AI deployment and adoption Archives - Inside Track Blog http://approjects.co.za/?big=insidetrack/blog/tag/ai-deployment-and-adoption/ How Microsoft does IT Thu, 23 Jul 2026 16:01:07 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 137088546 Streamlining business operations at Microsoft with an AI toolkit http://approjects.co.za/?big=insidetrack/blog/streamlining-business-operations-at-microsoft-with-an-ai-toolkit/ Thu, 23 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24720 At Microsoft, we manage one of the world’s largest global corporate operations. Our operations teams process hundreds of billions in revenue and millions of transactions while adapting to fast-changing business demands. Much of that work flows through Business Process Outsourcing (BPO) operations, where vendors support workflows such as order and agreement processing. As these processes […]

The post Streamlining business operations at Microsoft with an AI toolkit appeared first on Inside Track Blog.

]]>
At Microsoft, we manage one of the world’s largest global corporate operations. Our operations teams process hundreds of billions in revenue and millions of transactions while adapting to fast-changing business demands. Much of that work flows through Business Process Outsourcing (BPO) operations, where vendors support workflows such as order and agreement processing.

As these processes grew in scale and complexity, it became clear that improving something highly manual and already operating at massive scale would require a fundamentally different approach.

“With BPO, we’re dealing with high-volume, high-touch processes that are core to how the business runs,” says Jonathan d’Orgee, an AI transformation lead for Microsoft Business Operations.

For many organizations, the idea of overhauling a core business process can feel like a daunting step. At Microsoft we act as our own first customer, which gives us a way to test, refine, and de-risk that transformation in our own operations before bringing those proven patterns to customers. We call this approach Customer Zero.

In this case, that meant rethinking how high-volume operations could run better with AI directly embedded into day-to-day tasks, including building solutions using tools like Microsoft Dynamics 365 and Azure AI.

A photo of d'Orgee.

“We looked at manual steps, broken workflows, and disconnected systems as opportunities for AI transformation.”

Jonathan d’Orgee, AI transformation lead, Microsoft Business Operations

Identifying manual inefficiencies

On top of the complexity of handling so many transactions across the globe, Business Operations sometimes experienced periodic surges that could exacerbate inefficiencies. During these surges, the team would see a high volume of complex, time-critical transactions— especially at the end of the month or the quarter—and manual processes were too slow to keep up.

As we reviewed these inefficiencies, we looked for the most impactful use cases—places where we could integrate AI into workflows. To do this, we asked two important questions:

  • What types of transactions have the highest volume?
  • What parts of the process take the longest time or consume the most resources?

It was a classic case of the 80/20 rule—finding the 20% of the processes that required 80% of the work.

“We looked at manual steps, broken workflows, and disconnected systems as opportunities for AI transformation,” d’Orgee says.

An example might be where we receive an email asking to have a contract updated. In the former process, the email might sit there until a human could review it manually. Then someone would review it, direct it to the right queue, and assign it to the right person.  

“With AI in the workflow, emails and attachments are analyzed right when they arrive, and immediately assigned to the right queue and person,” d’Orgee says.

Taking these kinds of steps dramatically increased efficiency and reduced costs overall.

A photo of Venkata.

“With deep knowledge of our Business Operations ecosystem, we targeted high-volume, repeatable workflows across globally distributed operations. These were processes where AI could break traditional location and labor constraints, unlocking scalable automation and measurable business impact.”

Shashidhar Lanka Venkata, partner group engineering manager, Business Commerce Platforms

Configuring an AI toolkit

Once we’d identified the areas that were ripe for transformation, we set about developing an AI-driven solution on top of our existing critical workflow systems.

“With deep knowledge of our Business Operations ecosystem, we targeted high-volume, repeatable workflows across globally distributed operations,” says Shashidhar Lanka Venkata, a partner group engineering manager in the Business Commerce Platforms team. “These were processes where AI could break traditional location and labor constraints, unlocking scalable automation and measurable business impact.”

The BPO AI Toolkit is our AI operating system for business process operations. Its job is to help us with decision making. Built on Microsoft Dynamics 365 and Azure AI, it brings process mining, Microsoft 365 Copilot, Windows 365, and the Azure Marketplace together into AI-native workflows that can be reused by different vendors.

The toolkit is built on a handful of capabilities that work together:

Agentic memory turns tribal knowledge into structured operational intelligence that agents can access on demand.

Prebuilt agents provide enterprise-ready capabilities that teams can reuse instead of rebuilding workflows.

An agentic UI reduces context-switching time, helping operators focus on decisions and exceptions.

Digital Twins measures real end-to-end process performance and continuous improvement.

Agent Desktop provides secure access anywhere.

“It’s just part and parcel of working with AI, which is much different than working with more traditional ways of automating,” says d’Orgee.

He explains that because the AI is configurable, our teams are able to move faster. “The lead time is a lot shorter, and we’re able to make changes a lot more quickly.”

At the core of everything during this effort was the drive to constantly assess “the human buy-in:” How are people using this technology in a way that solves real problems at a global scale?

Keeping humans in the loop and measuring AI transformation

Integrating AI into existing workflows and processes isn’t just about the technology—it also should entail a cultural shift within an organization.

We wanted to ensure that our operations team was adopting the AI tools in the right way. That meant understanding which processes must still be human-led, such as areas where the handling of exceptions requires more discernment.

Rather than removing humans from the process, the team redefined the human role. AI now handles tasks such as data validation, case creation, and compliance checks, while our team members focus on judgment, exceptions, and continuous improvement.

“It’s really exciting for us, because operations has always been about trying to be efficient. With AI, it’s allowed for breakthroughs that we haven’t been able to achieve before.”

Jonathan d’Orgee, AI transformation lead, Microsoft Business Operations

That balance helped the team scale automation without losing the oversight and expertise needed to maintain quality.

The impact of this Frontier model has been significant. So far, we’ve been able to transform roughly a quarter of our BPO processes with AI. This has led to an 80% improvement in process quality and a 33% reduction in cost per transaction, d’Orgee says.  

More than 75% of the cases our teams work on are processed utilizing the AI toolkit. These gains are measured with Digital Twins, a process-mining model that monitors each workflow live, allowing teams to continuously track and improve. Building on this momentum, the team has plans to transform 80% of the BPO process with AI by fiscal year 2028.

A pie chart showing that more than 75% of our business-process cases are now assisted by an AI agent.

