces manual intervention, allowing network engineers to focus on higher-value tasks. Key components of AIOps include: 

  • Automated ticketing and remediation: AIOps automates the creation and resolution of tickets, reducing the time and effort required to manage incidents. This automation is particularly beneficial in environments with high ticket volumes, ensuring timely and efficient resolution of network issues. 
  • Ticket noise reduction: AIOps uses AI-powered ticket correlation, suppression, and enrichment capabilities to significantly reduce ticketing noise, enabling engineers to concentrate on the most critical issues.  
  • Automatic remediation: AIOps executes automatic troubleshooting and remediation actions on behalf of engineers to mitigate issues and keep outage duration and the associated business impact to a minimum. This is accomplished based on troubleshooting knowledge and successful remediation steps executed. 
  • Postmortem report generation: AI-powered tools generate detailed postmortem reports for network incidents, providing insights into the root causes and recommended remediation steps. This capability enhances the learning process and helps prevent future occurrences. 
A graphic shows the AIOps pipeline, from ingesting data; to observing, engaging, and acting on data; to driving results that improve service help and reduce manual effort.
The AIOps pipeline shown here includes the following steps: Collecting operational data, analyzing it with AI, generating insights, and using agentic automation to improve service health and reduce manual effort.

Network Infrastructure Copilot (NiC): The everyday AI assistant 

NiC is an AI assistant designed to support network engineers in managing complex network environments. NiC provides powerful data insights and documentation, enabling engineers to design, configure, analyze, and troubleshoot network issues using natural language queries. Key features of NiC include: 

  • Data insights: NiC helps engineers extract valuable data insights from various sources, such as wikis, SharePoint libraries, troubleshooting guides, and the infrastructure data lake (IDL). This capability streamlines data analysis and enhances decision-making to take impactful actions. 
  • Network artifacts interpretation: NiC understands key artifacts such as device logs and configurations, providing engineers with concise and relevant information. This capability greatly reduces the cognitive load on engineers to access and process the most critical data and insights required to manage a complex network environment. 
  • Simplified network observability: NiC enables non-networking personas (such as conference room technicians and facilities managers) to get quick glances at the health and configuration of their services without requiring deep understanding of network protocols and taxonomies. 
A photo of Suver.

“NiC and other AIOps agents have dramatically reduced the time engineers spend searching through documentation and other network artifacts to yield actionable insights, slashing effort from 25 minutes to under 5 minutes.”

Phil Suver, principal group product manager, Microsoft Digital
Network Copilot provides the ability to summarize network health, analyze data, allow for plug-ins, summarize documentation and wikis, and generate incident ops reports.
Network Copilot was created with the flexibility to access different data sources and handle a variety of network engineering workflow tasks.

“NiC and other AI Ops agents have dramatically reduced the time engineers spend searching through documentation and other network artifacts to yield actionable insights, slashing effort from 25 minutes to under 5 minutes,” says Phil Suver, a principal group product manager in Microsoft Digital.

A photo of Meduri.

“By staying close to our teams’ real needs, we were able to turn AI opportunities into practical solutions, delivering near-term value while laying the groundwork for lasting innovation.”

Anand Meduri, principal PM manager, Microsoft Digital

Driving impact through AIOps and next-gen AI agents 

These AI-driven solutions have significantly improved network reliability in several ways: 

  • Efficiency gains: The automation of routine tasks and the provision of actionable insights have drastically reduced the cognitive load on network engineers. In recent years, network practitioners have cumulatively saved over 20,000 hours on network infrastructure management. These efficiency gains free up engineers to focus on strategic initiatives that further enhance network performance.
  • Rapid issue detection and resolution: AI-powered anomaly detection and automated remediation ensure that potential issues are identified and resolved before they impact network performance. This proactive approach minimizes downtime and enhances overall network reliability.

“By staying close to our teams’ real needs, we were able to turn AI opportunities into practical solutions, delivering near-term value while laying the groundwork for lasting innovation,” says Anand Meduri, a principal PM manager for Microsoft Digital.

Lessons learned in building and deploying AIOps agents

To deliver sustainable business value at enterprise scale, we adopted an iterative approach focused on rapid experimentation, measurable outcomes, and continuous learning. As we evolved from automation-centric operations to an agent-driven operating model, three major themes emerged:

A photo of Moitra.

“By embedding AIOps and AI agents into our operational fabric, we are transforming manual workflows into autonomous, scalable digital labor. This is accelerating our journey toward a human-led, Frontier Firm future.”

Suvodip Moitra, senior product manager, Microsoft Digital
  • Prioritization and value realization: Not every workflow benefits equally from AI. We achieved the greatest impact by focusing on high-volume, repetitive, and time-sensitive operational activities such as incident triage, outage analysis, troubleshooting, and cross-system coordination. Prioritizing these use cases enabled us to demonstrate tangible productivity gains while building confidence in agent-led operations.
  • Human-agent collaboration and change management: The transition to agentic operations required more than technology adoption—it demanded new ways of working. Success depended on positioning agents as trusted digital teammates, augmenting engineers rather than replace them. Continuous feedback loops, user engagement, and incremental rollout strategies were critical to help us drive adoption and improve agent effectiveness over time.
  • Scalability, autonomous operations, and the Frontier Firm future: As our operational footprint continues to grow, we are moving from automated workflows to a scalable ecosystem of intelligent AI agents that can reason, coordinate, and act across the incident lifecycle. By embedding agents such as Smart Bonding, Outage Insights, and On-Demand Troubleshooting into daily operations, we are reducing human toil, accelerating resolution, and laying the foundation for a Frontier Firm operating model where engineers focus on strategy and innovation, while digital labor drives operational execution at scale.

“By embedding AIOps and AI agents into our operational fabric, we are transforming manual workflows into autonomous, scalable digital labor,” says Suvodip Moitra, a senior product manager in Microsoft Digital. “This is accelerating our journey toward a human-led, Frontier Firm future.”

Key takeaways

As we scaled our AI-driven network operations, we learned important lessons around automation, resilience, adoption, and enterprise readiness:

  • Network operations have shifted from reactive response to intelligent automation. The combination of AIOps, AI agents, and Network Infrastructure Copilot (NiC) has evolved network operations from reactive management to intelligent automation, reducing engineer toil through actionable insights, autonomous workflows, and streamlined decision-making.
  • AI is accelerating issue resolution while improving reliability. AI-powered correlation, anomaly detection, troubleshooting, and agent-led remediation help identify, diagnose, and resolve issues faster, improving reliability while minimizing operational disruption and downtime.
  • Efficient AI adoption depends on more than just technology. Successfully scaling AIOps, NiC, and AI agents requires strong change management, continuous feedback loops, targeted training, and iterative refinement to drive adoption and maximize business value.
  • Enterprise scale requires both resilient infrastructure and intelligent agents. Building for enterprise scale requires an architecture capable of supporting growing device and incident volumes, while at the same time enabling a network of intelligent agents that lays the foundation for a Frontier Firm operating model driven by human-led, AI-powered operations.

Try it out

Related links

The post Enhancing Microsoft network reliability with AIOps and Network Infrastructure Copilot appeared first on Inside Track Blog.

]]>
25154
From AI assistant to capable teammate: How Copilot Cowork is changing the way we work at Microsoft http://approjects.co.za/?big=insidetrack/blog/from-ai-assistant-to-capable-teammate-how-copilot-cowork-is-changing-the-way-we-work-at-microsoft/ Thu, 20 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25150 Most workdays don’t fall apart because employees lack ideas. Instead, challenges arise between intention and execution. What employees need is a way to set executional engines in motion so they can focus on higher-level work, stepping in only when necessary. At Microsoft, we’ve been working to close that gap with a new kind of agent: […]

The post From AI assistant to capable teammate: How Copilot Cowork is changing the way we work at Microsoft appeared first on Inside Track Blog.

]]>
Most workdays don’t fall apart because employees lack ideas. Instead, challenges arise between intention and execution. What employees need is a way to set executional engines in motion so they can focus on higher-level work, stepping in only when necessary.

At Microsoft, we’ve been working to close that gap with a new kind of agent: Copilot Cowork. Rather than a strict instruction-and-response approach, Cowork has taken the leap to multi-step action across an employee’s Microsoft 365 environment.

From task assistants to true digital coworkers

For years, the promise of AI at work has centered on task assistance, like creating drafts quickly, delivering better summaries, and providing faster answers. But knowledge retrieval isn’t partnership.

A photo of Kerametlian

“Cowork really sheds light on the art of the possible when it comes to agents, without the need for employees to build them for themselves. It has ignited people’s imagination around what agents can do.”

Stephan Kerametlian, senior director, Microsoft Digital

In Microsoft Digital, the company’s IT organization, we’ve been pursuing deeper impact for AI. We want agents to work alongside our employees, take on multi-step tasks, and produce real outputs, all while keeping the humans that direct their work in the loop.

Copilot Cowork represents that shift. It behaves less like a chatbot and more like a capable teammate that plans, executes, and checks in as it goes along.

“Cowork really sheds light on the art of the possible when it comes to agents, without the need for employees to build them for themselves,” says Stephan Kerametlian, a senior director in Microsoft Digital. “It has ignited people’s imagination around what agents can do, and it helps them understand that they don’t need to be a developer to get high-quality outputs very quickly.”

Microsoft 365 Copilot agents

Copilot Cowork is just one of the agents available through Copilot. Each is most effective in a specific set of scenarios.

Using Copilot Cowork to move from conversation to action

We created Copilot Cowork for workflows that span multiple steps, people, and applications. While traditional chat experiences answer questions or generate content, Cowork can interpret a request, create a plan, gather relevant context, and carry work forward over time.

A photo of Malekar.

“Work IQ packages relevance, ranking, and context into something AI can actually act on. It understands who you work with, what you’re working on, and which content matters in a given situation, helping the AI identify the right material and infer the steps needed to deliver an outcome.”

Swapna Malekar, principal product manager, Microsoft Digital

This agent can develop documents, coordinate meetings, generate research, create web applications, and manage ongoing tasks. It also provides visibility into its progress and requests approval before taking sensitive actions.

Key capabilities of Copilot Cowork

Multi-step plan execution
Handles entire workflows by breaking complex requests into steps across apps​

Approval checkpoints
Allows for full oversight with approval before sensitive actions: pause, resume, or cancel anytime​

Scheduled and recurring tasks
Automates regular workflows by running prompts on a schedule​

Cloud-native execution
Enables continual progress in a sandboxed cloud environment when the employee’s device is unavailable​

Built-in skills

  • Executes on common productivity and enterprise tasks across Microsoft Word, Excel, and PowerPoint, including PDF document creation, editing, and formatting
  • Handles email, scheduling, and calendar and meeting management in Outlook and Teams
  • Offers support for up to 20 custom skills

Work IQ, Microsoft’s intelligence layer for enterprise context, is the foundation of these capabilities. It helps Cowork understand relevant files, meetings, chats, collaborators, and organizational signals so that the agent can identify the right information for the task at hand. Cowork then uses that context to determine the steps needed to deliver the requested outcome.

“Work IQ packages relevance, ranking, and context into something AI can actually act on,” says Swapna Malekar, a principal product manager in Microsoft Digital. “It understands who you work with, what you’re working on, and which content matters in a given situation, helping the AI identify the right material and infer the steps needed to deliver an outcome.”

Our employees are already using Cowork to tackle work that would otherwise require multiple prompts and applications. With a single request, they can create presentations, establish Teams chats for collaboration, schedule recurring follow-up activities, begin building strategy documents, and more.

Cowork can also pull together emails, chats, documents, and news sources into a briefing or transform existing content into an interactive web experience. Throughout the process, employees can refine the work, answer clarifying questions, and approve actions before Cowork moves forward.

Helping employees embrace this watershed moment

During early adoption efforts for Cowork, we learned that successful usage depends as much on behavior change as on technology. Employees who approached Cowork simply as a better chatbot often saw incremental gains.

A photo of Glattbach.

“Cowork introduces a new way of thinking about work, where you hand off a complex task, close your computer, and the work continues on your behalf. For adoption specialists, the goal is to help employees recognize where that capability fits naturally into their day.”

Petra Glattbach, senior business program manager, Microsoft Digital

People who learned to think in terms of outcomes uncovered far more value. Instead of asking for a draft, they delegated a process. Instead of requesting a summary, they assigned a research task with a defined deliverable.

Agent Launchpad is an instructional program we’ve designed to develop our employees’ agentic AI skills. This effort, alongside other readiness resources, is encouraging people to identify recurring workflows, experiment with multi-step requests, and refine their collaboration techniques over time.

“Cowork introduces a new way of thinking about work, where you hand off a complex task, close your computer, and the work continues on your behalf,” says Petra Glattbach, a senior business program manager in Microsoft Digital. “For adoption specialists, the goal is to help employees recognize where that capability fits naturally into their day.”

This process isn’t about replacing existing ways of working overnight. It’s helping employees recognize where a digital coworker can reduce manual effort, accelerate execution, and create more time for higher-value work.

Boosting our role as Customer Zero with Cowork

Based on our experience as Customer Zero, the most effective Cowork users start with a real business problem and then explore how an agent can help solve it to drive core business outcomes.

For Jody Ryan, principal cloud solution architect for Microsoft 365 Copilot AI Business Solutions, Cowork quickly became part of her daily workflow. She’s used it to build interactive HTML experiences, create adoption sites, and rapidly prototype customer-facing concepts during live conversations.

“Cowork has become a powerful partner in my day-to-day work, helping me turn information into action so I can be more present, proactive, and impactful with my customers.”

Jody Ryan, principal cloud solution architect, Microsoft 365 Copilot AI Business Solutions

In one scenario, Cowork helped her transform a customer discussion into a working web prototype that she refined in real time based on live feedback. Going from whiteboarding to prototype to Agent was a natural progression that helped her customers visualize the real impact of Microsoft’s agentic capabilities.

One of the greatest surprises for Ryan was how much she enjoyed the customizable approach to human-in-the-loop approval checkpoints. For example, Cowork will find a time for a meeting, build a deck, and draft the invite email, but then pause for her review before sending it out. It’s all about identifying patterns of work and enabling Cowork to be part of them.

“Cowork has become a powerful partner in my day-to-day work, helping me turn information into action so I can be more present, proactive, and impactful with my customers,” Ryan says.

Employees in all kinds of roles across Microsoft are echoing Ryan’s experience. People are feeling the genuine evolution that agents like Cowork represent.

The skills we’ve learned over the last three years have been leading to this moment. By demonstrating the tangible impacts of AI through adoption initiatives, celebrating wins, and setting employees free to explore and create AI solutions to business challenges, we’ve positioned ourselves to capitalize on this next leap into more advanced AI tools.

One of our most important lessons has been that cultivating an AI-ready workforce throughout our Frontier Transformation journey has built a sense of confidence and capability with AI. Now that true agentic partnership is a possibility, that journey has prepared our people to get the most value out of tools like this.

The next chapter in the agentic workplace

The response to Copilot Cowork within Microsoft has taken us through an inflection point where AI has moved beyond assistance and into genuine execution. Our internal adoption efforts clearly demonstrate that shift.

A photo of Fielder.

“When agents can reason over organizational knowledge and then take action on our behalf, they become a powerful force for productivity and a critical aspect of how we lead Frontier Transformation.”

Brian Fielder, vice president, Microsoft Digital

Within three weeks of its internal release, Cowork had 20,000 users. Employees are actively exploring new ways to use the agent, from streamlining meeting preparation and follow-up work to creating content, conducting research, and managing complex projects.

We’ve learned that different teams often have different uses for different agents. But Cowork is emerging as a tool that can accommodate efforts reaching across a wide array of apps, data sources, workflows, and scenarios.

That’s a big shift, and employees are excited. Interest has been so strong that we’re expanding our enablement efforts, including new, Cowork-focused learning experiences within Agent Launchpad.

As we continue to evaluate Cowork, product feedback is helping us improve reliability, strengthen connections to enterprise data and external systems, and refine the quality of outputs. Even though it’s still in the early stages, teams are finding that Cowork can reduce administrative burden and help work move faster.

“Work IQ is helping unlock a new era where AI can understand the context behind our work, not just the content,” says Brian Fielder, vice president of Microsoft Digital. “When agents can reason over organizational knowledge and then take action on our behalf, they become a powerful force for productivity and a critical aspect of how we lead Frontier Transformation.”

For us at Microsoft, Cowork is more than a new agent. It’s providing a glimpse into a new future of work, where digital coworkers help employees focus more of their time on the aspects of their job that matter most.

