Agent Archives - Inside Track Blog http://approjects.co.za/?big=insidetrack/blog/tag/agent/ How Microsoft does IT Wed, 22 Jul 2026 22:14:38 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 137088546 Streamlining business operations at Microsoft with an AI toolkit http://approjects.co.za/?big=insidetrack/blog/streamlining-business-operations-at-microsoft-with-an-ai-toolkit/ Thu, 23 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24720 At Microsoft, we manage one of the world’s largest global corporate operations. Our operations teams process hundreds of billions in revenue and millions of transactions while adapting to fast-changing business demands. Much of that work flows through Business Process Outsourcing (BPO) operations, where vendors support workflows such as order and agreement processing. As these processes […]

The post Streamlining business operations at Microsoft with an AI toolkit appeared first on Inside Track Blog.

]]>
At Microsoft, we manage one of the world’s largest global corporate operations. Our operations teams process hundreds of billions in revenue and millions of transactions while adapting to fast-changing business demands. Much of that work flows through Business Process Outsourcing (BPO) operations, where vendors support workflows such as order and agreement processing.

As these processes grew in scale and complexity, it became clear that improving something highly manual and already operating at massive scale would require a fundamentally different approach.

“With BPO, we’re dealing with high-volume, high-touch processes that are core to how the business runs,” says Jonathan d’Orgee, an AI transformation lead for Microsoft Business Operations.

For many organizations, the idea of overhauling a core business process can feel like a daunting step. At Microsoft we act as our own first customer, which gives us a way to test, refine, and de-risk that transformation in our own operations before bringing those proven patterns to customers. We call this approach Customer Zero.

In this case, that meant rethinking how high-volume operations could run better with AI directly embedded into day-to-day tasks, including building solutions using tools like Microsoft Dynamics 365 and Azure AI.

A photo of d'Orgee.

“We looked at manual steps, broken workflows, and disconnected systems as opportunities for AI transformation.”

Jonathan d’Orgee, AI transformation lead, Microsoft Business Operations

Identifying manual inefficiencies

On top of the complexity of handling so many transactions across the globe, Business Operations sometimes experienced periodic surges that could exacerbate inefficiencies. During these surges, the team would see a high volume of complex, time-critical transactions— especially at the end of the month or the quarter—and manual processes were too slow to keep up.

As we reviewed these inefficiencies, we looked for the most impactful use cases—places where we could integrate AI into workflows. To do this, we asked two important questions:

  • What types of transactions have the highest volume?
  • What parts of the process take the longest time or consume the most resources?

It was a classic case of the 80/20 rule—finding the 20% of the processes that required 80% of the work.

“We looked at manual steps, broken workflows, and disconnected systems as opportunities for AI transformation,” d’Orgee says.

An example might be where we receive an email asking to have a contract updated. In the former process, the email might sit there until a human could review it manually. Then someone would review it, direct it to the right queue, and assign it to the right person.  

“With AI in the workflow, emails and attachments are analyzed right when they arrive, and immediately assigned to the right queue and person,” d’Orgee says.

Taking these kinds of steps dramatically increased efficiency and reduced costs overall.

A photo of Venkata.

“With deep knowledge of our Business Operations ecosystem, we targeted high-volume, repeatable workflows across globally distributed operations. These were processes where AI could break traditional location and labor constraints, unlocking scalable automation and measurable business impact.”

Shashidhar Lanka Venkata, partner group engineering manager, Business Commerce Platforms

Configuring an AI toolkit

Once we’d identified the areas that were ripe for transformation, we set about developing an AI-driven solution on top of our existing critical workflow systems.

“With deep knowledge of our Business Operations ecosystem, we targeted high-volume, repeatable workflows across globally distributed operations,” says Shashidhar Lanka Venkata, a partner group engineering manager in the Business Commerce Platforms team. “These were processes where AI could break traditional location and labor constraints, unlocking scalable automation and measurable business impact.”

The BPO AI Toolkit is our AI operating system for business process operations. Its job is to help us with decision making. Built on Microsoft Dynamics 365 and Azure AI, it brings process mining, Microsoft 365 Copilot, Windows 365, and the Azure Marketplace together into AI-native workflows that can be reused by different vendors.

The toolkit is built on a handful of capabilities that work together:

Agentic memory turns tribal knowledge into structured operational intelligence that agents can access on demand.

Prebuilt agents provide enterprise-ready capabilities that teams can reuse instead of rebuilding workflows.

An agentic UI reduces context-switching time, helping operators focus on decisions and exceptions.

Digital Twins measures real end-to-end process performance and continuous improvement.

Agent Desktop provides secure access anywhere.

“It’s just part and parcel of working with AI, which is much different than working with more traditional ways of automating,” says d’Orgee.

He explains that because the AI is configurable, our teams are able to move faster. “The lead time is a lot shorter, and we’re able to make changes a lot more quickly.”

At the core of everything during this effort was the drive to constantly assess “the human buy-in:” How are people using this technology in a way that solves real problems at a global scale?

Keeping humans in the loop and measuring AI transformation

Integrating AI into existing workflows and processes isn’t just about the technology—it also should entail a cultural shift within an organization.

We wanted to ensure that our operations team was adopting the AI tools in the right way. That meant understanding which processes must still be human-led, such as areas where the handling of exceptions requires more discernment.

Rather than removing humans from the process, the team redefined the human role. AI now handles tasks such as data validation, case creation, and compliance checks, while our team members focus on judgment, exceptions, and continuous improvement.

“It’s really exciting for us, because operations has always been about trying to be efficient. With AI, it’s allowed for breakthroughs that we haven’t been able to achieve before.”

Jonathan d’Orgee, AI transformation lead, Microsoft Business Operations

That balance helped the team scale automation without losing the oversight and expertise needed to maintain quality.

The impact of this Frontier model has been significant. So far, we’ve been able to transform roughly a quarter of our BPO processes with AI. This has led to an 80% improvement in process quality and a 33% reduction in cost per transaction, d’Orgee says.  

More than 75% of the cases our teams work on are processed utilizing the AI toolkit. These gains are measured with Digital Twins, a process-mining model that monitors each workflow live, allowing teams to continuously track and improve. Building on this momentum, the team has plans to transform 80% of the BPO process with AI by fiscal year 2028.

A pie chart showing that more than 75% of our business-process cases are now assisted by an AI agent.

D’Orgee urges organizations that want to apply our Customer Zero learnings to their own workflows to look for high-volume, high-effort, highly manual work. This will lead you to the best opportunities for automating your processes at scale and deliver the most benefit.

From finance to sales operations, teams across Microsoft have turned to the BPO AI toolkit to prove how reusable AI capabilities can drive enterprise-wide transformation.

“It’s really exciting for us, because operations has always been about trying to be efficient,” d’Orgee says. “With AI, it’s allowed for breakthroughs that we haven’t been able to achieve before. I’ve just been thrilled to come to work on that front.”

Key takeaways

You can use these lessons and insights from our AI transformation of BPO to guide your own workflow transformation:

  • Identify inefficiencies and find processes with repeatability and scale. Look for highly manual workflows that could benefit from AI integration.
  • Use workflow capabilities that can be configured across different scenarios. An AI toolkit that spans multiple stages can form the foundation for significant improvements and time savings.  
  • Test and iterate, following up on improvements as you learn. This enables adaption of the development process beyond traditional automation.
  • Keep humans in the loop and leading the way. Identify workflows where human judgment and handling of edge cases must take precedence.

Try it out

Related links

The post Streamlining business operations at Microsoft with an AI toolkit appeared first on Inside Track Blog.

]]>
24720
Taming our Python dependencies at Microsoft with AI http://approjects.co.za/?big=insidetrack/blog/taming-our-python-dependencies-at-microsoft-with-ai/ Thu, 25 Jun 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24491 At Microsoft, Python has long been one of our most popular programming languages. Our developers use it for building production systems, internal tools, automation workflows, and more. We estimate that at least 67,000 employees use it every day. At that scale, Python dependencies have emerged as a significant source of risk for us—representing the third-largest […]

The post Taming our Python dependencies at Microsoft with AI appeared first on Inside Track Blog.

]]>
At Microsoft, Python has long been one of our most popular programming languages. Our developers use it for building production systems, internal tools, automation workflows, and more. We estimate that at least 67,000 employees use it every day.

At that scale, Python dependencies have emerged as a significant source of risk for us—representing the third-largest vulnerability surface across the company.

The good news is that we have strong visibility into these vulnerabilities, with tools that continuously detect and surface risks across our codebases. The bad news is that turning those insights into action required a complex remediation process.

Updating a single code package often caused changes across multiple interdependent libraries. This required coordinated updates, validation, and testing to maintain system stability.

A photo of Arias.

“When AI arrived, I saw it as a great opportunity to finally fix a very complex problem we had: The level of entanglement involved in Python code dependencies. A simple script wasn’t going to resolve it—you needed the power of AI.”

Humberto Arias, senior product manager, Microsoft Digital

Multiply this by thousands of projects throughout our enterprise, and vulnerabilities accumulated much faster than we could resolve them. To address this challenge, we turned to AI.

Microsoft Digital—the company’s IT organization—has developed an AI-powered solution called Python Dependency Remediation. Designed to work directly within the developer workflow, this solution analyzes dependency chains, applies required updates, and automatically adjusts the code. This enables our engineers to remediate vulnerabilities quickly and consistently at enterprise scale.

“I’ve worked for years in the vulnerability management space at Microsoft,” says Humberto Arias, a senior product manager in Microsoft Digital. “When AI arrived, I saw it as a great opportunity to finally fix a very complex problem we had: The level of entanglement involved in Python code dependencies. A simple script wasn’t going to resolve it—you needed the power of AI.”

The tool has shown so much promise that we have begun releasing it externally, so that millions of Python developers around the world can take advantage of it.

A photo of Chiodo.

“I used to have this problem all the time. I upgrade one library, and then I’ve got to upgrade 17 other things, and something else breaks, and now my code is completely different.”

Rich Chiodo, principal software engineer, Python and Tools for AI

Flexibility leads to dependencies and risk

Python is a very flexible language, which is why it’s so popular among software developers. But that same flexible nature—it can be used across a wide range of scenarios—also means it forms deeply interconnected dependency chains. When one code library is updated, it can trigger changes across many others.

“I used to have this problem all the time,” says Rich Chiodo, a principal software engineer on the team responsible for Python Tools and AI. “I upgrade one library, and then I’ve got to upgrade 17 other things, and something else breaks, and now my code is completely different.”

A photo of Sheth.

“Developers avoid the upgrades because the dependency web is so complex. This means the vulnerabilities accumulate over time and can become a real security risk.”

Chintan Sheth, principal engineering manager, Viva Glint

Because the code is so interdependent and remediation is time-consuming, many developers skip updating their code packages, which can lead to security vulnerabilities.

Security compliance was often seen as a burden because it slows people down.

“Developers avoid the upgrades because the dependency web is so complex,” says Chintan Sheth, a principal engineering manager on the Viva Glint product team. “This means the vulnerabilities accumulate over time and can become a real security risk.”

A photo of Krishna Gollapelly.

“After my manager mentioned it, I reviewed the idea on the hackathon page, and it looked really interesting to me. So I jumped in, and we created a prototype and a demo video with a quick solution. That’s how it started.”

Shiva Krishna Gollapelly, senior software engineer, Microsoft Digital

Hacking our way to a solution

Like some of the best internally developed tools and processes, Python Dependency Remediation came out of a Microsoft hackathon project. These grassroots events allow our engineers to tackle interesting technical challenges in a collaborative, creative way.

“After my manager mentioned it, I reviewed the idea on the hackathon page, and it looked really interesting to me,” says Shiva Krishna Gollapelly, a senior software engineer in Microsoft Digital and the lead developer on the project. “So I jumped in, and we created a prototype and a demo video with a quick solution. That’s how it started.”

The fact that this solution came from a hackathon highlights the ideas-driven culture that we promote at the company.

“This really speaks to our special culture of innovation,” says Snigdha Bora, a principal group engineering manager for Employee Experience. “After this emerged from the hackathon, our developers realized it could solve a problem at scale—that it was worth taking through the full development cycle so we can release it for all of Microsoft, and maybe beyond.”

Solving the issue with one click (and AI)

Because the challenge was not detecting vulnerabilities but fixing them, we had to rethink how we addressed Python dependencies.

“The extension automatically finds the right updates and then fixes the vulnerabilities, so developers don’t need to do the research, the manual upgrades and fixes, run test cases, debugging—all those things that used to take so much time. With our solution, it’s just one button click and it does all of that automatically.”

Shiva Krishna Gollapelly, senior software engineer, Microsoft Digital

In the past, when engineers received a vulnerability notification, they would have to step outside their development workflow and address the issue. What was needed was a solution that could be enacted within their normal workflow—integrating remediation directly into the tools they were already using.

So, we created the Python Dependency Remediation extension for Visual Studio Code, a common Python development environment. Once installed, engineers can address vulnerabilities in the flow of their work.

A screenshot showing the extension detecting vulnerabilities in Python code.
The Python Dependency Remediation extension automatically detects vulnerabilities and then allows developers to fix them and update their code, right in the flow of their work.

“The extension automatically finds the right updates and then fixes the vulnerabilities, so developers don’t need to do the research, the manual upgrades and fixes, run test cases, debugging—all those things that used to take so much time,” Gollapelly says. “With our solution, it’s just one button click and it does all of that automatically, with the help of AI.”

The extension uses the APIs built into Visual Studio Code to connect with any AI model the user has access to. (If there is no AI model available, Gollapelly explains, the extension will still make the package updates but won’t do the remediation fixes to the code.) It also produces a report of the changes for the developer to review in case there’s a snag that needs troubleshooting.

“This tool removes a significant burden from our developers,” Bora says. “We are shifting the entire remediation process left, embedding it early in the development workflow. Developers can review the changes and move forward immediately, making the whole process more efficient.”

A photo of Saldivia.

“We’ve upgraded the library with new methods, calls, and structures. Now, let’s make sure everything works, check for errors in the code, etc. That’s the gap we’re bridging with AI.”

Angel Saldivia, software engineer, SharePoint

The result is that fixes and upgrades that used to take multiple hours of developer time now take minutes, and the code is much more reliable.

What the agent does in this solution is help close that loop, something that the engineer used to have to do.

“We’ve upgraded the library with new methods, calls, and structures,” says Angel Saldivia, a software engineer on the SharePoint product team. “Now, let’s make sure everything works, check for errors in the code, etc. That’s the gap we’re bridging with AI.”

From Customer Zero to global impact

One of the powerful things about working at Microsoft is that you get to help develop technology tools that can change the world. This is the case with Python Dependency Remediation as well.

A photo of Bora.

“We realized this technology had much broader value. There are hundreds of millions of Python users worldwide, so the impact could be massive.”

Snigdha Bora, principal group engineering manager, Employee Experience

As Bora explains, while the solution was being developed it was presented to Guido van Rossum, the creator of Python (and a Microsoft employee). He immediately saw the incredible potential of the concept.

“He suggested that we could take this solution to the world, not just to Microsoft,” Bora says. “We realized this technology had much broader value. There are millions of Python users, so the impact could be massive.”

To help make this happen, Microsoft Digital approached Graham Wheeler, a principal group engineering manager on the Python and Tools for AI team. Wheeler’s team is responsible for shipping Pylance, a development extension for Visual Studio Code used by more than 180 million developers worldwide.

A photo of Wheeler.

“One of the things we could do was provide a jumping-off point for this extension, so that when users installed Pylance they’d be prompted to also download Python Dependency Remediation. It can help raise awareness, because many users don’t actually do the dependency scanning and updating that they should.”

Graham Wheeler, principal group engineering manager, Python and Tools for AI

Wheeler and his team are in the process of incorporating the Python Dependency Remediation extension as an option during Pylance installation. This will open up a convenient vector for getting the tool in front of a huge audience, potentially revolutionizing Python development.

“One of the things we could do was provide a jumping-off point for this extension, so that when users installed Pylance they’d be prompted to also download Python Dependency Remediation,” Wheeler says. “It can help raise awareness, because so many users don’t actually do the dependency scanning and updates that they should. So, we’re helping with that challenge.”

Beyond Python, the AI-powered technology behind this extension might be applied to other dependency challenges as well. What started as a simple hackathon project could have huge ramifications for the future of software development.

“This solution can easily be adapted to other libraries, other programming languages,” Gollapelly says. “Whether you’re talking about C#, Angular, React, or another language, the concept is the same. The implications are vast.”

Key takeaways

Here are some points to keep in mind if you are thinking about tackling this kind of code-dependency issue at your organization:

  • AI can make the difference between simple awareness and actual resolution. We already had strong tools to detect Python vulnerabilities, but AI is what finally enabled remediation at scale across thousands of projects.
  • Python’s flexibility is both its strength and its biggest risk multiplier. Deep dependency chains mean that a single update can cascade into widespread breakage, with manual fixes slow and error-prone.
  • Automation embedded in the developer workflow is the breakthrough. By integrating directly into Visual Studio Code, Python Dependency Remediation allows developers to fix vulnerabilities with minimal friction—often in just one click.
  • AI dramatically compresses remediation time, from hours to minutes. Tasks that once required manual research, testing, and debugging are now handled automatically, improving both speed and code reliability.
  • The “shift left” approach is key to efficiency gains. Fixing dependency issues earlier in the development cycle reduces downstream complexity and keeps developers in the flow of their work.
  • This innovation has potential far beyond Microsoft—and beyond Python. With the potential for distributing the solution widely and adapting it to other languages, this breakthrough could reshape how developers everywhere manage dependencies.

Try it out

Related links

The post Taming our Python dependencies at Microsoft with AI appeared first on Inside Track Blog.

]]>
24491
Simplifying device registration at Microsoft with an agentic AI assistant http://approjects.co.za/?big=insidetrack/blog/simplifying-device-registration-at-microsoft-with-an-agentic-ai-assistant/ Thu, 25 Jun 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24507 When you’re busy at work, the last thing you want to do is spend hours getting a new device set up. In an ideal world, this process takes one, maybe two clicks—and then you’re off to the races. To make this ideal a reality, our team in Microsoft Digital—the company’s IT organization—created an agentic AI […]

The post Simplifying device registration at Microsoft with an agentic AI assistant appeared first on Inside Track Blog.

]]>
When you’re busy at work, the last thing you want to do is spend hours getting a new device set up. In an ideal world, this process takes one, maybe two clicks—and then you’re off to the races.

To make this ideal a reality, our team in Microsoft Digital—the company’s IT organization—created an agentic AI assistant that we’re now using to connect new devices to our network. We built the agent into GetConnected, the internal portal that 18,000 of our employees, vendors, and network administrators use each month to register their new devices to our network when they turn them on for the first time.

Our new workflow is simple, fast, and intuitive—and it’s a significant step up from our previous experience.

Creating the GetConnected AI assistant is part of the role we play as the company’s Customer Zero, where we test and use our technology and platforms first and then share our lessons learned with customers. In this case, we’re sharing how we used the Microsoft Agent Framework (MAF) to enhance onsite device management for our employees. GetConnected does not apply to remote device registrations.

A photo of Thompson.

“We’ve been looking across our set of services and capabilities to find places where we can do some experimentation leveraging AI. We wanted to be able to test our hypothesis around those AI investments and then be able to double down if it proved correct.”

Jason Thompson, principal PM manager, Microsoft Digital

Improving a highly trafficked internal tool using AI

Our employees use GetConnected to ensure their wired and wireless devices are registered on the network, as well as to extend device expiration dates and check on the status of their devices.

Heavy employee traffic and the repetitive actions users tend to take on GetConnected led us to realize that the tool was the perfect candidate for an agentic transformation. Our goal was to turn what was a five- or six-step process into something that could be completed in just one or two actions.

“We’ve been looking across our set of services and capabilities to find places where we can do some experimentation leveraging AI,” says Jason Thompson, a principal PM manager in Microsoft Digital. “We wanted to be able to test our hypothesis around those AI investments and then be able to double down if it proved correct.”