D’Orgee urges organizations that want to apply our Customer Zero learnings to their own workflows to look for high-volume, high-effort, highly manual work. This will lead you to the best opportunities for automating your processes at scale and deliver the most benefit.

From finance to sales operations, teams across Microsoft have turned to the BPO AI toolkit to prove how reusable AI capabilities can drive enterprise-wide transformation.

“It’s really exciting for us, because operations has always been about trying to be efficient,” d’Orgee says. “With AI, it’s allowed for breakthroughs that we haven’t been able to achieve before. I’ve just been thrilled to come to work on that front.”

Key takeaways

You can use these lessons and insights from our AI transformation of BPO to guide your own workflow transformation:

  • Identify inefficiencies and find processes with repeatability and scale. Look for highly manual workflows that could benefit from AI integration.
  • Use workflow capabilities that can be configured across different scenarios. An AI toolkit that spans multiple stages can form the foundation for significant improvements and time savings.  
  • Test and iterate, following up on improvements as you learn. This enables adaption of the development process beyond traditional automation.
  • Keep humans in the loop and leading the way. Identify workflows where human judgment and handling of edge cases must take precedence.

Try it out

Related links

The post Streamlining business operations at Microsoft with an AI toolkit appeared first on Inside Track Blog.

]]>
24720
AI for Knowledge Management: Keeping support content up-to-date at Microsoft http://approjects.co.za/?big=insidetrack/blog/ai-for-knowledge-management-keeping-support-content-up-to-date-at-microsoft/ Thu, 16 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24648 Our AI agents and self-help channels are often our employees’ first stop for support, and like anyone, they expect the answers they get to be correct. This makes accurate content essential. If our content is stale, even the best agent or search engines will return wrong answers, which is frustrating to everyone. “Knowledge management today […]

The post AI for Knowledge Management: Keeping support content up-to-date at Microsoft appeared first on Inside Track Blog.

]]>
Our AI agents and self-help channels are often our employees’ first stop for support, and like anyone, they expect the answers they get to be correct.

This makes accurate content essential. If our content is stale, even the best agent or search engines will return wrong answers, which is frustrating to everyone.

A photo of Olkies.

“Knowledge management today is about making sure people can find the right answers the moment they need them. When knowledge stays current, employees get unblocked faster and productivity improves, making the overall support experience far more efficient.”

Silvina Olkies, senior director, Service Management, Microsoft Digital

That means the knowledge bases that get tapped for answers need be accurate, and for that to happen, they need to be updated frequently and without delay.

Internally here at Microsoft, that’s where our team got involved.

We’re Microsoft Digital, the company’s IT organization, and our team saw an opportunity to use AI to dynamically and proactively update our knowledge management systems.

Our first step was—in partnership with our Global Help Desk—to strengthen our self-serve help and reduce the number of steps users need to take to find the right answers. It’s a process that many of our own customers can apply to their knowledge management transformation.

“Knowledge management today is about making sure people can find the right answers the moment they need them,” says Silvina Olkies, a senior director of Service Management in Microsoft Digital. “When knowledge stays current, employees get unblocked faster and productivity improves, making the overall support experience far more efficient.”

The challenge: Fragmented knowledge, manual reviews

For our Global Help Desk, the challenge wasn’t just the volume of content, but also its condition. Support knowledge is spread across thousands of self-service articles, agent-facing systems, and SharePoint sites, all constantly evolving.

A photo of Verdeck.

“If the knowledge isn’t accurate and current, the experience breaks down immediately. Bad content leads to bad answers.”

Kevin Verdeck, senior IT service manager, Microsoft Digital

In today’s fast-changing AI-powered world, it doesn’t take long for knowledge to become incomplete, out of date, or redundant. This shows up in the inaccurate answers employees might receive.

In an environment increasingly powered by search and AI, weak knowledge equals weak results.

“If the knowledge isn’t accurate and current, the experience breaks down immediately,” says Kevin Verdeck, a senior IT service manager in Microsoft Digital. “Bad content leads to bad answers.”

At our Global Help Desk, keeping that content current required a manual review process.

Our teams analyzed usage data, depended on support agents to report missing or outdated content, and worked through recurring review cycles that relied on subject-matter experts to help confirm whether articles were still accurate. This took significant time and coordination, and even then, some issues were identified only after employees had already hit a dead end.

The result was a system that was reactive and hard to scale.

When employees couldn’t find answers, issues were pushed to advanced support. Poor knowledge quality created poor outcomes, while those responsible for fixing it were struggling with maintaining it.

“One five-member team was reviewing 1,900 self-service KB articles and 1,700 agent-facing KB articles every six months, and that didn’t even include the many SharePoint sites,” Verdeck says. “It was basically their full-time job doing regular reviews.”

Turning raw data into knowledge

Our team in Microsoft Digital set out to build AI for Knowledge Management, a centralized system that could scale across multiple repositories, cut the manual work of keeping content current, reduce reliance on busy content owners, and prepare knowledge for people and AI to use.

A photo of Guddewala.

“When you have a large volume of data, it’s a silent gold mine. The sheer brilliance lies in taking that data, making it sing, and letting it tell you exactly where the treasure is.”

Ankit Guddewala, software engineer II, Microsoft Digital

An AI pipeline solution made sense because we wanted to fix the issue at scale.

The real opportunity was to turn every resolved support ticket into a signal that looked at what the employee was asking for (nature of the issue or request), whether the answer was already documented, and how the AI and human agents handled it. So, we began with our large amounts of support ticketing data and systems as the starting point.

“When you have a large volume of data, it’s a silent gold mine,” says Ankit Guddewala, a software engineer in Microsoft Digital. “The sheer brilliance lies in taking that data, making it sing, and letting it tell you exactly where the treasure is.” 

The stages to complete the work happen as follows:

  1. Ingest the raw support data: The team pulls in large volumes of incident data from our ticketing systems.
  2. Clean and structure noisy data: Tickets can include conversation notes, incomplete details, inconsistent writing styles, and abandoned issues. We use the AI enrichment layer to turn those details into structured fields, such as reported versus actual problems and remediation steps.
  3. Find patterns across incidents: We cluster tickets to help identify recurring issues and avoid cluttering the knowledge base with one-off scenarios.
  4. Compare patterns against existing knowledge: We use the system to search current articles and rank how closely the resolution aligns to current content to determine what steps to take next. For example:
    • Below 40 percent: Create knowledge
    • 40 to 80 percent: Update existing knowledge with missing details
    • Above 80 percent: No update needed
  5. Notify the appropriate knowledge managers: Subject-matter experts are notified by email so they can validate the change(s) and add more detail if needed.