Key takeaways

Here are some things to consider as you prepare your organization to make the most of Copilot Cowork:

  • Start with the work, not the technology. The most successful AI adoption happens when employees apply agents to real business challenges, recurring tasks, and daily workflows. Cowork becomes most valuable when people connect its capabilities to their own work context.
  • Think in outcomes, not prompts. Multi-step agents introduce a new way of working. Instead of asking AI to complete one task at a time, employees can delegate an entire process and then collaborate with the agent as work progresses.
  • Learn from others. Social learning accelerates adoption. Sharing examples, use cases, and lessons learned helps employees discover new possibilities and build confidence using agentic AI in their own roles.
  • Keep a human in the loop. Approval checkpoints, visibility into progress, and ongoing guidance enable employees to delegate work while maintaining accountability and trust.
  • Context drives better outcomes. Work IQ helps agents understand the relationships between people, content, meetings, conversations, and organizational knowledge, allowing for more relevant actions and results.
  • Experiment continuously. AI capabilities are evolving rapidly. Rather than trying to keep up with every new development, regularly revisit the tools available and look for new opportunities to apply them to your work.
  • Treat agents as coworkers, not tools. The greatest gains come when employees view agents as collaborators that can take ownership of meaningful work, freeing people up to focus on judgment, creativity, and decision making.

Try it out

  • Ready to try Copilot Cowork? You can access the agent through the Microsoft Frontier program. Start today.

Related links

The post From AI assistant to capable teammate: How Copilot Cowork is changing the way we work at Microsoft appeared first on Inside Track Blog.

]]>
25150
From AI ambition to enterprise execution: Our Customer Zero journey http://approjects.co.za/?big=insidetrack/blog/from-ai-ambition-to-enterprise-execution-our-customer-zero-journey/ Thu, 20 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25145 For many organizations, the next phase of AI is to move beyond vision and into execution. Most leaders understand the opportunity that AI presents, but turning that ambition into meaningful, repeatable impact across the business remains difficult. At Microsoft, we’ve found that sharing our AI transformation stories—especially how individuals and teams have harnessed the power […]

The post From AI ambition to enterprise execution: Our Customer Zero journey appeared first on Inside Track Blog.

]]>
For many organizations, the next phase of AI is to move beyond vision and into execution. Most leaders understand the opportunity that AI presents, but turning that ambition into meaningful, repeatable impact across the business remains difficult.

At Microsoft, we’ve found that sharing our AI transformation stories—especially how individuals and teams have harnessed the power of AI to address common business, technical, and operational challenges—is the key to accelerating our customers’ AI transformation. As Customer Zero, we test our technology, products, and approaches in-house first, then use the lessons learned to help our customers get the most out of technology.

A photo of Bardeen.

“AI transformation only becomes real when it becomes part of how work gets done. Our role is to lead with our own experience and share what we’re learning, so our customers can move faster from ambition to execution.”

Lorraine Bardeen, corporate vice president, Microsoft Frontier Company

Working across numerous teams at Microsoft, we’re building a library of reusable evidence and lessons learned. These will enable our customers to go from experimentation to operational impact with greater speed and confidence.

In our experience, progress came from prioritizing the best AI use cases, grounding them in real workflows, and building repeatable patterns that teams could trust. That principle shapes our Customer Zero strategy, which is to bring those patterns together so that customers can learn from the same questions about AI that we’ve been working through internally here at Microsoft, including:

  • Where to start
  • How to build confidence
  • How to govern consistently
  • How to turn isolated wins into a sustainable, AI-powered competitive advantage

“AI transformation only becomes real when it becomes part of how work gets done,” says Lorraine Bardeen, corporate vice president of the Microsoft Frontier Company. “Our role is to lead with our own experience and share what we’re learning, so our customers can move faster from ambition to execution.”

This is why our Customer Zero insights are so important: They’re a direct channel for sharing what our teams here at Microsoft are learning as we apply AI in the day-to-day work of sales, operations, supply chain, finance, customer service, software engineering, IT, and other business functions.

Turning learnings into practice

Shortening the distance between strategy and execution for our customers and giving them concrete examples of what scale looks like in practice is a key mission for our Customer Zero team. Our goal is to help readers start with our larger Microsoft AI transformation story and then move to focused examples, role-specific lessons, and practical assets that can be adapted for their own organizations.

The leadership lens is part of what makes our Customer Zero journey valuable, showing customers how organizations can build momentum through funding the right priorities, exercising practical governance, and facilitating change management that helps people adopt new ways of working.

“The most important thing you can do is create a clear, funded set of priorities in an AI operating model,” Bardeen says. “And those priorities need to be supported by human-centered change and adoption.”

Our AI transformation stories make that guidance tangible by illustrating how specific teams at Microsoft approached familiar business problems, what and how they changed, and actionable insights that customers can apply to their own businesses.

AI transformation at scale

The result is an evidence base that shows how we transformed, so you can learn from our journey across all three of the patterns we’ve identified within Frontier transformation:

Across each of these patterns, we seek to answer a critical question: What does AI transformation actually look like when it successfully moves beyond pilots and into enterprise-scale operations?

Here are examples of each of these patterns in action, along with what we’ve learned as Customer Zero in deploying, managing, and leveraging these solutions across Microsoft.

Human with assistant

In Microsoft Customer Service and Support, new technical support engineers no longer have to spend weeks getting up to speed before they can contribute with confidence. Instead, they work on real customer cases from the start, with an AI assistant embedded directly in their workflow. The assistant surfaces relevant knowledge, recommends next steps, and helps guide decision making in the moment. In our Customer Zero pilots, onboarding competency assessments were completed up to 3.3 times faster.

The lesson is simple but powerful: Learning is more effective when it happens in the flow of work, where employees can build skills while solving real problems.

Human-agent teams

Our supply chain planners have traditionally spent hours comparing demand signals, reviewing forecasts, and analyzing scenarios before making decisions. Today, agents automate much of that work. Planners can interact with the system using natural language and rapidly explore different options.

The primary benefit is faster, higher-quality planning decisions. By automatically comparing demand plans, surfacing meaningful changes, and explaining their impact through natural language and visualizations, the agents reduce the effort required to analyze planning data. Planners spend less time gathering and reconciling information and more time evaluating exceptions and responding to changes in demand. Internal telemetry estimates the solution saves up to 80 hours per planning cycle.

Our Customer Zero experience here reinforced that the quality of the user experience matters. Simple changes, like adding richer visualizations, helped make agent-assisted planning easier to understand and encouraged broader use across teams.

Human-led, agent-operated

In Microsoft Finance, AI agents are helping collections teams move faster and make better decisions. Connected to SAP and Dynamics 365, agents can predict late payments, identify potential customer disputes, categorize and summarize cases, route inquiries to the right owner, and provide AI-generated recommendations that help teams focus on the highest-priority work.

By reducing the manual effort required to assess customer accounts and resolve issues, the AI solution has cut case-handling time by 22 percent and reduced customer inquiry-handling times by as much as 60 percent. Collection teams are resolving inquiries up to 2.5 times faster, while improved automation and decision support helps accelerate quote-to-cash processes, contributing to a 48 percent reduction in time from quote to deal close. The result is not just time savings, but faster customer responses, improved operational efficiency, and more capacity for our finance professionals to focus on the activities that have the highest business impact.

Across all these scenarios, a consistent pattern has emerged: The biggest gains come when AI is embedded into established processes, supported by strong governance, and designed around the realities of daily work.

“Our responsibility is to lead by doing—and to share those lessons openly. Customer Zero is how we help our customers turn AI from opportunity into operational reality.”

Lorraine Bardeen, corporate vice president, Microsoft Frontier Company

Moving faster with greater confidence

While our journey is far from over, we’ve already identified numerous practical themes for leaders who are ready to embrace AI transformation within their own organizations. That is the promise of Customer Zero: to share our own operational lessons with customers while those lessons are still timely enough to be useful.

“Our responsibility is to lead by doing—and to share those lessons openly,” Bardeen says. “Customer Zero is how we help our customers turn AI from opportunity into operational reality.”

For organizations trying to move from AI ambition to enterprise execution, the guidance you’ll find here will reduce uncertainty and accelerate progress. Microsoft is still learning, and that’s part of the point. By sharing practical evidence from across our business as it happens, we can help our customers move faster with greater confidence, better context, and a clearer sense of what transformation looks like in the real world.

Key takeaways

Here are some tips and guidance that can help your organization undergo AI transformation, based on our own Customer Zero experience at Microsoft:

  • Start with a business problem that people recognize in their daily work. Transformation gains traction when it addresses friction employees already feel, whether that is fragmented data, slow preparation, inconsistent coaching, or uncertainty about how to use a new tool.
  • Make leadership visible. Executive sponsorship matters most when leaders model the behavior, share what they are learning, and help teams make tradeoffs.
  • Build trusted foundations. Whether the foundation is data, governance, or change support, scale is hard to sustain when the basics are inconsistent. “Shift left” to ensure your foundations are solid before you start to build the proverbial house.
  • Design for the flow of work. The most effective experiences in Microsoft’s own journey have reduced switching and lessened the amount of translation people have to do before they can act. AI is most useful when it meets people where they already work.
  • Treat listening as part of the operating model. The best programs did not launch and then freeze. They improved because teams kept gathering feedback, refining the experience, and adjusting based on real usage.

Try it out

Related links

The post From AI ambition to enterprise execution: Our Customer Zero journey appeared first on Inside Track Blog.

]]>
25145
Empowering employees after the call: Enabling and securing Microsoft Teams meeting data retention at Microsoft http://approjects.co.za/?big=insidetrack/blog/empowering-employees-after-the-call-enabling-and-securing-microsoft-teams-meeting-data-retention-at-microsoft/ Thu, 13 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25075 Microsoft Teams meetings help our globally distributed and digitally connected employees create meaningful hybrid work experiences. When those meetings are recorded and transcribed, or their data becomes available to AI-powered digital assistants, their value extends far beyond the meeting itself. Once captured, meeting data becomes a source of organizational knowledge that helps employees catch up […]

The post Empowering employees after the call: Enabling and securing Microsoft Teams meeting data retention at Microsoft appeared first on Inside Track Blog.

]]>
Microsoft Teams meetings help our globally distributed and digitally connected employees create meaningful hybrid work experiences. When those meetings are recorded and transcribed, or their data becomes available to AI-powered digital assistants, their value extends far beyond the meeting itself.

Once captured, meeting data becomes a source of organizational knowledge that helps employees catch up on discussions, revisit decisions, track commitments, and surface unresolved issues. AI-powered experiences such as Microsoft 365 Copilot and Work IQ can connect insights across meetings, helping teams understand how conversations, decisions, and workstreams evolve over time and ensuring important information doesn’t get lost.

Although these features have proven to be incredibly useful to our employees and our wider organization, there are also concerns about how retaining Microsoft Teams meeting data and AI insights might affect our security posture, records retention policy, and privacy. Just like any other company, we at Microsoft must balance these different factors accordingly.

At Microsoft Digital, the company’s IT organization, we’re leading cross-disciplinary conversations on this topic to help ensure that we get it right.

The value of Teams meeting data

Within a meeting, the Microsoft 365 Copilot sidebar experience helps our late-joining employees catch up on what they’ve missed, provides intelligent prompts to review unresolved questions, summarizes key themes, and creates notes or action items.

A photo of Jensen.

“The value of a meeting should not end when the meeting ends. Transcription and AI help transform conversations into durable knowledge—making decisions easier to find, commitments easier to track, and information easier to access for everyone who needs it.”

Chanda Jensen, senior product manager, Microsoft Digital

The benefits of AI in meetings extend beyond the live meeting experience as well. When meeting content is available after the meeting, AI can transform conversations into accessible organizational knowledge. Transcripts and underlying documentation—including, notes, decisions, and action items—enable participants to revisit discussions, catch up on missed meetings, verify decisions, and accelerate follow-up work.

Our Microsoft Teams meeting data retention efforts focus on three key categories of artifacts: Underlying documentations, transcripts, and the AI-generated artifacts that help power Microsoft 365 Copilot and Work IQ experiences.

Microsoft Teams meeting data and AI artifact retention

Meeting recordings

90-day Teams meeting expiration policy

  • Cloud video recording
  • Audio
  • Screen-sharing activity

Transcripts

90-day Teams meeting expiration policy

  • Transcript
  • Captions

AI-generated meeting artifacts

90-day Teams meeting expiration policy

  • Meeting summaries and intelligent recaps
  • Notes, decisions, and action items
  • Copilot interactions (queries and responses)
  • Insights and organizational knowledge derived from meeting content

Transcription provides the underlying documentation that makes these AI-powered experiences possible. By making transcription and AI capabilities available in meetings while preserving organizer, administrative, compliance, and sensitivity controls, organizations can choose how these capabilities are used while enabling users to benefit from more effective collaboration and knowledge retention.

“The value of a meeting should not end when the meeting ends,” says Chanda Jensen, senior product manager in Microsoft Digital. “Transcription and AI help transform conversations into durable knowledge—making decisions easier to find, commitments easier to track, and information easier to access for everyone who needs it.”

Policy considerations for meeting data retention

The value of these tools is clear, but data-retention obligations also play an important compliance role that organizations like ours need to consider.

A photo of Heade.

“When individuals generate recordings or other artifacts during meetings, we tend to think of them as an individual’s data, but they actually represent the company’s data. We want to empower individuals, but we have to remember the retention and volume impacts of these artifacts on the company can be substantial.”

Rachael Heade, director of records compliance, Microsoft Corporate, External, and Legal Affairs (CELA)

First, producing and retaining this kind of data can be complex if it isn’t governed properly. For us at Microsoft, this data represents day-to-day general business practices that elevate productivity, and factors such as security and privacy must be considered when managing it. Second, data-rich artifacts like video recordings require a lot of space, quickly eating up cloud storage budgets.

“When individuals generate recordings or other artifacts during meetings, we tend to think of them as an individual’s data, but they actually represent the company’s data,” says Rachael Heade, director of records compliance in Microsoft’s legal division. “We want to empower individuals, but we have to remember the retention and volume impacts of these artifacts on the company can be substantial.”

In light of these potential impacts, some organizations simply opt out of enabling Microsoft Teams meeting recordings.

Asking the right questions to assemble the proper guardrails

Leaders in Microsoft Digital and Corporate, External, and Legal Affairs (CELA), our legal division, are working to balance the benefits of Microsoft Teams meeting data retention with our compliance obligations, aiming to provide empowering experiences for our employees while also keeping company data safe.

“Organizations are always concerned about centralized control over the retention and deletion of data artifacts,” Heade says. “You have excited employees who want to use this technology, so how do you set them up so they can use it confidently?”

Like many policy conversations, getting this right starts with the governance team in Microsoft Digital and our internal partners asking employees from across the company who are responsible for data governance the right questions:

  • When should a meeting be recorded and when shouldn’t it?
  • What kind of data gets stored?
  • Who can initiate recording, and who can access it after the meeting?
  • How long should we retain meeting data?
  • Where does the data live while it’s retained?
  • How can we control data capture and retention?
  • What does this mean for eDiscovery management?

These questions help us think about the proper data-retention guardrails. Our IT perspective is only one part of the puzzle, so we’re actively consulting with CELA, corporate security, privacy, the Microsoft Teams product group, the company’s data custodians, and our business customers throughout this process.

A photo of Johnson.

“As an organization, this is about thinking through your tenant position and getting it to a reasonable state.”

David Johnson, tenant and compliance architect, Microsoft Digital

Our conversations have brought up distinctions that any organization should consider as they build policy around Microsoft Teams meeting retention:

  • The length of time a meeting’s data remains fresh, relevant, or useful
  • Consideration of the difference between AI-generated archival content versus the full meeting transcript
  • The different risks inherent with recordings compared to transcriptions
  • Establishing default policies while allowing limited variability and flexibility when employees require it

“As an organization, this is about thinking through your tenant position and getting it to a reasonable state,” says David Johnson, tenant and compliance architect in Microsoft Digital.

From sharing perspectives to crafting policy

Our policies around Microsoft Teams meeting data retention continue to evolve, but we’ve already implemented some highly effective practices, policies, and controls. Every organization’s situation is unique, so it’s important that you speak to your legal professionals to craft your own policies. But our work should give you an idea of what’s possible through the out-of-the-box features within Microsoft Teams.

The policies we’ve put in place represent a mix of technical defaults, meeting options, and empowering employees to make informed decisions about usefulness and privacy. They also build on the foundations of our work with sensitivity labeling, which helps secure data across our tenant.