The team decided to start small, focusing on a couple of the most popular and crucial functionalities within GetConnected.

A photo of Dave.

“We’d seen previous projects that were very ambitious fail because they tried to achieve too much at one time. Based on customer feedback, we noticed that registration is the simplest, most common action that users were having trouble with. So we said, ‘Let’s do that first.’”

Aayush Dave, product manager, Microsoft Digital

It was also important to listen to our employees—our Customer Zero frontline users. They told us which actions in the experience mattered most to them.

“We’d seen previous projects that were very ambitious fail because they tried to achieve too much at one time,” says Aayush Dave, a product manager in Microsoft Digital. “Based on customer feedback, we noticed that registration is the simplest, most common action that users were having trouble with. So we said, ‘Let’s do that first.’”

Next up was deciding how the agent would appear in the portal. The Microsoft 365 Copilot model of a sidebar chat menu worked well for other workflows, so it seemed appropriate to approach the new GetConnected experience in a similar way. This enabled us to create a new experience alongside the existing workflow, so customers could still access the original process (should they need to) and compare the two experiences.

“Other teams might decide to automatically replace the UI with an agent,” says Faris Mango, a principal software engineering manager in Microsoft Digital. “But that’s hard, because now you’re forcing people to use the agent. If it’s not ready to be used at full capacity, they don’t have an alternative to accomplish what they intended. We wanted to avoid that situation.”

Testing out Microsoft Agent Framework (MAF)

To build the agent, we considered two paths.

The first was to directly call the Model Context Protocol using JavaScript, an option that would require significant amounts of coding on our part.

A photo of Sullivan.

“Some declarative agent systems do all of the things in the background, and you don’t get to turn all the little knobs. MAF gives you the flexibility to make the experience exactly what you want.”

Darron Sullivan, principal software engineer, Microsoft Digital

The second was to use Microsoft Agent Framework (MAF), which proved to be simpler and more customizable for our needs.

“Some declarative agent systems do all of the things in the background, and you don’t get to turn all the little knobs,” says Darron Sullivan, a principal software engineer in Microsoft Digital. “MAF gives you the flexibility to make the experience exactly what you want.”

The tricky part, however, was that MAF was fairly new at the time. In fact, the week that the team started developing the GetConnected agent was the same week that MAF was released in preview internally. As we were building out our agent, the framework was going through its own updates, which threatened to hinder our progress. Even one small change to the framework could break our tool’s entire functionality.

“They were moving really fast, and we were adopting new features and finding new bugs all the time,” Sullivan says. “You had to go through that rapid iteration and development, which is a challenge, but it was also pretty awesome because we’re working on the cutting edge.”

The upside was that we were able to provide valuable feedback to the MAF engineers, which in turn could supercharge the work we were doing on our agent. As a bonus, our partnership drove other teams to pursue similar projects.

“The knowledge sharing across our org was notable and crucial,” Dave says. “Our team was one of the first to start building a solution like this, and we presented in numerous architecture forums to share the components and frameworks we were using, and the teams we were working with. This brought the tide up for all boats in our organization, encouraging other teams to start kicking off similar projects as well.”

Building a seamless, discoverable interface

The agent currently has several key functions, the most prominent of which is to register a device on your behalf.

Previously, employees would have to fill in a long, complicated form that asked for a lot of technical details that they often didn’t know offhand, like type of device or the preferred network.

Instead of just selecting options and approving, the flow is more conversational. The user can start with a suggested prompt like “Help me register a device,” and the agent will ask for the required information (with examples for each field). If the user isn’t sure about something (for example, how to find a MAC address), they can ask follow-up questions, and the agent will pull in FAQ and help content to guide them.

Once all the required details are collected, the agent can complete the registration on the user’s behalf after the user approves it.

Once it has your approval, the chatbot submits the request and replies whether or not it was successful. Users can also ask the agent to show devices that are expired or will soon expire, then prompt the agent to renew those devices if desired.

A screenshot of the The GetConnected Portal homepage with the GetConnected AI Assistant asking the user how it can help.
The GetConnected AI assistant asks Aayush Dave, a product manager in Microsoft Digital, how it can help him in an interface that appears on the GetConnected portal homepage.

Seamlessly integrating the agent into GetConnected required upgrading the existing user interface using Fluent.

These updates were needed to support the AI interface integration. Specifically, we introduced a custom header action to launch the AI side panel. Prior to upgrading, doing this would have required using Coherence components outside of their intended patterns.

A photo of Chambers.

“We used Fluent AI components to build the AI interface. This helped ensure a consistent Microsoft look and feel across the experience, built-in accessibility for scenarios like screen readers and mobile usage, and components that are designed for conversational and agent-driven interactions.”

Nathan Chambers, software engineer, Microsoft Digital

To stay consistent with the existing app architecture, we upgraded core dependencies like Fluent UI and Coherence to their latest versions. As part of upgrading Coherence across several major versions, it also required us to move the feedback experience to Centro to align with the updated patterns. We then needed to update other parts of the experience like navigation, FAQ, and release notes to match those newer component patterns.

“We used Fluent AI components to build the AI interface,” says Nathan Chambers, a software engineer in Microsoft Digital. “This helped ensure a consistent Microsoft look and feel across the experience, built-in accessibility for scenarios like screen readers and mobile usage, and components that are designed for conversational and agent-driven interactions.”

While making these upgrades, we ran tests to ensure the experience was accessible—for example, for screen reader users or others who might access GetConnected on their phones.

A photo of Mango.

“You can have an amazing, strong piece of software that is well built and focuses on security. But if you don’t have the traffic or people are not using it, it’s worthless.”

Faris Mango, principal software engineering manager, Microsoft Digital

Next, we wanted the agent to be as discoverable as possible. Without people actually navigating to it, there would be no way to show proof of concept. So, we built it so the agent automatically popped open via a side panel when someone loaded GetConnected.

“You can have an amazing, strong piece of software that is well built and focuses on security,” Mango says. “But if you don’t have the traffic or people are not using it, it’s worthless.”

We also wanted to gather early feedback from users. Before releasing it to the entire company, we had internal team members and frequent GetConnected users give the agent a try. Almost immediately, it was clear we had too many approval notices.

“At the beginning, we would have approvals for every single action. For example, if you wanted to see a device in different regions like Puget Sound, Latin America, or Canada, you had to do a separate approval for each region,” Dave says. “This was a very painful experience. So we removed all the approvals and pared it down to a one-click experience.”

Users also had issues with the approval language, which they said was hard to understand and looked like an error message. The next iteration took out much of the technical jargon, making the message more conversational and easier to read.

An agent experience driven by feedback

Our work as Customer Zero is never done. For GetConnected, we’re eager to keep collecting feedback. One major goal is to improve the agent’s performance, making it faster and more responsive.

Our feedback survey is tied directly to a performance dashboard, which tracks metrics like new and returning users, total unique users, conversions, and interactions. Each user submission generates a work item.

“When users leave feedback about something they don’t like, I feed that to the team, and then we sit down and figure out how we can improve that specific part of the experience,” Dave says.

With each update, we’re seeing the payoff of more users and more interactions. The traditional method of registering a device is also seeing a drop-off as more people lean on the agent for assistance.

“Before, you used to have to go into the system and change something about the experience manually. Now, our engineers are going to an AI model and telling it, ‘Hey, you’re doing this part wrong, please improve it.’”

Aayush Dave, product manager, Microsoft Digital

Looking ahead to more use cases

Building an agent has allowed the team to embrace an entirely new type of engineering.

“Before, you used to have to go into the system and change something about the experience manually,” Dave says. “Now, our engineers are going to an AI model and telling it, ‘Hey, you’re doing this part wrong, please improve it.’”

It’s also serving as a reminder to seek progress over perfection.

“AI is changing things so quickly,” Thompson says. “It’s better to do rapid prototyping and roll it out, and start getting the data in terms of how successful the experience is. Then you can let that guide you, in terms of how you iterate going forward.”

Because of the success we’ve had with the GetConnected device registration feature, we’re already exploring other capabilities, including bulk operations to accommodate our facilities managers who need to onboard many devices at once. As AI agents become mainstreamed in many workflows across our organization, we anticipate usage and functionality will continue to grow exponentially.

Key takeaways

If you want to create a similar agent to streamline processes or automate workflows in your organization, keep these tips in mind:

  • Transition gradually and maintain existing experiences. Until you’re confident users are happy with the new product, continue to give them access to original workflows. This allows them to compare experiences and provide contextual feedback.
  • Remove unnecessary steps for simpler processes. The user  need to formally approve every step along the way. Cut the cognitive load and focus on getting user signoff where it counts.
  • Check existing systems for compatibility. Before diving into design, ensure that your current systems can support your goals, and address any gaps early on to avoid running into limitations later.
  • Get feedback early and often. Release a minimum viable product to users to make sure it aligns with how they work, and fix any bugs before expanding its capabilities.
  • Maintain a low ego. Take user feedback to heart. Put their needs first, rather than what you think the product should be.

Try it out

Related links

The post Simplifying device registration at Microsoft with an agentic AI assistant appeared first on Inside Track Blog.

]]>
24507
From data sprawl to AI-driven seller insights at Microsoft http://approjects.co.za/?big=insidetrack/blog/from-data-sprawl-to-ai-driven-seller-insights-at-microsoft/ Thu, 18 Jun 2026 15:15:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24357 Sellers at Microsoft have access to a wide range of data to help them understand their business, identify risks, and focus on opportunities. Over time, new systems and reporting tools expanded the amount of data available to them. At first glance, helping sellers improve the way they work looks like a data challenge because we […]

The post From data sprawl to AI-driven seller insights at Microsoft appeared first on Inside Track Blog.

]]>
Sellers at Microsoft have access to a wide range of data to help them understand their business, identify risks, and focus on opportunities. Over time, new systems and reporting tools expanded the amount of data available to them.

At first glance, helping sellers improve the way they work looks like a data challenge because we tend to believe more data equals better decisions. However, when we explored how they use data to prepare for customer meetings and internal business reviews, we saw a different pattern.

The amount of data they had available to them had increased—but so had the manual effort needed to turn it into useful and actionable insights. In fact, our sellers were spending more time looking for relevant information than they were spending engaging with customers to improve their experience.

As part of our Customer Zero approach at Microsoft, we apply our technologies internally and use that experience to understand what works at scale so we can pass that knowledge onto our customers. In this case, our discoveries unearthed a deeper issue with how our sellers interact with data in their day-to-day work.

Too much data, not enough insight

The increased amount of data available to our sellers gave them more options but also more information to process. It also introduced fragmentation.

A photo of Toomey.

“I think the big feedback pain point we got was that we have way more data than our sellers were used to. You give us a gigantic well of data, but how I use that data to execute my job is fragmented.”

Michael Toomey, revenue insights lead, Finance Data and Experience

A significant portion of our sellers’ time went into finding, interpreting, reconciling, and analyzing the information before any actual decisions or customer interactions were taking place. In some cases, sellers were navigating hundreds of reports and dashboards across multiple systems. In others, they were exporting data into spreadsheets, building their own analyses, and assembling presentations manually. They told us they were overwhelmed by the amount of data they had access to.

“I think the big feedback pain point we got was that we have way more data than our sellers were used to,” says Michael Toomey, a revenue insights lead on our Finance Data and Experience team. “You give us a gigantic well of data, but how I use that data to execute my job is fragmented.”

This tedious manual user experience didn’t match the fast pace of our work. Sellers needed to move quickly, and we needed a way to empower them to find the data and insights they needed to be able to make actionable decisions immediately.

Instead of continuing to expand the amount of data available to our sales force, we concentrated on making the existing data easier to access, understand, and use.

Beginning with a trusted data foundation

The starting point was the data itself. Our sales organization draws from many systems, each of which has its own structure, definitions, and refresh cycles. Without alignment across these systems, even seemingly simple seller questions could produce different answers depending on the data source. This created more work as our sellers hunted down which answer was the correct one.

We consolidated all this data into a unified model on Microsoft Fabric, creating a shared data foundation across the organization. It included standardized definitions, consistent metrics, and common hierarchies. Data from more than 70 systems was brought together into one governed environment.

This step required coordination across teams and ongoing attention to evolving data governance. It established trust in our data that made it easier to streamline the user experience for our sales teams down the line.

Streamlining how sellers work with data

With a consistent data foundation put into place, we turned our attention to how sellers could most effectively access and use the information.

Instead of asking sellers to navigate a portal of reports, we designed role-based dashboards that reflect how people actually work. Individual dashboards are curated based on role, workflow, and responsibilities, helping our sellers quickly find what they needed without searching across systems. We transformed the work surrounding actionable insights, too: Power BI surfaces intelligent insights to our sellers’ dashboards every morning, automatically giving them their priorities for the day and providing an overview of their funnel.

Before this transformation, building PowerPoint presentations for customers and summarizing reports were routine but tedious parts of the preparation process for our sellers before they spoke to customers. These preparatory steps have been streamlined or automated wherever possible, reducing seller time spent on repetitive manual tasks.

Empowering sellers using AI

With the data organized and cleaned and the user experience transformed, we introduced AI to overhaul how our sellers interact with the information available to them.

“A lot of what we’re trying to do is get to a native Microsoft 365 Copilot experience where we meet people where they’re working every day. And then work is optimized to be able to reason over our day to pull the data in.”

Michael Toomey, revenue insights lead, Finance Data and Experience 

To find the information they’re looking for, sellers can now ask questions in natural language and receive answers directly in the tools they already use. Insights powered by Power BI Copilot, Fabric, and AI Foundry are delivered proactively, helping sellers prioritize their day, generate summaries, and assemble materials for meetings without working through each step manually.

Insights that previously required a great deal of time to uncover are surfaced directly. The relevant reports are automatically routed to sellers based on their job description and client base. Sellers can also subscribe to continuously updated reports and have them surfaced each morning to their inbox.

These capabilities are available in the tools our people already use, which means they don’t have to spend time learning new product suites. The information they’re looking for can be surfaced through tools like email or within Microsoft Teams, which means sellers can stay focused on their work without needing to switch between systems.

Processes that once took hours can now be completed in minutes.

“A lot of what we’re trying to do is get to a native Microsoft 365 Copilot experience where we meet people where they’re working every day. And then work is optimized to be able to reason over our day to pull the data in,” Toomey says.

What changed

The most visible shift we’ve observed is how sellers spend their time. Less effort goes into finding, assembling, and reconciling information, and more attention is directed toward understanding customer needs and making decisions that actively move the business forward.

After deploying this model across our sales organization, we saw meaningful improvements in both efficiency and effectiveness, including:

  • 100,000 seller hours saved annually
  • 30% reduction in data ingestion costs
  • 10x faster insight generation
  • 1,500 reports retired and consolidated

We credit our success to building a trusted data foundation; a streamlined, intuitive user experience; and embedding AI into the flow of work to help our sellers surface insights and information with a few clicks instead of spending hours sifting through irrelevant inputs.

We learned that executive sponsorship and active change management were essential to transforming the department successfully. Concentrating on consistency and departmental alignment around a set of trusted, verified, well-governed data and shepherding people through shifting how they worked with the data were just as important as adding AI into the process.

Looking ahead

At the heart of our trusted data foundation is the semantic layer, the place where our business definitions, metrics, and data quality are standardized across the organization. It’s now the engine that powers our agents. Because those definitions live in one governed place, our agents can reason over our data products with confidence, and we can trust what they surface.

That foundation is already bearing fruit. A new generation of personal and role-based agents at Microsoft is taking on the workflows that were consuming our sellers’ time, such as meeting preparation, pipeline reviews, and customer insight generation. These processes are now running on the governed data infrastructure we built. Everything draws from the same source of truth, so everything our agents work with is consistent, reliable, and ready to act on.

This return on our platform investment is bringing us closer to becoming a Frontier Firm where our people spend less time searching for the answers and more time acting on them.

Key takeaways

If you’re looking to transform how your teams interact with data and AI, consider these lessons from our experience:

  • Start with a trusted data foundation: Standardize your definitions, governance, and ownership before layering on AI.
  • Simplify before you scale: Reduce fragmentation and rationalize your reports to eliminate unnecessary complexity.
  • Design for real workflows: Focus on how y our people work, not just how your data is organized.
  • Embed AI into the flow of work: Deliver insights where your people already are instead of requiring them to search across systems or learn a new product suite.

Try it out

Related links

The post From data sprawl to AI-driven seller insights at Microsoft appeared first on Inside Track Blog.

]]>
24357
Meet DigitalMe: Our AI digital twin that works on our behalf http://approjects.co.za/?big=insidetrack/blog/meet-digitalme-our-ai-digital-twin-that-works-on-our-behalf/ Thu, 11 Jun 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24102 Have you ever wanted a clone to help you keep up with your work? In an always-on business environment, even routine collaboration can be overwhelming. But in an environment of Frontier Transformation, this challenge represents an opportunity for AI. Our employees don’t need to handle all their work alone anymore, because agents can now extend […]

The post Meet DigitalMe: Our AI digital twin that works on our behalf appeared first on Inside Track Blog.

]]>
Have you ever wanted a clone to help you keep up with your work?

In an always-on business environment, even routine collaboration can be overwhelming. But in an environment of Frontier Transformation, this challenge represents an opportunity for AI.

Our employees don’t need to handle all their work alone anymore, because agents can now extend their responsiveness and reach. Here in Microsoft Digital, the company’s IT organization, one of those AI agents is acting as a digital twin for just that purpose. It’s called DigitalMe, a personal virtual proxy designed to keep work moving when our employees are busy with other tasks.

Always-on knowledge without always-on employees

Large meetings generate a constant stream of questions, side conversations, and follow-up items. They’re often more than a single presenter or moderator can manage in real time. Important insights get buried in chat threads, queries go unanswered, and valuable momentum gets lost.

For our teams at Microsoft, this challenge became especially visible during large-scale readiness sessions, where subject matter experts found themselves inundated with requests for clarification and guidance.

A photo of Kerametlian.

“In order for our transformation into a Frontier Firm to be successful, we need to step back and ask what works well for employees, what doesn’t work well, and where agents can help.”

Stephan Kerametlian, senior director, Microsoft Digital

That’s not the only place where employees can use an extra hand. When people are out of the office, that doesn’t mean work stops. Their coworkers often need access to their colleagues’ knowledge to move mission-critical work forward, even when they’re not reachable.

“In order for our transformation into a Frontier Firm to be successful, we need to step back and ask what works well for employees, what doesn’t work well, and where agents can help,” says Stephan Kerametlian, a senior director in Microsoft Digital. “We’re crossing the horizon into human-led, agent-operated patterns of work.”

One team in Microsoft Digital created DigitalMe to explore what that future could look like in practice.

DigitalMe: A personal digital twin for Microsoft employees

For the members of our Employee Experience Success team responsible for adoption efforts around Microsoft 365 Copilot and Microsoft Copilot Studio in the Greater China Region, readiness meetings were becoming unwieldy because of attendee questions.

A photo of Bu.

“Our purpose was to use as little code and as much natural language as possible so people could modify their own personal DigitalMe easily. In Copilot Studio, you can manage agents as a solution. So users can just download and import a zip file, modify an agent like DigitalMe according to their business context and preferences, then use it.”

Ju Bu, business program manager, Microsoft Digital

The team wanted a way to focus on running the meeting while simultaneously providing their knowledge to participants. They decided to create an agent to help deal with the deluge of queries: DigitalMe.

At its core, DigitalMe is a personal, context-aware digital twin with versions that operate in both Microsoft Teams and Microsoft Outlook. It draws on the same knowledge bases and resources that its user can access, for example, SharePoint sites and Teams channels.

The team designed DigitalMe in Microsoft Copilot Studio and prioritized a low-code approach. At most, the creators used code to build 15–20% of the agent and accomplished the rest using natural language prompts.

“Our purpose was to use as little code and as much natural language as possible so people could modify their own personal DigitalMe easily,” says Ju Bu, a business program manager in Microsoft Digital. “In Copilot Studio, you can manage agents as a solution. So users can just download and import a zip file, modify an agent like DigitalMe according to their business context and preferences, then use it.”