“Our goal is to free people from the manual work of maintaining content so they can focus on improving its quality. With the right human-in-the-loop balance, AI can do the heavy lifting while people make sure the final knowledge is accurate and useful.”

Namrata Ladda, product manager II, Microsoft Digital

The result is far less time spent reviewing thousands of articles during every review cycle. We keep humans in the loop to validate the output. Their feedback helps tune the AI model, so it improves over time.

“Our goal is to free people from the manual work of maintaining content so they can focus on improving its quality,” says Namrata Ladda, a product manager in Microsoft Digital. “With the right human-in-the-loop balance, AI can do the heavy lifting while people make sure the final knowledge is accurate and useful.”

Impacts and what’s next on the journey

Using our new AI for Knowledge Management platform, our Global Help Desk teams can identify knowledge gaps without waiting for someone to report them. They’re using AI to generate structured article drafts so humans can focus on quality, not search through data.

The Global Help Desk projects the solution will save them an estimated 16,000 hours annually; result in a 10 percent reduction in support tickets; and reduce the number of advanced support escalations. This leaves everyone on the team more time to directly help employees more quickly, when needed.

“Turning our knowledge base from a static thing into a living knowledge base is a big step forward,” Ladda says. 

Other Microsoft teams, including HR, have expressed interest in leveraging the content management platform. Once the product has completed internal testing, AI for Knowledge Management will be released to all company employees and customers.

“This solution moves knowledge management from manual maintenance to an intelligent capability that helps organizations scale and apply what they know more effectively,” Olkies says.

Key takeaways

Here are some actions your organization can take right away to strengthen your own knowledge foundations:

  • Start with knowledge. Treat your knowledge base as the source of truth that determines whether AI and self-help succeed.
  • Audit how knowledge is maintained. Look beyond publishing workflows to understand how gaps and outdated content show up in real usage.
  • Spot and remove manual bottlenecks. Identify where people are spending the most time searching and reporting knowledge and target those steps for automation.
  • Use AI to maintain, not just serve, content. Apply AI to identify gaps and refresh out-of-date information.

Try it out

Related links

The post AI for Knowledge Management: Keeping support content up-to-date at Microsoft appeared first on Inside Track Blog.

]]>
24648
Boosting accessibility at Microsoft with help from neurodivergent employees http://approjects.co.za/?big=insidetrack/blog/boosting-accessibility-at-microsoft-with-help-from-neurodivergent-employees/ Thu, 16 Jul 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24655 As new technologies reshape how people work, accessibility must move beyond compliance with the Americans with Disabilities Act and other inclusive legislation around the world to become supportive of how different people process information. Traditional approaches can fall short when it comes to the needs of neurodiverse people, leaving gaps in usability and inclusion. At […]

The post Boosting accessibility at Microsoft with help from neurodivergent employees appeared first on Inside Track Blog.

]]>
As new technologies reshape how people work, accessibility must move beyond compliance with the Americans with Disabilities Act and other inclusive legislation around the world to become supportive of how different people process information. Traditional approaches can fall short when it comes to the needs of neurodiverse people, leaving gaps in usability and inclusion.

At Microsoft, this shift is grounded in years of investment in our neurodiverse employees. From launching our Microsoft Neurodiversity Hiring Program to building a company-wide focus on neuro-inclusive employee experiences, we bring our lived experience to how we design and build our products.

We set out to better understand where our products could do more for all our users and challenge established accessibility norms.

“When we create space for neurodivergent voices to shape our products, we don’t just improve accessibility, we build better technology for everyone. Accessibility is strongest when it is informed by lived experience, and initiatives like our product feedback sessions make sure those voices directly influence how our products evolve.”

Neil Barnett, chief accessibility officer, Microsoft Accessibility

Neurodiversity Celebration Week became the launch point for a new approach to product feedback and co-design at Microsoft. We used the event to create an ongoing program that brings the perspectives of neurodivergent employees directly into the product development process, especially individuals who experience challenges with executive functioning tasks such as focus, learning, memory, organization, and task completion.

For our first feedback round, 150 neurodivergent employees evaluated 10 products across multiple divisions using real-world scenarios. Rather than focusing only on traditional accessibility checks, they shared insights on how products support everyday thinking, learning, and productivity.

The feedback provided product teams with a deeper understanding of where experiences can be simplified or made more intuitive and easier to navigate. More importantly, it established a repeatable process for gathering perspectives from people across the cognitive spectrum, helping teams build products that work better for more people.

“When we create space for neurodivergent voices to shape our products, we don’t just improve accessibility, we build better technology for everyone,” says Neil Barnett, chief accessibility officer in Microsoft Accessibility. “Accessibility is strongest when it is informed by lived experience, and initiatives like our product feedback sessions make sure those voices directly influence how our products evolve.”

How neurodiversity can help a broader audience

Neurodiversity refers to the idea that neurological differences—including autism, ADHD, and dyslexia—are a natural part of human diversity. It recognizes that there’s no single “right” way for the brain to work.

A photo of Shanaberger.

“Neurodivergent employees bring an innovative way of thinking and have ideas that help make our products better.”

Tarena Shanaberger, senior PM, Microsoft Accessibility

Product groups at Microsoft value feedback from our neurodiverse employees. However, without a consistent way to get it, product groups had to reach out with ad hoc requests through the different inclusion networks at the company.

We saw an opportunity to create both lasting change and more efficiency in this process.

“Neurodivergent employees bring an innovative way of thinking and have ideas that help make our products better,” says Tarena Shanaberger, a senior PM on the Microsoft Accessibility team.

Designing with lived experience

Neurodivergent inclusion is most valuable when it’s built in early in the product lifecycle, preferably before assumptions take hold and shape the product in ways that are harder to change later.

A photo of Niblock.

“Lived experience is a genuine form of expertise. You can have telemetry, design reviews, usability metrics, and KPIs that mean things to people who review data, but there are aspects of cognitive load and human behavior that become much more visible when you involve people who experience systems differently.”

Karl Niblock, architect, Engineering and Architecture Group Security

Karl Niblock, an architect in our Engineering and Architecture Group Security team, believes that early intent can result in experiences that delight users by making products “shockingly” easy and a joy to use, even for something as routine as logging into a tool.

Designing systems that help reduce unnecessary cognitive friction means more people can do their best work consistently and with more confidence. Those are the types of human-centered insights that aren’t possible to derive from data alone.