Here are some of the practices we follow and features we use:

  • Transcript attribution opt-out gives employees agency and reassures them that we honor their privacy.
  • Recommending that employees “tell and confirm” before recording empowers and supports our people to speak up when they don’t believe the meeting should be recorded or don’t feel comfortable with this choice. Employees in the meeting can also stop the recording, if needed, or determine if automatic recording was set up but is not appropriate.
  • Visual indicators that a meeting is being recorded and that transcription has started, allowing users to request that a meeting stop being recorded or to leave the call.
  • User education, through an internal recording smart-use statement document, helps employees understand the implications of recording, when not to record, and when not to speak in a recorded call.
  • We do not use compliance recording. While compliance recording could enforce full consent collection, unmuting themselves, we decided that opt-outs and user notices provided sufficient agency to our employees.
  • We offer meeting labels that limit who can record, meaning only the organizer or co-organizer can initiate recordings for meetings labeled “highly confidential.”
  • Meeting labels are informed by content shared within the meeting. If content is shared in the meeting that has a higher label than the meeting itself, the organizer is prompted to re-label it.
  • Meeting labels are inherited and applied to all meeting artifacts, recordings, transcripts, and notes. This means that meeting knowledge remains protected, and any AI consumption of that recording will automatically inform the consumer of the sensitivity and required protections.
  • Only meeting organizers can download meeting recordings, keeping the meeting data contained and restricting sharing.
  • The default OneDrive and SharePoint meeting expiration is set to 90 days to ensure we minimize the risk of data leakage or cloud-storage bloat.
  • The default Meeting AI Archive is set to an 18-month retention policy. That allows questions and decisions from the meeting to be leveraged by the team for post-meeting insights but ensures that data is not kept forever.  
  • Deletion is applied in a consistent manner under the business general categories of our retention schedule. The schedule supports our designation of the Teams artifacts as productivity tools and resources, but not as official company records. This stance controls data volume, reduces review and production burden, and ultimately reduces risk (including security and privacy factors).

Balancing productivity with sensible data governance

At Microsoft, we apply different retention periods to different types of meeting data, based on their purpose and business value. Full meeting recordings and transcripts are governed by a default 90-day expiration policy, helping reduce privacy, security, and storage risks while ensuring employees can still benefit from recordings in the near term.

“The bottom line is that we rely on our employees to be good stewards of the company. Because we’ve got a good governance model in place for Teams and solid overall hygiene for our tenant, we’re well set up to deal with the evolution of the product and make these decisions.”

David Johnson, tenant and compliance architect, Microsoft Digital

Separately, AI-generated meeting knowledge—such as questions, decisions, and other insights extracted from meetings and used to support discovery and knowledge-sharing—can be retained for up to 18 months, allowing teams to benefit from the value of those insights long after the original transcript has expired.

These policies are designed to balance employee productivity with responsible data governance, ensuring that important information remains available when useful but is not retained indefinitely. They reflect the three core tenets we use to inform our governance efforts: empower, trust, and verify.

“The bottom line is that we rely on our employees to be good stewards of the company,” Johnson says. “Because we’ve got a good governance model in place for Teams and solid overall hygiene for our tenant, we’re well set up to deal with the evolution of the product and make these decisions.”

The net outcome of all of this work is that our organization is more confident in our approach to meeting knowledge, resulting in more meetings being recorded or transcribed and generating more valuable post-meeting artifacts.

We can’t specifically recommend that an organization follow our blueprint entirely, but asking questions similar to the ones we’ve outlined here can help you build a strong Teams data-governance foundation. With a firm grasp of the technology and close collaboration with key stakeholders, you can guide your own policy decisions and unlock more value for your employees.

Key takeaways

Here are some tips for approaching meeting data retention policies and practices at your company:

  • Face your fears and get comfortable with being a little uncomfortable. First establish your concerns about Teams data retention, then work toward optimizing your policy compliance.
  • Consider how to support your company’s compliance obligations while still allowing your employees to take advantage of the product’s data-retention features. Let those things live together side-by-side.
  • Connecting with your legal team is essential, because they’re the experts on assessing complex compliance questions. Leveraging legal expertise not only drives clarity on complex compliance questions but also allows you to surface opportunities and constraints around how and when to use meeting data features specific to your business or industry.
  • Investigate meeting labels and what policies you might want to apply to different meetings, based on sensitivity and other attributes.
  • Engage your security team to discuss how labeling and post-meeting protections can address any company security concerns.

Try it out

Related links

The post Empowering employees after the call: Enabling and securing Microsoft Teams meeting data retention at Microsoft appeared first on Inside Track Blog.

]]>
25075
Resolving repetitive support tickets at Microsoft with AI automation http://approjects.co.za/?big=insidetrack/blog/resolving-repetitive-support-tickets-at-microsoft-with-ai-automation/ Thu, 13 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25059 Across Microsoft, our product teams rely on lab environments to develop, test, validate, and troubleshoot products before they reach customers. These labs are typically made up of virtual machines (VMs) that can be quickly deployed and scaled as needed. At Microsoft Digital, the company’s IT organization, we now offer Managed Cloud Labs (formerly known as […]

The post Resolving repetitive support tickets at Microsoft with AI automation appeared first on Inside Track Blog.

]]>
Across Microsoft, our product teams rely on lab environments to develop, test, validate, and troubleshoot products before they reach customers. These labs are typically made up of virtual machines (VMs) that can be quickly deployed and scaled as needed.

At Microsoft Digital, the company’s IT organization, we now offer Managed Cloud Labs (formerly known as MyWorkspace), a self-service, Azure-based platform that enables our employees to create and manage the lab environments they need. With more than 150,000 VMs hosted in Managed Cloud Labs across the organization, keeping those environments healthy is essential to maintaining engineering productivity.

When a VM becomes unavailable, however, diagnosing the issue can require significant manual effort. Today, an engineer may begin troubleshooting by attempting to access the VM, reviewing logs, and running diagnostic commands to identify the root cause. While this process can sometimes resolve the problem, it requires the engineer to remain actively involved throughout the investigation, validating findings and testing potential fixes.

At the scale of Managed Cloud Labs, even routine VM issues can add up to a significant productivity cost. That’s why our team went looking for a way to automate troubleshooting. The answer was AI.

A photo of Bobik.

“The Troubleshooting Agent is the first integration of Azure Serial Console and AI that streamlines VM troubleshooting. It significantly reduces the toll on support engineers and speeds up problem resolution.”

Dominika Bobik, technical lead, Azure Serial Console

We and our partners on the product group side engineered a solution for Managed Cloud Labs VMs using Azure Serial Console and agentic AI. This approach—which includes an Info Agent and a Troubleshooting Agent—has been a great success, allowing engineers to identify what’s broken and repair the issue in minutes instead of hours.

“The Troubleshooting Agent is the first integration of Azure Serial Console and AI that streamlines VM troubleshooting,” says Dominika Bobik, a technical lead in the Azure Serial Console product group. “It significantly reduces the toll on support engineers and speeds up problem resolution.”

A new path for VM support issues

When we analyzed our support incidents, two recurring challenges emerged: Users needed faster answers to everyday how-to questions, and they needed a quicker path to resolution when remote access to their virtual machines via Remote Desktop Protocol (RDP) failed.

For how-to questions, the issue usually wasn’t the platform. Our employees were often blocked because they needed assistance with straightforward tasks: How to change a password, update a lab quota, or deploy a custom workspace.

A photo of Le.

“We had a lot of repetitive how-to questions, where the answers could be found in our user guide. An AI agent made more sense because as the product changes, we update the user guide—our one source of truth—and the Info Agent always provides the latest instructions.”

Thien-Y Le, senior product manager, Microsoft Digital

Connectivity issues are more disruptive. When our employees can’t use RDP to connect to a virtual machine, diagnosing the problem means checking across networks, OS configuration, and Azure infrastructure to determine which layer has failed. This typically results in a work stoppage, unless they can quicky recreate the lab.

In some cases, rebuilding a lab may take only a few minutes. However, many of our customers rely on highly customized virtual machines that have been fine-tuned over years to fit their environments. These labs are essential for investigations, troubleshooting, and development work, and rebuilding them can take much longer. Being unable to remotely access a provisioned lab can also become a critical blocker for active customer case work. These kinds of labs require immediate attention.

Those experiences shaped our Managed Cloud Labs Agent Experience solution, which pairs an Info Agent for user education and a Troubleshooting Agent for connectivity issues. The Info Agent answers how-to questions conversationally, using retrieval-augmented generation (RAG) to draw from internal documentation as well as the user guide.

“We had a lot of repetitive how-to questions, where the answers could be found in our user guide,” says Thien-Y Le, a senior product manager in Microsoft Digital. “An AI agent made more sense because as the product changes, we update the user guide—our one source of truth—and the Info Agent always provides the latest instructions.”

Automating the troubleshooting process

The Troubleshooting Agent changes the support model. When one of our engineers selects a virtual and reports an RDP problem, the agent investigates the VM, diagnoses the cause, and attempts a repair. Throughout the session, it gives the user a running summary of what it’s detecting and the actions it’s taking, making the automated work visible to the user but also “hands-free.”

When RDP or run commands are broken, our support engineers would typically turn to Azure Serial Console as an expedient path to the VM when all else fails. The Troubleshooting Agent automatically takes that same serial console path, but adding an AI agent to the process required retooling to automate the human action.

Our team built an orchestrated crew of AI agents behind that user experience. We used Microsoft Foundry to host our models and Microsoft Agent Framework to manage the overall troubleshooting workflow and orchestrate the different agents. To help with evaluations, we utilized the Azure AI Evaluation software development kit.

A session begins with programmatic checks, then moves on to a read-only diagnostic orchestrator agent that decides what information to gather and tools to use. It can query Azure resource health, call Managed Cloud Labs APIs, and route work to a specialized Windows RDP diagnostic agent that drives the serial console.

A photo of Deans.

“We deliberately break test VMs in dozens of ways and expect the Troubleshooting Agent to repair them, then run evals to make sure the fixes are safe and consistent.”

Joshua Deans, senior software engineer, Microsoft Digital

The process reads early signals. For example, if Azure resource health points to a clear problem, the orchestrator stops there instead of running more complex diagnostics. When the system identifies an issue it can safely address, an auto-repair orchestrator restarts the VM, resets a password and network interface, or sends serial console commands to correct a configuration problem. It then validates whether the fix has succeeded before closing the loop.

When the agent can’t safely resolve something, because the fix carries risk or the issue falls outside its known scenarios, it provides the full diagnostic context to the user. This context can then be given to a human support engineer, who can pick up the thread from there instead of starting over.

Making that reliable across the many Windows operating systems that Managed Cloud Labs supports took a lot of testing and careful tuning under close collaboration with the Azure Serial Console product group.

“We deliberately break test VMs in dozens of ways and expect the Troubleshooting Agent to repair them, then run evals to make sure the fixes are safe and consistent,” says Joshua Deans, a senior software engineer in Microsoft Digital.

Decreasing wait times

Our Troubleshooting Agent targets the 20% of ticket volume that comes from the common issues our support team typically resolves without escalation. The Info Agent addresses another 30% to 40%. Together, the team aims to take on about half of all ticket volume.

A photo of Deshpande.

“With the Troubleshooting Agent, the same class of issue that once took more than 90 minutes to resolve is identified in less than 10 minutes. The agent provides immediate self-remediation to reduce downtime and has become an essential part of my workflow.”

Hrishi Deshpande, senior tech support engineer, Microsoft Exchange

In the first month of using the Troubleshooting Agent, we were able to:

  • Reduce the average time to mitigate a common connectivity ticket from 16 hours to 15 minutes.
  • Save our employees more than 1,200 hours a month in wait time.

“With the Troubleshooting Agent, the same class of issue that once took more than 90 minutes to resolve is identified in less than 10 minutes,” says Hrishi Deshpande, a senior tech support engineer in Microsoft Exchange. “The agent provides immediate self-remediation to reduce downtime and has become an essential part of my workflow.”

What’s next on our journey

We intend to add tooling for firewall issues to the Troubleshooting Agent and keep expanding the orchestrator to cover more signals over time.

 A photo of Dadwal.

“Every transformative platform starts with a single capability that proves what’s possible. For us, that’s the VM Troubleshooting Agent, the foundation beneath it, and the future it unlocks.”

Vikram Dadwal, principal software engineering manager, Microsoft Digital

Our team sees the next chapter as helping inform broader Azure capabilities, so the same self-healing approach can reach anyone running Azure VMs.

“Every transformative platform starts with a single capability that proves what’s possible,” says Vikram Dadwal, a principal software engineering manager on the Managed Cloud Labs team in Microsoft Digital. “For us, that’s the VM Troubleshooting Agent, the foundation beneath it, and the future it unlocks.”

For Le, that future is about what AI is making possible for users: intelligent support that feels immediate and always within reach. She likens it to giving every user their own personal support engineer. That shift from reactive troubleshooting to proactive, self-healing support is the larger opportunity that Managed Cloud Labs is addressing.

“We envision a future where troubleshooting becomes invisible,” Le says “It’s a world where systems automatically identify and remediate issues, eliminating the need for customers to open support tickets or seek assistance.”

While Managed Cloud Labs is an internal Microsoft platform, the principles behind it—self-service provisioning, governance guardrails, automation, AI-driven optimization, and cost management—can be implemented using Microsoft Azure services. Click through to learn more about how Azure helps organizations build and manage cloud environments at scale and how to get started building your own static web apps.

Key takeaways

As you consider where AI automation can help your own support model, keep these ideas in mind:

  • Start with repetitive work. Look for high-volume, low-complexity issues where support teams already follow consistent diagnostic and repair patterns.
  • Keep trusted knowledge current. AI agents are only as useful as the documentation and source-of-truth content they rely on.
  • Make automation visible. Give users a clear view of what the system is checking and validating, so that self-service support builds confidence instead of creating uncertainty.
  • Design for safe, smooth handoff. When an agent can’t resolve an issue safely, make sure it passes useful diagnostic context to the user so that support engineers can pick up from there, rather than starting over.

Try it out

Related links

The post Resolving repetitive support tickets at Microsoft with AI automation appeared first on Inside Track Blog.

]]>
25059
Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft http://approjects.co.za/?big=insidetrack/blog/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft/ Thu, 13 Aug 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25067 At Microsoft, we manage around 500,000 Windows client devices worldwide, from employee laptops to servers to meeting room systems. In an environment that large, it’s complex and challenging to maintain end-to-end security. Every one of those devices relies on Secure Boot, a Windows security capability that verifies firmware, boot loaders, and operating system components before […]

The post Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft appeared first on Inside Track Blog.

]]>
At Microsoft, we manage around 500,000 Windows client devices worldwide, from employee laptops to servers to meeting room systems. In an environment that large, it’s complex and challenging to maintain end-to-end security.

Every one of those devices relies on Secure Boot, a Windows security capability that verifies firmware, boot loaders, and operating system components before startup. This system helps ensure all our Windows devices run only trusted software and protects us against threats that target the boot process.

When three Microsoft-issued Secure Boot certificates approached expiration in 2026, our team in Microsoft Digital, the company’s IT organization, knew we needed to take action early and get ahead of the update. By partnering with the Microsoft Office of the CISO and several of our product teams, we developed an approach that ensured secure-by-default devices from the firmware up.

Updating the foundation of device trust

Secure Boot sits at the foundation of Windows security. Without updated certificates, devices would lose the ability to receive future Secure Boot protections and other boot-level security improvements.

A photo of Quintana.

“We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.”

Luis Quintana, principal engineering group manager, Endpoint Security

To maintain protection, we needed to replace three legacy certificates with four new ones across a diverse device fleet. Replacing the certificates was straightforward. The real work was validating the update across thousands of device models and deployment scenarios.

Secure Boot certificates needing replacement

  • KEK: Microsoft Corporation KEK CA 2011 → Microsoft Corporation KEK 2K CA 2023
    Covers: Database updates (DB and DBX)
  • UEFI CA: Microsoft Corporation UEFI CA 2011 → Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023
    Covers: Third-party UEFI modules, bootloaders, and option ROMs
  • Windows Boot chain: Microsoft Windows Production PCA 2011 → Windows UEFI CA 2023
    Covers: Windows Boot Manager and boot components

We started early so we could test, validate, and gradually deploy the updates before the certificate expiration dates arrived. That approach helped us strengthen the security posture of our devices while minimizing disruption to employees and business-critical systems.

“Updating hundreds of thousands of devices without disrupting people and business operations is no small task,” says Luis Quintana, principal engineering group manager for Endpoint Security. “We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.”

Leading the update across a complex device estate

We first began this work in 2024 by partnering with the Windows Servicing and Delivery team, which helped us identify device models the certificate renewal might affect. We tested those models end to end in our Client Test Lab, then deployed the update to a pilot group of around 35,000 devices using a controlled firmware release (CFR). That pilot achieved a 95% success rate, which gave us the confidence to scale up.

A photo of Dagdelen

“Intune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate. It helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.”

Kubilay Dagdelen, senior service engineer, Microsoft Intune

In February 2026, we kicked off the broader effort across our entire Windows 11 device ecosystem. Reporting and telemetry formed our essential starting point.

Microsoft Digital partnered with the Windows Autopatch, Intune, and Microsoft Defender for Endpoint teams to identify which devices already included the latest certificates because they were released after 2025, which devices needed the update, and which failed. In support of these efforts, the Autopatch team built fleet-wide reporting of Secure Boot status directly into Intune, turning raw telemetry into a live compliance dashboard.

“Intune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate,” says Kubilay Dagdelen, a senior service engineer on the Microsoft Intune team. “It helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.”