Equipped with an employee’s full knowledge base, DigitalMe can respond in Outlook and Teams on its human counterpart’s behalf. To ensure transparency, a label appears at the beginning of each message indicating that it originates from the agent.

DigitalMe also reinforces context for the requester by including their original question in quotations. Finally, the agent @-mentions the recipient to notify them effectively.

The team identified two primary use cases for the agent:

  • Moderating live sessions. In large meetings, DigitalMe acts as an always-on co-moderator, answering questions in real time using scoped, preloaded knowledge. By speaking for them in the meeting chat, it helps presenters stay focused while ensuring attendees receive timely, accurate responses. Surfacing information instantly enhances both the efficiency and quality of the session. DigitalMe has the added advantage of being able to pull from resources the presenter might not recall in the moment. Over time, the agent captures and reuses questions and answers, turning live engagement into a growing knowledge base.
  • Extending employee availability. DigitalMe also provides a way for employees to remain responsive when they’re out of the office. It can monitor Teams chats or incoming emails, generate context-aware replies, and surface relevant knowledge for colleagues without human intervention. In practice, it’s proven especially valuable for teams distributed across widely different time zones and for handling project handoffs during onboarding or time-off scenarios.

A key advantage of DigitalMe is its ability to move beyond simple question-and-answer use cases. In some scenarios, it can also trigger workflows like creating tasks or capturing frequently asked questions.

A photo of Cheng.

“Our vision was that DigitalMe shouldn’t just be an assistant. It should function as our digital twin in the cyber world.”

Kai Cheng, program manager, Microsoft Digital

It was important to incorporate human-in-the-loop capabilities. When DigitalMe encounters gaps in its knowledge, it can flag those moments for follow-up, prompting users to refine and expand their knowledge sources. It represents another way that human-led, agent-operated processes continuously improve outcomes.

“Our vision was that DigitalMe shouldn’t just be an assistant,” says Kai Cheng, a program manager working in change management, digital transformation, and AI in Microsoft Digital. “It should function as our digital twin in the cyber world.”

In live sessions, DigitalMe has helped presenters stay focused while maintaining high levels of engagement, responsiveness, and support for participants. Employees are increasingly using it to bridge time zones, support knowledge transfer, and keep projects moving in their absence.

Key impacts of DigitalMe

Here are a few examples of results from our early experiments with DigitalMe:

  • Questions answered: 158 questions handled in one 60-minute session
  • Presenter time saved: Around 60–90 minutes of manual moderation effort
  • Audience engagement: More than 60 chat messages per session, with increased Q&A participation
  • Response accuracy: Around 90% of questions answered satisfactorily
  • Post-session value: 100% of questions and answers captured for reuse as FAQs
  • Adoption: Expanded use across teams, including learning and readiness programs

Extending the impact of DigitalMe

After seeing DigitalMe’s early success, our global readiness and adoption professionals identified the agent as an opportunity to turn individual innovation into a scalable capability. After templatizing the agent in collaboration with its original creators, we’ve now included it in our Agent Starter Kit. This resource makes it easy for employees to create their own personal versions of several useful agents.

A photo of Jones.

“Employees often think building an agent might be complex and time-consuming, and that limits their willingness to try and turn their ideas into working solutions. But tools like this show them how easy it can be.”

Alexandra Jones, director of business programs, Microsoft Digital

Our Agent Starter Kit walks employees through importing a ready-made agent, connecting it to their knowledge sources, and adapting it to their specific workflows. This approach has shifted DigitalMe from a single solution into a repeatable pattern, helping employees across the company move from curiosity to hands-on adoption. We’ve also incorporated the Agent Starter Kit into our Agent Launchpad skilling program to accelerate our employees’ agentic expertise as part of a Frontier firm

There’s an added benefit as well. By getting tools like DigitalMe into people’s hands through templatized versions they can modify and configure themselves, we’re highlighting how easy it can be for even nontechnical workers to build agents themselves.

“Employees often think building an agent might be complex and time-consuming, and that limits their willingness to try and turn their ideas into working solutions,” says Alexandra Jones, director of business programs in Microsoft Digital. “But tools like this show them how easy it can be.”

For organizations that want to replicate this kind of solution, the path is increasingly straightforward. By lowering the barrier to entry with templatized agents and no-code tools, our team in Microsoft Digital has demonstrated that any employee can build tailored, high-impact assistants without deep technical expertise.

How to get started creating agents like DigitalMe

  • Start with a real problem. Identify where employees feel overwhelmed and a need exists. That could be high-volume meetings, repetitive questions, or delayed responses.
  • Use a working template. Create prebuilt agents to accelerate development instead of starting from scratch.
  • Scope your knowledge sources. Ground your agent in trusted content like SharePoint, documentation, and FAQs to ensure accurate responses.
  • Design for specific triggers. Consider where and when the agent should act: Should it act on your behalf in in Teams, answer emails for you, or take other actions on your behalf.
  • Iterate with feedback. Track gaps in responses and expand your knowledge base over time to improve accuracy and usefulness.

By combining these practices and learning from our experience in Microsoft Digital, you can quickly move from experimentation to impact with agents. To get started at your company, sign up for a trial of Copilot Studio.

A photo of Wooldridge.

“The goal of Frontier Transformation is that AI is just there as you’re working, helping you practically do your job to enhance the experience and add value in real time.”

Kevin Wooldridge, senior director of digital transformation, Microsoft Digital

Looking ahead, we’re exploring ways to deepen these capabilities by adding memory and behavioral context so DigitalMe can better reflect individual working styles. The goal is to evolve it from a helpful assistant into a more complete digital representative.

Together, these advances point toward a future where employees routinely work alongside agents that grow, learn, and contribute more over time.

“DigitalMe is an example of the genuine, practical application of agentic use in the flow of work,” says Kevin Wooldridge, senior director of digital transformation in Microsoft Digital. “The goal of Frontier Transformation is that AI is just there as you’re working, helping you practically do your job to enhance the experience and add value in real time.”

Key takeaways

Follow these tips to start experimenting with agents like DigitalMe.

  • Ease and success bring adoption. Even fearful or resistant employees can become interested in participating when they have an easy onramp like templatized agents.
  • Be brave. Have a bias for building and trying agents. They’re rarely as difficult to build as some workers might imagine.
  • Start by setting your tech people free. They’re likely to demonstrate the art of the possible, become leaders in the space, and bring others along for the ride.
  • Encourage potential agent builders to take a step back and look at the basics. That reflection will help them learn to identify opportunities for agentic help in their roles.

Try it out

Related links

The post Meet DigitalMe: Our AI digital twin that works on our behalf appeared first on Inside Track Blog.

]]>
24102
Building AI skills for the future: How we’re reimagining learning with AI Skills Navigator http://approjects.co.za/?big=insidetrack/blog/building-ai-skills-for-the-future-how-were-reimagining-learning-with-ai-skills-navigator/ Thu, 04 Jun 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23960 Across every industry, the expectations placed on IT professionals are changing fast. AI is no longer a specialized capability reserved for data scientists or developers. It’s a foundational skillset for architects, engineers, administrators, and technical leaders who are responsible for enabling transformation across their organizations. “The pace of AI innovation has far outstripped how people […]

The post Building AI skills for the future: How we’re reimagining learning with AI Skills Navigator appeared first on Inside Track Blog.

]]>
Across every industry, the expectations placed on IT professionals are changing fast. AI is no longer a specialized capability reserved for data scientists or developers. It’s a foundational skillset for architects, engineers, administrators, and technical leaders who are responsible for enabling transformation across their organizations.

A photo of Radhakrishnan.

“The pace of AI innovation has far outstripped how people learn. The old model of static catalogs, fragmented experiences, and a mindset of ‘consume content and move on’ doesn’t work in this new world, where roles are evolving in real time and every employee is expected to be AI proficient.”

Kavitha Radhakrishnan, general manager, Global Skilling

At Microsoft, this shift exposed a critical gap for us. While access to learning content has expanded dramatically, clarity about how to build and maintain skills has not kept pace. Our IT professionals often know they need to build AI capabilities but struggle with where to start, how to prioritize, and how to align their growth with business outcomes.

This is where our Global Skilling team identified an opportunity.

“We started with a simple observation: The pace of AI innovation has far outstripped how people learn,” says Kavitha Radhakrishnan, a general manager in Global Skilling product development. “The old model of static catalogs, fragmented experiences, and a mindset of ‘consume content and move on’ doesn’t work in this new world, where roles are evolving in real time and every employee is expected to be AI proficient.”

This situation led to the development of a cutting-edge solution: The AI Skills Navigator.

From content overload to guided capability building

At its core, AI Skills Navigator represents a shift in how learning is designed. Instead of asking learners to navigate sprawling catalogs of courses, the platform is built to guide them through a purposeful journey tied to their role, their goals, and the demands of their organization.

“Traditional learning catalogs answer the question, ‘What can I learn?’” Radhakrishnan says. “AI Skills Navigator answers the question, ‘What do I need to learn next—and why does it matter?’”

For IT professionals, that difference is significant:

  • Learning paths are aligned to real-world scenarios and roles
  • Content is curated and structured rather than fragmented
  • Progression moves from foundational understanding to applied capability
  • Skills are validated through credentials that signal actual proficiency

This approach helps IT teams move beyond passive learning and toward what Microsoft describes as “active capability building at scale.”

How AI Skills Navigator works for IT professionals

AI Skills Navigator is designed to meet IT professionals where they are, whether they are building foundational understanding, creating agents, or deploying and managing AI-powered solutions in production.

The experience is anchored in four key principles:

  1. Curated skilling playlists aligned to real roles. Learners engage with curated playlists mapped to their role and responsibilities. These playlists guide progression from foundational proficiency to deep expertise and leadership with AI.
  2. Applied skills, not just content consumption. The platform emphasizes hands-on, lab-based experiences where learners build and demonstrate real capabilities. Applied Skills credentials validate what learners can do, not just what they have completed.
  3. Multimodal learning in the flow of work. Content is delivered in formats that fit how professionals learn day to day, including interactive modules, video, and audio-first experiences like podcasts. This makes it easier to build skills without stepping out of the workflow.
  4. Skills validation with organizational visibility. Progress and credentials give individuals a way to demonstrate expertise. At the same time, organizations gain visibility into skill development and readiness at scale.

Behind the scenes, the experience is designed to deliver personalization at scale.

“The most important architectural decision we made was treating personalization as a ‘data and signals problem’ before it became a model problem,” says Iliyas Chawdhary, a principal group software engineering manager in the Global Skilling product group. “We built AI Skills Navigator on a modular foundation: a unified content catalog, separate skills and roles taxonomy, an identity and profile layer, and a recommendation surface connected through well-defined contracts. That separation enables us to make updates without rewriting the experience.”

By separating content, roles, identity, and recommendations into modular components, the platform can continuously evolve as technologies and job expectations change.

A photo of Vaidyanathan.

“The most consistent feedback from IT practitioners is that they need to move quickly from understanding AI to actually operating it.”

Priya Vaidyanathan, director of product management, Global Skilling

A differentiated approach to AI skilling

While many platforms provide access to AI learning content, AI Skills Navigator is differentiated by how it connects learning to real-world outcomes.

“The most consistent feedback from IT practitioners is that they need to move quickly from understanding AI to actually operating it,” says Priya Vaidyanathan, director of product management for Global Skilling. “The focus on governance, security, and how to enable their organizations without slowing innovation is a key differentiator for us.”

AI Skills Navigator is different from other learning experiences in several other ways:

  • Built around roles and tasks, not course catalogs. Content is organized into curated playlists aligned to roles and real work scenarios. Learners are not choosing from a library of courses; they are guided to build the specific skills needed to perform in their role, from first exposure to applied execution.
  • Orchestrated by specialized agents, not a single recommendation engine. Multiple agents work together to create playlists, guide learning sessions, and ensure content quality. This allows the experience to adapt to the learner, while maintaining grounding in trusted, curated Microsoft content. The result is guidance that is both personalized and reliable.
  • Designed to build capability over time, not deliver one-time learning. The platform is designed for repeat engagement. As learners return, recommendations evolve based on progress, feedback, and emerging skills; this enables continuous skill development rather than a one-time completion model.
  • Embedded into how work happens, not separate from it. Integration with Microsoft 365 Copilot brings skilling into the tools professionals already use and learning happens alongside real tasks, making it easier to apply skills immediately instead of learning in isolation.

Turning learning into team capability

For organizations, one of the most powerful features of AI Skills Navigator is the ability to align teams around shared learning goals. Skilling playlists enable leaders to define capability journeys that map directly to business priorities.

Instead of assigning generic training, leaders can create structured paths that guide teams toward specific outcomes, like becoming AI literate, managing agents in the enterprise, or building expertise in agent development. This approach transforms learning from an individual activity into a shared experience.

For IT professionals, this means learning is no longer abstract—it becomes directly connected to their role, their team, and the transformation initiatives they support.

Building momentum with an AI Skills Fest

To accelerate skills development through a moment of shared learning, we’re hosting our second global AI Skills Fest initiative in June 2026. The annual event is designed to bring focus, energy, and community to the AI Skills Navigator experience.

AI Skills Fest brings together:

  • A global audience of learners across different roles and skill levels
  • Curated learning experiences aligned to real-world scenarios
  • Opportunities to engage, practice, and validate new skills

The initiative builds on the success of last year, when we brought together more than 126,000 participants in a single day of learning to achieve a Guinness World Record for AI skilling participation. This milestone demonstrated both the demand for AI skills and the power of creating a shared learning moment at global scale.

In 2026, the focus is shifting from the record itself to sustaining long-term engagement. Our AI Skills Fest is designed to help learners discover the right entry points into AI Skills Navigator and build momentum that continues well beyond the event.

“We want learners to think of it less as a single event and more as a catalyst for ongoing skilling at scale,” Radhakrishnan says.

Bringing AI skilling directly to Inside Track

To make these learning opportunities even easier to discover, we’re taking the next step by integrating AI Skills Navigator content directly into the Inside Track experience. This integration will provide IT professionals with:

  • Direct access to curated learning journeys, aligned to Inside Track content
  • Seamless pathways from insight to action
  • A clearer connection between Microsoft’s own transformation story and the skills required to replicate it

For our readers, this creates a new kind of experience. Instead of simply learning how Microsoft approaches AI, you’ll be able to immediately start building the skills needed to apply those insights at your own organizations.

Look for curated deep links from Inside Track stories into AI Skills Navigator starting in the second half of 2026. Additionally, we’ll be adding links to our site navigation and Careers page to make it simpler to help you discover and build role-specific AI skills.

A photo of Chawdhary.

“From an assistant, to a coach, to a learning companion—the endpoint doesn’t feel like a learning platform at all. It just makes you better at your job.”

Iliyas Chawdhary, principal group software engineering manager, Global Skilling

A new model for learning in the era of AI

AI is reshaping how organizations operate, how teams collaborate, and how work gets done. For IT professionals, staying relevant means continuously building new capabilities.

AI Skills Navigator represents our answer to that challenge. The initiative moves beyond static content to create a guided, adaptive, and integrated learning experience. AI Skills Navigator just feels different—and better—than other learning platforms.

“From an assistant, to a coach, to a learning companion—the endpoint doesn’t feel like a learning platform at all,” Chawdhary says. “It just makes you better at your job.”

The era of AI demands a new approach to learning, and that approach is built on a foundation of role clarity, relevance, and continuous growth.

Key takeaways

If you are thinking about promoting AI skilling among your own employees, keep the following in mind:

  • Start your journey now. Explore the IT Professional playlist in AI Skills Navigator to identify the skills most relevant to your role.
  • Align learning to outcomes. Don’t just take courses: Define the AI capabilities your role or team needs, then use structured playlists to guide progress.
  • Make learning continuous. Plan for regular, incremental skilling rather than one-time training events to keep pace with AI innovation. The AI Skills Navigator playlists are constantly being updated to help you keep up with the pace of change.
  • Leverage AI-powered guidance. Use AI-driven recommendations, playlists, and coaching experiences to accelerate learning and reduce time to value.

The post Building AI skills for the future: How we’re reimagining learning with AI Skills Navigator appeared first on Inside Track Blog.

]]>
23960
Microsoft Build 2026: Empowering our developers to adopt agentic AI at Microsoft http://approjects.co.za/?big=insidetrack/blog/microsoft-build-2026-empowering-our-developers-to-adopt-agentic-ai-at-microsoft/ Tue, 02 Jun 2026 19:15:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23855 In Microsoft Digital, the company’s IT organization, our journey to agentic AI has been an evolution—one that began with early experimentation in AI-powered productivity and has grown into a coordinated effort to enable intelligent, scalable solutions across the enterprise. As AI capabilities advanced, we saw an opportunity to move beyond individual productivity gains and toward […]

The post Microsoft Build 2026: Empowering our developers to adopt agentic AI at Microsoft appeared first on Inside Track Blog.

]]>
In Microsoft Digital, the company’s IT organization, our journey to agentic AI has been an evolution—one that began with early experimentation in AI-powered productivity and has grown into a coordinated effort to enable intelligent, scalable solutions across the enterprise.

As AI capabilities advanced, we saw an opportunity to move beyond individual productivity gains and toward something more transformative: Empowering our developers to build intelligent agents that can automate workflows, streamline operations, and create new business value.

Realizing this vision required more than new tools. We needed to rethink how we foster development, govern innovation, and operate at scale.

A photo of Fielder

“We’ve made a lot of progress enabling our developers to build agents that make us more productive. We’re Customer Zero at Microsoft, which means we’re the first to deploy and use the technology and services that we later sell to our customers. Those learnings give us a unique perspective and story to share about the journey our developers have been on with AI and agents.”

Brian Fielder, vice president, Microsoft Digital

Today, we’re sharing the foundation we built that supports this shift.

We’re driving employees across Microsoft to create and use AI agents—from simple, task-focused solutions to enterprise-grade applications available across the company. It’s all supported by a secure, governed, and extensible platform.

“We’ve made a lot of progress enabling our developers to build agents that make us more productive,” says Brian Fielder, vice president of Microsoft Digital, the company’s IT organization. “We’re Customer Zero at Microsoft, which means we’re the first to deploy and use the technology and services that we later sell to our customers. Those learnings give us a unique perspective and story to share about the journey our developers have been on with AI and agents.”

Within the context of Microsoft Build 2026, we’re sharing what it really takes to move from experimentation to impact. Through this collection of stories and resources, we highlight how we’re empowering our developers to build with agentic AI—from establishing governance and platform capabilities to driving adoption and delivering real-world outcomes. Our goal is to provide practical insights you can use to accelerate your own AI journey.

“We hope you find the journey we’ve been on practical and useful,” Fielder says. “When it comes to agents, we’re accelerating fast and scaling at an enterprise level. As our story continues to evolve, we look forward to sharing it with you.”

Guidance for developers: How we manage agentic AI at Microsoft

These articles outline our vision for agentic AI, showing how we’re building a secure, governed, and extensible foundation for AI agents—from Work IQ and Copilot Studio to Agent 365, Azure DevOps, and Model Context Protocol—so developers can create scalable, high-value solutions across the enterprise.

Our IT guide to becoming a Frontier Firm

These stories share our IT playbook for becoming a Frontier Firm, highlighting a practical path to enterprise AI maturity through agentic transformation, operational scale, responsible innovation, and partnership—showing how IT leaders can balance governance, modernization, and employee engagement while building an AI-first organization.

Working as developer in IT at Microsoft in the era of AI

These stories explore what it means to work in Microsoft Digital during the AI era, showing how developers and knowledge workers are reshaping engineering, the employee experience, and their own career growth through AI-powered tools, new ways of working, and personal journeys that reflect the evolving culture of IT at Microsoft.

Key takeaways

From our journey enabling agentic AI across Microsoft Digital, several key principles have emerged to help organizations move from experimentation to scalable, enterprise-wide impact.