“Lived experience is a genuine form of expertise,” Niblock says. “You can have telemetry, design reviews, usability metrics, and KPIs that mean things to people who review data, but there are aspects of cognitive load and human behavior that become much more visible when you involve people who experience systems differently.”

When people share their experiences, everyone can learn and benefit.

“One of the patterns I often see is dead-end workflows, where a user follows the process exactly as instructed but ends up stuck, with no obvious next step,” Niblock says. “For someone with dyslexia or autism, the challenge is often not the task itself but the repeated effort of decoding similar-looking instructions and trying to determine what went wrong. By designing clear recovery paths, plain-language guidance, and visible next actions, we can dramatically reduce cognitive friction. Those improvements help neurodivergent users, but they also make products easier and less stressful for everyone.”

Building a better path for product feedback

Software engineer Jordan Cowe surfaced an idea to host an annual neurodiversity bug bash to uncover where products pose challenges for neurodivergent users. He explains that neurodivergent employees are often some of the first people to identify points of friction before release and says that the bug bash helped shine attention on these issues and encourage product group action on the feedback.

A photo of Cowe.

“If something affects a neurodivergent employee, it likely also affects many people who don’t identify as neurodiverse. Fixing these issues improves the products for everyone, making them easier to use and better at keeping users engaged.”

Jordan Cowe, software engineer II, Copilot Engineering team

This bug bash led to a structured way to bring in testers, distribute feedback results to product groups, and infuse key learnings into our products. Our testers asynchronously went through the instructions, followed the scenarios, recorded their screens, talked through their pain points, and completed a product survey. We used the results to rate product usability, which helped us identify issues and ideas for improving our products.

“If something affects a neurodivergent employee, it likely also affects many people who don’t identify as neurodiverse,” Cowe says. “Fixing these issues improves the products for everyone, making them easier to use and better at keeping users engaged.”

What feedback looks like from the product side

Microsoft AI UX researcher Audrey Aday used feedback from the co-design sessions to explore what makes an AI response feel inclusive, useful, and manageable. Tester feedback showed that the issue wasn’t capability, it was control.

A photo of Aday.

“Instead of treating accessibility as a check-the-box exercise, we’re building relationships with neurodivergent employees and embedding their feedback into the full product development lifecycle. We’re moving away from ‘test this for us once’ to ‘build this with us, continuously.’”

Audrey Aday, UX researcher II, Microsoft AI Design

Testers consistently said Copilot can feel overwhelming when it returns too much information at once. They want more control (not less capability) over how much detail they see. In response, product teams are exploring custom instruction menus, smarter defaults, and adaptive personalization that learns individual preferences without creating extra work.

Product teams across Microsoft see lived experiences as a quality driver, not an edge case. Neurodivergent employees help teams spot usability opportunities that benefit everyone, especially around information overload, pacing, and clarity.

“Instead of treating accessibility as a check-the-box exercise, we’re building relationships with neurodivergent employees and embedding their feedback into the full product development lifecycle,” Aday says. “We’re moving away from ‘test this for us once” to ‘build this with us, continuously’.”

How the Inclusive Tech Lab supports co-design

Support also comes from the Inclusive Tech Lab, where Microsoft design teams work directly with users with disabilities to uncover exclusionary designs and identify new product opportunities.

A photo of Heinzen.

“The best time to engage with us is when employees are starting something new or revising old designs. The Inclusive Tech Lab helps teams partner with disabled advisors early in the design process.”

Sarah Heinzen, senior designer, Microsoft Design and Research

The lab connects teams with people who bring their lived experience across different scenarios, such as limited mobility, photosensitivity, low vision, and neurodivergence. This co-design approach brings in users early and keeps them involved so their lived experience can shape product decisions from the start.

“The best time to engage with us is when employees are starting something new or revising old designs,” says Sarah Heinzen, a senior designer on the Microsoft Design and Research team. “The Inclusive Tech Lab helps teams partner with disabled advisors early in the design process.”

Building feedback into how we work

While the product teams work on incorporating feedback, we’re hard at work solidifying this continuous feedback loop and adding it to everyday product development at Microsoft.

Partnering with the Inclusive Tech Lab, we’re setting the foundation for making that a reality using:

  • One consistent path to feedback. Product teams have a unified way to engage with employees from the disability and neurodiversity communities.
  • A participant pool of testers. We’re building a diverse network of volunteers to make sure diverse lived experiences consistently inform product decisions.
  • Inclusive ways of working. We’re establishing guidelines to make sure testing scenarios match real user needs.

The expectation is start early, stay engaged, and build with the people you’re designing for.

“Even as a software engineer and someone who’s neurodivergent, accessibility used to feel like something you thought about later,” Cowe says. “Now I pause early and ask: Does this make sense for real users? Is it clear? Is it usable? It’s changed how I build. I’m looking for the small friction points, the things people struggle with, and I’m catching them sooner. It’s made me a better engineer.”

Key takeaways

You can use these guidelines to broaden accessibility standards at your organization:

  • Start with your people. Build feedback loops with employees who bring diverse perspectives.
  • Design inclusive feedback experiences. Make it easy for people with different cognitive styles to contribute.
  • Bring product teams into the conversation early. Turn feedback into co-design.
  • Move beyond compliance. Focus on usability and real-world productivity. 

Try it out

Related links

The post Boosting accessibility at Microsoft with help from neurodivergent employees appeared first on Inside Track Blog.

]]>
24655
Taming software licensing sprawl at Microsoft with an AI-driven solution http://approjects.co.za/?big=insidetrack/blog/taming-software-licensing-sprawl-at-microsoft-with-an-ai-driven-solution/ Thu, 09 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24605 It’s a common challenge at any large enterprise—important, related data scattered across the organization, residing in disconnected silos. If only there was an efficient way to pull them together into a single system to aid transparency and business decision making. Enter the power of sophisticated data tools and agentic AI.  A great example of this […]

The post Taming software licensing sprawl at Microsoft with an AI-driven solution appeared first on Inside Track Blog.

]]>
It’s a common challenge at any large enterprise—important, related data scattered across the organization, residing in disconnected silos. If only there was an efficient way to pull them together into a single system to aid transparency and business decision making.

Enter the power of sophisticated data tools and agentic AI. 

A great example of this came when our Microsoft Digital engineers and product managers were trying to get a handle on our sprawling software licensing landscape—thousands of third-party tools that our employees rely on in their work.