A ringed approach across a range of devices

We started small, using telemetry signals to identify device cohorts based on their risk of failure. Starting from the simplest devices to update, we gradually scaled across models that carried more complexity, keeping backups and loaner machines ready to support global operations in case of disruption. After just 70 days, we had achieved 86% compliance across all our devices.

A photo of Savagur.

“This has been an opportunity to strengthen our security foundation. It’s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.”

Pandurang Savagur, senior product manager, Microsoft Digital

But we don’t just maintain employee devices. Our hardware estate spans meeting rooms, secure admin workstations, digital signage, and executive devices. These different device types demanded different Secure Boot approaches.

To tackle this challenge we established a virtual team, with members responsible for each of these surfaces holding weekly syncs and leadership updates. For example, our 15,000 meeting room devices run a custom Windows 11 image, so we partnered with OEMs to release firmware for them.

Meanwhile, cloud PCs on Azure infrastructure needed scheduled reboots to update, so we let employees choose when to restart. For our server cohort, where telemetry gaps made progress hard, Microsoft Defender for Endpoint delivered the independent visibility we needed.

“This has been an opportunity to strengthen our security foundation,” says Pandurang Savagur, a senior product manager on the Device Lifecycle team in Microsoft Digital. “It’s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.”

Our Customer Zero experience: Expertise and process pathfinding

Our role as Customer Zero shaped how we approached this process. As both the creators and users of Microsoft technology, we have direct access to product teams as well as intimate knowledge of our tools’ capabilities.

A photo of the Evgrafova.

“Technology and culture matter equally here, and our Microsoft culture means we know what’s coming and can act proactively through direct access to our engineering groups.”

Yulia Evgrafova, principal security service engineer, Office of the CISO

Intune served as our execution engine, orchestrating policies and remediation scripts across more than 90% of our devices with precision. Autopatch and Defender added speed through visibility.

Thanks to the lessons we learned throughout our update journey, we’re in the process of incorporating capabilities we developed internally into each solution for public release. We’ve also established steps that can help you manage your own Secure Boot certificate updates.

“Technology and culture matter equally here, and our Microsoft culture means we know what’s coming and can act proactively through direct access to our engineering groups,” says Yulia Evgrafova, a principal security service engineer for our Office of the CISO. “On the technology side, we have the expertise to experiment and the privilege of reaching engineering teams directly.”

Secure by default and ready for what’s next

Thanks to thorough telemetry and a measured approach to rolling out the update, we’ve now reached 97% compliance globally, all while keeping our failure rate under one percent and our support burden low. Our devices now validate trusted firmware and boot components by default, keeping the list of trusted components current and closing gaps that attackers could exploit at startup.

This work continues as we collect logs on devices that need attention and remediate the stragglers, including meeting rooms and virtual machines. That long tail is the hard part, but it’s a natural component of any effort at this scale.

What we built here reaches well beyond one certificate update. Telemetry gave us the visibility to protect devices without disrupting people, and that aspect of this rollout will guide get compliant and stay compliant in the future.

“This effort serves as a playbook for many different initiatives that we’ll take on in the future,” Quintana says. “One of the biggest lessons is how we can balance experience and protection between Microsoft Digital and our security teams.”

Key takeaways

As you update your own Secure Boot certificates, keep the lessons we learned internally during this process in mind:

  • Start early and validate with pilots. Give yourself enough runway to test on representative hardware, because certificate updates touch the firmware layer and you don’t want surprises at scale.
  • Make telemetry your foundation. Reliable, fleet-wide visibility tells you which devices need updates, which have already succeeded, and where the real risks are before you deploy anything.
  • Deploy in phased rings. Start with low-risk devices and progress toward high-risk and older hardware, using guardrails at each stage to avoid boot failures and contain any issues.
  • Plan extra time for difficult device types. Older hardware, meeting room systems, servers, and end-of-support devices present the biggest hurdles, so identify them upfront and budget the effort they demand.
  • Build a virtual team culture. Bringing every stakeholder together, from security to leadership, gives each group a chance to shape the plan while also securing the budget and support that the effort requires.
  • Treat secure-by-default as the new standard. Secure Boot is no longer an opt-in position, so communicate early and enforce consistently. Remember that people need to know the change is coming and that you’re doing everything possible to make it happen smoothly.

Try it out

Related links

The post Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft appeared first on Inside Track Blog.

]]>
25067
Building a trusted IT asset inventory with Fabric and AI at Microsoft http://approjects.co.za/?big=insidetrack/blog/building-a-trusted-it-asset-inventory-with-fabric-and-ai-at-microsoft/ Thu, 06 Aug 2026 16:15:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25018 For an enterprise company like Microsoft, understanding exactly which devices are connected to our corporate network is essential. As the company’s IT organization, we in Microsoft Digital manage millions of network-connected assets. An asset could mean an employee device, network infrastructure, pieces of equipment that sit inside the data center or buildings, or anything else […]

The post Building a trusted IT asset inventory with Fabric and AI at Microsoft appeared first on Inside Track Blog.

]]>
For an enterprise company like Microsoft, understanding exactly which devices are connected to our corporate network is essential.

As the company’s IT organization, we in Microsoft Digital manage millions of network-connected assets. An asset could mean an employee device, network infrastructure, pieces of equipment that sit inside the data center or buildings, or anything else that gets connected to our network.

Information about these assets previously lived within disparate systems, processes, and teams scattered across the company. This fragmentation created a barrier to the establishment and maintenance of a trusted IT asset inventory.

For example, if a security team needed information such as device ownership, location, and the lifecycle status of a device involved in a potential security incident (which remains rare at Microsoft), the dispersed nature of the previous system meant a lot of manual outreach across the organization. This was time-consuming and frustrating for our IT team, and it also delayed security incident response times.

This limited visibility also made it more difficult to manage the company’s hardware investments in an efficient way, something that we knew needed fixing. And because we realized this is a challenge our customers are also having, we—the company’s Customer Zero—agreed to share what we learned with you along the way.

To get started, we launched a multi-year effort to inventory our enterprise IT assets. This inventory brought together previously disconnected sources, improved data quality, and created the foundation for future AI-powered asset management experiences across the enterprise.

Why asset inventory matters

At Microsoft, we prioritize security over all other business outcomes. Our security teams depend on accurate, up-to-date information about network devices to protect the company’s virtual environment, detect any issues promptly, and respond to security incidents efficiently. Any time spent tracking down essential details like device ownership and network identity can lead to delays in incident response.

A photo of Sahoo.

“One of the early challenges we faced was that we weren’t operating as a single organization—we were a collection of businesses. Each business leader had developed their own governance frameworks, operating practices, and approaches to managing assets, making consistency and alignment difficult to achieve.”

Debashis Sahoo, principal group manager, Microsoft Digital

We on the IT team don’t control the acquisition process of assets across every business unit of the company, which meant asset inventory was constantly changing and there was no direct oversight for when new devices entered the network.

“One of the early challenges we faced was that we weren’t operating as a single organization—we were a collection of businesses,” says Debashis Sahoo, a principal group manager in Microsoft Digital. “Each business leader had developed their own governance frameworks, operating practices, and approaches to managing assets, making consistency and alignment difficult to achieve.”

Another important element of IT asset inventory is the financial aspect.

We inventory all high-value devices in our network to determine our financial footprint in the IT asset arena, which includes both devices that are being actively used—including laptops, printers, and deployed IoT devices—and devices that aren’t currently being deployed on our network.

“For employee devices in Microsoft, 60% of our employees own more than one device,” says Aniruddha Das, a principal product manager in Microsoft Digital. “For developers, typically they have a primary device. They might also have a backup workstation, but a lot of times what we have seen is these devices sit in inventory and they don’t get deployed, which means we have our capital tied in but not being utilized. We want to know what’s tied in so that we have good information about what to purchase next year.”

These undeployed devices were a prime focus of our inventory efforts. We also prioritized finding which devices had reached their end of service life limits and needed to be replaced. Older devices don’t get patched as often, which can expand the attack surface of IT infrastructure.

The scale of these different challenges meant we couldn’t work on everything at once. Our team worked with security stakeholders to identify the devices and attributes that were most critical to the company’s security on a daily basis. We determined that network devices, lab devices, and Internet of Things (IoT) devices should take priority.

Driving alignment through iterative leadership check-ins

Our answer to this challenge was to build a process that connected to any system that might have information about a security-related asset inside the company.

To create this new system, which we call the Enterprise Asset Data Platform (EADP), we brought together stakeholders from across Microsoft in a Kaizen continuous improvement initiative.

When we waded in, we found the task of standing up a new IT asset inventory proved more wide-ranging in scope than we initially anticipated. Asset data was peppered across myriad systems, each of which served a different business need. The networking, security, real estate, lab, and enterprise asset management teams all had stakes in the outcome of this initiative. We ran a two-day program to identify focus areas and divide them into different segments, such as the IoT and lab segments.

The Kaizen process helped us establish common goals across departments, define what success would look like, and create a roadmap. We used this exercise to create a charter defining what issues we wanted to address and get universal alignment around the shared goal of improving inventory quality and completeness.

We aimed to cut down the time it takes to address and remediate security incidents and stand up weekly, biweekly, and monthly operating reviews around governance for the 12 months following the Kaizen to monitor the progress of the initiative. This was to remove any blocks that might arise and make sure teams were aligned throughout the process.

Modernizing our inventory solution

Expanding our IT asset inventory capabilities meant we needed to modernize the tech that underpinned them. Our device data was initially collected from over 70 sources aggregated into a central inventory, which meant we encountered a wealth of issues with duplication, data quality, and clashing governance.

In ingesting all this data, we took over data management from the teams who distribute devices here at Microsoft, which cleaned up our data because it more accurately reflected what was really being used by our employees and contingent staff. This allowed us to reduce our per-person spend by  22%, a significant savings.

And we’re making more improvements. If one of our business units is planning to buy a new set of laptops or lab devices, we can now “see that,” and can mine our data at that point, instead of hoping to learn about the acquisition from a secondhand source.

The complexity of standing up and maintaining this process demanded that we create our data platform, which we built on Microsoft Fabric. With this system, data is ingested, enriched, reconciled, and surfaced through curated datasets designed for operational use, removing the need to manually review each device and compare it against what’s already on record.

Accelerating our progress using AI

Building a trusted inventory delivered immediate security and operational benefits to our organization. But we quickly realized that the same foundation could support a broader goal: Using AI to help our employees and contingent staff find, understand, and act on asset information. With consistent data now available across the enterprise, we could begin building intelligent experiences on top of the inventory, rather than asking users to navigate dozens of disconnected systems.

As a platform provider, Microsoft Fabric holds all the device data across the company; the majority of our AI workload is on this platform. If a Microsoft team needs to create an AI experience for their business unit and wants to use those capabilities, they can do it by connecting to our Microsoft Digital suite of AI tools.

A photo of Kaul.

“AI has improved our engineering efficiency drastically and reduced our time to value significantly. We’re able to deliver value and identify gaps much sooner than before.”

Ashwin Kaul, senior product manager, Microsoft Digital

We’re constantly looking for new ways to create valuable experiences for different domains and business units at Microsoft. We’re currently in the process of creating agent-based experiences that streamline tasks like lab operations, device tracking, and asset updates. Our operators will eventually be able to interact with our AI-powered assistants using natural language, streamlining the process of finding and using the information they need.

Because inventory records are now standardized and trusted, teams no longer needed to spend time reconciling data across systems. That consistency also created an opportunity: using AI to help employees interact with asset information more naturally.

When it comes to selecting which devices a user needs, AI can understand the user’s persona, their role, and make recommendations for which devices would best suit that user’s experience. From there, the user can choose from the AI’s device recommendations. This device selection process, which used to take anywhere from 15–20 days, can now be completed in minutes.

“AI has improved our engineering efficiency drastically and reduced our time to value significantly,” says Ashwin Kaul, a senior product manager in Microsoft Digital. “We’re able to deliver value and identify gaps much sooner than before.”

AI also helps us track and trace and then remediate security issues within our extensive network of IoT devices, which contain thousands of lights sensors, temperature controls, and other device types across the campuses of our offices globally. We partnered with our real estate team to use Microsoft Copilot studio to stand up agentic AI capabilities for data quality checks to make sure that all these devices are being accurately documented.

At our Kaizen event, we chose a goal of a 90% improvement for inventory completeness and accuracy. We’ve made a 74% improvement compared to our baseline as of summer 2026, and we’re on track to end the year with an 85% improvement.

Our AI-powered foundation for the future

For our team in Microsoft Digital, the journey began with a simple objective: Gain a trusted view of the company’s technology assets. The result is a stronger security posture, improved operational efficiency, and a data foundation that can support increasingly intelligent experiences.

One great example of these kinds of new experiences: We’re currently in the process of developing a Labs Asset Management Agent, or LAMA. LAMA will be a human-led, multi-agent Frontier Firm experience for our employees that will hugely simplify Microsoft Labs operations.

Our labs have a huge amount of operational processes to manage and run. Once we simplify these processes and reduce the amount of manual intervention needed to manage lab devices, we anticipate reducing vendor and hardware costs using this agentic AI. Our goal is to speed up the pace at which we can do lab deployments by 50%.

As organizations look for new ways to apply AI, our experience demonstrates an important principle: the quality of AI outcomes depends on the soundness of the underlying data. Building a trusted asset inventory may not be the most visible part of an AI strategy, but it is often one of the most important.

Key takeaways

If you’re looking into how to improve IT asset management at your organization, consider these lessons from our experience:

  • Start with a clear business outcome goal. We focused first on security, which helped create urgency and alignment across teams. 
  • Bring leadership stakeholders together early. Effective asset management spans multiple organizations, including security, operations, infrastructure, and business teams. Make sure you have visible, confirmed buy-in from the leadership of each affected business function.
  • Establish measurable goals. Define the data quality and inventory metrics that matter to track your progress.
  • Improve your processes before modernizing your technology. Understanding and streamlining your workflows can have as much impact on efficiency gains as incorporating new tools into your tech stack. 
  • Use AI to accelerate your modernization. AI can help reduce your engineering effort, improve your data quality, and create more intuitive operational experiences.
  • Treat asset inventory as a strategic capability. High-quality asset data enables better security.
  • Stand up a continuous improvement Kaizen. Getting executive sponsorship and buy-in as well as alignment across functions at a Kaizen event is invaluable. It makes the effort collective and gives everyone a feeling of ownership over the outcome.

Try it out

Related links

The post Building a trusted IT asset inventory with Fabric and AI at Microsoft appeared first on Inside Track Blog.

]]>
25018
Optimizing Azure resources at Microsoft with AI and Managed Cloud Labs http://approjects.co.za/?big=insidetrack/blog/optimizing-azure-resources-at-microsoft-with-ai-and-managed-cloud-labs/ Thu, 06 Aug 2026 16:10:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25012 Virtual labs give our employees at Microsoft on-demand access to the environments they need for development, testing, troubleshooting, and customer support. But at our scale—we have hundreds of thousands of labs and virtual machines internally here at Microsoft—determining the right amount of cloud resources for each workload becomes a significant challenge. Managed Cloud Labs (formerly […]

The post Optimizing Azure resources at Microsoft with AI and Managed Cloud Labs appeared first on Inside Track Blog.

]]>
Virtual labs give our employees at Microsoft on-demand access to the environments they need for development, testing, troubleshooting, and customer support.

But at our scale—we have hundreds of thousands of labs and virtual machines internally here at Microsoft—determining the right amount of cloud resources for each workload becomes a significant challenge.

Managed Cloud Labs (formerly MyWorkspace) is our internal, Azure-based cloud-labs-on-demand platform that supports more than 20,000 labs and 150,000 VMs across our customer support, cloud solution architecture, engineering, testing, and release teams.

With Managed Cloud Labs, our employees can model all different kinds of lab environments. Some environments might support a simple customer issue, while others re-create a complex enterprise infrastructure scenario.

Each lab runs with a mix of workloads, performance needs, storage demands, and usage patterns. Its flexibility makes Managed Cloud Labs beneficial; it’s also what makes cost optimization difficult.

For example, our business leads configure CPU, memory, and storage quota limits for their teams within Managed Cloud Labs, typically based on the largest environment used. Yet after these quotas have been set, there wasn’t an easily scalable way to determine if a given lab was provisioned for more capacity than it actually needed, resulting in unnecessary excess cost for these teams.

As the annual cost of Azure resources on Managed Cloud Labs climbed to eight figures at Microsoft, finding a better solution became urgent. This was especially true for storage performance—one of the platform’s primary cost drivers. Our team in Microsoft Digital, the company’s IT organization, went to work on a new approach that connected real usage telemetry with the infrastructure decisions that drive cost.

The result is an AI optimization service that can process performance telemetry, user behavior, infrastructure configuration, and cost signals across Managed Cloud Labs. The service learns how resources are used and can right size them for labs, matching the needs of each individual workload without disrupting the teams who depend on it every day.