  • Treat your organization as Customer Zero. Use your own AI capabilities first to generate real-world insights, validate scenarios, and build credibility before scaling to customers.
  • Build a foundation for scale. Establish a secure, governed, and extensible platform that enables developers to create AI agents—from simple solutions to enterprise-grade applications.
  • Empower developers to drive transformation. Move beyond productivity gains by enabling developers to build intelligent agents that automate workflows and unlock new business value.
  • Align governance with innovation. Rethink how you enable development, govern AI, and operate at scale to balance flexibility with responsible use.
  • Connect tools, platforms, and workflows. Integrate AI capabilities across your ecosystem—linking platforms, governance models, and development tools to support consistent, scalable adoption.
  • Translate experimentation into impact. Focus on turning early AI exploration into coordinated, enterprise-wide efforts that deliver measurable outcomes.

The post Microsoft Build 2026: Empowering our developers to adopt agentic AI at Microsoft appeared first on Inside Track Blog.

]]>
23855
Governing AI agents at scale: Lessons from our journey at Microsoft http://approjects.co.za/?big=insidetrack/blog/governing-ai-agents-at-scale-lessons-from-our-journey-at-microsoft/ Thu, 21 May 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23618 Empowering employees and protecting your organization through agent governance Welcome to the agentic frontier Agents are expanding the frontier of enterprise AI. By creating tools that surface knowledge, take actions, and even reinvent workflows, organizations can apply the power of AI to business processes in new and innovative ways. But this shift raises questions for […]

The post Governing AI agents at scale: Lessons from our journey at Microsoft appeared first on Inside Track Blog.

]]>

Empowering employees and protecting your organization through agent governance

Welcome to the agentic frontier

Agents are expanding the frontier of enterprise AI. By creating tools that surface knowledge, take actions, and even reinvent workflows, organizations can apply the power of AI to business processes in new and innovative ways.

But this shift raises questions for business and IT leaders: How do you get the benefits of agents without putting your organization and employees at risk? How do you encourage citizen developers to create agents freely while maintaining control, security, privacy, and compliance?

At Microsoft Digital, the company’s IT organization, we’re putting practical governance structures in place to ensure our internal agents are useful, safe, and properly scoped. Through a deliberate strategy of empowerment with established guardrails, we’re unlocking the potential of agentic transformation while maintaining the trust that defines our work.

The AI maturity model and frontier transformation

Agentic AI has made a new operational model possible, one that blends machine intelligence with human judgment, creating AI-operated, human-led teams.

We call organizations that enact this model Frontier Firms.

As organizations move toward this new operational state, they progress from foundational AI assistance through escalating levels of agentic maturity and complexity. First, humans operate with help from an AI assistant like Microsoft 365 Copilot. Then, human-agent teams work together. But the future lies with humans leading teams of agent users: AI agents that perform core labor with relative autonomy.

Pattern 1: Human with assistant—every employee has an AI assistant that helps them work better and faster.
Pattern 2: Human-agent teams—agents join teams as “digital colleagues,” taking on specific tasks at human direction.
Pattern 3: Human-led, agent-operated—humans set direction, and agents execute business processes and workflows, checking in as needed.

Capturing the benefits of this model relies on many factors, but in our experience as Microsoft Digital, two main tenets are instrumental to a successful transformation:

  1. Empowering employees and teams to create and experiment with their own agents
  2. Properly governing those agents to protect the enterprise

It’s a balance. If you set agent builders free without the proper guardrails, you risk data overexposure, agent sprawl, and security vulnerabilities. However, being too restrictive about governance stifles individual imagination, workflow reinvention, and innovation that can come from agentic AI.

A photo of Fielder.

“At Microsoft, we’ve moved beyond envisioning the agentic future into operating within it every day. Our experience as Customer Zero gives us a unique perspective on what it takes to govern AI agents at scale, turning early lessons into proven practices that help organizations innovate with confidence.”

We’re here to help you find the right balance for your organization.

This guide shares what we’ve learned along the way. As you read, you’ll follow our journey as Customer Zero at Microsoft, and you’ll gain access to tips and resources that we’ve assembled to help you apply our expertise to your own agent governance practice.

Every organization is different, and your experience will differ from ours in terms of risk tolerance, technical capability, resourcing, and more. This guide highlights some principles and best practices you can apply to your own business context, needs, and objectives.

“At Microsoft, we’ve moved beyond envisioning the agentic future into operating within it every day,” says Brian Fielder, vice president of Microsoft Digital. “Our experience as Customer Zero gives us a unique perspective on what it takes to govern AI agents at scale, turning early lessons into proven practices that help organizations innovate with confidence.”

Now is the time to seize this opportunity. Follow along to start your own journey toward frontier transformation and capture the benefits of trusted, connected agentic intelligence.

Learn from our experience governing agents

Within Microsoft Digital, we’ve been acting as Customer Zero for frontier transformation by creating the tools, infrastructure, and processes that power agents at Microsoft.

Our goal is to make it easy for employees to engage with agentic tools freely and adaptably while maintaining safety and responsibility. The path to this objective relies on a three-pronged approach to governance:

  • Embedded governance functionality: Agent creation and publishing tools should incorporate good guidance, governance, and guardrails out of the box, making agents people create essentially self-governing.
  • IT oversight: This is a new space and a new way of working, so it isn’t feasible for all agents to self-govern at this point. As an IT organization, we fill gaps in governance through reviews and oversight. We establish risk-based policies around types of agents, exposure and sharing, and other pivots.
  • User education: It’s almost impossible to predict every governance gap and need, so educating our users helps them avoid accidentally increasing risk. Our Agents at Microsoft team and individual change managers are the guides for these efforts. Employees can also refer to resources like Microsoft Learn courses and the Agent Builders SharePoint hub.

Throughout this journey, we’ve empowered our employees to create all kinds of agents, ranging from simple personal tools built by people working in every function, with every level of technical skill, all the way to AI-powered enterprise tools designed by professional developers for use across lines of business and even the entire company.

As part of the process, we’ve incorporated guardrails to ensure less technical employees are limited to tools that simply retrieve enterprise knowledge, such as SharePoint Agent Builder or Copilot Studio, while software engineers get the full power of any tool they need that can take action or automate workflows, including Microsoft Foundry and Microsoft 365 Agent Toolkit.

SharePoint

  • Lowest level of difficulty
  • For all roles
  • Function: information-retrieval only
  • Microsoft 365 content
  • Light governance
  • Lowest risk

Copilot Studio Agent Builder

  • Low difficulty
  • For all roles
  • Function: information-retrieval only
  • Microsoft 365 content and web sources
  • Light governance
  • Low risk

Copilot Studio (full)

  • Low to moderate difficulty
  • For all roles
  • Function: task completion
  • Microsoft 365 content + connectors to external channels
  • Advanced governance
  • Higher potential for risk

Agent Toolkit, Foundry

  • Highest difficulty
  • For developers
  • Function: workflow automation
  • Multiple internal and external channels
  • Advanced governance
  • Highest potential for risk

Over the course of this journey, we’ve learned valuable lessons about effective agent governance, including:

  • How to build an impactful but flexible governance strategy
  • Strategies for creating an AI-ready data ecosystem
  • Ways to apply appropriate policies and controls for highly diverse agents
  • Approaches for tracking the impact and value of agents

Chapter 1: Building your agent governance strategy

Thinking through your organizational needs and building a framework to govern agents

As we’ve incorporated agents into different aspects of our organization, we’ve also deepened their involvement in employees’ daily workflows and core business processes. Because of this, we’re diligent about the governance guardrails and policies that protect our organization.

We’ve accumulated a wealth of knowledge and insights in this area through our efforts governing Microsoft 365 Copilot. Based on this experience, some of the key priorities that we made sure to adhere to included:

  • Effectively applying controls to ensure users and apps don’t get access to privileged information
  • Preventing employees from creating agents that violate company policies
  • Balancing the freedom for employees to share their creations with the need to prevent agent sprawl
  • Delineating which agents are authoritative and applicable for enterprise functions and which ones are meant for employees’ own personal use.
  • Inventorying agents to provide lifecycle management
  • Securing and protecting confidential data while respecting our responsible AI principles: Fairness, reliability and safety, privacy and security, transparency, accountability, and inclusiveness
  • Unlocking telemetry that enables us to govern agents effectively

By focusing on each of these dimensions, our governance team has centered its efforts on the value these agents provide to the company while also ensuring organizational safety and trust. To realize this value, we emphasize three key principles that help protect both our employees and the organization:

Security

We’ve established standards for data classification, policies for handling confidential information, and other security measures to protect data from unauthorized access, misuse, and disclosures. Microsoft Purview powers these capabilities through data labeling, rights management, and data loss prevention.

Privacy

Privacy compliance measures keep personal data protected and ensure agents adhere to regulatory frameworks in the regions where we operate. We conduct regular privacy assessments for all applications, including high-impact agents.

Regulation

Regulatory compliance assessments ensure agents meet prevailing legal standards. Our legal and compliance teams carefully monitor AI guidelines, regulations, and laws as they evolve so we can understand and incorporate them into these assessments.

We incorporated elements of our tenant’s minimum bar for governance into how we secure agents. Those include Microsoft Purview Information Protection, a functional inventory, activity logging, lifecycle management, and the ability to properly isolate agents so that they don’t cross data boundaries.

Our overarching tenant governance strategy is to govern items like documents and data at the container level. However, within a SharePoint site, for example, the added functionality of agents demands that we introduce further controls like sharing limits, breadth of knowledge sources, agent metadata, and information about an agent’s behaviors.

Turning priorities into principles

To operationalize governance, we developed six principles that guide our approach to agents. They form the governance foundation for a wide matrix of agent creation and usage opportunities.

  1. We ensure a strong data hygiene foundation so we can trust our data estate as employees build and use agents.
  2. We empower employees to build personal agents that can access permitted services and data sources to help automate and accelerate their tasks.
  3. We empower teams and lines of business to build agents with known lower-risk patterns to accelerate impact.
  4. We provide a smooth release path for engineering teams to develop agents designed for enterprise functions so they can access all the services and sources they need. This includes the same software development lifecycle (SDLC) reviews and certifications as other enterprise software, which we outline in Chapter 3.
  5. We accelerate innovation through agent and automation templates while maintaining an AI Center of Excellence (CoE) to help teams think through their opportunities.
  6. We reimagine employee experiences and task execution to simplify and optimize productivity.

Securing control through agent lifecycles

As we strategized to operationalize good governance, agent lifecycles became one of our most crucial tools. We superimposed the enterprise lifecycle on top of these policies, with both user-based and attestation-based lifecycles.

This means we treat agents owned by individual employees like any other user app and delete them when they leave the organization. Meanwhile, we ensure that agents owned by teams have a lifecycle that’s defined by the tenant and tied to attestation, our internal enterprise SDLC, and accountability confirmations.

This approach helps us combat sprawl by eliminating agents that no longer serve a purpose. It provides a solid foundation for more fine-tuned, matrixed policies and practices.

Governing amid real-time technology acceleration

One recent development illustrates how the rapid advancement of AI technology requires us to stay ahead of policy for new features.

Model Context Protocol (MCP) adds new capabilities, but also new risks and challenges. It’s a simple standard that lets AI systems communicate with the right tools and data without custom integration work. Instead of building a new connection or API every time, teams plug into a common pattern.

That standardization delivers speed and flexibility, but it also changes the security equation. We’ve extended our security and governance practices to account for MCP servers.

Our practices and policies help us govern agents effectively in this new environment. First, we assess security across four layers: Applications and agents, the AI platform, data, and infrastructure. We establish a secure-by-default strategy by positioning every remote MCP server behind our API gateway and establishing practices for vetting, identity management, automation that slows agents at the right moments, context trimming, and server isolation.

As you define policies for governing your own agentic ecosystem, you can take inspiration from our process. Start by asking questions about what you want to accomplish and what you want to protect, then move on to establishing your most important priorities. From there, you can cement those priorities into policies.

Learning from our approach to agent governance strategy

Match policies to progress on your AI journey

The complexity of agent governance depends on the maturity of your organization and where you are in your adoption journey. Start slowly to let that maturity grow over time.

A strong policy framework is the foundation

Lean on existing app governance policies, then layer agent-specific structures on top.

Take your cues from established standards

Global regulations around privacy, security, and responsible AI provide a good baseline for establishing governance policies. Assign teams to work through these regulations and incorporate their insights into your agent governance strategy.

Decide on your comfort level with risk

Bring cross-disciplinary experts together from across your organization to determine what level of risk is acceptable for different agents and their use cases. Put guardrails in place for low-risk scenarios and establish processes for supporting more complex or sensitive use cases. Evaluate what data sources agents can extract information from. Establish whether users have shared sensitive data sources.

Change is constant

Plan to reassess and revise your governance structure regularly. Agents are evolving rapidly, as is the tooling surrounding them, so maintaining good governance policies will be an ongoing practice.

Governance is a value driver for employees

Governance isn’t just about protecting your organization. It also provides the right patterns to make sure your employees are getting value from agents. Establish strong measures of business value and a robust methodology for management and assessment of agents through ongoing tracking. This kind of observation and telemetry is foundational and should be a key part of your governance efforts.

Key takeaways

Use these tips based on what we learned here at Microsoft to build your strategy for agent governance at your company:

  • Establish a cross-disciplinary agent Center of Excellence. Bring together stakeholders across the organization to define priorities, goals, and shared practices for agent adoption.
  • Right-size oversight based on risk. Determine your organization’s risk tolerance and define which agents require more or less involvement from IT, security, and compliance teams.
  • Operationalize agent oversight and management. Establish an oversight model and implement tools that help manage agents at scale.
  • Establish change management and adoption. Determine and implement a strategy for driving adoption to educate and empower employees.
  • Create a centralized governance and information hub. Provide employees and agent builders with a single place to find guidance, standards, and governance information.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 2: Establishing a solid data foundation for agent governance

Setting agents up for success using a secure, robust data foundation

Operating according to an escalating maturity model means we’ve done the foundational work to secure and govern our data estate for Microsoft 365 Copilot. Many of the same principles apply to agents, with the added complexity of incorporating additional data sources.

To lead these efforts, we established a cross-functional team of data professionals within our AI CoE. This team is mostly comprised of Microsoft Digital employees who support corporate functions like Corporate, External, and Legal Affairs (CELA) and Global Workplace Services. Together with our AI CoE, this team helped us define what it means to have AI-ready data.

In essence, AI-ready data just means information we’ve certified for AI workloads. We certify those data sources using Microsoft Purview to identify defects in our core data products, and we’ve also built AI-powered assessments to certify which data lakes are AI-ready.

In most ways, governance is tool-agnostic and rooted in basic principles. With robust data labeling, data hygiene, and permissions in place alongside our AI tools, which respect labels by default, we can confidently give every employee the ability to build basic agents and trust in our governance guardrails. For decades, the challenge of data analysts and engineers was maintaining a consistently reliable source of truth despite inconsistent data quality, insufficient governance, and years of collecting data in silos. Microsoft Fabric and Microsoft Purview can help resolve these issues.

We’re embracing a more balanced, federated approach to data management today. We call this approach a data mesh. Rather than allowing unchecked decentralization or forcing all our data into a single centralized system, the data mesh formalizes domain ownership while embedding governance, quality, and interoperability directly into shared platforms.

Graphic shows our data mesh architecture surrounded by the platform services layer and the data management zones layer.
Our data mesh architecture helps us preserve trust and establish a strong governance foundation while preventing data from becoming siloed.

The data mesh connects and distributes, data products across domains, enabling shared data access and compute while scaling beyond centralized architectures.

Platform services are standardized blueprints that embed security, interoperability, policies, standards, and core capabilities — providing guardrails that enable speed without fragmentation.

Data management zones provide centralized governance capabilities for policy enforcement, lineage, observability, compliance, and enterprise-width trust.

With this approach, our domain teams publish data as well-defined, discoverable products, while common standards for security, metadata, and compliance are enforced through automation rather than manual processes. This model preserves enterprise trust and consistency without sacrificing speed or autonomy. By adopting a data mesh mindset, we can scale analytics and AI more effectively across the organization while still keeping ownership closely connected to the business focus.

Confidentiality labels, the practical framework for data protection

To operate according to Zero Trust principles, we needed a coherent system that lets us see, label, and protect data. Otherwise, the burden of data loss prevention would fall solely on employees, who would have to exercise individual discretion whenever they decided how to house and share potentially sensitive content.

With labeling, it’s important to strike a balance between the depth necessary for supporting an array of data governance controls and the simplicity to ensure labeling isn’t burdensome for users.

We decided on four overarching labels for container and file classification, each with its own sub-labels. The highest-level schema looks like this:

  1. Highly confidential: We only share our most critical data with named recipients.
  2. Confidential: Any items crucial to achieving our goals feature limited distribution.
  3. General: Employees can share daily work–like personal settings and postal codes–internally throughout Microsoft.
  4. Public: We share unrestricted data meant for public consumption freely. That includes information like publicly released source code and openly announced financials.

For our risk tolerance and organizational needs, we made the decision to protect data designated confidential or higher. As a result, we contain data flows to their tenants and only trust suitable storage destinations for content. That suitability depends on a storage location’s ability to gate which connectors can work with particular source data and sensitivity labels.

The administrators responsible for workspaces like SharePoint sites set default labels. These labels serve as a foundation for appropriate access and circulation for objects within those containers. It takes the burden of labeling off of employees. The sensitivity labels that administrators apply map to several different categories of policies that can anticipate and help to mitigate data loss and risk.

They communicate four key areas:

  1. Breadth of availability: Labels determine whether the workspace is broadly available internally or is a private site.
  2. External permissions: We administer guest allowance via the group’s classification, allowing specified partners to access teams when appropriate.
  3. Sharing guidelines: We tie important governance policies to the container’s label. For example, can an employee share this workspace outside of Microsoft? Is this group limited to a specific division or team? Is it restricted to specific people? The label establishes these rules.
  4. Conditional access: While we haven’t implemented this policy at Microsoft, tying identity and device verification to container labels can introduce additional governance controls.

Within Microsoft Digital, we’ve put a lot of thought into how each of our labels aligns with relevant policies. You can see more of the logic behind our sensitivity labels and their policies in this graphic:

A chart shows the different types of data container labels and what level of access is given for each one.
Our Microsoft Digital schema clearly lays out what each container sensitivity label means and how it affects content.

If a container owner needs different policies for a set of files to provide greater external access, they can self-service new groups without accidentally violating our governance practices.

At Microsoft, we use Microsoft Purview, which is our suite of data estate management tools, but you can use your tool of choice to apply labels in your environment. Microsoft tools will respect them. Microsoft Purview helps us accomplish three important tasks: mapping our labeling structure onto the relevant policies, verifying them against our standards, and backstopping self-service data loss prevention practices through automation.

Automation is particularly useful. We’ve configured Microsoft Purview Information Protection to scan automatically for wayward credentials, malicious user behaviors, and other sensitive information in items without the proper protections. When Purview detects a violation, our governance team receives alerts that prompt them to contain the risk by upgrading an item’s sensitivity label or requiring employees to remedy the issue.

The result is a system that allows flexibility for employees to self-manage their digital workspaces while providing guardrails that help our governance experts take appropriate actions without overtaxing their time and resources.

Our approach within Microsoft Digital is just one way to create an AI-ready data estate, but aspects of our story will hold true for almost any organization. Consider establishing a body to take over responsibility for AI-ready data, developing your primary goals for AI-ready data, unifying your data estate, and implementing a system of confidentiality labels.

Learning from our approach to agent governance strategy

Define the responsibility for AI-ready data

Identify and assign enterprise data owners to implement and oversee the processes that guarantee data quality.

Create intuitive labels

Your employees will be the ones applying labels, so make those labels intuitive. For example, “highly confidential” is easy to understand, while “business-critical” could be interpreted in many ways from a sensitivity standpoint.

Don’t overwhelm your users

Make labeling simple and intuitive to ensure it isn’t overwhelming. Employees should have a limited set of choices to keep things comprehensible.

Use existing defaults

Identify the security needs and regulatory compliance that are specific to your organization and use built-in governance controls available through Microsoft tools.