“We realized there were all these fragmented, scattered repositories of licensing data across many teams, all with different ownership,” says Ahmed Musa, a senior software engineer in Microsoft Digital, the company’s IT organization. “There was no visibility into what contracts existed or how they were being used. We needed a single solution.”

The answer was IntelLicense, an enterprise-wide intelligence platform that collects product information, licensing contracts, cost data, employee usage telemetry, and supplier details in one system. This all comes together in our Software Asset Management (SAM) portal, where we deliver enterprise-grade governance through a modern user experience.

A photo of Musa.

“IntelLicense is a game-changer for us. Before, internal software licensing was manual and labor-intensive—it could take months to make sense of the data. Now, an answer that used to take up to six months for us to track down can be generated immediately using this platform we’ve created.”

Ahmed Musa, senior software engineer, Microsoft Digital

Our IntelLicense platform uses the advanced capabilities of agentic AI to answer queries and generate insights on the data, giving us much greater understanding and visibility while enabling us to reduce license duplication, simplify procurement, and cut spending.

This benefits our employees who need to license software, our software asset managers, and our Procurement team, which manages the process on our back end to make sure the company isn’t wasting money and resources—especially considering the company makes significant annual investments in third-party software licensing.

This solution shows how at Microsoft we’re constantly looking for ways to apply AI to help solve enterprise-level challenges at scale—the hallmark of a Frontier Firm.  

“IntelLicense is a game-changer for us,” says Musa, the principal architect for the project. “Before, everything around internal software licensing was manual and labor-intensive,—it could take months to make sense of the data. Now, an answer that used to take up to six months for us to track down can be generated immediately using this platform we’ve created.”

Uncovering the challenge

With more than 200,000 employees working across over 100 countries worldwide, attempting to centralize information at an organization the size of Microsoft is never easy. The state of our third-party software licensing system was no different.

A photo of Chandra Pydimarri.

“As we looked beyond just employees finding software and deeper into the process, we began to see the challenge was also about purchasing, how we dealt with suppliers, and how we managed the licenses at a higher level. That’s where we saw the big opportunity.”

Revanth Chandra Pydimarri, senior product manager, Microsoft Digital

We began this journey nearly three years ago. The first big need we identified came from employee feedback that indicated it was difficult to figure out how to identify and license third-party software tools. But as we began to analyze the larger picture, we realized that the problem was much more layered and complex.

“As we looked beyond just employees finding software and deeper into the process, we began to see the challenge was also about purchasing, how we dealt with suppliers, and how we managed the licenses at a higher level,” says Revanth Chandra Pydimarri, a senior product manager in Microsoft Digital. “That’s where we saw the big opportunity.”

But by expanding the scope of the project, we were setting off on a long and technically daunting quest.

A photo of Selveraj.

“I think we counted 19 different systems that contained relevant licensing data. Working with all the different teams to pull that data together was the first big challenge we had to go after.”

Jay Selveraj, principal software engineering manager, Microsoft Digital

Tackling the data first

The first step was to gain visibility into all our third-party software contracts, our suppliers, and the actual product usage across the company. But our teams were operating in silos, each maintaining their own agreements and data about software licenses.

“This was fundamentally a data problem,” says Jay Selveraj, a principal software engineering manager in Microsoft Digital. “The enterprise data for license management is highly distributed, non-standard, and spread across the company. I think we counted 19 different systems that contained relevant licensing data. Working with all the different teams to pull that data together was the first big challenge we had to go after.”

A screenshot showing sample data from the IntelLicense Software Asset Management portal.
The Software Asset Management (SAM) portal gives our asset managers and procurement agents rich data insights into our third-party software licensing across the enterprise.

To fully understand the software asset management process, Selveraj and Chandra Pydimarri were charged with creating a journey map to show the steps, dependencies, and stakeholders involved.   

“It was a very daunting task for us,” Selveraj says. “We identified so many different bottlenecks. And that’s when we decided we can’t just troubleshoot the existing process—we needed to build a new platform that would span the enterprise.”

To accomplish this, they turned to Microsoft Fabric, which at the time was a relatively new product. Fabric provided the power and flexibility needed for this kind of project.

A photo of Ararso.

“Microsoft Fabric was designed as a unified data platform for engineers, making it an ideal fit for this project.”

Misrak Ararso, senior software engineer, Microsoft Digital

And as Customer Zero for Microsoft, we were excited to be early adopters of Fabric (it had just gone into public preview). The fact that we were able to try it out on a real enterprise challenge we were facing was both a strategic advantage and a bonus.

“Microsoft Fabric was designed as a unified data platform for engineers, making it an ideal fit for this project,” says Misrak Ararso, a senior software engineer in Microsoft Digital, who also worked on IntelLicense. “It has great features like Data Wrangler, which allowed us to drill down on the data and clean it up quickly. We also used Microsoft OneLake, which meant we avoided having to duplicate data before working on it.”

Ararso appreciates how Microsoft Fabric continues to evolve with new AI capabilities, making it an increasingly powerful and beneficial tool for data engineering.

“Early adoption wasn’t always smooth,” she says. “We encountered challenges, sharing feedback when we did, and we benefited from improvements as the platform matured alongside our implementation.”

Reducing waste and saving money in procurement

Before we developed IntelLicense, our Procurement team at Microsoft also struggled to answer basic questions about our software licenses.

A photo of Amiri.

“It was very difficult to gauge usage, consolidate agreements, and do cost optimization. And when we tried to audit our contracts and move licenses around, it all had to be done manually and took a lot of time and effort. IntelLicense addresses that.”

Rasa Amiri, senior sourcing manager, Financial Operations

The Procurement team is responsible for negotiating contracts, pricing, and terms and conditions with thousands of different suppliers. However, it can be difficult to negotiate volume discounts and manage the other aspects of licensing if you don’t have a holistic view across the enterprise.

In a typical example, one group at Microsoft might purchase 20 software licenses from a particular supplier, but then only use 15 of them. Another team needs 5 licenses, but they have no idea that there are unused licenses they could tap from the other group, so they purchase their own. And when an employee moves teams or leaves the company, their software licenses often go unused rather than get reassigned.

“It was very difficult to gauge usage, consolidate agreements, and do cost optimization,” says Rasa Amiri, a senior sourcing manager in our Financial Operations group. “And when we tried to audit our contracts and move licenses around, it all had to be done manually and took a lot of time and effort. IntelLicense addresses that.”