Using AI to match cloud resources to workload needs

Managed Cloud Labs was designed as a cost-efficient lab platform, enabling us to quickly provision and deprovision resources on demand. However, due to the popularity of the service, usage and costs continued to rise. The obvious solution was cutting resources or imposing blanket quota, but this would risk damaging the very user experience that made the service valuable.

“It’s an incredible amount of data for a human to analyze. Even using our reporting and querying database capabilities, it would be very difficult to manage manually.”

Nathan Prentice, principal product manager, Microsoft Digital

To assess whether a lab is over-provisioned, our team would need to inspect every virtual machine, CPU, disk, performance tier, usage pattern, and cost signal across an enormous, constantly changing environment. Our team uses existing tools like Azure Advisor to help analyze resource configurations and usage telemetry and provide recommendations for optimizing resources, but storage costs remained a concern.

CPUs can be turned off when not in use, but operating systems and data disks preserve the state of each lab and keep incurring costs. That made storage the most promising place to reduce costs without breaking the experience.

Our team built an AI workflow that analyzes 30 days of disk usage data—including read/write operations and usage trends—then recommends whether a disk should stay on premium storage or move to a lower-cost SKU. This helps us individually evaluate each lab, VM, and disk, then recommend or apply the right performance tier, rather than forcing everyone into the same blanket policy.

“It’s an incredible amount of data for a human to analyze,” says Nathan Prentice, a principal product manager in Microsoft Digital. “Even using our reporting and querying database capabilities, it would be very difficult to manage manually.”

Building intelligence into the platform

We focused on extending the cost optimization capabilities through an intelligent, data-driven framework that evaluates real-world infrastructure usage at scale. The team developed a system that identifies opportunities to optimize storage performance tiers based on actual workload requirements. A disk may be appropriately sized for capacity, but workload telemetry often reveals that it does not require the performance characteristics of a higher-cost storage SKU.

Building on Azure’s native optimization capabilities and recommendations from Azure Advisor, the team created an AI-powered workflow that analyzes billions of telemetry signals, including disk utilization trends, throughput, IOPS, workload behaviors, and performance patterns. AI models hosted on Azure AI Foundry assess historical and real-time usage data to generate high-confidence recommendations while continuously evaluating potential risks to application performance and user experience.

A photo of Tibdewal.

“We saw an opportunity to combine Microsoft AI capabilities with operational telemetry to change how cloud cost optimization is performed. By using AI models hosted on Azure AI Foundry and enriching them with real-world workload and performance data, we built an intelligent decision framework that identifies optimization opportunities across Azure resources at scale.”

Nirag Tibdewal, senior software engineer, Microsoft Digital

We designed the solution with an emphasis on reliability, governance, and operational safety. Recommendations pass through multiple layers of validation and policy-driven guardrails. Managed services perform safety checks and assess workload impact, making sure recommendations meet predefined confidence thresholds before any action is considered.

To further minimize risk, the team adopted a phased deployment strategy. The system initially operated in observation mode, generating recommendations without taking action. Recommendations are validated in pre-production environments before being rolled out incrementally across increasingly larger virtual machine populations. This approach allowed the team to validate outcomes and refine recommendation quality to build confidence in the system and provide a seamless experience for engineers.

“We saw an opportunity to combine Microsoft AI capabilities with operational telemetry to change how cloud cost optimization is performed,” says Nirag Tibdewal, a senior software engineer in Microsoft Digital. “By using AI models hosted on Azure AI Foundry and enriching them with real-world workload and performance data, we built an intelligent decision framework that identifies optimization opportunities across Azure resources at scale.”

Tangible impacts without disruption

The Microsoft Customer and Partner Solutions (MCAPS) team has been working with the Managed Cloud Labs AI solution since January. MCAPS support engineers work with Microsoft customers and partners who face issues with our products. They use Managed Cloud Labs to set up labs that replicate customer environments and can be used to investigate these issues and test fixes.

Sometimes these lab environments are used to test performance and to scale related issues, so the business leads configure resource quotas at high levels. But often the labs are built to test configuration issues where large storage capacity or high IOPs aren’t required, resulting in mismatches between Azure resources the teams are paying for and what they actually need.

“With this AI-driven solution, we’ve reduced Azure Storage costs by 40%. We’re targeting underutilized disks that can be resized to less costly SKUs while still providing the required performance, with no impact to users. Cost savings is a significant priority for our leadership, so our ability to save this amount of money without impacting users has been a big success.”

Kevin Williamson, principal technical advisor, MCAPS

Our solution lowers costs for MCAPS and frees up constrained Azure capacity for other Microsoft teams. The storage-cost reduction is already saving the team a significant chunk of money without having to change business rules or impact support engineers.

“With this AI-driven solution, we’ve reduced Azure Storage costs by 40%,” says Kevin Williamson, a principal technical advisor in MCAPS. “We’re targeting underutilized disks that can be resized to less costly SKUs while still providing the required performance, with no impact to users. Cost savings is a significant priority for our leadership, so our ability to save this amount of money without impacting users has been a big success.”

Optimizing at scale

We can now focus on optimization at platform scale. We’ve reduced premium disk deployment from 95% to approximately 16% without reported disruptions. And we’re hosting the same scale as before, but doing it at 20% to 30% lower cost.

Our engineers are unaffected by lab performance, and they haven’t changed the way they work.

A photo of Ferris.

“We advanced infrastructure efficiency by building a time-series–driven pipeline to better understand real disk usage patterns across workloads. This supports AI-powered SKU recommendations, helping make Azure-based lab environments more data-driven and cost-efficient while intelligently optimized at scale.”

James Ferris, software engineer, Microsoft Digital

While Managed Cloud Labs is an internal Microsoft platform, the principles behind it—self-service provisioning, governance guardrails, automation, AI-driven optimization, and cost management—can be implemented using Microsoft Azure services. Click through to learn more about how Azure helps organizations build and manage cloud environments at scale and how to get started building your own static web apps.

Key takeaways

Here are some tips to help your organization improve your cloud efficiency:

  • Replace assumptions with telemetry before right-sizing cloud resources. Identify where telemetry exists today and use it to challenge resource assumptions.
  • Use AI to scale what humans can’t. With tens of thousands of labs and VMs, AI analyzes usage patterns across disks, CPUs, and workloads to deliver recommendations no manual process could match.
  • Target storage for the biggest savings. By focusing on disk performance tiers—rather than size—teams reduced one of the largest cost drivers without impacting lab functionality.
  • Treat cost optimization as a continuous capability, not a one-time cleanup. By embedding optimization directly into the platform, cost management becomes continuous instead of reactive.
  • Use guardrails to protect the employee experience. Pair AI-driven recommendations with validation steps and human-designed safeguards so optimization improves cost efficiency without disrupting the teams who rely on the platform.

Try it out

Related links

The post Optimizing Azure resources at Microsoft with AI and Managed Cloud Labs appeared first on Inside Track Blog.

]]>
25012
How Microsoft Digital Asia used AI to create human connection across continents http://approjects.co.za/?big=insidetrack/blog/how-microsoft-digital-asia-used-ai-to-create-human-connection-across-continents/ Thu, 06 Aug 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25024 Here at Microsoft Digital, the company’s IT organization, we believe AI can be a powerful force for building community. In our Microsoft Asia region, our employees recently used AI tools to create a collaborative digital comic book featuring regional leaders traveling across Asia in a hot air balloon, visiting teams in different countries and learning […]

The post How Microsoft Digital Asia used AI to create human connection across continents appeared first on Inside Track Blog.

]]>
Here at Microsoft Digital, the company’s IT organization, we believe AI can be a powerful force for building community. In our Microsoft Asia region, our employees recently used AI tools to create a collaborative digital comic book featuring regional leaders traveling across Asia in a hot air balloon, visiting teams in different countries and learning about their local cultures along the way.

A photo of Glattbach.

“To bring us together, we definitely got creative after COVID, and even more so when AI came in. We did a lot of fun team games where we would share and represent our region.”

Petra Glattbach, senior business program manager, Microsoft Digital

What began as a creative experiment to reconnect people in the post-pandemic era quickly became a way for globally distributed employees to reconnect with one another after years apart.

The comic book—the brainchild of Petra Glattbach, a senior business program manager based in Australia—grew out of a broader effort to rebuild personal connections across a region spanning Australia, New Zealand, Japan, China, Singapore, and India.

“To bring us together, we definitely got creative after COVID, and even more so when AI came in,” Glattbach says. “We did a lot of fun team games where we would share and represent our region.”

AI-generated comic-book panels showing Microsoft Digital leaders in Sydney, including a view of the North Sydney office building and the Sydney Harbour Bridge.
Next stop, Australia: This AI-generated scene showing Sydney is taken from a comic book that one of our Microsoft teams created for internal distribution. The book follows our leaders as they “travel” across Asia, using storytelling to celebrate local cultures and strengthen connections among team members.

For many years before the COVID-19 pandemic, these teams had maintained a strong sense of community through regular regional gatherings and global conferences, creating a rhythm of in-person collaboration and camaraderie that they deeply valued.

Pre-pandemic, companies around the world hosted in-person events to keep their networks strong and make new connections. Remote work was an outlier, and most businesses operated on a face-to-face basis. COVID and its accompanying restrictions transformed professional interactions around the world, platforming remote work as the norm.

Microsoft was no exception.

Maintaining connection in a distributed world

Microsoft 365 Copilot was being rolled out during this time, and employees were encouraged to incorporate it into their daily workflows. Like many people across different businesses and industries, having our employees incorporate AI into daily work was equal parts exciting and anxiety-inducing for the Asia teams.

The employees in the Asia region thus found themselves trying to solve two challenging problems: How do you foster real workplace community when in-person meetups are infrequent and difficult? And how do you build your confidence with AI tools in the workplace? Maybe, they thought, there was a way to tackle both challenges at the same time.

The Asia teams initially focused on the community-building side of the quandary. They started small, organizing gatherings like themed quiz games, cultural trivia, and other online events designed to bridge the gap between the virtual and real worlds.

In the spirit of our company’s AI rollout, the Asia region also began experimenting with different forms of AI. They initially used it for more organizational tasks, such as event brainstorming and planning. However, once they began experimenting, it occurred to them that more creative, community-driven projects might be the perfect opportunity to encourage people to learn about AI while having fun and building closer relationships between geographically separated teams.

A photo of Stone.

“What it really did for us was normalize the idea of using AI. It allowed us to move culturally from trying to use this new technology to do our jobs to the idea that it can help us in many different ways.”

Alan Stone, senior director of business programs, Microsoft Digital

The advent of Hello There

The teams started with some small-scale creative team games and experiences, such as making songs and short videos that represented their different cultures. For instance, every six months one of our teams would run an event they called “Hello There.” They’d randomly assign three people from different parts of the world to find a half-hour in their week for a conversation, and suggest a topic for the group to chat about.

At a time when the company was no longer regularly flying employees together in person, the initiative helped recreate the spontaneous personal connections that had once happened naturally during regional events and conferences. They then asked the participants to use AI to generate an image that told the story of the things they spoke about, which they posted in a dedicated Viva Engage channel.

The generated images were fun for everyone to see and comment on, and they helped employees learn more about one another. The experience gave globally distributed employees an opportunity to connect not just as coworkers, but as people, despite the distance between them.

“What it really did for us was normalize the idea of using AI,” says Alan Stone, senior director of business programs in Microsoft Digital. “It allowed us to move culturally from trying to use this new technology to do our jobs to the idea that it can help us in many different ways.”

Using AI for a creative group project

After a few regional cycles of iterative experimentation with these creative capabilities, our teams in Asia decided to use AI for a more ambitious group project—something that would require teams from multiple countries to work together toward the same goal. They wanted to create an item that represented the Asia region, celebrated their unique cultural attributes, and boosted the AI literacy of their employees.

That’s where Glattbach’s comic book idea came in. Inspired by the popularity of manga and graphic storytelling across Asia, she had the idea of showcasing both the technological capabilities and powerful collaborative nature of AI by creating a comic book using AI-driven tools.

She proposed the project in a meeting with Stephen Kerametlian, a senior director of business program management in Microsoft Digital. Knowing his love of James Bond films, his team created a comic book of Kerametlian as a Bond character, flying to visit employees in countries around the region. Kerametlian says receiving a personalized, AI-generated comic book from team members he hadn’t physically seen in years was a defining and personally touching moment.

“They even managed to get my wife and two-year-old son into the book,” Kerametlian says. “We’re an international team. Through that comic book, I was able to travel the world and ‘see’ my entire team, which I haven’t seen in person since before the pandemic. We had so much fun with it.”

Glattbach’s idea was then translated into a wider-reaching effort across the different teams based in Asia. Groups in different countries would each create a chapter of the shared narrative. Two regional leaders, Alan Stone, and Wai Leong Chan, were main characters in the story, traveling across Asia in a hot air balloon and touching down in each country to visit the team and learn about their culture.

The project enabled team members to learn to use AI while completing a fun and creative effort together. Regional leaders created a purposefully safe, low-stakes environment to encourage experimentation and play.

“It was an opportunity for people have a little bit of fun, knowing they’re experimenting and learning in a safe environment,” says Jane Davis, a director of business programs in Microsoft Digital who’s based in Australia. “I love how easy it was for everybody to get involved and experiment with AI as a shared community.”

The teams prioritized joy and creativity over the final output, encouraging people to work together and fostering an environment where they could learn from one another. Each team shared prompts, compared results, and built on others’ ideas to come up with their country’s chapter of the comic book.

A photo of Kerametlian

“We unlocked a ton of usage and value from Copilot through something as simple as a comic book. It turned out to be very powerful, and inspired people to use the technology for their own work as well.”

Stephan Kerametlian, senior director of business program management, Microsoft Digital

This larger comic book project was a runaway success. It became a companywide example of successful peer-to-peer learning, cross-cultural exchange, and creative collaboration.

“We were able to rally communities around it; we didn’t have to beg people to join the work sessions, because they were super-popular,” Kerametlian says. “We unlocked a ton of usage and value from Copilot through something as simple as a comic book. It turned out to be very powerful, and inspired people to use the technology for their own work as well.”

Participation grew rapidly; employees were genuinely excited to get involved.

“AI is strengthening our day-to-day productivity,” says Shunsuke Kubota, a senior field IT manager in Microsoft Digital, who is based in Japan. “We’re generating more connections, resulting in more sharing of ideas. I think it’s kicked off an incredible creativity and innovation loop.”

And that’s a win for everyone at Microsoft.

A photo of Davis.

“People think that AI is replacing human connections. We purposely chose to think about creative ways that our community can use AI as an enabler of human connection across geographies in Asia, especially since Microsoft Digital is a global team.”

Jane Davis, director of business programs, Microsoft Digital

Future collaborations with AI

The success of this AI collaboration project has inspired teams across Microsoft to adopt a similar approach to community building, including groups in Europe and the Middle East.

“People think that AI is replacing human connections. We purposely chose to think about creative ways that our community can use AI as an enabler of human connection across geographies in Asia, especially since Microsoft Digital is a global team,” Davis says. “We’re asking, how do you come together as a community? How do you do it in a virtual way, in a way that enables social and experimental learning?”

As these efforts illustrate, when used intentionally and purposefully, AI technology is a powerful tool for amplifying and enhancing human ties in a widely distributed world. As the technology continues to advance, we believe it offers an opportunity to rethink how people connect, learn, and grow together.

“AI is something that’s driving community,” Davis says. “People are discovering these new, innovative opportunities to connect, and AI is their creative partner in making it happen.”

Key takeaways

For organizations that are curious about adopting AI technology to help create their own sense of connection and community, the Asia region’s experience offers a number of lessons:

  • Start with people, not technology. Successful community-building initiatives address the human need for connection. Anchor your efforts in relationships and cultural exchange, rather than rolling out AI for its own sake.
  • Make experimentation feel safe and low stakes. Encourage psychological safety for your team by making your initial AI experiments easily accessible. Emphasize fun and play over any ultimate output.
  • Use AI as a shared learning opportunity. Instead of formal training, let learning happen organically through collaboration. Encourage peer-to-peer learning rather than top-down instruction.
  • Combine structure and guardrails with creativity. Providing high-level guardrail materials like shared prompts, formats, and collaboration tools can make project outputs consistent across teams, while leaving plenty of room for experimentation and expression.

Try it out

Related links

The post How Microsoft Digital Asia used AI to create human connection across continents appeared first on Inside Track Blog.

]]>
25024
Implementing Agent 365: How we’re governing and managing AI agents at Microsoft http://approjects.co.za/?big=insidetrack/blog/implementing-agent-365-how-were-governing-and-managing-ai-agents-at-microsoft/ Thu, 06 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24764 Building readiness for Agent 365 at Microsoft At Microsoft, we’re on a Frontier Transformation journey to reimagine work and redefine processes through the power of agentic AI. Microsoft Digital, the company’s IT organization, operates a large and diverse population of agents, built across a broad range of tools and technical capabilities. With Microsoft Agent 365, […]

The post Implementing Agent 365: How we’re governing and managing AI agents at Microsoft appeared first on Inside Track Blog.