Key takeaways

You can use these tips based on what we learned here at Microsoft to tackle agent governance at your company:

  • Establish a cross-functional data council. Form a data council to help promote a culture of AI-ready data with professionals from all relevant disciplines, including human resources, legal, security, IT, and anyone else who can share relevant expertise.
  • Certify datasets for AI workloads. Limit agents to datasets that have been certified as “AI-ready” to minimize hallucinations and reasoning errors.
  • Define your labeling parameters. Keep the number of labels to five main labels with five sub-labels each. The fewer you use, the better.
  • Align your sensitivity labels with policies. Consider how your labels line up with breadth of availability, external permissions, sharing guidelines, and conditional access.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 3: A matrixed approach to agent governance

Governing different types of agents for different contexts, built with different toolsets

Our customers have expressed a strong desire to start building agents, but they’re concerned about where to begin and how to manage those agents once they’re built. They worry about persistent problems such as hallucinations and agent sprawl. These concerns are especially pronounced on IT teams.

During our Customer Zero journey, we’ve learned that the diversity of agent types and creation methods means there’s no one-size-fits-all approach to governance. Generalized approaches will only get you so far.

We’ve found it helpful to think about different kinds of agents along an escalating spectrum of development complexity:

The Microsoft Digital agent controls model, spanning citizen, partnered, and professional development models and their relevant tools.
The agent controls model we’ve developed at Microsoft Digital spans different agent-building methods for different kinds of creators using a spectrum of tools.

There’s an entire matrix of different parameters that apply to an agent at any level of this spectrum, and they all require different policies. Those parameters include:

  • Level of reach: Personal agents, limited sharing (like development environments or team boundaries), or enterprise-wide distribution
  • Agent-building tool: SharePoint agent builder, Agent Builder in Microsoft 365 Copilot, Microsoft Copilot Studio, or tools geared to more professional developers (such as Microsoft Foundry or Microsoft 365 Agent Toolkit)
  • Knowledge sources and content accuracy: Public sites, SharePoint and OneDrive, directly uploaded files, enterprise apps and systems, or third-party knowledge bases
An overview of the range of agent-building tools and our matrixed approach to governing them across different parameters.
Our matrixed approach to agent creation and governance spans a wide array of tools, knowledge sources, actions, channels, and more.

Each of these parameters creates a pivot that we need to govern, and we’ve carefully assembled a set of policies and controls to account for them. As our understanding and use of agents advances, we’re continually updating how we match their characteristics and capabilities with relevant policies and any applicable reviews.

Within Microsoft Digital, we’ve adopted a risk-based approach that helps us establish a matrixed model for agent governance. The foundational idea is that we identify potential harms for each kind of agent, then assign policies for the level of review and oversight they require.

For example, simple agents that can only read and present data tend to be low risk. Because their access is tied to their creators’ identities and access, our data governance structures and guardrails can prevent overexposure. But for agents that have capabilities like writing data, taking action, or creating items, more reviews are necessary.

A matrix of agent governance policies, pivoted by parameter

The following matrix enumerates the factors that determine how we govern different kinds of agents created using different tools. This matrix helps our employees understand the agent creation process and helps us maintain safety and control.

SharePoint agent builder

What users can build: Knowledge-only agents
These agents reason over Microsoft 365 Copilot collaboration data, and they’re gated to the SharePoint environment where they’re created.

Technical proficiency: No-code

Knowledge sources: SharePoint, custom instructions

Capabilities: Not applicable

Actions and plug-ins: Not applicable

Sharing and publishing: Copilot navigation in SharePoint, sharing by link, sharing in Microsoft Teams chat

Custom engine or bring-your-own model: Not applicable

Reviews: No review needed
IT doesn’t gate knowledge-only agents outside of governance tied to SharePoint sites. Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.

Agent Builder in Microsoft 365 Copilot

What users can build: Knowledge-only agents
These agents feature graph connectors from a preapproved catalog to expose additional data.

Technical proficiency: No-code

Knowledge sources: SharePoint, external websites, custom instructions, additional internal knowledge sources via graph connectors

Capabilities: Code interpreter, image generator

Actions and plug-ins: Not applicable

Sharing and publishing: Individual use, sharing by link

Custom engine or bring-your-own model: Not applicable

Reviews: No review necessary
These agents only access graph data available in Copilot. Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.

Microsoft Copilot Studio

What users can build: Task and custom agents
These agents connect to more systems through connectors and orchestration logic to handle more complex scenarios. We might publish agents at this level of complexity and utility to our agent catalog for wide organizational use.

Technical proficiency: Low-code or pro-code

Knowledge sources: SharePoint, external websites, custom instructions, additional internal knowledge sources via advanced graph connectors, Power Platform connectors

Capabilities: Not applicable

Actions and plug-ins:
Retrieval and task agents: Read-only actions
Custom agents: Read or write actions using Power Platform connectors

Sharing and publishing:
Retrieval or task agents in a personal developer environment: Sharing by link with up to 10 people
Custom agents: Publishing to 10 people or the agent catalog in Microsoft 365 Copilot Chat
Broad publishing: Requires a review similar to professionally developed apps, including an understanding of the agent’s data implications

Custom engine or bring-your-own model: Custom Azure OpenAI large language models (LLMs)

Reviews: Custom agents for our catalog require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review.

Microsoft Foundry

What users can build: Retrieval, task, and custom agents
These agents may or may not connect to more systems through connectors and orchestration logic to handle more complex scenarios. We might publish agents produced at this level of complexity and utility as Microsoft Teams apps or to our agent catalog for wide organizational use.

Technical proficiency: Pro-code

Knowledge sources: SharePoint, external websites, custom instructions, additional internal knowledge sources via graph connectors

Capabilities: Code interpreter, image generator, Teams chats and channels

Actions and plug-ins: API actions

Sharing and publishing: Publishing as an app in Teams or as an agent in the catalog in Copilot Chat

Custom engine or bring-your-own model: Custom Azure OpenAI large language models (LLMs)

Reviews: Custom agents for publishing as a Teams app or in our catalog require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review.

In addition to mapping out our policies for governing agents, the matrix illustrates how we see their relative utility across the organization. It demonstrates an escalation from personally useful to organizationally useful agents. Their governance policies and controls escalate accordingly.

Regionality is an additional concern. Regulatory compliance might vary, but it’s important to keep in mind that certain kinds of data access and actions might be perfectly permissible in one region, but not in another.

One example is our Employee Self-Service Agent, a central resource employees can turn to for help with IT support, HR questions, and facilities requests. Because it can access potentially sensitive personal information, this agent required additional review from European works councils to ensure it met all relevant workplace standards.

As you facilitate the experimentation and innovation with agents across your workforce from citizen developers to pro developers, consider adopting a similar matrixed approach to agent governance. It starts with understanding your organization’s needs, your risk tolerance, and the different employee populations you want to equip with agent-building capabilities.

Learning from our matrixed approach to agent governance

Figure out your building environment strategy

Decide which scenarios match up with specific environments and make those environments available to the relevant employees.

Design governance structures that scale from low-code to more advanced agentic tools

With the proliferation of AI agents, platform-level approvals similar to the Power Platform model at Microsoft can ensure rapid innovation while requiring review for individual high-impact scenarios.

Build trust through transparency and structure

A clear, well-documented approval process helps internal regulatory advisors understand new AI technologies and establishes the trust needed for productive, long-term collaboration.

Treat regional partners as strategic allies in the agentic future

Early feedback on digital agents from regional partners like works councils helps improve product design, accelerate approvals, and reduce fear or misconceptions about AI in the workplace.

Don’t forget that Copilot Studio is part of Power Platform

You can use what you’ve learned empowering citizen developers in Power Platform to guide your work with agents.

Key takeaways

Use these tips based on what we learned here at Microsoft to tackle agent governance at your company:

  • Establish your tolerance for risk. Determine where the most prevalent risks emerge across different populations and kinds of agents. Remember, you control the guardrails in your environment.
  • Determine what agent-building tools you want to roll out and who can use them. Different populations benefit from different agent-building capabilities. Put thought into what individuals and teams can create and the degree of partnership each level will need from IT.
  • Define your governance parameters for different kinds of agents. Determine the best ways to hedge against risk at every level. For example, you might choose to trust in tenant governance for simple agents and establish reviews for more complex tools.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 4: Tracking, impact, and value

Managing agents and assessing their business impact for the organization

It’s clear that agents bring astonishing capabilities to the enterprise. For many organizations, what remains unclear is exactly how to measure their impact. Without that information, businesses are at a loss for ways to articulate value and drive improvement.

Tracking agents is also a crucial component of preventing sprawl: We need to understand what agents we have, how employees are using them, what critical processes they’re supporting, and if they’re contributing value or need to be retired.

We’re at the beginning of our impact-tracking journey, but our work can provide a starting point for your own efforts to measure the value of AI initiatives at your organization.

Managing our agent catalog through comprehensive tracking

Microsoft Digital partners with other internal organizations to ensure we’re prioritizing the right agents and avoiding agent sprawl. Ideally, these engagements take place before teams start building their agents so we can avoid wasted effort or duplicated work.

Still, ongoing management efforts are crucial to keeping our agent ecosystem healthy. Telemetry is the key to assessing usage and ensuring compliance. We’ve developed our own internal tooling to ensure that:

  • Metadata is complete and available
  • The tooling tells us the right information about our agents
  • The tools connect properly with other compliance tooling, like Microsoft Purview

This telemetry also reveals agent behaviors, shows how agents do their work, and tracks events, actions, and policy baselines.

These capabilities help us gain visibility into policy adherence and violations, and then to conduct enforcement actions. We also track the speed of reaction and mitigation. AI-ready data and robust guardrails mean we head off most violations before they occur.

A robust inventory, an agile policy framework, and an automated workflow for enforcement are cornerstones for successfully governing agents at scale.

The release of Microsoft Agent 365, now in early access, represents the next step in agent observability and management, two key aspects of agent governance and sprawl mitigation. This control pane for agents incorporates many of our learnings as we’ve bridged governance gaps through IT intervention.

Some of the key aspects of the control pane:

The registry

Provides a complete view of agents, and the enterprise agent store makes it easy to find the right agents for each role and business process within familiar workflows in Microsoft 365 Copilot and Teams.

Visualization

Delivers the observability layer, including role-specific oversight, compliance and audit features, and performance measurements that can help organizations track their agents’ impact and see where they contribute value.

Interoperability

Ensures Agent 365 is open to any Microsoft-built or partner ecosystem, while delivering work intelligence through access to data and Microsoft 365 apps.

Security features

Provide crucial confidence through visibility into security posture, detection and response capabilities, and intelligent runtime defense.

As Customer Zero for Agent 365, we’re excited to have a platform for observability and telemetry that encompasses everything from agentic creation through usage.

Tracking governance from agent inception

Professionally developed agents add a new dimension of tracking and governance, because we need standards in place for ensuring compliant agent-building and to remediate any issues.

We use our Azure DevOps instance to catalog apps on our tenant, and we’ve applied this practice to agents created professionally for lines of business and enterprise agents. This tool contains our service tree with product and app log registration, which is tied to our KPI dashboard and scoring system that validates agent data against our policies.

Our expectation is that all new apps and agents start from a place of compliance. Any new agent is registered through this platform, and we expect adherence within the first 14 days. In our experience, the introduction of new metrics, policies, or timeframes as our governance policies evolve is where agents tend to drop out of compliance. The priority is restoring compliant status.

We’ve established a series of metrics to help track and manage these expectations:

  • Enablement velocity
  • Renewal velocity
  • Agents in compliance
  • Time to remediation of noncompliance

Through a DevOps process built on our preexisting software development lifecycle practices, we’ve applied governance not only to agents themselves, but to the process of building them professionally.

Measuring progress and unlocking value

Properly measuring value depends on concrete definitions of success and metrics that support it. Articulating AI’s impact came with several challenges. First, we had to land on a consistent taxonomy for different measurement areas. Then we needed to make the relevant data accessible, ensure its quality, and confirm it made sense.

The Microsoft Digital AI Value Framework is our flexible, modular tool for measuring the impact of our AI initiatives. With tools for measurement firmly in place, we can effectively demonstrate value and guide further decision-making.

Revenue impact

Direct contributions to revenue generation and business growth

Example metrics:

  • Increased sales or customers
  • Improved customer targeting
  • Higher lead quality
  • Deal velocity

Productivity and efficiency

Efficiency gains while completing tasks and processes without a reduction in quality

Example metrics:

  • Increased throughput
  • Process optimization
  • Task automation

Security and risk management

Improvements in identifying, preventing, and managing security vulnerabilities and risks

Example metrics:

  • Vulnerability detection or prevention
  • Reduction in data security incidents
  • Increased compliance with responsible AI standards

Employee and customer experience

The impact of AI initiatives on employee satisfaction, engagement, and productivity

Example metrics:

  • Employee or customer engagement satisfaction with products or services
  • Improved employee health scores

Quality improvement

Enhancements in the quality of deliverables, services, and processes

Example metrics:

  • Higher-quality deliverables
  • Confidence in code quality
  • Accuracy of numbers

Cost savings

Reduction in operational costs and resource allocation efficiencies

Example metrics:

  • Operational efficiencies
  • Improved resource allocation
  • Future cost avoidance

We plan to use the following capabilities to improve the overall ecosystem:

  • Filtering our agent inventory on specific criteria like the type of agent or how it was built
  • Enhancing governance-specific actions we can take with agents in areas like ownership and quarantining
  • Gaining visibility into trends like agent usage
  • Ingesting agent blueprints and defining policy templates

We’re still in the midst of our agentic measurement journey at Microsoft, but the blueprint for tracking already exists. Your organization might be in the early stages of agent readiness and deployment. If that’s the case, it could be helpful for you to internalize the lessons we’ve learned as Customer Zero and apply them as early as possible in your own journey toward AI maturity.

Learning from our agent adoption experience

Think proactively, not retroactively

If you put effort into tracking agentic impact early in your AI maturity journey, you’ll be poised to start capturing insights immediately instead of applying your methodology retroactively.

Involve a wide array of stakeholders

This workstream needs oversight from different kinds of stakeholders, including your leadership team, IT, Microsoft 365 administrators, agent developers and builders, and employee champions. That will provide the sponsorship, expertise, and perspective you need for success.

Different measurements will be appropriate for different phases of your initiatives

These measurements include monthly, weekly, or daily active usage; consider which metrics make sense at each phase of an AI initiative.

Establish a continuum of value

Agents need to tie into real business goals, so it’s important to establish metrics that actually speak to those objectives. Cascade business goals to concrete KPIs with well-defined timelines and track those diligently.

Embrace the red

Try to think of underperformance not as failure, but as data. Performance data over time helps you course correct or pivot, making sure you invest where it matters.

Key takeaways

Here are some important steps to keep in mind as you embark on your own tracking and measurement efforts for agents:

  • Establish priorities and parameters for tracking agents. Consider measurements that relate to sprawl, usage, and coverage, and build them into your telemetry tooling.
  • Pull your stakeholders together to establish measurement parameters. Cascade business priorities into measurable value.
  • Conduct ongoing tracking. Establish a cadence for tracking and reviewing progress with your team.

Learn more

How we did it at Microsoft

Further guidance for you

Governing the frontier to scale innovation

AI agents are rapidly becoming core contributors to how work gets done. As our experience within Microsoft Digital demonstrates, realizing their full potential demands more than powerful tools or enthusiastic builders. It requires thoughtful governance that evolves alongside your AI maturity, protects what matters, and gives employees the confidence to innovate responsibly.

As you consider your own strategy for managing agents, it can be helpful to keep one truth in mind: Governance is a catalyst for progress, not a barrier. By embedding guardrails into tools, grounding agent creation in AI‑ready data, applying risk‑based and matrixed policies, and reinforcing all of it through adoption and education, we’ve been able to expand agentic capability without sacrificing security, privacy, or trust.

From our experience, we’ve learned that governance works best when it’s:

  • Proportional, scaling with risk and agent complexity
  • Embedded, not bolted on after the fact
  • Human‑led, recognizing that accountability and judgment remain essential
  • Iterative, adapting as technology, regulations, and business needs evolve

When you design governance this way, it allows experimentation, learning, and impact at scale. Employees feel empowered to build agents that solve real problems, while IT and compliance teams gain visibility and control without becoming bottlenecks. Crucially, leaders can measure value, manage risk, and make informed decisions about where to invest next.

A photo of Alaparthi.

“At Microsoft, we believe the future of agentic AI depends on governance that empowers people first. The structures should be invisible when they’re working, intentional when they’re needed, and trusted by everyone they serve.”

This is the foundation of the Frontier Firm: Organizations where humans lead and agents operate, guided by clear principles and trusted systems.

As you continue your AI maturity journey, remember that there is no single, correct governance model. Your approach will reflect your risk tolerance, regulatory environment, data maturity, and organizational culture. The practices outlined here provide a proven starting point informed by real-world deployment at enterprise scale.

“At Microsoft, we believe the future of agentic AI depends on governance that empowers people first,” says Vijaya Alaparthi, principal group product manager in Microsoft Digital. “The structures should be invisible when they’re working, intentional when they’re needed, and trusted by everyone they serve.”

Now is the moment to act. Start with strong foundations. Empower your builders. Measure what matters. And treat governance not as a constraint, but as a strategic advantage that allows your organization to move faster, innovate safely, and lead confidently on the agentic frontier.

Key takeaways

Here are the high-level learnings and insights that you need to consider as you embark on your own agent governance journey, based on what we’ve learned here at Microsoft:

  • Treat governance as an enabler of innovation, not a brake. Effective agent governance is what makes large‑scale innovation possible. When you embed guardrails into platforms, data, and processes, employees can build and experiment confidently without exposing the organization to unnecessary risk or slowing progress.
  • Match governance rigor to agent risk and maturity. Not all agents need the same level of oversight. A risk‑based, matrixed approach lets organizations trust lightweight, personal agents while applying deeper reviews to agents that write data, take actions, or operate across business‑critical systems.
  • Start with AI‑ready data and zero‑trust foundations. Strong agent governance rests on secure, well‑labeled, high‑quality data. Clear ownership, intuitive sensitivity labels, default protections, and automation reduce reliance on user judgment and allow agents to operate safely at scale.
  • Embed governance where agents are built and used. The most effective governance is built into tools and workflows, not enforced through manual reviews alone. Defaults, limits, identity‑based access, lifecycle controls, and telemetry should apply automatically so agents are governed by design.
  • Plan for the full agent lifecycle to prevent sprawl. Agent inventories, ownership models, attestation, and retirement processes are essential. Governance needs to account for how you create, share, evolve, audit, and ultimately decommission agents, whether individuals or enterprise teams are responsible for building them.
  • Reinforce governance through adoption and education. Guardrails work best when employees understand them. Targeted adoption programs, clear guidance, prerequisites for advanced tools, and visible leadership sponsorship can help employees build responsibly and recognize their role in protecting the organization.
  • Measure what matters to prove value and drive improvement. Visibility drives trust. Telemetry, observability, and clear metrics that span productivity, quality, risk reduction, and experience allow organizations to track impact, course‑correct early, and continuously improve their agent ecosystem.

Learn more

Try it out

Get started building and managing agents at your company with Microsoft Agent 365.

The post Governing AI agents at scale: Lessons from our journey at Microsoft appeared first on Inside Track Blog.

]]>
23618
Transforming IT support across Microsoft with the Employee Self-Service Agent http://approjects.co.za/?big=insidetrack/blog/transforming-it-support-across-microsoft-with-the-employee-self-service-agent/ Thu, 07 May 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23517 We’re in a new world of work support today, where Microsoft 365 Copilot and agentic AI make getting detailed help with a problem as easy as typing a quick question into a chat interface. At Microsoft, we’ve put that potential into action by building the Employee Self-Service Agent, a centralized “front door” for employee support […]

The post Transforming IT support across Microsoft with the Employee Self-Service Agent appeared first on Inside Track Blog.

]]>
We’re in a new world of work support today, where Microsoft 365 Copilot and agentic AI make getting detailed help with a problem as easy as typing a quick question into a chat interface.