IntelLicense structure

UX layer

Role-based portal and embedded Copilot that surfaces software insights, recommendations, and actions for employees, software asset managers, and procurement specialists

AI layer

Multi-agent orchestration system that interprets user intent, calls plug-ins and APIs, and executes workflows

Data layer

Built on a unified Fabric/OneLake foundation that includes entitlement (contracts), provisioning (users/devices), and usage data

The IntelLicense solution consists of three parts: a UX layer, an agentic AI layer, and a data layer.

According to Amiri, one helpful feature of IntelLicense is the ability to see if a software license is not being used, and then directly contact that employee (or license owner) to say, “Hey, it looks like you’re not using this license. Can we reallocate it?”

“We have a real-time dashboard called the SAM portal that we can now use for that, focused on our top 200 suppliers,” Amiri says. “Now, every time we negotiate a deal, it’s uploaded into IntelLicense with all the details—the cost, the contract, the number of licenses. Not only does it help us with reallocation, it helps us quickly resolve issues we have with suppliers who want to charge us for overuse.”

Musa agrees.

“The IntelLicense platform can identify overlapping tools already in use and surface relevant alternatives, enabling more informed, cost-efficient decisions across the organization,” he says.

Introducing these kinds of efficiencies can quickly generate significant cost savings at an organization the size of Microsoft. Our internal data shows that IntelLicense drove substantial savings in software licensing fees over the last fiscal year. And we have greater ambitions for the future—Chandra Pydimarri cited industry studies that show up to 20% of third-party software spending is unnecessary. That’s huge potential savings for an enterprise organization.

A photo of Sengar.

“As we evolved the platform, we realized that users don’t want just another dashboard—they need decision intelligence. They need a system that can connect signals across datasets, surface actionable insights, and guide decisions in real time, so they can move faster and act with confidence.”

Urvi Sengar, senior software engineer, Microsoft Digital

Adding an AI layer

The Software Asset Management portal was a strong foundation for centralizing licensing data, but we wanted to take the solution further.

It was one thing to centralize and surface data with all the relevant data about third-party software licenses. It was a whole different challenge to build a system that helped the user understand the data, ask the right questions, and turn insights into decisions.

“As we evolved the platform, we realized that users don’t just want another dashboard—they need decision intelligence,” says Urvi Sengar, a senior software engineer in Microsoft Digital. “They need a system that can connect signals across datasets, surface actionable insights, and guide decisions in real time, so they can move faster and act with confidence.”

So Sengar and her fellow engineers set to work adding an agentic layer to IntelLicense that could provide those AI-driven insights. They used Microsoft Foundry to create a multi-agent solution that could handle all the various needs users of the system might have.

“With the multi-agent architecture that we followed, we have a workflow manager that delegates any user query to specialized agents,” Sengar says. “One agent handles license management, another deals with supplier management, another can support audit scenarios. Each agent understands the user’s intent and can call any deterministic workflows when needed.”

Sengar sees the agentic layer as the transformation of IntelLicense from a reporting tool into an intelligent system that can deliver contextual, on-demand insights and help users take action through workflows. It also aligns with the growing expectations for a more conversational, Copilot-like AI experience, where users can ask questions naturally and receive meaningful, actionable responses in real time.

“The platform delivers proactive insights through the portal while also enabling users to explore them on-demand, in the context of their work,” Sengar says.

She goes on to describe a scenario where a software asset manager is in the middle of negotiating a contract with a supplier. If they have a new idea, question, or strategy they want to validate, the portal can surface relevant recommendations and insights right away. If they want to go deeper, they can use the chat interface to ask questions and get instant access to the latest context-aware information in a dynamic way, without having to leave the flow of their work.

“That’s where we see the future of AI-driven work going,” Sengar says. “It’s using AI not only to surface insights, but to help people explore them further, act on them, and make better decisions faster.”

Applying intelligence across the enterprise

Large enterprise organizations like Microsoft face this kind of challenge in many areas: how to maximize efficiency by centrally managing a process that is scattered across many different teams and systems, with data that is often inaccessible or systems that are incompatible. Teams have often developed different ways of accomplishing the same task and are reluctant to change.

A photo of Selveraj.

“We want to make the biggest difference for the company—that’s the ultimate goal. At the end of the day, we want to make sure there is plenty of cost savings produced. Beyond that, we want to apply as much intelligence as possible to the problem, so that AI is impacting all aspects of the process.”

Senthil Selveraj, principal group product manager, Microsoft Digital

Our approach is to apply AI where it makes sense, using continuous improvement principles to guide us. We also look to our AI councils to make sure that we’re following best practices.

This ensures that when we at Microsoft Digital tackle something like software licensing, we’re going to achieve a transformational result that will pay big dividends across the company.

“We want to make the biggest difference for the company—that’s the ultimate goal,” says Senthil Selveraj, a principal group product manager in Microsoft Digital. “At the end of the day, we want to make sure there is plenty of cost savings produced. Beyond that, we want to apply as much intelligence as possible to the problem, so that AI is impacting all aspects of the process. That’s where we’ll see the largest, most impactful benefits.”

Key takeaways

If you are interested in ways to address third-party software licensing management at your organization, keep in mind these learnings from our own experience:

  • The more fragmented and complex the data problem, the stronger the case for agentic AI. Microsoft Digital used AI to unify disconnected licensing data and turn a sprawling challenge into a scalable solution.
  • Centralizing data was the foundation for this solution. By consolidating nearly 20 separate data systems into a single platform, IntelLicense gave us the visibility we needed to drive smarter decisions.
  • Agentic AI transforms static dashboards into dynamic decision-making systems. Instead of manually analyzing reports, our users can now query the system and receive real-time, context-aware insights.
  • Enterprise-wide visibility unlocks immediate cost savings and efficiency gains. IntelLicense reduced redundant licenses, improved reallocation, and saved over $16 million in a single year.
  • Embedding AI across workflows delivers impact at every level of the organization. From individual employees to procurement leaders, intelligent automation improves outcomes, speed, and user experience across the board.

Try it out

Related links

The post Taming software licensing sprawl at Microsoft with an AI-driven solution appeared first on Inside Track Blog.

]]>
24605
Simplifying expense approvals at Microsoft with AI-powered risk assessment http://approjects.co.za/?big=insidetrack/blog/simplifying-expense-approvals-at-microsoft-with-ai-powered-risk-assessment/ Thu, 09 Jul 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24595 Every manager has experienced it: The dread of approving a stack of expense reports while critical work stands idle. This tedious process has even garnered its own internal descriptor: “Approval fatigue.” Here at Microsoft, we’re no different. Complaints about the time and effort required to approve expense reports have been consistent from managers across our […]

The post Simplifying expense approvals at Microsoft with AI-powered risk assessment appeared first on Inside Track Blog.