]]>

Building readiness for Agent 365 at Microsoft

At Microsoft, we’re on a Frontier Transformation journey to reimagine work and redefine processes through the power of agentic AI.

Microsoft Digital, the company’s IT organization, operates a large and diverse population of agents, built across a broad range of tools and technical capabilities. With Microsoft Agent 365, we now have visibility into more than 500,000 agents.

This distributed control plane has brought agent inventory and governance into one place, giving us a clear view of agent categories, metadata, usage, and ownership information. Agent 365 has also improved our ability to track agent lifecycle and bring in new risk insights.

There’s more work to be done, but it’s already enabling enterprise-scale agent management at Microsoft. Agent 365 provides helpful information about our agent ecosystem, including the top platforms used to create them and the agents our employees use most. It presents this info in helpful, all-up views like the dashboards below.

We’re increasingly connecting agents to business-critical data, involving them in vital workflows, and using them to drive concrete business outcomes. This shift to agentic workflows has inevitably led to questions about operational readiness:

  • How do we further accelerate AI-powered innovation without losing visibility, trust, and control?
  • How do we create useful, powerful agents while governing them safely?

Agent 365 is becoming an essential vehicle for answering these questions as we enhance agent oversight and control for everyone involved in Frontier Transformation, from AI administrators to security professionals to business decision makers.

Agent 365: A response to the challenges of agentic governance

At Microsoft, we share many of the concerns of our customers about properly governing and managing the wide array of agents we build and surface across different platforms. We take a “self-service with guardrails” approach to our productivity estate, which means we give employees the ability to create new workspaces across their Microsoft 365 applications, while we secure assets by default and expand access based on employee needs.

The same is true for agent creation. As a result, the number of agents within our organization has grown rapidly.

A photo of Fielder.

“Agent 365 is giving us the confidence to let innovation happen everywhere while ensuring we always understand what agents are doing, how they’re evolving, and where IT needs to engage as a trusted partner in the process.”

Individuals and teams can create agents through a variety of platforms, including Microsoft 365 Copilot Agent Builder, Microsoft SharePoint, Microsoft Teams, Microsoft Copilot Studio, Microsoft Azure AI Foundry, and Agents Toolkit Software Development Kit (SDK). Each platform has its own tools, back-end systems, and ways to view inventory, usage, and risk.

As agents began operating across apps and runtime environments, the need for us to break down management and governance siloes became apparent. An effective method for managing this new class of enterprise asset was required.

We wanted one shared view of all agents in our organization, tightly connected to the people responsible for administration, governance, security, and business outcomes. That’s a challenging prospect—something that no organization has done before.

Microsoft created Agent 365 in response to these needs. In Microsoft Digital, we’ve been working alongside the Agent 365 product team to implement this suite of tools within our production tenant. We’re putting these core capabilities into practice, providing a unified way to observe, manage, govern, and secure agents as they scale across our organization.

“Agent 365 is giving us the confidence to let innovation happen everywhere while ensuring we always understand what agents are doing, how they’re evolving, and where IT needs to engage as a trusted partner in the process,” says Brian Fielder, vice president of Microsoft Digital.

This guide shares what we’ve learned so far:

  • How we’re using Agent 365 in Microsoft Digital
  • Where we’re supplementing it with additional practices
  • Lessons learned that can help you use Agent 365 more effectively, whatever your scale or AI maturity level

From product vision to production

As Customer Zero for Agent 365, it’s important that we’re candid about our journey. Much of the product’s value comes from how we’re incorporating it into our current processes, alongside existing tools.

Scale is also relevant. For smaller or simpler tenants, readiness comes faster. At an organization like Microsoft, with hundreds of thousands of agents, there are times when manual oversight isn’t enough.

We’re actively involved in co-developing the product, uncovering opportunities for capabilities like automation and programmatic solutions to support administration and governance at scale. As part of this process, we’ve partnered closely with the product team to provide continuous feedback and share learnings from our hands-on experiences.

A photo of Smith

“This has been a strong partnership—daily standups, tracking real issues, and embracing the feedback needed to make the product better. Microsoft Digital plays a critical role as our Customer Zero while operating at a scale like no one else.”

Today, we’re using core Agent 365 capabilities while actively sharing feedback with the product group in the following areas:

  • Centralizing an accurate inventory of all agents running in the tenant across Microsoft and third‑party platforms to provide a genuinely unified registry across all agent platforms.
  • Extending existing enterprise controls by integrating with Microsoft Entra for agent identity, Microsoft Purview for data security and compliance, Microsoft Defender for threat protection, and the Microsoft 365 admin center for operations—all enhanced for improved agent control and management.
  • Assisting processes to streamline the lifecycle for agents, including new lifecycle metadata like draft vs. published status, ownership tracking, and usage analysis.
  • Surfacing actionable insights and risk signals related to agent behavior, access, data usage, and runtime activity, helping IT prioritize attention and response.
  • Supporting enterprise scale through automation and APIs to help manage large, diverse agent deployments without relying on manual management.

While full lifecycle capabilities for certain agent platforms, risk signals, and enterprise-scale automation evolve, we continue to partner with the product group to close gaps while existing processes support current operations.

“This has been a strong partnership—daily standups, tracking real issues, and embracing the feedback needed to make the product better,” says Ray Smith, corporate vice president for the Agent 365 product group. “Microsoft Digital plays a critical role as our Customer Zero while operating at a scale like no one else.”

Chapter 1: Establishing a foundation of practice for agent administrators

A new opportunity to break down silos between roles

As we began scaling agents inside Microsoft, we discovered that the future of agent management would need to evolve from our current ways of working. We wanted a world where we could create and use agents broadly while keeping administration manageable and consistent.

Getting there required new patterns of practice for IT, especially for administrators operating across different focuses. Agent 365 unifies observability between enterprise roles, acting in concert with the broader Microsoft suite of administration, security, identity, and governance tools.

Here is a summary of the needs of different personas involved in the agent-building and management processes, grouped by office and broken down by role:

Office of the CIO

Developers and makers

Build, test, and deploy intelligent agents at scale

Products: Agent Builder, Copilot Studio, Microsoft Foundry

IT administrators

Control, govern, and monitor agents across the organization

Product: Microsoft 365 Admin Center

Agent users and business decisions makers

Get work done faster with AI-powered assistance

Products: Copilot and Teams

Office of the CISO

SecOps

Detect threats and secure agent activity in real time

Product: Microsoft Defender

Data and compliance

Protect data and enforce compliance policies

Product: Microsoft Purview

Identity manager

Manage identities and access agents and users

Product: Microsoft Entra

We’ve found that our most effective AI administrators come from existing Microsoft 365 backgrounds, because they already have deep expertise with mature tools and processes. Whether they’re generalists or specialists, your administrators will already be positioned to manage agents at scale and use their skills and experience with the tools and insights that Agent 365 delivers.

Shifting from siloed administration to coordinated responsibility

Up until this point at Microsoft, managing agents has been the responsibility of the platform administrators who control agent creation tools. SharePoint administrators manage SharePoint agents, Power Platform administrators manage Copilot Studio agents, and so on. Meanwhile, identity, security, and compliance teams handle their respective layers using Microsoft Entra, Microsoft Defender, and Microsoft Purview—often independently.

We know that this model has the potential to break down as agents become more powerful and more interconnected, and as new agent types begin to run autonomously with their own identities.

A photo of Clare

“With agents in action across multiple spaces, managing them is a special challenge. It was clear that we needed a silo-buster to govern this new ecosystem effectively.”

Within Microsoft Digital, we’re using Agent 365 to differentiate agent management from platform-specific administration without replacing existing expertise. Instead of creating a single, centralized agent manager that encroaches into each platform’s territory, Agent 365 gives us one shared view across platforms, so administrators can coordinate their work with the same data and context.

With this new, single pane of glass, we’re building shared responsibility and clear handoffs where they make the most sense. For example, our AI administrators manage the full lifecycle of Microsoft 365 Copilot Agent Builder agents. But when Copilot Studio is involved, they collaborate with Power Platform administrators to strategically manage those agents in their specific environment.

Agent 365 provides the connective tissue by providing details and common metadata as we move between platforms and administrators.

“With agents in action across multiple spaces, managing them is a special challenge,” says Jonathan Clare, principal service engineering manager in Microsoft Digital. “It was clear that we needed a silo-buster to govern this new ecosystem effectively.”

Evolving agent management from existing roles

One key insight we’ve uncovered from this work is that agent administration doesn’t require a new IT skill set. It builds on the same foundational experience we already use to manage products like Power Platform, SharePoint, Exchange, and Entra, or other identity-based systems.

A photo of Johnson

“We’re still iterating on the seams between administrators with different responsibilities. Agent 365 is providing the space for AI and identity administrators to work closely alongside their colleagues in security, compliance, and governance.”

The core skills of maintaining accurate inventory, ensuring visibility and access, managing lifecycle, and mitigating risk are already mature and deeply established in our organization. Agent 365 now gives us the broad insight we need to oversee all agents in one place.

From there, we can lean into our well-developed expertise and mature processes with newly enhanced tools, shared metadata, logging, and controls. This coordination gives each team in sequence a sense of clarity and partnership, rather than feeding effort up and down a chain of approval.

“We’re still iterating on the seams between administrators with different responsibilities,” says David Johnson, a principal PM architect in Microsoft Digital. “Agent 365 is providing the space for AI and identity administrators to work closely alongside their colleagues in security, compliance, and governance.”

As we progress, we’re developing a three‑part administrative model facilitated by the oversight that Agent 365 provides.

AI administrators, the primary users for Agent 365

  • Oversee complete agent inventory and usage at the tenant level
  • Manage the agent lifecycle with the platform coordination to cover a broad range of agent types
  • Provide the connective tissue between security, governance, identity, and platform administrators

Agent Identity administrators, new with Agent ID

  • Manage agent identities after provisioning and throughout the agent’s lifecycle
  • Manage lifecycle events tied to users, access changes, and deprovisioning
  • Build identity backed policies for agent workload management and risk mitigation

Security, compliance, and governance teams

  • Define the guardrails that apply to agents and agent blueprints, portable specifications for agents’ identities, capabilities, constraints, policies, data access, and lifecycles
  • Approve the kinds of data, tools, and permissions agents can request
  • Set agent evaluation and risk assessment criteria along with risk-aligned approval workflows
  • Align publishing and runtime decisions with risk tolerance and security policy

Agent 365 facilitates this model by providing comprehensive agent coverage. This acts as a shared coordination layer, bringing different administrator, security, identity, and governance roles into a unified space.

A diagram showing the relationship between AI administrators from within Microsoft Digital and the Office of the CISO that collaborate within Agent 365.
Agent 365 has been a “role buster” for our team, because deploying it effectively requires people from different administrative disciplines to come together and operate as one team. 

Agent 365 in practice: Agent publishing and workflows

We didn’t create Agent 365 to handle every IT workflow. Many approval, vetting, and escalation processes are specific to an organization’s risk posture and operating model. At Microsoft, we’re currently handling much of that logic using an existing risk assessment and publishing workflow while evaluating how Agent 365 capabilities can simplify those steps. An example of the type of risk we look for is when an agent could read sensitive data and write it to destinations with broad access, like external sites or apps.

There are several areas of risk we use Agent 365 to assess:

The levels of agent risk, color-coded from green to red, and how they align with different areas like data, compliance, security, and identity.
Agent 365 plays complementary roles in our agent risk assessment model while we continue to work with the product team to enhance and scale risk assessment features.

Agent 365 itself assists us with additional risk awareness:  

Real-time

  • Observability across agents
  • Surfacing signals from identity, security, and governance systems
  • Supporting the ability to act when risks or issues surface

Proactive

  • More intelligent risk insight during the agent permissioning and approval processes
  • Consistent agent publishing into the environment
  • Forthcoming capability: the ability to integrate with our existing agent review and publishing process that spans multiple teams, including administration, governance, and security

As you consider ways to collaborate across your own administrator teams, our silo-busting approach can act as a helpful guide.

Key takeaways

Use these practices to build your foundation for agent administration:

  • Clearly parse security, governance, AI administration, and identity responsibilities. Define collaborative channels and explicit handoffs between the teams that manage these domains.
  • Treat Agent 365 as an oversight and coordination layer. It isn’t a replacement for platform or identity administrator expertise, but it’s the best place to look at the big picture.
  • Determine your criteria for agent risk assessment and publishing approval. Collaborate with relevant security, privacy, HR, legal, and other teams to calibrate your risk tolerance.
  • Define your agent lifecycle expectations. Tie these back to any governance you may have in agent creation workloads like SharePoint and Copilot Studio.
  • Establish visibility first, then layer in approval workflows. Match them to your organization’s risk tolerance and operating model.
  • Avoid creating a bureaucratic choke point. Successful agent administration depends on partnership and choreography, not centralization, where one administrator does it all.
  • Invest in cross-collaboration. Strengthen virtual teams, especially across identity, security, and agent creation surfaces.
  • Expect your administrative model to evolve. As Agent 365 matures and new lifecycle and approval capabilities become available, new practices will emerge organically.

Learn more

How we did it at Microsoft

Further guidance

Chapter 2: Building a registry of agents to manage them at scale

A centralized source of truth for AI agents across the enterprise

As agents have proliferated across Microsoft, visibility has proven essential for robust governance. Without a clear understanding of all the agents that exist in our environment, including their origin and how people use them, it’s very difficult to make informed decisions or respond confidently when risks emerge. Establishing a thorough registry of agents and their key information is a critical step in governing the ecosystem.

Agent 365 provides that oversight.

Why an agent registry matters

An agent registry establishes the foundation for oversight, control, and compliance. As an organization introduces more agents, the environment can quickly become fragmented and difficult to track.

A comprehensive registry provides a single, authoritative inventory that makes every agent visible, tracks ownership, and captures key metadata. With that baseline, organizations can consistently govern, secure, and manage their agents with confidence.

A photo of Powers

“Managing agents begins with having a complete inventory with rich information, like their name, lifecycle status, type, ID, owner, where we created them, and where we’re using them. Once you have that level of clarity, everything else—security, compliance, lifecycle management—becomes much easier to manage.”

At the scale of a company like Microsoft, even small gaps in visibility can quickly become operational hurdles or compliance liabilities. Without that foundation, an organization faces substantial risks:

  • Ownerless agents remain active after employees leave the company.
  • Shadow or unsanctioned agents are difficult to detect.
  • Oversight is unreliable with respect to agent growth, usage, and impact.

“Managing agents begins with having a complete inventory with rich information, like their name, lifecycle status, type, ID, owner, where we created them, and where we’re using them,” says Mike Powers, an AI administrator in Microsoft Digital. “Once you have that level of clarity, everything else—security, compliance, lifecycle management—becomes much easier to manage.”

Agent 365 registry capabilities

Within Agent 365, the registry acts as a central inventory enriched with metadata. We use that metadata to meet compliance, security, and management standards, including:

  • Agent ownership and associated teams
  • Creation platforms and publishing surfaces
  • Lifecycle states like “draft” or “published”
  • User scope: who can discover and use the agent

In Microsoft Digital, we’re providing real-world feedback to the Agent 365 product group to enable even more types of metadata, like differentiation between system vs. user-created agents, and new agent types like AI teammates. We’re also using metadata surfaced from the platform where the agent was created, for example, the Power Platform environment ID for Copilot Studio agents and the Azure AI Foundry subscription details for Foundry agents.

Agent 365 amalgamates all of this metadata into a single view.

This structure matters because agents vary widely. Some are short‑lived experiments. Some belong to only one employee, while others are broadly shared. Treating them all the same doesn’t make sense.

From an administrative perspective, the registry gives us:

A summary view of total agent count

Insights around growth and adoption

Identification of agents without owners

Analytics on platforms used to make agents and their usage trends

Search, sort, and filtering with customizable columns to get detailed views across agent types

Robust inventory export capabilities to support collaboration with security, compliance, and business stakeholders

Establishing our Agent 365 registry

The agent registry is an out-of-the-box feature for Agent 365, so there’s nothing to deploy or configure. As Customer Zero, we’ve focused much of our early work on validating the registry for accuracy and completeness.

Agent 365 automatically ingests agent metadata from supported platforms. This technology is still new, so we’ve partnered with product teams across SharePoint, Power Platform, Azure AI Foundry, and other builder experiences to reconcile counts, ensure accuracy, and request additional relevant metadata.

For first-party tools, Agent 365 creates registry entries automatically. Third-party agents can also benefit from automatic registration if their creators use the Agent 365 SDK during development.

For pro‑code scenarios, Entra Agent ID is key. Registering an agent through Entra assigns it a formal identity, which lays the groundwork for consistent identity and lifecycle management and conditional access policies.