At Microsoft, we’ve put that potential into action by building the Employee Self-Service Agent, a centralized “front door” for employee support inquiries on all things Microsoft. Whether the question is related to an IT, human resources (HR), or campus services-related challenge, this agentic solution delivers geographically relevant, role-specific content on demand.

Our agent was rolled out in stages to our global workforce, as we continually added topic categories, features, and geographic availability. It eventually reached our entire workforce—more than 300,000 employees and vendors in 103 countries and regions—before being publicly released last November.

Our team in Microsoft Digital—the company’s IT organization—played a pivotal role in our global rollout, working closely with the product team and providing valuable feedback throughout development. It’s all part of our Customer Zero philosophy here at the company.

The agent proved its value early, piloting in large, primarily English-speaking regions—including Canada, India, the UK, and the US—and reaching more than half of our global workforce. But we wanted to raise the bar, so we turned to the rest of Europe.

The next chapter in the rollout was the Europe North region, which brought in 21 countries that are home to a wide variety of languages, cultures, country-specific HR policies, and nuanced IT support requirements.

A photo of Hvass.

“For the Employee Self‑Service Agent to work in Europe North, we had to listen locally to understand each country’s realities and respect those differences, rather than forcing a single global approach.”

Allan Hvass, director, Employee Experience in Europe North, Microsoft Digital

However, early deployments in smaller markets in the region revealed that when local content for a specific geography was missing, the agent sometimes defaulted to policies related to the US or other unrelated countries. Sensitive HR scenarios and strict country-level rules increased the complexity and resulting challenges.

Our team in Microsoft Digital met the challenge by working through front‑end field adoption and back‑end product updates to successfully land the Employee Self-Service Agent in Europe North’s small and midsize countries. This included adapting the product to distinct local realities in each country.

“For the Employee Self‑Service Agent to work in Europe North, we had to listen locally to understand each country’s realities and respect those differences, rather than forcing a single global approach,” says Allan Hvass, director for Employee Experience in the Europe North region of Microsoft Digital.

Mobilizing field representatives

To help with the tricky aspects of driving local adoption of  the Employee Self-Service Agent, our team in Microsoft Digital formed an adoption advisory team. The team included leadership representatives from all major countries and business divisions.

The group established on‑the‑ground field representatives to create better communications channels with the Europe North countries. This helped us learn what was and wasn’t working locally while we extended support for neighboring countries and kept excitement around the agent alive.

A photo of Rusen.

“I encouraged my colleagues to use the agent, and then to tell customers about their experience,” Rusen says. “A story grounded in real use is much more powerful and authentic than any slide deck.”

Daniel Rusen, sales enablement and operations leader, Europe North

Because the team had already been communicating about the agent internally, including hosting all-hands meetings to spark early usage, we were able to collect thousands of instances of employee feedback. Key themes surfaced, including policy accuracy by country, quality of language, and IT support variance by market.

Daniel Rusen, a sales enablement and operations leader for Europe North, served as one of the field representatives. He helped the advisory team close the loop between the field and the core project by highlighting the language and local relevancy issues that were reported. He also became an evangelist for the agent, encouraging other sales executives to use the tool and experience it first-hand.

“I encouraged my colleagues to use the agent, and then to tell customers about their experience,” Rusen says. “A story grounded in real use is much more powerful and authentic than any slide deck.”

Driving adoption with contextual experiences

To support the rollout of the Employee Self-Service Agent across Europe North, we designed an adoption approach aligned with regional priorities and local ways of working.

We focused on making the value of the agent immediately tangible. Through Microsoft Viva Engage communications, we connected the agent directly to Europe North business goals and highlighted the most relevant, high-impact scenarios—helping employees quickly recognize when the agent was the right “front door” for their support needs.

A photo of Dubuisson.

“Adoption is not about pushing a tool, it’s about helping people recognize, in their own context, when it truly makes their day easier. By focusing on relevant scenarios, simple communication, and hands-on experiences, we made the Employee Self-Service Agent useful from the start.”

Edith Dubuisson, senior business program manager, Employee Experience in Europe North, Microsoft Digital

To avoid overwhelming users, we prioritized simple, focused communication formats. For example, an Advent calendar campaign combined the agent with Copilot capabilities, enabling employees to discover one practical, actionable use case at a time.

In parallel, we hosted targeted readiness sessions to demonstrate key end-to-end scenarios and share practical tips and best practices. This ensured employees not only understood the value of the agent, but also felt confident using it from day one—creating a strong and positive first experience.

“Adoption is not about pushing a tool, it’s about helping people recognize, in their own context, when it truly makes their day easier,” says Edith Dubuisson, a senior business program manager in Microsoft Digital. “By focusing on relevant scenarios, simple communication, and hands-on experiences, we made the Employee Self-Service Agent useful from the start.”

Fine-tuning the agent

Built in Copilot Studio, the Employee Self-Service Agent works on global, regional, and area levels to make sure that users receive the content that corresponds to their geographical location and preferred language.

The Microsoft Global Support Services group manages the agent capability and improvements, driven by a strong partnership with internal engineering teams. The team triaged feedback and partnered with the product group to tag accurate policies and knowledge by country, and to tune agent behavior and guardrails for localized content. They prioritized quick fixes and high-impact content gaps.

Updating the Employee Self-Service Agent to fix content mismatches in Europe North wasn’t about tweaking the AI in isolation. Instead, we needed to overhaul the content that the agent relies on.

A photo of Finney.

“Instead of treating mismatches as failures alone, we used them as signals to improve the underlying content—revising articles, correcting categorization, and closing gaps in coverage. Over time, this combination of tightly scoped data sources, country-level tagging, and ongoing content curation turned the agent into a far more reliable assistant.”

David Finney, director, IT Service Management, Microsoft Digital

The team “grounded” the agent in a set of trusted, IT-approved sources: About 250,000 vetted knowledge base articles and 15-20 different internal SharePoint sites containing policies, guidelines, how-to articles, and related information.

Then they tackled regional nuances, one of the biggest drivers of content mismatches (when a user gets a reply based on content that doesn’t match their country or region). The team tagged content by geography (such as UK-only or Romania-only), so the agent would be fed the correct information for that geographic area.

The process of fixing mismatches also yielded insights.

David Finney, a director of IT Service Management in Microsoft Digital, frames the process as a clear lesson: AI is only as good as the content behind it, so the real work is often on the back end.

“Instead of treating mismatches as failures alone, we used them as signals to improve the underlying content—revising articles, correcting categorization, and closing gaps in coverage,” Finney says. “Over time, this combination of tightly scoped data sources, country‑level tagging, and ongoing content curation turned the agent into a far more reliable assistant.”

Impact and results

The Global Support team added a continuous feedback loop to keep the agent’s content aligned with reality. Users can flag low-quality and inaccurate answers directly through the agent interface. That data flows to a dedicated knowledge management team, creating an efficient pipeline for feedback to inform back‑end fixes and product improvements.

A photo of Jepsen.

“We’re measuring success by a reduction in tickets, but that’s based on the user having a better experience using the Employee Self-Service Agent versus calling our global help desk and talking to a person. We can only be truly successful if we are creating a better experience for our users.”

Anders Jepsen, director, Field IT Management, Microsoft Digital

Today, the Employee Self-Service Agent’s metrics are moving in the right direction.

The team is optimistic as the Global Support Services data shows agent activity steadily increasing after it officially went live last October, as shown in the following image. At the same time, usage of Legacy Bot (an existing digital support chatbot) decreased, along with support interactions via phone, email, and web.

Chart showing increased use of Employee Self-Service Agent in Europe North over the first six months of official release (October 2025 to March 2026).
Data from Global Support Services shows use of the Employee Self-Service Agent in Europe North rose to account for more than half of all support interactions after just six months, as usage of Legacy Bot (brown band) and phone, email, and web support (light blue band) decreased.

This data suggests the agent is meeting its ultimate goal: To provide users with an improved support experience, including better first‑touch answers that build employee confidence and yield faster issue resolution. This reduces escalation to human-run support channels and decreases the volume of tickets our employees have to create.

“We’re measuring success by a reduction in tickets, but that’s based on the user having a better experience using the Employee Self-Service Agent versus calling our global help desk and talking to a person,” says Anders Jepsen, a director of Field IT Management in Microsoft Digital. “We can only be truly successful if we are creating a better experience for our users.”

What’s next for self-service support

Our experience deploying the Employee Self-Service Agent in Europe North has allowed us to create a playbook for other small and midsize countries in similar situations, including dealing with multiple languages and specific regional policies.

A photo of Berghofer.

“Our long-term ambition is to reduce our human-led support tickets by 40 percent. In some areas, like Europe North, we are already taking a significant step toward that.”

Trent Berghofer, general manager, Microsoft Digital Modern Support

The agent now serves as both a self-service tool and the first contact point for employee questions. It doesn’t completely remove humans from support, because if that first point of contact doesn’t resolve the IT issue, a team of humans is available to help.

In the end, the fewer support tickets that are opened, the more time employees can have back for higher-value tasks.

“Our long-term ambition is to reduce our human-led support tickets by 40 percent,” says Trent Berghofer, a general manager in Microsoft Digital Modern Support. “In some areas, like Europe North, we are already taking a significant step toward that.”

The Employee Self-Service Agent is a great example of using the power of AI to increase employee productivity and efficiency, as they access highly curated support through the tool on demand. It fits in with our company’s overall strategic efforts to evolve into an AI-driven Frontier Firm.

“The agent brings IT, HR, and facilities together in one place,” Dubuisson says. “It’s not just a Q&A bot. It gives you information, guides you, and even holds your hand through troubleshooting. The agent tells you what to do and can even do it for you. It standardizes, simplifies, and still lets you chat with someone or get a call back when you need it.”

Key takeaways

Here are steps organizations can take today to implement an AI-powered employee support hub:

  • Evaluate your employee support systems. Assess whether employees have a single, trusted “front door” for support issues, or if your organization’s support is still fragmented across different tools.
  • Audit local policy coverage in your AI solutions. Identify where tools may be defaulting to global or geographically incorrect content–especially in regions with multiple countries or languages–to validate accuracy and boost trust.
  • Pilot localized AI support efforts in a diversified region. Engage regional HR, IT, and field adoption teams early on to make sure that AI experiences reflect real, country-specific employee needs.

The post Transforming IT support across Microsoft with the Employee Self-Service Agent appeared first on Inside Track Blog.

]]>
23517
Microsoft CISO advice: Apply engineering fundamentals to securing AI http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-apply-engineering-fundamentals-to-securing-ai/ Thu, 30 Apr 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23334 Agentic AI, like any software, is just one part of a business solution. It is not the only element that needs to be secured. Engineers need to approach securing agentic AI in the corporate IT ecosystem the same way they would consider any security problem—from end to end. Yonatan Zunger, CVP and deputy CISO for […]

The post Microsoft CISO advice: Apply engineering fundamentals to securing AI appeared first on Inside Track Blog.

]]>
Agentic AI, like any software, is just one part of a business solution. It is not the only element that needs to be secured. Engineers need to approach securing agentic AI in the corporate IT ecosystem the same way they would consider any security problem—from end to end.

Yonatan Zunger, CVP and deputy CISO for Microsoft, suggests focusing exclusively on hardening a piece of software to security threats may make it difficult to use and introduce a new risk when users get frustrated and try to bypass controls. This is why engineers need to consider not just individual components but how they work together to maintain productivity.

“Think of every system as a socio-technical system containing many parts, and all of them working together in unison have to be secured,” Zunger says.

Watch this video to see Yonatan Zunger explain why engineering fundamentals are critical to building resilient AI systems. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=YU-8lpwPtm0 )

The post Microsoft CISO advice: Apply engineering fundamentals to securing AI appeared first on Inside Track Blog.

]]>
23334
Becoming a Frontier Firm: A guide for deploying AI agents based on our experience at Microsoft http://approjects.co.za/?big=insidetrack/blog/becoming-a-frontier-firm-a-guide-for-deploying-ai-agents-based-on-our-experience-at-microsoft/ Thu, 16 Apr 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=22868 A how-to guide for governing, implementing, adopting, supporting, and measuring the impact of AI agents from Microsoft Digital, the company’s IT organization. The agentic future: Our journey to becoming a Frontier Firm at Microsoft A new way of working, a modern way to achieve more The rate of change for AI tools and technology continues […]

The post Becoming a Frontier Firm: A guide for deploying AI agents based on our experience at Microsoft appeared first on Inside Track Blog.

]]>

A how-to guide for governing, implementing, adopting, supporting, and measuring the impact of AI agents from Microsoft Digital, the company’s IT organization.

The agentic future: Our journey to becoming a Frontier Firm at Microsoft

A new way of working, a modern way to achieve more

The rate of change for AI tools and technology continues to accelerate, and new opportunities to reimagine business processes and employees’ day-to-day workflows are emerging. Agents are the driving force behind this next leap forward.

As a result of this technological shift, a new organizational blueprint is emerging. It blends machine intelligence with human judgment to create systems that are AI-operated but human-led.

We have a name for an organization that enacts this model: The Frontier Firm.

As organizations progress toward this goal, they move from foundational AI assistance through escalating levels of agentic maturity and complexity. First, humans operate with help from an AI assistant like Microsoft 365 Copilot. Then, human-agent teams work together. But the future lies in humans leading teams of agent users: AI agents that perform core labor with relative autonomy.

Pattern 1: Human with assistant—every employee has an AI assistant that helps them work better and faster.
Pattern 2: Human-agent teams—agents join teams as “digital colleagues,” taking on specific tasks at human direction.
Pattern 3: Human-led, agent-operated—humans set direction, and agents execute business processes and workflows, checking in as needed.

This has been a three-year process for us at Microsoft, and throughout our journey, we’ve had to allow adequate time for deliberate planning and careful execution. Just as importantly, we invested early in clear, consistent internal communications to help employees understand what agents are, why they matter, and how they could safely participate in building them. That shared understanding created the confidence and momentum required to scale agent creation across a global workforce.

“It’s a truly transformative time,” Brian Fielder, vice president of Microsoft Digital. “What we’ve learned from embracing the agentic future at Microsoft is only making us more eager to see organizations empower their employees to take the lead in a world where human judgment and machine intelligence work in harmony.”

Our Frontier Firm journey so far

Within Microsoft Digital, the company’s IT organization, we’re taking a leadership role in reimagining core processes and workflows. These efforts rest on four pillars of practice:

  • We envision and implement the AI-first workplace of the future.
  • We empower our employees to build their own agents that help supercharge their productivity by providing the training, resources, and inspiration they need.
  • We define guardrails and safeguard our environment so our employees can maximize the power of AI while keeping our enterprise safe and secure.
  • We’re the voice of company’s internal AI transformation, and we provide the blueprint for our customers to accelerate their own AI journeys.

To guide our steps, we’ve established a cross-disciplinary initiative we call Agents at Microsoft. We’re looking at agentic transformation from an end-to-end perspective that reaches into every aspect of building, publishing, governing, managing, and getting the most value out of agents.

Six pillars of the workstreams involved with the Agents at Microsoft initiative: Strategy and value realization, analytics, accelerators, change management, governance, and publish and lifecycle.
Our Agents at Microsoft initiative represents part of a 360-degree approach to agentic maturity. These six pillars each represent a distinct workstream, each with its own accountable team.

As we’ve incorporated agents into more and more aspects of our organization, key questions have surfaced:

  • How do we balance freedom for employees to create agents against the need to manage sprawl?
  • How do we put guardrails around agentic capabilities so they can be useful, without introducing undue risks?
  • How do we differentiate between agents of different complexity and capability, and how do we adjust our strategies around them accordingly?
  • Where can we use agents to fill enterprise functions, and who should be responsible for creating those crucial tools?
  • How can we adapt existing software development standards to AI tools?
  • How can we minimize the risk of data over-exposure through AI?

It’s possible you’re also considering where agents fit into your organization. If so, it’s likely that you’re wrestling with many of the same questions. We’re here to help.

This guide shares our experience as Customer Zero for agents at Microsoft. As you read, you’ll be able to follow our journey to defining what it means to govern agents safely, implement them effectively, guide their adoption by employees, build a foundation for support, and track their impact through effective measurement.

We’ll share some of the most important lessons we’ve learned so far, along with readiness checklists and resources that can help you advance agentic maturity at your organization. With this guide in your toolkit, you’ll have a framework for building a strategy that incorporates agents into your business goals safely, responsibly, empathetically, and impactfully.

“As we harness the transformative power of AI agents, it’s our responsibility in IT to ensure that technology not only enhances decision making but also fosters a culture of innovation and collaboration across the organization,” says Stephan Kerametlian, a business program management senior director in Microsoft Digital.

The agentic future is here. We’ve explored the path forward, and we’ve seen the exciting places it leads. This guide can help you take your first steps and start realizing those possibilities today.


Expert insights

A photo of Fielder.

“It’s a truly transformative time. What we’ve learned from embracing the agentic future at Microsoft is only making us more eager to see organizations empower their employees to take the lead in a world where human judgment and machine intelligence work in harmony.”

Brian Fielder, vice president, Microsoft Digital

A photo of Kerametlian.

“As we harness the transformative power of AI agents, it’s our responsibility in IT to ensure that technology not only enhances decision-making but also fosters a culture of innovation and collaboration across the organization.”

Stephan Kerametlian, business program management senior director, Microsoft Digital


Chapter 1: Advancing good governance to meet the agentic moment

Maintaining privacy, security, and compliance while respecting regulatory frameworks

Agents offer powerful opportunities to enhance employee productivity, but they also introduce concerns. For example, how do we keep privileged information where it belongs? And how do we keep employees from building agents that violate company policies?

In answering these questions, Microsoft Digital’s governance team focused on the value the company is trying to derive from agents.

We wanted to give employees and teams the freedom to build without risk to the business or introducing agent duplication and sprawl. We wanted to weave robust, reliable agentic experiences into enterprise workflows. We also needed to secure and protect confidential data while respecting responsible AI principles.

“Our principles haven’t changed, but they’ve evolved,” says David Johnson, a tenant and compliance architect at Microsoft Digital. “With AI, the need for proactive governance is far greater than ever before, so we’re putting structures in place that take some of the labor around managing agents off of IT.”

There are some cornerstone constructs that underpin our agent governance strategy. There’s a tenant that holds employees accountable, a reasonably clean data estate, a lifecycle for the agents users-they disappear when the employee leaves. 

We’ve developed six core principles to guide our approach to governing agents:

  1. We ensure a strong data hygiene foundation so we can trust our data estate as employees build and use agents.
  2. We empower employees to build personal agents that can access services and data sources those users can already access to help automate and accelerate their tasks.
  3. We empower teams and lines of business to build agents with known lower risk patterns to accelerate impact.
  4. We provide a smooth release path for engineering teams to develop agents designed for enterprise functions so they can access all of the services and sources they need.
  5. We accelerate innovation through agent and automation templates while maintaining an AI Center of Excellence (CoE) to help teams think through their opportunities.
  6. We reimagine employee experiences and task execution to simplify and optimize productivity.

As a result of our experience establishing strong governance for Microsoft 365 Copilot, we’d already laid a firm foundation for an agent-ready data estate. In some ways, governance is tool-agnostic, rooted in basic principles. With appropriate data labeling, data hygiene, and well-managed permissions in place alongside tools that respect labels by default, we can confidently give every employee the ability to build basic agents and trust in our governance guardrails.

A matrixed approach to agent governance

The sheer diversity of agents and their use cases means we need a multifaceted approach to governance. A matrix of different parameters applies to any agent, and each of those elements requires its own approach to policy.

In practice, agent governance structures echo our overall maturity approach. Simple, personal, lower-risk agents with built-in guardrails act as a starting point for employee experimentation and require very little oversight. As a result of our robust data hygiene foundation, if an employee has access to the grounding content, these agents are low-risk accelerators for things they can already do on their own. Meanwhile, higher-impact agents demand greater attention that echoes our security development lifecycle (SDLC) for internal apps, which include more extensive, cross-disciplinary reviews.