]]>
Every manager has experienced it: The dread of approving a stack of expense reports while critical work stands idle. This tedious process has even garnered its own internal descriptor: “Approval fatigue.”

Here at Microsoft, we’re no different.

Complaints about the time and effort required to approve expense reports have been consistent from managers across our organization.

“We continuously heard feedback from our leaders that they were spending too much time approving expense reports,” says Michael He, a senior business program manager in the Greater China Region. “They didn’t know where the potential risk actually was, so they had to review everything in detail.”

At Microsoft Digital, the company’s IT organization, we’ve taken this challenge on by introducing an AI-powered Intelligent Risk Engine.

A photo of Wangmo.

“The Intelligent Risk Engine cuts through complexity, pointing approvers straight to the expenses that warrant attention. This clears up the noise that has been driving review fatigue, especially at quarter’s end.”

Sangay Wangmo, Microsoft Digital experience director, Middle East and Africa

With this new tool, we shifted approvals from uniform, manual scrutiny to automated, risk-based decision making. This enables faster reviews, reduced cognitive load, and improved compliance outcomes.

“The Intelligent Risk Engine cuts through complexity, pointing approvers straight to the expenses that warrant attention,” says Sangay Wangmo, a Microsoft Digital experience director for our Middle East and Africa region. “This clears up the noise that has been driving review fatigue, especially at quarter’s end.”

Looking ahead, we plan to expand the tool to include automated approvals for low-risk cases, creating a more scalable, intelligent, and efficient process. This will ease the pain for our managers and allow them to focus on their strategic work.

Manual approvals in a complex compliance environment

Across our global enterprise, we handle nearly a million expense reports annually. In regions such as Central and Eastern Europe, the Middle East, and Africa (CEMA), our expense approval processes are shaped by diverse regulatory requirements in many different countries.

A photo of Parbhoo.

“As organizations scale, managers naturally have more direct reports, which means more approvals to process. At the same time, accountability for all compliance still sits with the manager, which adds pressure.”

Kethan Parbhoo, general manager, Central and Eastern Europe, Middle East, and Africa

To take one example, the Middle East and Africa—featuring multiple subregions, languages, and local policy nuances—presents a complex challenge for expense management. Applying a consistent risk lens to every case is difficult.

To ensure they stay compliant, leaders often review expense reports in detail, including verifying receipt accuracy, matching invoice data, and checking supporting information (like attendee lists). This level of review requires substantial time and attention, particularly for managers with large teams who receive a high volume of submissions. This becomes even more time-consuming as groups grow.

“As their organizations scale, managers naturally have more direct reports, which means more approvals to process,” says Kethan Parbhoo, a general manager in the Central and Eastern Europe, Middle East, and Africa region. “At the same time, accountability for all compliance still sits with the manager, which adds pressure.”  

The current tool, MS Expense, which was useful in a pre-AI environment, doesn’t provide an optimal user experience. The process was repetitive and depended heavily on manual validation. Existing tools provide limited support for prioritizing risk or simplifying these tasks, resulting in a similar effort being applied to both low- and high-risk expenses. 

As a result, leaders experience increased workload, slower approval timelines, and continued exposure to potential compliance gaps, despite careful review. 

The four top-level internal pain points of the old approval process can be summarized as: 

  • Not knowing where the risk is 
  • Approvals take too much time, especially at quarter’s end 
  • Too much effort is spent on low-risk, routine reviews 
  • Issues are found too late, triggering audits and resubmissions after the fact

The Intelligent Risk Engine is helping us address all of these in a unified, cohesive way.

A photo of Carnrite.

“The system leverages a combination of AI-based risk checks and policy-driven risk checks. This produces a quantifiable baseline score that allows for easier comparison and risk assessment.”

Eric Carnrite, principal product manager, Travel and Expense

AI-assisted risk scoring embedded in MS Approvals 

The Intelligent Risk Engine that our team developed integrates with the existing MS Approvals system, shifting from volume-based checks to risk-based decisioning. We embed this analysis directly into the workflow.

The risk engine evaluates each expense report against multiple criteria, including receipt matching (which leverages AI and optical character recognition), spending patterns, and policy alignment. It assigns a risk score (1-100) and a risk level—1 at the low end and 5 at the high end—and then highlights specific areas that might require attention. 

“The system leverages a combination of AI-based risk checks and policy-driven risk checks,” says Eric Carnrite, a principal product manager for the Travel and Expense team. “This produces a quantifiable baseline score that allows for easier comparison and risk assessment.”

Expense risk score table

Risk score

Risk level

What this means

What to know

Expected action

0–25

Negligible

  • No material anomalies detected
  • Expense aligns with policy and normal spending patterns
  • Designed for fast processing
  • Many negligible risk reports may eventually be auto-approved
  • Approve
  • No additional review unless something is obviously incorrect

25–50

Low

  • Minor issues or weak signals detected
  • Expense is generally compliant
  • Risk indicators are informational
  • No deep investigation is expected
  • Quick reasonableness check
  • Review flagged items only if something appears unusual
  • Approve if expense makes sense

50–75

Medium

  • One or more policy violations or anomalies detected
  • Expense may still be valid but needs attention
  • Most common ‘review required’ category
  • Indicators show where to look, not what decision to make
  • Review flagged line items
  • Request clarification if needed
  • Approve only when justified and reasonable

75–90

High

  • Significant anomaly detected
  • Higher likelihood of non-compliance if not validated
  • High risk does not automatically mean rejection
  • More likely reviewed by audit
  • Perform thorough review
  • Validate receipts and details
  • Return for correction if needed
  • Reject if not compliant

90–100

Critical

  • Strong indicators of serious non-compliance or potential legal/fraud risk
  • Requires immediate and careful handling
  • Typically prioritized for audit or compliance review
  • Do not approve
  • Perform full review
  • Escalate to Finance Compliance
  • Reject unless concerns resolved

The tool also explains why something has been flagged. This allows approvers to quickly understand where to focus their review and to catch issues early, rather than after the fact. 

“AI is effectively doing the initial assessment that a human would otherwise have to do,” Parbhoo says. “It gives you a strong signal, so you can decide quickly where deeper review is needed.” 