Acting on the registry

The registry is a living system. Ownership changes, while lifecycle states and usage signals update automatically.

That means the registry supports critical processes for administrators that include:

  • Passing audits for elements like tracking agent ownership
  • Presenting the tenant’s agent footprint and usage to business decision makers
  • Scoping agents to specific users, or excluding users based on regional or regulatory requirements
  • Highlighting high‑impact agents based on usage and runtime

A single view has been one of the most valuable outcomes for us, enabling informed operational decisions and peer-to-peer collaboration.

Looking ahead

The registry is also the prerequisite for future experiences, including broader agent discovery and publishing. Moving forward, it will provide the context we need to guide reuse, review, publishing, and eventual retirement to support intentional agent lifecycle practices over time. As a result, it will be easier to combat sprawl and ownerless agents.

In Microsoft Digital, our early Agent 365 efforts have focused on validating our agent registry to lay the foundation for comprehensive observability. It may be helpful for you to mirror this approach.

Key takeaways

Here’s what we’ve learned during the initial stages of building and operating our agent registry:

  • The registry isn’t just an inventory. It’s the foundation for agent governance and insights to help take more informed actions and avoid risk.
  • Establish accountability. Use the registry to ensure every agent has a clear owner and lifecycle state.
  • Dive deep for the most value. Analyze the Agent 365 inventory export files and compare them with any previous methods you used to gather information about agents, for example, Power Platform, SharePoint, or other bespoke methods, to ensure accuracy and consistency.
  • Break down silos using the agent registry. The information Agent 365 provides will break down administrative silos across IT, security, identity, and business teams for more informed and collaborative analysis and discussions about agent adoption.

Learn more

How we did it at Microsoft

Further guidance

Chapter 3: Visualizing agents to support oversight and action

Observability: Scaling beyond dashboards

At the scale of an organization like Microsoft, dashboards alone aren’t enough. We already have hundreds of thousands of agents in use across the company. At that scale, it would be impossible to review these agents individually. We rely on well-established governance in the form of guardrails, established software development lifecycle procedures, and risk-based app and agent management policies that trigger reviews when we detect risk.

Agent 365 helps us operationalize oversight using automation and rules engines, programmatic access via APIs and scripting, and bulk actions based on attributes like permissions, connectors, and usage patterns.

A simple user interface is essential for visibility, assessment, and decision‑making. Programmatic access is essential for execution. Effective agent administration requires both.

The lesson is that administering agents during Frontier Transformation requires a new approach that breaks out of traditional roles and inter-team hierarchies. By incorporating our experience into your own planning, you can use Agent 365 more effectively.

Why visualization matters

As agents spread across Microsoft, we learned that inventory alone isn’t enough. Knowing an agent exists is helpful, but understanding how people use it, how it connects to data and other agents to complete workflows, and where risks or concentration points emerge is what makes effective governance possible at scale.

In a Frontier Firm where almost anyone can create agents, observability is a core pillar of management. Like many organizations, we built agents first and only later confronted the challenge of seeing what existed. Agent 365 will help other organizations reverse that order by surfacing agent behavior continuously from the start.

A photo of Ceurvorst

“Just this first layer of visualizing our agent ecosystem in one central place is a big step toward flowing them into our business processes and demonstrating ROI more effectively.”

Visualization is helping us address questions we couldn’t answer before:

  • Where is agent growth accelerating?
  • Which agents are widely used?
  • Where do risk hot spots occur across connectors, data sources, and permissions?
  • What demands attention now, and what can wait?

“We’re uncovering so many new use cases for agents,” says Amy Ceurvorst, a director of business programs in Microsoft Digital. “Just this first layer of visualizing our agent ecosystem in one central place is a big step toward flowing them into our business processes and demonstrating ROI more effectively.”

The agent landscape changes quickly, and with Agent 365, we can look at usage at the individual agent level to track shifts over time. For example, Cowork (Frontier) is one of our newest agents, but in just a few weeks it became our most widely used.

In a recent review of Cowork adoption, Agent 365 allowed us to quickly analyze names, session activity, and locations for Cowork’s 58,000 active users in just a few minutes.

This is also where Agent 365 complements rather than replaces Viva Insights:

  • Viva Insights combines Agent 365 data with our organization’s people data to provide enhanced insights into agent usage across the organization.
  • Agent 365 provides oversight for the full agent estate: registry, publishing, ownership, lifecycle, and governance.

Both are important, but they serve different personas. Where Viva helps clarify usage for adoption leaders and change managers, Agent 365 helps determine what action IT should take next.

The Viva Insights Agent Dashboard extends the data in Agent 365 by translating agent inventory and telemetry into executive‑ready insights on adoption, usage patterns, and trends across the organization. By combining agent activity with organizational context, it helps leaders understand where people are using agents, how adoption is evolving over time, and where opportunities or risks may exist.

Together, Agent 365 and Viva Insights provide a governed, end‑to‑end view that supports informed decisions about scaling and governing agents to drive business impact.

From insight to action

One of our biggest lessons as Customer Zero is that visualization only matters if it leads to action. In Agent 365, insights increasingly surface as prioritized scenarios, such as risky, ownerless, or unused agents. We can then pair those insights with paths to response—for example, meeting compliance expectations by re-assigning or retiring ownerless agents.

A photo of Zimmer

“Agent 365 is saving us time by helping us analyze the kinds of issues that are common in agent management and bringing those to our administrators’ attention. It acts as a command center that surfaces those issues programmatically, so we’re able to prioritize the actions we need to take.”

Visualization in Agent 365 is about prioritization. For us, some of the most valuable scenarios include:

The goal is to focus attention where it counts.

“Agent 365 is saving us time by helping us analyze the kinds of issues that are common in agent management and bringing those to our administrators’ attention,” says Nate Zimmer, a senior product manager in Microsoft Digital. “It acts as a command center that surfaces those issues programmatically, so we’re able to prioritize the actions we need to take.”

Continuously clearing the fog

Observability is never finished. New agent types and creation tools continue to emerge. Agent 365 helps us embrace that reality by connecting signals across Microsoft 365, identity, security, and compliance for a continuously updated view of an evolving agent landscape.

We believe the Agent Map is going to be a differentiator in agent visualization, and we’re closely working with the product team to inform new, robust capabilities that will help us drill down to find hot spots, details on agent connectors, tools, and knowledge sources more easily.

For example, we use the large surface area provided by the Agent Map to search and filter for exactly what we want and then dive deeper into details.

Observability has been crucial for helping us guide agent usage at Microsoft. As you conduct Frontier Transformation at your organization, consider ways that observability has led to better oversight for our team, and incorporate them into your AI administrators’ discipline.

Key takeaways

Think about these lessons from Microsoft Digital as you considering using visualization for managing your agents:

  • Prioritize your attention. Use visualization to surface and remediate your greatest liabilities.
  • Scale through technology. Pair visualizations with the registry to operate at the right level of detail. Many visualization features also support targeted exports, for example, exporting just the users accessing a specific agent.
  • Prepare for new issues and risks. With greater visibility comes heightened awareness of issues. Expect visualization to surface new risks and new personas as agent adoption grows.

Learn more

How we did it at Microsoft

Further guidance

Chapter 4: Securing agents and aligning Agent 365 with organizational priorities

Melding agent oversight, identity, security, and governance

In Microsoft Digital, we’ve learned that securing agentic AI isn’t about inventing an entirely new security model. Instead, the focus should be on extending the identity, data, and threat protections we already trust, while also making risk visible in one place. Agent 365 plays a critical role by surfacing agent‑related security signals in a single view so that IT teams can see what matters quickly, even when remediation happens elsewhere.

The agentic security challenge

Up to this point, understanding agent risk has meant pulling information from multiple tools and manually stitching together context. Identity management lives in one place, data protection in another, and threat insights somewhere else. That makes it harder for IT administrators to spot patterns and gain insight.

A photo of Enjeti

“A lack of visibility creates real security risk, exposed data access, unmonitored behaviors, and unmanaged identities. Agent 365 helps us regain control by building a comprehensive inventory and risk profile of agents.”

Other factors compound the challenge:

  • People and teams are creating agents quickly, accelerating the need for manual reviews.
  • Agents can operate across apps, data sources, action types, data, and data destinations, and they carry the potential for other agents to expand the attack surface, complicating oversight and control.
  • Risk emerges at multiple stages, both during agent development (design time) and during execution (run time).

“This lack of visibility creates real security risk, exposed data access, unmonitored behaviors, and unmanaged identities,” says Prathiba Enjeti, a principal security manager for the Microsoft CISO organization. “Agent 365 helps us regain control by building a comprehensive inventory and risk profile of agents.”

Theoretically, existing agent governance policies and practices should mitigate these risks, but there are always exceptions. It’s easy to miss early warning signals, and teams may only detect issues after they have an impact.

Agent 365 helps us identify and remediate those issues.

Agent 365 as a security visibility layer

As we bring Agent 365 into our operational workflows, it connects with Microsoft Purview, Microsoft Entra, and Microsoft Defender, surfacing relevant agent‑specific risk insights in a cohesive experience. That reduces fragmentation and supports more informed, coordinated decisions.

You can see how Agent 365 capabilities apply to different members of the agent administration and management ecosystem.

A three-part Venn diagram featuring areas where Agent 365 breaks down silos between different agent administration roles: IT, identity, and security.
Agent 365 facilitates coordination between different administrator roles.

Rather than replacing those tools, Agent 365 ingests identity signals from Entra, data signals from Purview, and runtime behavior from Defender. In practice, we think about agent security in two main categories:

  • Buildtime risk: These signals surface when people create or configure agents. Examples include overly broad permissions, insecure configurations, or missing responsible AI safeguards. Seeing these early helps reduce downstream risk and rework.
  • Run-time risk: As agents operate, they can expose data unexpectedly, become susceptible to vulnerabilities like prompt injection, or lose protection as data moves across systems. Run-time visibility becomes even more important as agents begin working together.

Agent 365 doesn’t eliminate these risks, but it does have the capacity to make them more visible, traceable, and easier to prioritize and mitigate. Follow‑up actions still happen in Entra, Purview, and Defender, but now those administrators benefit from improved oversight and coordination.

What we’ve learned so far

Internally, broader visibility has helped us uncover issues we had difficulty tracking before, like ownerless agents spanning multiple platforms or unexpected data handling behaviors. While more broadly available agent oversight might seem intimidating because it widens scrutiny, we’ve found that additional data and insights have accelerated alignment and improved decision making.

With Agent 365, we now have better conversations through shared context and metadata. As a result, IT, security, and business teams can discuss adoption trends and mitigate risk using the same information instead of chasing it across tools.

Key takeaways

You can follow the lessons we’ve learned while further securing agents using Agent 365:

  • Oversight is not a replacement for security.  Use Agent 365 as a central visibility layer, not a substitute for existing security tools and practices.
  • Creation and operation both contain risks. Expect security signals at both build time and runtime.
  • Build a practice of consolidation. Prioritize investigation using consolidated signals, even when remediation happens elsewhere.
  • Choreograph the tools between teams and functions. Integrate Agent 365 into existing security operations rather than creating parallel workflows.

Learn more

How we did it at Microsoft

Further guidance

Conclusion: Turning visibility into confidence as agents scale

As we reflect on the early days of Agent 365, visibility is the foundation for everything that follows. As Customer Zero, our priority has been to understand the full extent of agents across our environment.

The real value will come when we can drill down further. How are people using agents? What risk patterns repeat? What building and usage trends emerge as Frontier Transformation progresses?

A photo of Tiwari

“When we started, I thought the hardest part would be the technology, but it turned out to be building the weekly rhythm where IT, security, identity, product, and business unit teams could look at the same picture, make decisions from the same facts, and act together. My advice to every IT leader is to establish that governance rhythm before your agent count grows faster than your ability to manage it.”

As we mature in our use of Agent 365, it will give us greater ability to move from simple metrics like volumes of agents to more meaningful measures of impact. It will also help us see trends in our environment by segmenting low-use experimental agents from business‑critical digital workers so we can move beyond isolated usage to scaled adoption.

It’s important to be clear about where we are on this journey. Our operating model for Agent 365 isn’t complete. Much of our current focus is still on seeing clearly by surfacing trends, comparisons, and emerging patterns we couldn’t identify before.

“When we started, I thought the hardest part would be the technology, but it turned out to be building the weekly rhythm where IT, security, identity, product, and business unit teams could look at the same picture, make decisions from the same facts, and act together,” says Garima Tiwari, a principal product manager for Agent 365 Customer Zero in Microsoft Digital. “My advice to every IT leader is to establish that governance rhythm before your agent count grows faster than your ability to manage it.”

That visibility is already paying dividends by revealing duplication, ownerless agents, and cross‑platform risks that would otherwise remain uncovered. Over time, those insights will increasingly feed automation, lifecycle workflows, and deeper integrations across identity, security, and governance.

Looking ahead, our next steps are about translating this oversight into action at scale. That will include preparing for broader agent discovery, refining lifecycle management, and enabling new personas, such as managers who are responsible for selecting, creating, and overseeing digital workers. It will also encapsulate learning as new agent types, tools, and usage patterns emerge. Change is constant in a Frontier Firm environment; readiness is something you build continuously, not something you check off once.

A photo of Kerametlian

“Agent 365 represents a new operating model for AI at scale. By bringing visibility, governance, and security together, it helps organizations move beyond experimentation and toward a future where agents are trusted and embedded in everyday work, all without slowing innovation.”

Our overall message in this guide is straightforward: You don’t need to have every answer on day one. What matters most is establishing the conditions for safe evolution as agents scale. Think about clear administration practices, a reliable registry, effective observability, and security signals you can trust. Here at Microsoft, Agent 365 has become an important part of that foundation.

“Agent 365 represents a new operating model for AI at scale,” says Stephan Kerametlian, a senior director in Microsoft Digital. “By bringing visibility, governance, and security together, it helps organizations move beyond experimentation and toward a future where agents are trusted and embedded in everyday work, all without slowing innovation.”

We’ll continue sharing what we learn as Customer Zero. As your organization moves through its own Frontier Firm transformation, we hope these lessons help you build the confidence to innovate quickly, supported by comprehensive insights, thoughtful governance, and security that scales with your ambition.

Key takeaways

Here are the essential top-level learnings that we’ve developed from our Customer Zero experience with Agent 365 so far. They can help guide your own readiness and implementation journey:

  • Agent governance is becoming a team sport. Agents touch on identity, permissions, data access, workflow automation, compliance, and business outcomes. That means agent governance requires cross-team alignment.
  • Start with visibility, not perfection. You don’t need a fully mature operating model on day one. What matters most is creating shared visibility and data about what agents exist, how people use them, and where risks or opportunities are emerging.
  • Treat agent management as an evolution of IT practice. Managing agents builds on familiar disciplines like identity, lifecycle, access control, and security rather than replacing them.
  • Clearly define roles and handoffs. Effective agent governance depends on clear coordination between security teams, AI administrators, identity administrators, and platform owners. Think choreography, not hierarchy.
  • Use registries and metadata to enable an increased understanding of agents. A reliable agent registry with ownership, lifecycle state, and usage data is foundational. Without it, agent sprawl, duplication, and ownerless agents become unavoidable as adoption grows.
  • Rely on visualization to focus attention where it matters most. Visualization is about surfacing patterns, hotspots, and trends so IT can prioritize action, especially in large or complex environments.
  • Plan for continuous learning, not a finished state. Agent ecosystems evolve quickly. New agent types, tools, and usage patterns will continue to emerge. Readiness is an ongoing capability that improves as oversight, automation, and governance mature together.

Try it out

Related links

The post Implementing Agent 365: How we’re governing and managing AI agents at Microsoft appeared first on Inside Track Blog.

]]>
24764
How Microsoft built an AI coach to scale personalized sales training http://approjects.co.za/?big=insidetrack/blog/how-microsoft-built-an-ai-coach-to-scale-personalized-sales-training/ Thu, 30 Jul 2026 16:15:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24937 What would happen if you built an AI version of your CEO to coach thousands of sellers? At Microsoft, that question emerged from a much larger challenge: How to rapidly upskill our customer and partner-facing teams in a way that is scalable, role-specific, and grounded in real business conversations. To bring this to life, we […]

The post How Microsoft built an AI coach to scale personalized sales training appeared first on Inside Track Blog.

]]>
What would happen if you built an AI version of your CEO to coach thousands of sellers?

At Microsoft, that question emerged from a much larger challenge: How to rapidly upskill our customer and partner-facing teams in a way that is scalable, role-specific, and grounded in real business conversations. To bring this to life, we focused on how our sellers could practice and apply these skills in real-world scenarios.

One example of this approach is Agent J.ai. This agent is an on-demand, AI-powered coach we designed to enhance the skills and performance of 64,000 of our Microsoft Commercial employees serving in sales roles. And it’s not just any AI-powered coach—it’s modeled off of Judson Altoff, CEO of our commercial organization.