SharePoint, Agent Builder in Microsoft 365, Copilot Studio, and Copilot Studio + Microsoft 365 Agents Toolkit and the level of agent governance required for each.
Our matrixed model for agent governance spans low-complexity, low-risk agents as well as more advanced tools created by professional developers.

To accommodate agent-creation experiences across this spectrum, we’ve enabled several different building platforms and processes employees and teams can use to create the AI tools they need.

  1. We opened up Agent Builder in Microsoft 365 Copilot for all employees to create read-only declarative agents.
  2. We created an environment strategy and governance in Power Platform to manage personal environments featuring data connectors with lower risk but high value.
  3. We enabled a process to flow the data that teams need into production Power Platform environments featuring data connectors. These agents initially come with sharing limits until the agent receives risk approval.

This structure provides the ability to safely create agents of increasing complexity while ensuring they remain secure and contained until they get the necessary reviews for wider sharing and data exposure.

Our governance guardrails, review policies, and publishing scope varies based on the tool used to create an agent, the level of technical proficiency it requires, its grounding in knowledge sources, its capabilities, the actions it can take, the plug-ins it requires, and whether it includes a custom engine or a bring-your-own model.

The following examples illustrate two different agent scenarios:

An employee builds a knowledge-only agent using Agent Builder in Microsoft 365 Copilot.

This agent features graph connectors from a pre-approved catalog for exposing additional data, easily created using no-code tools. Its knowledge sources are limited to SharePoint and OneDrive sites accessible to the employee, along with external websites, custom instructions, and additional internal sources through graph connectors. As a result, the risk of data overexposure is limited. These agents can’t take action, they don’t rely on plug-ins, and they’re tied to our data hygiene foundation. The employee can only use the agent personally or share it through a link.

No review necessary: Our team in Microsoft Digital honors reactive take-down requests like any other self-service construct, but does not provide proactive gating.

Professional developers build an agent to manage enterprise workflows.

Agents created using pro-code tools can include custom connectors and orchestration logic to handle more complex scenarios, and their builders typically intend them to become Microsoft Teams apps or part of our agent catalog for wide organizational use. Their knowledge sources can be almost anything, from internal SharePoint sites to third-party apps, so they’ll often need to make use of APIs. For these apps, knowledgeable builders can create custom Azure OpenAI large language models (LLMs).

Reviews: These agents require reviews for security, privacy, accessibility, responsible AI, and an environment-specific maker stack review. This review stage is essential because these agents can potentially transform or write data outside their places of origin. These capabilities represent both the power of agents and the risk we need to evaluate.

As you consider your own governance structures and policies, think about where agents and the ability to create them fit your needs and risk tolerance. Then learn from the different parameters of our governance matrix to access a working model for your own agentic transformation.


Expert insights

A photo of Johnson.

“Our principles haven’t changed, but they’ve evolved. With AI, the need for proactive governance is far greater than ever before, so we’re putting structures in place that take some of the labor around managing agents off of IT.”

David Johnson, tenant and compliance architect, Microsoft Digital

A photo of Hasan.

As you consider your own governance structures and policies, think about where agents and the ability to create them fit your needs and risk tolerance. Then learn from the different parameters of our governance matrix to access a working model for your own agentic transformation.

Aisha Hasan, Power Platform and Copilot Studio product manager, Microsoft Digital


Balancing utility and manageability in our agent ecosystem

Empowering employees and teams to simply and securely create agents has been a top priority as we move toward AI maturity at Microsoft, but we also want to eliminate agent sprawl.

Aside from complicating agent management, sprawl has several user-side disadvantages. For example, if more than one team were to create an agent that points to HR information, the employee experience would suffer, because our users wouldn’t be sure which agent serves as the authoritative source of truth.

Our team in Microsoft Digital partners with other internal organizations to ensure we’re prioritizing the right agent development projects and avoiding agent sprawl. Ideally, these engagements take place before teams start building their agents so we can avoid wasted effort or duplicate work.

If a pre-existing agent fits the target scenario, we encourage a team to use that agent instead of creating a redundant solution. For employees who want to create their own agents, we recommend that they first search for an existing tool in our agent catalog to avoid duplication.

User-based lifecycles and periodic attestation are also key pieces of the puzzle. Requiring attestation helps ensure that agents cease to exist once they’re no longer useful or their owner leaves the company.

The release of Microsoft Agent 365, now in early access, represents the next step forward in agent observability and management, two key aspects of agent governance and sprawl mitigation. This control pane for agents incorporates many of Microsoft’s Digital’s learnings as we’ve bridged governance gaps through IT intervention.

  • The registry provides a complete view of agents. The enterprise agent store makes it easy to find the right agents for each role and business process within familiar workflows in Microsoft 365 Copilot and Teams.
  • Visualization provides the observability layer, including role-specific oversight, compliance and audit features, and performance measurement that can help organizations track their agents’ impact and see where they contribute value.
  • Interoperability ensures Agent 365 is open to any Microsoft-built or partner ecosystem, while also delivering work intelligence through access to data and Microsoft 365 apps.
  • Security features provide crucial confidence through visibility into security posture, detection and response capabilities, and intelligent runtime defense.

“The next step in our governance journey will be using AI to help us govern AI,” says Aisha Hasan, Power Platform and Copilot Studio product manager at Microsoft Digital. “We’re looking at ways AI can help us manage this new space, and we believe Agent 365 will be the foundation for our deterministic approach to governance.”

As you strategize to deepen AI maturity at your organization, our experience will help you operationalize many of the aspects of governance we’ve pioneered as Customer Zero for agentic AI, especially with the wide release of Agent 365. By adopting the principles we’ve illustrated in this chapter, you can accelerate your transformation and advance your maturity rapidly and securely.

Learning from our experience with agent governance

A strong data foundation is crucial

We’ve built respect for labeling and data governance policies into the tooling for AI assistants and agents, but it’s dependent on a well-governed data estate. Invest time and effort in establishing that foundation.

Decide on your comfort level with risk

Bring cross-disciplinary experts together from across your organization to determine what level of risk is acceptable for different agents and their use cases. Put guardrails in place for low-risk scenarios and establish processes for supporting more complex or sensitive use cases. Evaluate what data sources agents can extract information from. Do you have confidence that users haven’t over-shared data access?

Agents aren’t always like applications—adjust your processes accordingly

We quickly learned that reasonable processes, approvals, and workflows for internal application development didn’t scale well with agents. Consider a risk-based assessment model.

Change is constant

Plan to reassess and revise your governance structure regularly. This technology is evolving rapidly, as is the tooling surrounding it, so maintaining good governance will be an ongoing practice.

Governance is a value driver for employees

Governance isn’t just about protecting your organization. It also provides the right patterns to make sure your employees are getting value from agentic technology. Establish strong measures of value and a robust pane for management and assessment. Observability and telemetry will be foundational, so ensure you build that into your governance efforts.

Continue non-agentic workstreams

Enterprise technology environments are additive and incremental. Don’t cease your efforts to create and govern other internal technologies. Instead, maintain a holistic ecosystem.

Key takeaways

Use these tips based on what we learned here at Microsoft to tackle agent governance at your company:

  • Establish a cross-disciplinary agent center of excellence: Bring together stakeholders across the organization to define priorities, goals, and shared practices for agent adoption.
  • Put strong data and information protection policies in place: Establish clear governance for your data estate, including labeling and information protection, to support responsible agent use.
  • Right-size oversight based on risk: Determine your organization’s risk tolerance and define which agents require more or less involvement from IT, security, and compliance teams.
  • Define a clear agent building tool strategy: Decide which tools employees and teams can use to create agents, balancing empowerment with governance.
  • Operationalize agent oversight and management: Establish an oversight model and implement tools like Agent 365 that help manage agents at scale.
  • Create a centralized governance and information hub: Provide employees and agent builders with a single place to find guidance, standards, and governance information.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 2: The Microsoft roadmap for implementing agents

Developing a plan to advance AI maturity while unlocking agentic value at every level of our organization

Implementing agents across your organization is intertwined with your larger AI transformation efforts. At Microsoft, we’ve adopted an escalating maturity model that unfolds across five stages.

Graphic showing the five stages of the Microsoft AI maturity model: awareness and foundation, active pilots and skill building, operationalize and govern, enterprise-wide adoption, and transformation with agentic AI.
AI maturity starts with simple awareness and foundational usage, then progresses to more complex patterns of interaction between humans and agents.

Putting the Microsoft AI maturity model into practice

Whatever stage you’re at in your AI journey, you’ll likely experience many of the same challenges and opportunities we do at Microsoft.

Stage 1: Awareness and foundation

Building a foundation means setting a bold vision for your AI journey, anchored in clear business outcomes. At this stage, it’s important to engage your executive sponsors early to foster cross-functional collaboration and empower experimentation.

At Microsoft, we established our AI Center of Excellence (CoE) to help guide and drive adoption of Microsoft 365 Copilot, as well as a Data Council that powers our AI-ready data strategy. As we’ve moved into the agentic future, these teams have been instrumental in maintaining forward momentum.

The company also established the Office of Responsible AI (ORA) to advance AI development, deployment, and secure and trustworthy innovation through governance, legal expertise, internal practice, public policy, and guidance on sensitive uses and emerging technology. ORA partners closely with product and engineering teams alongside other trust domains like privacy, digital safety, security, and accessibility to align our work with Microsoft’s six responsible AI principles:

  • Fairness
  • Reliability and safety
  • Privacy and security
  • Transparency
  • Accountability
  • Inclusiveness

Target outcomes include

A foundational strategy, governance principles, and leadership buy-in to kickstart AI projects.

Stage 2: Active pilot programs and skill building

We started by launching targeted pilot projects across different areas of the company. This process encouraged experimentation and used hackathons to surface a broad range of ideas. From there, we selected the most promising initiatives by evaluating business value against implementation effort and focused resources on a select group of high-impact projects.

To establish early-stage governance, we required all pilots to undergo responsible AI and architectural reviews.

Target outcomes include

The first tangible benefits of AI, including efficiency gains, time and cost savings, quality improvements, and an emerging internal talent pool that paves the way to scale successful solutions.

Stage 3: Operationalize and govern

At this point, we worked to scale and integrate AI solutions across the company. We strengthened our data and AI infrastructure to support this transition by formalizing enterprise governance with clearly defined steering teams. Our AI CoE, Data Council, and Office of Responsible AI helped accelerate implementation, ensure the ongoing quality of structured data, and oversee ethical AI use and compliance. Collaboration among these groups was crucial for ensuring our AI initiatives remained within acceptable bounds while delivering tangible business impacts.

Target outcomes include

Multiple AI use cases running at enterprise scale under robust oversight, with cross-functional alignment on AI objectives and the business value they’re delivering.

Stage 4: Enterprise-wide adoption

To consolidate our gains and achieve AI adoption across the enterprise, we prioritized making AI a core consideration in every new project and process by asking where AI-driven intelligence could deliver real impact. That could be by boosting efficiency, enhancing user experiences, or unlocking new business value. From there, we aligned our AI initiatives with our organization’s strategic goals by empowering business leads to synchronize efforts and continuously update our AI roadmap.

We also cultivated a data-driven culture through ongoing, large-scale training while making AI tools a natural part of everyday work. To accomplish that, we established rigorous impact tracking with clear measurement of the amount of value delivered. Key metrics include time savings, cost reduction, and quality improvements. We reviewed these outcomes regularly at the leadership level to maintain accountability.

Our Continuous Improvement CoE has been instrumental in the process of aligning AI initiatives with our organizational goals and providing a framework for progress. It operates according to four principles:

  1. A clear definition of winning, based on expectations
  2. Disciplined execution
  3. Constrained problem-solving with urgency
  4. Sustained replication and acceleration

Target outcomes include

Measurable, data-driven monitoring of AI for your business that’s powered by a continuous improvement mindset.

Stage 5: Transforming your business with agentic AI

At stage five, we’ve been working to embed AI into every aspect of our operations and culture. We started by leveraging the expertise of our AI CoE to foster innovation, drive continuous improvement, and keep our AI initiatives evolving using structured mechanisms like a Kaizen funnel to crowdsource, prioritize, and advance ideas that extend the impact of AI across the enterprise.

We also further strengthened governance to address the advanced challenges of agentic applications, including responsible scaling of generative AI and effective mitigation of AI hallucinations. Finally, we focused on refining human-AI collaboration so our teams can offload routine tasks to AI agents and concentrate on higher-value work.

One tactic that’s been highly successful here at Microsoft Digital is conducting “Fix, Hack, Learn” weeks, where we encourage employees to identify opportunities for improving our services. So far, these initiatives have yielded multiple AI-powered breakthroughs that are already in production.

Target outcomes include

Significant efficiency gains and innovations from AI, including recognition as a leader in enterprise AI adoption.

As you advance along the AI maturity curve at your organization, keep these essential ingredients in mind:

  1. Executive sponsorship and governance
  2. Responsible AI by design
  3. Data foundations, architecture reviews, and technical readiness
  4. Talent, skills, and culture
  5. Impact tracking and accountability
  6. Change management and communication
  7. Continuous improvement, innovation, and partnerships

It’s important to remember that these elements aren’t static, but iterative. You’ll need to continue to evolve them over time as your enterprise AI transformation continues. But the five stages of enterprise AI maturity we’ve outlined in this chapter form an overarching framework to keep you moving forward.

Learning from our agent implementation experience

Invest in data infrastructure and AI platforms

Building robust data infrastructure ensures your organization is prepared to leverage AI, supporting scalable, innovative, and secure AI-driven solutions.

Foster a culture of innovation and collaboration

Champion an AI-forward culture where innovation and collaboration drive the adoption of agentic AI.

Align AI initiatives with strategic business goals

Ensuring AI initiatives align with business goals maximizes impact and positions your organization to succeed in the rapidly evolving world of agentic AI.

Implement ethical practices based on our responsible AI principles

Adopting ethical AI practices builds trust, ensures responsible innovation, and prepares your organization to navigate the evolving landscape as AI becomes central to business operations and decision-making.

Position IT to facilitate the transition to a Frontier Firm

At a minimum, your IT leaders and practitioners need to prepare your data estate for agentic workloads, partner to identify and enable prioritized business scenarios, and then actively participate in enterprise transformation through skilling, change management, and measurement activities.

Evolve your enterprise IT infrastructure to embrace dynamic and adaptive agent-based systems

Moving from traditional deterministic systems to agentic systems that introduce probabilistic behaviors, autonomous decision-making, and continuous learning requires new architectural thinking, audit capabilities, and governance models.

Key takeaways

Here are some key tips for implementing agents at your organization, based on what we’ve learned through our own experience here at Microsoft:

  • Align agent efforts with business priorities: Partner with leadership to establish clear business priorities that guide agent adoption and investment.
  • Define success and how you’ll measure it: Determine business goals and metrics of success that allow you to track impact and value over time.
  • Put the right governance structures in place: Establish steering committees across implementation, data, responsible AI, and continuous improvement to guide decision-making.
  • Start with early adopters and focused pilots: Identify enthusiastic users and promising pilot programs to validate value and refine your approach.
  • Scale what works across the enterprise: Determine which initiatives deliver the greatest value and are ready for broader, enterprise-wide adoption.
  • Support change through targeted skilling and enablement: Develop skilling and change management strategies that address the needs of both technical and nontechnical employees.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 3: Driving adoption to capture value across the organization

Readying our workforce for the agentic future through targeted enablement, skilling, and cross-company collaboration

Change management is an important part of our AI maturity journey. All the technical readiness in the world means nothing if we don’t build a transformative culture. The spectrum of agents, use cases, and creation methods is wide, but enabling them all requires one thing: an AI-first mindset.

“An important part of agentic adoption is telling stories to help people understand where AI’s value comes alive or why they should build agents. Examples from peers and real-world use cases are two of our most effective methods for getting people into the AI-first mindset.”

Driving adoption for agents represents a fundamental shift from an AI assistant like Microsoft 365 Copilot, which delivers a comparable experience for every employee. With the agentic mindset, the point is for individuals to be selective about the agents they choose to use—and more significantly, the agents they choose to create.

We also structure our enablement efforts to channel employees into different behaviors based on what’s available and what they might need to build:

  • First, we enable employees to discover and use agents that are already published and available.
  • If an agent that serves their use case doesn’t exist, employees can build their own, starting with simple no-code agents.
  • For complex agents, we channel employees, teams, and lines of business into using Copilot Studio and other, more full-featured pro-code tools.

Regardless of the behavior we’re trying to enable, we follow a four-phase strategy that takes inspiration from Prosci’s ADKAR model, which progresses through awareness, desire, knowledge, ability, and reinforcement. Our adoption efforts align with the Microsoft Engagement Framework, which we’ve developed specially for driving adoption of our products. You can learn more about our overarching approach in our Microsoft 365 Copilot readiness guide.

“An important part of agentic adoption is telling stories to help people understand where AI’s value comes alive or why they should build agents,” says Amy Rosenkranz, a principal product manager on the Copilot Extensibility team within Microsoft Digital. “Examples from peers and real-world use cases are two of our most effective methods for getting people into the AI-first mindset.”

We’re applying several tried-and-tested change management techniques to our organization-wide adoption efforts. These are relevant to both non-developer employees who want to create simple agents and professional developers working on tools for their teams, lines of business, and the entire enterprise.

Cohort-based coordination

We divide our adoption campaigns along two pivots: Internal organizations like legal or sales and marketing, and regions like North America or Europe. Different cohorts have different focuses, but the strategy is similar. Our company-wide adoption leads spearhead our efforts, and we identify members of target cohorts who can support the adoption, including change managers, leadership sponsors, and employee champions.

Adoption communications

We treat internal communications as a primary driver of agent adoption and creation, not just a distribution channel for training. Our initial communications focused on building confidence, reducing fear, and reinforcing clear norms for responsible agent building. We used consistent messaging across leadership communications, learning content, and employee channels to normalize experimentation and help employees understand when to create an agent, when to reuse one, and where to go for guidance.

AI Agent Launchpad

During our deployment of Microsoft 365 Copilot, we experimented with event-driven skilling in the form of Camp Copilot and Copilot Expo. Now, we’ve adapted these kinds of skilling events to agents as well. AI Agent Launchpad takes employees on a learning path through five modules to help them discover, use, and build agents confidently:

  1. AI mindset in motion: Employees learn about the concept of the Frontier Firm.
  2. Introduction to agents: This module covers the basic principles and definitions of AI agents to establish a foundation of understanding for agent creation and usage.
  3. Explore existing agents: Participants build the new habit of discovering available agents to see if any existing tools meet their needs.
  4. Build agents with ease: Employees polish their agent building skills in Copilot Chat and SharePoint with an expert in a hands-on lab environment.
  5. Build with Copilot Studio: This module goes deeper into designing, connecting, testing, and publishing more powerful agents.

Each module features self-learning readiness, live sessions, gamification, and Credly badges. Instead of a global, centralized event, we’ve modularized the experience so local or organization-level leaders can adapt it to their particular cohort’s needs, while still providing support from centralized adoption leads. We’ve also created a freely available resource organizations can use to plan and run their own virtual skilling events around AI adoption.

Copilot builder champs

Our initial AI rollout showed us first-hand the power of peer leadership in driving adoption, so we adapted the strategy behind our highly successful Copilot Champs Community into our Copilot builder champs program. This initiative makes use of peer connections, success stories, and a Viva Engage community, and we refocused it on enabling employees to create the agentic solutions they need.

These champions represent some of our strongest adoption evangelists on their respective teams. We also created a Microsoft SharePoint hub with resources, best practices, agent publishing information, and more.

Integration and incentivization

We collaborate with managers to integrate AI into their teams’ routines. Often, we’ll use mini-challenges or gamification strategies to encourage agent usage. We recognize top contributors with shout-outs or small awards. We’ve also found that it makes these efforts more engaging to blend work tasks with personal interests.

Formalizing change management for professional developers

We apply more focused adoption initiatives for the professional developers who create team, line-of-business, and enterprise agents. Because their efforts are reimagining how work gets done across the organization, we need to ensure these agents are aligned with business goals, built securely and responsibly, and drive the impact the company needs. The process unfolds across five steps.