For our sales, partner, and service teams, this project represented a shift in how we approach skilling internally. We’re not just delivering training on Microsoft AI solutions; we’re using AI itself to power how those skills are learned in practice.

At Microsoft, this is what Customer Zero looks like in real-world scenarios—using our own AI solutions to solve a core business challenge: Helping customer-facing teams build skills for real customer and partner conversations at scale.

We’re building and testing AI tools inside the organization, observing what consistently works, and sharing practical insights with our customers.

Upskilling employees on Microsoft AI solutions

Upskilling thousands of employees at scale—and giving them customized instruction that fits their specific needs—is a tremendous challenge for any organization. Teams have limited time, and there’s the issue of making sure the content is up to date and in line with organizational strategy. These teams also need to access accurate, specific information across a vast content repository.

Our internal AI Transformation team had already embarked on a global campaign to educate and train our customer and partner-facing teams on Microsoft AI solutions. They had developed job aids, demos, and videos tailored to sales scenarios like account planning, opportunity qualification, and customer meeting prep. They’d also launched campaigns, Learning Days, and contests like “The Road to 60,” which encouraged teams to reach 60% daily active usage of our Al solutions.

These initiatives showed positive results, with a 68% boost in customer planning efficiency for an account executive, and a 62% gain in agile workflows for a business program manager. But the teams also realized that AI itself could help scale and customize this training even further. That’s where Agent J.ai came in.

Upskilling with a familiar AI coach

According to Stacey Herod, a senior learning manager here at Microsoft, project members gathered focus groups of employees in varying roles across the commercial organization to help understand the issues that customer and partner-facing teams face. They pinpointed challenges with speaking the language of the customer, establishing executive presence, connecting solutions to business outcomes, and understanding how to best serve as a trusted advisor to customers.

The team wanted to develop a coaching experience that could simulate real customer conversations and reflect how strong sellers actually operate in the field.

At the center of that experience is a familiar voice modeled after Althoff. For customer and partner-facing teams, Althoff’s approach represents how experienced leaders define the vision and share deep expertise that speaks to our customers’ needs.

“It started as a fun experiment—replicating Judson as a mini version of himself, where you could always have him by your side, coaching you in real time,” Herod says. “But it quickly revealed an opportunity to scale executive-level guidance. Now, customer and partner-facing teams can bring their own scenarios and engage with a trusted voice—making learning more personal and impactful.”

Instead of a one-to-many model, we can now interact with and learn from that perspective on demand.

Learning isn’t about just accessing information; it’s about understanding how experienced leaders navigate conversations, connect solutions to business outcomes, and build trust with customers and partners. Modeling the experience on that perspective helped translate those behaviors into a scalable, practical format.

Althoff was fully onboard with the project and closely involved with its creation, adhering to the company’s principles around responsible and ethical AI use. We also knew that having executive buy-in and sponsorship is critical when it comes to increasing adoption of tools like Agent J.ai across the company.

A photo of Herod.

“We want people to feel comfortable practicing conversations with artificial intelligence, so they can refine their approach and be prepared ahead of a customer meeting, not practicing with their customers.”

Stacey Herod, senior learning manager, Microsoft

Rethinking how skills are built with AI

At Microsoft, this shift is already underway. Agent J.ai is part of a broader ongoing effort to rethink how skills are built with AI, and our employees are trusting the experience. Importantly, conversations that our employees are having aren’t tied to individual identities, rather the content is curated to the specific needs around upskilling employees. That sense of privacy made it easier for sellers to engage openly and use it without hesitation.

“There’s behavioral change happening at the agentic level—people’s level of comfort using agents,” Herod says. “We want people to feel comfortable practicing conversations with artificial intelligence, so they can refine their approach and be prepared ahead of a customer meeting, not practicing with their customers.”

Practice is central to this model.

“Agent J.ai fundamentally changes skilling—from static training to dynamic, scenario-driven coaching. It adapts in real time to each seller’s context, enabling hundreds of roles and limitless customer scenarios to be addressed instantly—something our industry has never achieved at this scale.”

Jennifer Wheeler, senior learning manager, Microsoft

Role-playing helps simulate realistic, highly customized conversations that customer and partner-facing teams might have with a certain type of client or executive. For example, an account executive might need to prepare for an upcoming conversation with a chief security officer.

Our AI coach’s training must be able to recognize that context.

“Agent J.ai fundamentally changes skilling—from static training to dynamic, scenario-driven coaching,” says Jennifer Wheeler, a senior learning manager at Microsoft. “It adapts in real time to each seller’s context, enabling hundreds of roles and limitless customer scenarios to be addressed instantly—something our industry has never achieved at this scale.”

An AI agent trained on curated content, Microsoft’s customer engagement and coaching frameworks, and a trusted persona could finally deliver what teams lacked—authentic conversation practice tailored to real scenarios, industries, and executive audiences.

Launching and refining our AI coach

We rolled Agent J.ai out quickly, with a focus on iterating based on real-world use. From the start, members of the cross-functional team prioritized capturing feedback and continuously refining the experience based on how sellers use the tool in practice.

A photo of Felker.

“We are seeing the rise of voice-first subject matter expertise agents across industries, and Agent J.ai has demonstrated what’s possible in the Frontier.”

Max Felker, principal product manager, Microsoft

The team began the Agent J.ai project in earnest in March 2025 and shipped the first version just five months later in July. Input from super users helped test specific scenarios, while broader anonymous forms surfaced key insights.

One example: In the user experience, we discovered that using overly realistic or animated avatars for the AI coach could be perceived by users as gimmicky and might prove more expensive to produce. A simple photo avatar ended up doing the trick.  

As a voice-based coaching agent, Agent J.ai is designed for spoken, two-way conversations with users.

“We are seeing the rise of voice-first subject matter expertise agents across industries, and Agent J.ai has demonstrated what’s possible in the Frontier,” says Max Felker, principal product manager for Microsoft.

Incorporating updated industry trends and live events

Staying current is critical for customer-facing teams, especially when conversations shift quickly based on new announcements and industry trends.

“I had a couple of people who said, ‘This is incredible. This saved me hours, or weeks, and I was able to have it in 5 minutes.’ That’s something we never thought would be possible.”

Stacey Herod, senior learning manager, Microsoft

Typically, pulling information together for real customer conversations took time. Powered by Microsoft Azure and Azure AI, Agent J.ai can incorporate announcements from events like Microsoft Ignite, so the AI coach could help prepare sales teams for questions about the latest news.

“I had a couple people who said, ‘This is incredible. This saved me hours, or weeks, and I was able to have it in 5 minutes,’” Herod says. “That’s something we never thought would be possible.”

Others reported saving up to 50% of their standard prep time, not to mention more than $80 million in deals that were influenced through refined strategy and approach.

In the end, the team was laser-focused on making something valuable and accessible for their sales teams.

“If the Agent wasn’t useful, then our learners were never going to come back and use it,” says Herod, a seller in the past herself. “You have one shot to impress sellers. We’re a tough community.”

Key takeaways

Here are some of the lessons Herod and her team learned from building Agent J.ai that you can consider as you plan your own AI skilling efforts:

  • Start with understanding the needs of your users. From focus groups to community learning calls, define the problem with the people living it. Build with your users, grounding your work in the challenges they are trying to solve.
  • Don’t stop listening once you launch. Sustained value comes from continuous feedback and iteration.
  • Create safe, trusted environments for practice by pairing strong privacy protections with clear communication. Build secure, compliant, and responsible AI experiences, and explicitly reinforce that your sellers can safely use role-play to prepare for real conversations.
  • Drive adoption through intentional change management. Because you’re developing an agentic coach, it’s critical to train your users on how to get value from it. Build this muscle through targeted campaigns and hands-on enablement that highlight what’s fundamentally different.
  • Trust matters as much as sponsorship. Solve the biggest validated problems with your users, earn their sign-off, and build a coalition of sponsors and influencers. When people see their problems reflected and solved, adoption scales organically.

Try it out

Related links

The post How Microsoft built an AI coach to scale personalized sales training appeared first on Inside Track Blog.

]]>
24937
Unlocking the value of Microsoft 365 Copilot and agents at Microsoft http://approjects.co.za/?big=insidetrack/blog/unlocking-the-value-of-microsoft-365-copilot-and-agents-at-microsoft/ Thu, 30 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24946 In Microsoft Digital, our company’s IT department, we get to share our internal learnings on deploying and using Microsoft 365 Copilot and agents with many of our enterprise customers. During in-person briefings, I often remind our customers that generative AI systems like Copilot and Copilot Cowork are still quite new, and that they upend decades […]

The post Unlocking the value of Microsoft 365 Copilot and agents at Microsoft appeared first on Inside Track Blog.

]]>
In Microsoft Digital, our company’s IT department, we get to share our internal learnings on deploying and using Microsoft 365 Copilot and agents with many of our enterprise customers.

During in-person briefings, I often remind our customers that generative AI systems like Copilot and Copilot Cowork are still quite new, and that they upend decades of human-computer interaction patterns. For over 40 years, we’ve trained knowledge workers to memorize patterns in the GUI to support their productivity.

With Copilot and agents, you can type nearly anything as a prompt and instantly get a detailed response, or create an agent to autonomously complete a business process on your behalf. It’s a very new way of working, and it’s no surprise that many knowledge workers—and even engineers themselves—are still adapting.

More than anything, our customers are looking for one key insight: They want to know how we measure and define the business value of Copilot and agents at Microsoft, especially through the lens of increased productivity and cost savings. After all, AI systems represent a significant investment for our customers, and leaders want to have confidence that they’ll yield sufficient ROI to justify the cost, knowing that the payback period isn’t immediate.

Six steps to proving value

So, how do you prove the value of AI-powered tools in the enterprise? There are six main steps that I share with customers that I believe are critical, based on the empirical evidence we’ve gathered in Microsoft Digital.

Graphic showing the six steps for measuring Copilot and agent value: identifying pain points, measuring processes, investing in enterprise AI skilling, deploying Copilot by cohorts, measuring identified processes, and recapturing value from time saved.
This graphic shows the six main steps for measuring Copilot and agent value in an organization.

Our big mistake? We didn’t instrument all the arduous business processes that slow us down and impact effectiveness before our deployment, so that we could more easily prove the value of AI across our enterprise after deployment.

Here are further details on the six measurement steps to keep in mind:

  1. Before you deploy, talk to people who are doing the frontline work in your organization. These should be hands-on managers or influential individual contributors (ICs), not executives or mid-level managers who are abstracted away from the work (although these individuals can be useful in helping identify the right SMEs to talk to).

For each role, identify three to five everyday pain points that could benefit from Copilot or agents. These could be operational, business, or technological processes, all of which can be improved by thoughtful applications of AI. This phase provides a great chance to use Six Sigma skills or other continuous improvement (CI) methodologies to evaluate your processes and identify waste, then consider how a combination of CI and AI could make them more efficient.

  1. Once identified, instrument and measure each of the processes to get baseline data on the average time it takes to complete them. Then the hard work begins—you need to think deeply about how AI could make those processes better. This could be through defining a series of step-like prompts that take away the toil. It could be through further AI-powered automation to make some of the steps go away. It could be applications of AI that validate outputs to ensure that rework is minimized. More and more, it could be an agent that completes the work on the employee’s behalf.

If you lack detailed telemetry for the process in question, you have two options. The first is preferable: Build end-to-end telemetry, so you have observability throughout the process in question. While this is always the best way to reliably measure productivity gains at scale, there is also a second option: Identify a cross-section of ICs and measure them the old-fashioned way as they complete the process in question—with a stopwatch. Take the average of several people to get a better sense of how much time is typically needed to complete the task. Then consider how AI could make that process more efficient, while also improving the resulting business outcomes.

  1. Concurrent with your investigation into ways that AI can improve productivity and reduce toil, you need to invest in enterprise AI skilling, ideally by role. The fact is, engineers are going to use AI differently than operations staff, who are going to use it differently than sales and marketing pros. Yes, there are common skills for each, but the best training is tailored to the role, grounded in the experience of using Copilot or agents to address challenges or opportunities that commonly arise in their day-to-day work.

It’s also important to ensure your employees understand the strengths and weaknesses of current AI models. No model is perfect, and understanding where reasoning errors can occur will help them avoid accepting AI-generated output that may be inaccurate. Human discernment and observability is a critical step in validating AI outputs.

A best practice is to gate access to generative AI; require employees to engage in both general and role-specific training prior to their provisioning to ensure they immediately unlock value in their work.

  1. After you’ve trained your employees and given them the skills to succeed with AI and agents in the enterprise, begin your deployment in earnest. For tools like Copilot, we recommend deploying in cohorts by role, focusing on employees who will immediately see the greatest benefit. At Microsoft, we started with our sales team and then gradually deployed to the remaining employee population over the course of several months. This enabled us to scale up our skilling programs, governance strategies, and support function in anticipation of increased volumes. For agents, deploy to support the biggest pain points first, then monitor and observe agent performance before scaling to additional business or operational processes.
  2. Post-deployment, give it a few weeks, then return to those same processes you identified in the first step and measure the average time savings. If time savings aren’t as significant as you hoped with either Copilot or agents, go back to process evaluation and employee skilling and continue to refine your approach.

This whole process is intentionally iterative—you’re not likely to get it exactly right on the first attempt. But if a process that used to take 30 minutes can now be completed in 10, you’ve obviously made a big difference that will save a lot of time when extrapolated across an entire fiscal year. Even better if that end-to-end process is now being completed by an autonomous agent, with a human reviewing and validating the output.

After you’ve succeeded in one domain, identify different role leaders and find another batch of processes that could be improved with a combination of continuous improvement and AI. There’s really no limit to the scope of ways you can positively impact your employees if you maintain a sharp focus on continually improving their experience with Copilot and agents.

  1. The final step: Reclaim the value from those productivity savings and apply it to new business challenges or opportunities. Let’s be clear—most enterprises aren’t investing in AI solely to give their people back time. They’re trying to do more with less, enabling their workers to be more productive and generate more value for the company.

In this crucial final phase, you need to be thoughtful and deliberate about how you’ll use the time saved with AI. If your people are saving two hours per week on average, how will they use that time? There are innumerable ways you could redeploy that time to address new business challenges or opportunities. The key is to be intentional in maximizing value, so it aligns with your team and your company’s goals and ambitions. Then report those savings to the appropriate members of the leadership team, to help them understand how their AI investments are paying off.

There you have it—you now possess the tools to quantify the value of your generative AI investments in the enterprise, using them to recapture value and drive more business impact thanks to the power of Copilot and agents.

Boosting AI adoption with structured change management

As you can see from the graphic above, it’s important to surround the AI value measurement process with structured change management and ongoing employee skilling. In Microsoft Digital, we’ve learned that even the most useful or intuitive technologies won’t see widespread adoption without a deliberate and sustained change management effort that’s localized to meet the disparate needs of a global organization.

In our case, that meant cultivating and supporting a community of Copilot Champions who have become the backbone of our global change management strategy. This community is now 10,000+ strong and even has its own Viva Engage forum, where our Copilot enthusiasts answer employee questions and share useful prompts.

Unfortunately, just doing AI skilling once won’t be enough. The pace of change with Copilot and agents is simply too great to do one training effort and then move on. Building an AI-forward culture takes time, and ongoing opportunities to learn and improve skills are one of the best ways to help your employees build the AI habit.

The Microsoft 365 Admin Center has an “AI adoption score” that can help you see—by cohort—how successfully people are building that habit. Having employees who use Copilot three times per week in any way is enough to build an AI-focused workforce, enabling your company to unlock the value of AI in the enterprise.

The promise of generative AI is significant, and there’s no doubt that you’ll see qualitative benefits in your organization even if you don’t instrument every process. But in an era of tight IT budgets, having the quantitative data necessary to calculate the ROI of your investments in Copilot and agents will make it far more likely that you’ll get financial support from your executive team to deploy and succeed at scale.

Key takeaways

Here are some key things to remember as you embark on your own Copilot and agent value measurement efforts:

  • Start at the beginning. Work with influential individual contributors and frontline managers to identify operational, business, and technological pain points, then measure those processes to understand their impact. Carefully consider how AI could accelerate each of those processes through structured prompts, workflow automation, and other techniques.
  • After you identify time savings, be thoughtful in applying that reclaimed capacity to new business opportunities or challenges. The point isn’t to just save time or lower costs—it’s to unlock productivity, so your employees can do more with less and create new ways for your business to thrive.
  • Generative AI skilling is not a one-time event—it’s an ongoing investment in your people to help them seize this generational opportunity with AI. Beyond general AI skills, consider how role-based training could help you accelerate the aptitude of specific employee groups in your organization.

Try it out

Related links

The post Unlocking the value of Microsoft 365 Copilot and agents at Microsoft appeared first on Inside Track Blog.

]]>
24946