1. Driving product adoption

This step echoes our broader adoption initiatives. We cultivate leadership alignment and sponsorship, comprehensive communication plans, training and upskilling programs, champion-led peer support, and integration into daily work with incentives.

2. Agent ideation and development

Here, we capture high-value use cases by mapping out processes and pain points we could improve with agents. Then we prioritize and select pilots and empower small interdisciplinary teams to build, test, and refine those agents.

3. Agent discovery and advocacy

Once we’ve completed our pilot programs, we identify the agents with the most potential impact, broaden their development, establish a catalog for observability and discoverability, and showcase success stories.

4. Workforce transformation

At this point, we’re ready to map workflows for human-AI optimization, capture scenarios that are especially useful for key roles, commit to wider AI skills training, develop our workforce into “agent bosses,” and work to measure and communicate impact.

5. Feedback and listening

Tracking the impact of your efforts is crucial. We established a feedback loop to drive further success through telemetry and analytics, employee feedback, and insights from our support channels and FAQs. Then we analyze and triage those insights and close the loop with users by communicating how their feedback drives change.

Whatever your goals and whichever segment of your workforce you target, it’s important to understand that adoption doesn’t happen by accident. True workforce transformation won’t take place without appropriate adoption activities.

As you launch your own adoption initiatives, consider who your audience is, what they need to build confidence and competence, and how you can unlock agentic value for them across your organization.

Learning from our agent adoption experience

Be thoughtful about your audience

Vary your efforts between non-developer and developer audiences, different geographies and internal organizations, and specific goals. Put together a methodology for thinking about what agents you want and what benefits they’ll provide, then determine who the best builder is.

Don’t just enable agents—empower the enterprise

Your goal isn’t just to activate agents for agents’ sake. Think carefully about what workflows and value you’re trying to unlock, and how agents can get you there. Break down aspects of roles and workflows, and see how agents fit in.

Establish multiple vectors for skilling

Different modalities work for different employees. Use every tool at your disposal, from live events to peer leadership to self-guided learning, and communicate them across all available channels.

In many ways, this is a reset

Your employees may have just become comfortable with Copilot, and agents might feel like a whole new horizon. That’s true. Have patience and understand that this is an entirely separate adoption path.

Showcase and celebrate success

People need to see value and possibilities for agents in their own work. When pilots or personal agents create results, socialize them widely and encourage employees to try them out. Nothing encourages experimentation with agents like successful usage.

Leadership sponsorship is absolutely crucial

Leaders both set expectations and bear the standard of your organization’s culture. They can be the figureheads of transformation by setting priorities, participating in communications, and leading by example.

Key takeaways

Here are some important steps to keep in mind as you embark on your own adoption and change management efforts for agents:

  • Establish strong adoption leadership early: Assign a dedicated adoption lead, form a cross-functional adoption team, and align change managers, executive sponsors, and employee champions around clear ownership and cadence.
  • Design adoption around real work and real people: Identify priority cohorts, personas, and usage scenarios, then tailor messaging, enablement, and communications to how each group works and learns.
  • Define success before you deploy: Set clear KPIs and success criteria likefeature usage, scenario adoption, and employee sentiment, and put a measurement and feedback plan in place from day one.
  • Enable employees through structured onboarding and learning: Combine readiness communications, live learning, self-service resources, and a centralized enablement asset library to help employees build confidence and momentum.
  • Activate champions and leadership to amplify adoption: Launch champion communities, empower leaders to model usage, and use internal channels to reinforce behaviors and share progress.
  • Continuously listen, learn, and iterate: Gather feedback through surveys and listening sessions, surface success stories, and apply insights to refine adoption, reinforcement, and resistance management plans.
  • Extend and optimize for professional developer teams: Support advanced agent ideation, development, discovery, and advocacy while using ongoing feedback to drive workforce transformation at scale.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 4: Providing support at the agentic frontier

Bolstering agentic transformation through solid groundwork, human oversight, and AI-driven support

With many forms of technology, support is fairly simple. You identify pain points and common issues with a relatively static technology, create self-service tools to help users with those challenges, and make subject matter experts available in the form of a dedicated support team.

But AI is evolving too quickly for that model, and agents are too diverse and individualized for a static approach. As a result, our support apparatus for agents needs to be much more flexible. Within Microsoft Digital, our goal is to make it easy for employees to engage with agentic tools freely and adaptably while maintaining safety and responsibility.

The path to this objective relies on a three-pronged approach to governance:

  • Embedded governance functionality: The ideal state is that our agent creation and publishing tools should incorporate good guidance, governance, and guardrails out of the box so the agents people create are essentially self-governing.
  • IT oversight: This is a new space and a new way of working, so it isn’t feasible for all agents to self-govern at this point. As an IT organization, Microsoft Digital fills gaps in governance through reviews and oversight. We do this by establishing risk-based policies around types of agents, exposure and sharing, and other pivots we addressed in our governance chapter.
  • User education: It’s almost impossible to predict every governance gap and need, so educating our users helps them avoid accidentally stepping out of bounds. Our Agents at Microsoft team and change managers are the linchpins of these efforts, and employees can lean on resources like Microsoft Learn courses and the Agent Builders SharePoint hub.

Of course, we do have a support team of AI subject matter experts available to employees for any questions they can’t answer themselves. Our HelpDesk support team operates independently from other enablement vehicles, but human support representatives can only accomplish so much. It’s important not to create bottlenecks by relying on conventional support. After all, the promise of AI is to reduce the burden on humans, and that’s no different for our support teams.

A photo of Sydorchuk.

“On our journey to Frontier Firm, we’re working really hard to accelerate processes and remove roadblocks so people can get to value much faster. This is crucial for agentic scenarios because we’re using these iterations to polish and improve the tools we create.”

AI itself is becoming a cornerstone solution for this challenge. An AI-driven approach aligns with the idea of the Frontier Firm, where humans lead and agents operate, in this case by supporting other humans as they explore AI more deeply.

This is a relatively new approach, but we’re already using agents to provide support in several ways:

  • We operate an agent called Ask MICA (Microsoft Intelligent Compliance Agent). This tool provides information and support for compliance issues.
  • Agents help us evaluate the risk profiles of other agents. Automating risk assessment accelerates publishing by minimizing human reviews or questions to support specialists.
  • We use an agent to perform checks against standards for responsible AI, security, privacy, and access to sensitive information.
  • We’re also partnering with our product groups to develop automated agent-building enablers and accelerators that can support ideation and evaluation for new ideas instead of relying on groups like the AI CoE to step in for that kind of support.

In reimagining the support experience this way, we’re focused on maximizing efficiency so that humans remain in the loop, but only for edge cases where AI can’t help. That’s the best use of their time and unique human talent. Meanwhile, we’re continuing to develop and implement agents to support employees for increasing numbers of non-edge cases.

Continuous improvement practices help propel this work forward. Much of that work comes from targeted conversations around pain points. For example, an agent builder might share that it’s taking too long to get security reviews for their projects. To us, that signifies that a security review agent may be useful.

“On our journey to Frontier Firm, we’re working really hard to accelerate processes and remove roadblocks so people can get to value much faster,” says Mykhailo Sydorchuk, a Customer Zero lead for Microsoft 365 integrated experiences at Microsoft Digital. “This is crucial for agentic scenarios because we’re using these iterations to polish and improve the tools we create.”

It’s important to remember that humans will always need to be involved in supporting other humans. But the more assistance agents can provide your support specialists, the more they can focus on tasks that absolutely require human attention. As you consider where AI might fit into your support efforts, our journey can shed some light on the possibilities agents represent.

Learning from our experience with providing support around agents

Emphasize proven agents to minimize the need for support

If you’ve built dedicated first-party agents within your organization, encourage employees to favor those through internal communications. They’re less likely to require support in the first place.

Identify opportunities for AI-driven support

Listen to employees’ pain points and concerns. Recurring themes and issues probably mean there’s an opportunity for agentic support.

Meld adoption and support

Education and skilling initiatives build employee competency to minimize their need for support. If people understand standard use cases thoroughly or know where they can find the right information, they’re more likely to reach out to support specialists only on real edge cases.

Backstop support as much as possible

Microsoft is working to make our tools as self-service as possible. Where gaps appear for your organization’s specific use cases, fill those with IT backstops and employee enablement resources. Hopefully, your support team can be your final resort.

Key takeaways

Here are some key things to remember as you develop your support plan for agents at your company:

  • Build agent expertise within support teams early: Provide targeted training, skilling, and early access so support teams can become trusted agent subject matter experts.
  • Reduce support demand through proactive enablement: Identify IT backstops and employee enablement opportunities that prevent common issues before they require support intervention.
  • Operationalize agentic support at scale: Identify recurring issues across non-developers and professional developers, select high-value opportunities for agentic support, build and test support agents, and actively promote them to drive adoption.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 5: Tracking the impact of your agents

Building the apparatus for effective measurement to ensure our agentic ecosystem drives business value

Effective governance, implementation, adoption, and support don’t mean anything if your agents aren’t driving the impact your organization wants. But how do you understand that impact if you can’t track and measure it? And what should your measurement criteria be?

Within Microsoft Digital and the company’s leadership team, we’re currently thinking through these ideas to ensure we’re capturing all the value agents have to offer. We’re still developing our approach, but the questions we’ve asked and our measurement parameters will be helpful to consider as you track your own agents’ impact.

First, there’s a difference between tracking agent volume, agent usage, and agent value. Employees creating massive numbers of agents that never get used don’t drive impact. Agent usage is closer to the mark, and it can be a good indicator of which tools are meaningful to employees or might deserve potential promotion for use throughout your organization. Still, usage doesn’t necessarily correlate to business value.

To really articulate value, you need to dive into the specifics of what you intend your agents to do. There are several dimensions to consider:

  • Types of agents: First-party enterprise agents, third-party agents, line-of-business or team-based tools and individually created agents all have different purposes and capabilities. They need different measurement strategies.
  • Personas: Who is creating the agent, and what are their maturity and needs? What value does a user get compared with a developer or administrator? There’s also team versus individual value. For teams, we tend to measure impact in terms of workflows automated or pain points relieved. For individual users, it’s all about satisfaction, productivity, quality, and efficiency gains.
  • Data: Different agents access varying degrees of data. How do you assess the ways they provide access and deliver insights?
  • Creation versus discovery and usage: We want to encourage both agent creation when it meets a unique need and agent discovery when a useful agent already exists. Each requires its own measurement parameters.

Our roadmap to agentic impact tracking

We aren’t starting from scratch when it comes to tracking agentic impact. Our Continuous Improvement CoE has already done extensive work aligning targeted and sanctioned AI initiatives with greater business value and tracking them over time. The concept is based on defining top-level value, cascading that value into operational drivers that deliver results, creating action plans and delivering AI solutions to achieve those goals, and then tracking them over time.

We’re currently progressing along a roadmap to a more holistic impact tracking methodology we can use to identify, consolidate, and build agent analytics for all makers, developers, administrators, and Microsoft Digital teams. As time goes on, this approach will accelerate product improvements, improve the builder experience, and cater to reporting and analysis requirements.

Our journey has three main goals:

  1. Authoritative, clean, deduplicated data
  2. A baseline for creation and usage, and well-defined key performance indicator (KPI) targets
  3. Advanced insights to accelerate the agentic ecosystem at Microsoft

In service of these goals, we’re progressing through a five-phase process:

Our five steps for setting up our agent analytics: Set requirements, partner with product teams, establish methodologies, set KPIs, and report and analyze findings.
We’re currently in phases three and four of our five-phase plan for holistic agentic analytics methodology.

As this methodological structure for tracking agentic impact has come together, we’ve used various tools to help us gain visibility. These include Viva Insights, Microsoft 365 admin center, and an internally built declarative agent tracker, with visibility typically provided by Microsoft Power BI. With the release of Microsoft Agent 365, now available through the Frontier program, we’ve gained a more streamlined vehicle for observability and telemetry.

Three feature sets will be especially useful for tracking value:

  • Registry provides a complete view of agents to give us maximum visibility and trackability across our entire agentic ecosystem.
  • Visualization includes measurement features to track agent performance, speed, and quality so we can assess ROI and make informed deployment decisions.
  • Interoperability ensures we can connect to an open ecosystem of both Microsoft and partner tools.

As Customer Zero for Agent 365, we’re excited to have a platform for observability and telemetry that encompasses everything from agentic creation through usage.

We plan to use the following capabilities to improve the overall ecosystem:

  • Filtering our agent inventory on specific criteria like the type of agent or how it was built
  • Enhancing governance-specific actions we can take with agents in areas like ownership and quarantining
  • Gaining visibility into trends like agent usage
  • Ingesting agent blueprints and defining policy templates

We’re still in the midst of our agentic measurement journey at Microsoft, but the blueprint for tracking already exists. Your organization may be in the early stages of agent readiness and deployment. If that’s the case, it will be helpful for you to internalize the lessons we’ve learned as Customer Zero and apply them as early as possible in your own journey to AI maturity.

Learning from our approach to tracking agentic impact

Think proactively, not retroactively

If you put effort into tracking agentic impact early in your AI maturity journey, you’ll be poised to start capturing insights immediately instead of applying your methodology after the fact.

Involve a wide array of stakeholders

This workstream needs oversight from different kinds of stakeholders, including your leadership team, IT, Microsoft 365 administrators, agent developers and builds, and employee champions. That will provide the sponsorship, expertise, and perspective you need for success.

Establish a continuum of value

Agents need to tie into real business goals, so it’s important to establish metrics that actually speak to those objectives. Cascade business goals to concrete KPIs with well-defined timelines and track those diligently.

Embrace the red

Try to think of underperformance not as failure, but as data. Performance data over time helps you course correct or pivot, making sure you invest where it matters.

Key takeaways

Here are some tips as you develop a strategy for measuring the impact of agents at your organization:

  • Assemble a cross-functional analytics and adoption team: Bring leadership, IT, Microsoft 365 administrators, agent builders, and employee champions together to ensure shared ownership and accountability.
  • Clarify analytics and insight requirements up front: Identify, source, and clearly articulate the data and insights needed to measure agent adoption and impact.
  • Build an analytics foundation and iterate over time: Consolidate data sources, establish baselines, and develop initial analytics that can evolve as usage grows.
  • Define and standardize agent KPIs: Finalize a clear, consistent set of metrics aligned to business outcomes and adoption goals.
  • Turn insights into action through reporting: Apply analytics and reporting to inform decisions, optimize adoption efforts, and drive continuous improvement.

Learn more

How we did it at Microsoft

Further guidance for you

Applying lessons from our agent deployment at your organization

You’ve learned from our AI maturity journey. It’s time to get started on yours.

Becoming a Frontier Firm might seem daunting. But the agent-building and agent-adoption practices we’ve articulated in this guide can help you gradually and thoughtfully progress toward a new organizational blueprint, one that blends machine intelligence with human judgment. It can help you build systems that are AI-operated but human-led.

By capitalizing on the lessons we’ve learned during our internal deployment, you can both speed up the process of building and deploying agents at your company while avoiding frustrating pitfalls. If you anchor your work in careful planning and use the steps and resources we’ve provided here, you’ll be on the path toward true business transformation through agentic workflows.

A photo of Alaparthi.

“Embracing AI transformation is an opportunity for IT leaders to take part in defining the future of their organizations. Our role as technical professionals has never been more revolutionary, and our team can support yours as you reimagine workflows to make AI part of your everyday reality.”

You’re not in this alone. If you’re looking for support or knowledge on any aspect of your deployment, reach out to our customer success team.

“Embracing AI transformation is an opportunity for IT leaders to take part in defining the future of their organizations,” says Vijaya Alaparthi, a principal group product manager at Microsoft Digital. “Our role as technical professionals has never been more revolutionary, and our team can support yours as you reimagine workflows to make AI part of your everyday reality.”

Frontier opportunities are present across every aspect of your organization today. Partner with us and take your first steps toward this exciting agentic future.

Key takeaways

This guide captures what we’ve learned as we’ve deployed agents across our entire global organization. Here are the key things to remember as your company moves from early AI adoption to a large and thriving agentic ecosystem:

  • Advance governance early: Establish a strong and trusted data foundation that includes labeling, protections, and a risk-based governance model before enabling broad agent creation. Establishing your governance foundations for Microsoft 365 provides the confidence to open up Copilot without hiding data. Clear guardrails, differentiated oversight, and lifecycle management help ensure safe innovation without sprawl.
  • Follow a maturity roadmap: Use an escalating AI maturity model that progresses from awareness to enterprise-wide adoption and agentic transformation to sequence your rollout. This staged approach aligns AI investments with business goals while building the culture, skills, and infrastructure you need to scale.
  • Drive targeted adoption: Treat agent adoption as its own transformation journey, distinct from assistant-based tools like Microsoft 365 Copilot. Cohort-driven skilling, champion communities, localized learning, and leader-led communications accelerate confidence and empower both makers and users.
  • Empower builders at all levels: Support no-code creators and professional developers with tailored enablement, clear publishing workflows, and accessible resources. This ensures individuals can create personal agents while teams can safely build enterprise-grade tools that unlock high-value scenarios.
  • Reimagine support with AI: Blend embedded governance, flexible IT backstops, and AI-driven support agents to reduce friction and scale help resources. As employees experiment with agents, automated checks, accelerators, and intelligent support tools keep humans focused on true edge cases.
  • Track impact holistically: Distinguish between agent creation, usage, and value by establishing KPIs that map directly to real business outcomes. A unified telemetry and observability layer powered by tools like Microsoft Agent 365 enables clear measurement, optimization, and proof of return on investment.
  • Continuously evolve toward becoming a Frontier Firm: Advance your culture, architecture, governance, and workforce practices iteratively as agentic capabilities grow. By combining human judgment with autonomous agentic operations, your organization can unlock transformational efficiency, innovation, and scale.

Learn more

How we did it at Microsoft

Further guidance for you

Try it out

Get started with Microsoft Agent 365 at your company.

The post Becoming a Frontier Firm: A guide for deploying AI agents based on our experience at Microsoft appeared first on Inside Track Blog.

]]>
22868
Microsoft CISO advice: How to build trustworthy agentic AI http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-how-to-build-trustworthy-agentic-ai/ Thu, 16 Apr 2026 15:15:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23173 Building production-ready solutions with agentic AI comes with inherent risks. When agents make mistakes or hallucinate, the potential impacts can multiply rapidly. “It turns out that it’s very easy to write AI-powered software, but it’s very hard to write AI-powered software that works right in real-world cases,” says Yonatan Zunger, CVP and deputy CISO for […]

The post Microsoft CISO advice: How to build trustworthy agentic AI appeared first on Inside Track Blog.

]]>
Building production-ready solutions with agentic AI comes with inherent risks. When agents make mistakes or hallucinate, the potential impacts can multiply rapidly.

“It turns out that it’s very easy to write AI-powered software, but it’s very hard to write AI-powered software that works right in real-world cases,” says Yonatan Zunger, CVP and deputy CISO for Microsoft.

Yunger explains how important it is to test if you want to build trustworthy agentic AI.

Watch this video to see Yonatan Zunger explain how to build trustworthy agentic AI. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=eNU7c48541M)

Key takeaways

Here are best practices to apply while building trustworthy agentic AI:

  • Prototype. Test. Iterate. Think of and try prompts your real users might give your agentic AI. Use real data. From those trials, build a set of test cases and keep testing.
  • Use AI tools to amplify testing. Evaluating agents requires a “try it and repeat it” mindset. Using AI Foundry with such tools as Python Risk Identification Tool amplifies these assessment capabilities.
  • Record your tests. Applying this practice, as you would with unit testing, enables you to repeat evaluations as your data models and agents evolve.
  • Don’t skimp on testing. Test early, test often, test with real data. This is the best way to understand what your agent might do when it encounters the unexpected.

The post Microsoft CISO advice: How to build trustworthy agentic AI appeared first on Inside Track Blog.

]]>
23173