With our new model, low-risk expenses can be reviewed and approved with minimal effort, while higher-risk items receive closer examination. It just makes sense to prioritize our work this way.

“Previously, a $10 coffee receipt required the same level of scrutiny as a $300 invoice, which doesn’t make sense at scale,” Wangmo says. “Leaders are forced to treat everything the same, even when the risk level is clearly different.”

Early returns indicate significant improvements. These include:

  • Immediate productivity gains, as approvers stop reviewing all expenses manually
  • Reduced rework and late‑stage audit findings 
  • Stronger governance at scale, without adding headcount or introducing new manual processes
A photo of He.

“It pulls the three parts together: Employees, approvers, and auditing and compliance. It will ultimately make it more proactive for all parties involved, rather than reactive—making sure the whole flow of the expense process is more meaningful.”

Michael He, senior business program manager, Greater China Region

Future direction: Expanded automation and standardization 

This kind of AI-powered technology will eventually allow us to pull everything together in one unified system, meeting the needs of all the major players in the expense management process.

“It pulls the three parts together: employees, approvers, and auditing and compliance,” He says. “This will ultimately make it more proactive for all parties involved, rather than reactive—making sure the whole flow of the expense process is more meaningful.”

And we’re not done innovating. The current risk engine implementation establishes a foundation for further automation, and that’s where we’re headed.

One planned enhancement is the automatic approval of low-risk expenses, subject to compliance approval. This could produce significant savings and greater efficiency across our organization.

“With auto-approvals, we’re not talking about a nominal amount,” Carnrite says. “At this point, we’re targeting up to 75 percent of expense reports being automatically reviewed and approved. This could save us around 150,000 to 200,000 person-hours a year—and that’s at the manager and director level.”

We’ve also added advanced optical character recognition (OCR) technology into our expense tools. This now allows for automatic categorization of expenses, so employees don’t have to enter the category manually for each item.

A photo of Segura.

“The end goal is an AI agent that can proactively create an expense report for you and ask you to review it. You would just validate it and move it forward, instead of building it from scratch.”

Salvador Segura, director of business programs, Field Capability Services

Additional future improvements could include expanded use of AI for data validation, receipt processing, and identification of inconsistencies across submissions. Over time, the goal is to support a standardized approval framework that adapts to regional differences while maintaining consistent risk evaluation and reducing manual workload.

At the next level, we’re hoping to use AI to eventually fully automate the creation of expense reports as well. This would be essentially the Holy Grail for this function.

“The end goal is an AI agent that can proactively create an expense report for you and ask you to review it,” says Salvador Segura, a director of business programs in Field Capability Services. “You would just validate it and move it forward, instead of building it from scratch.” 

It’s this kind of AI-powered work environment that we’re pushing for at Microsoft Digital as we play a leading role in our company’s ongoing Frontier Firm journey.

Key takeaways

If you’re still struggling with manual expense approvals at your organization, here are some things to consider about our Intelligent Risk Engine solution:

  • AI-powered risk scoring eliminates approval fatigue. By directing managers to the small subset of expenses that actually require scrutiny, the Intelligent Risk Engine removes the need for exhaustive manual review.
  • Risk-based decisioning replaces one-size-fits-all approvals. Automated scoring and clear risk levels allow approvers to prioritize high-risk items and quickly resolve lower-risk charges.
  • Embedded intelligence accelerates workflows and improves accuracy. Integrating AI directly into MS Approvals highlights issues, explains flags, and enables faster decisions earlier in the process.
  • Managers gain time back while strengthening compliance. Reduced manual effort, fewer late-stage audit findings, and better risk visibility improve governance without adding headcount.
  • Global complexity is made simpler with the help of AI. The solution accounts for diverse regulations across regions, reducing cognitive load for approvers.
  • Automation is helping us target significant efficiency gains. Our product roadmap includes plans to auto-approve low-risk items, potentially saving up to 200,000 manager hours annually.
  • Future innovation points to fully AI-driven expense management. The ultimate goal is for AI-generated expense reports, which will shift users from building reports to simply validating them.

Try it out

Related links

The post Simplifying expense approvals at Microsoft with AI-powered risk assessment appeared first on Inside Track Blog.

]]>
24595
Taming our Python dependencies at Microsoft with AI http://approjects.co.za/?big=insidetrack/blog/taming-our-python-dependencies-at-microsoft-with-ai/ Thu, 25 Jun 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24491 At Microsoft, Python has long been one of our most popular programming languages. Our developers use it for building production systems, internal tools, automation workflows, and more. We estimate that at least 67,000 employees use it every day. At that scale, Python dependencies have emerged as a significant source of risk for us—representing the third-largest […]

The post Taming our Python dependencies at Microsoft with AI appeared first on Inside Track Blog.

]]>
At Microsoft, Python has long been one of our most popular programming languages. Our developers use it for building production systems, internal tools, automation workflows, and more. We estimate that at least 67,000 employees use it every day.

At that scale, Python dependencies have emerged as a significant source of risk for us—representing the third-largest vulnerability surface across the company.

The good news is that we have strong visibility into these vulnerabilities, with tools that continuously detect and surface risks across our codebases. The bad news is that turning those insights into action required a complex remediation process.

Updating a single code package often caused changes across multiple interdependent libraries. This required coordinated updates, validation, and testing to maintain system stability.

A photo of Arias.

“When AI arrived, I saw it as a great opportunity to finally fix a very complex problem we had: The level of entanglement involved in Python code dependencies. A simple script wasn’t going to resolve it—you needed the power of AI.”

Humberto Arias, senior product manager, Microsoft Digital

Multiply this by thousands of projects throughout our enterprise, and vulnerabilities accumulated much faster than we could resolve them. To address this challenge, we turned to AI.

Microsoft Digital—the company’s IT organization—has developed an AI-powered solution called Python Dependency Remediation. Designed to work directly within the developer workflow, this solution analyzes dependency chains, applies required updates, and automatically adjusts the code. This enables our engineers to remediate vulnerabilities quickly and consistently at enterprise scale.

“I’ve worked for years in the vulnerability management space at Microsoft,” says Humberto Arias, a senior product manager in Microsoft Digital. “When AI arrived, I saw it as a great opportunity to finally fix a very complex problem we had: The level of entanglement involved in Python code dependencies. A simple script wasn’t going to resolve it—you needed the power of AI.”

The tool has shown so much promise that we have begun releasing it externally, so that millions of Python developers around the world can take advantage of it.

A photo of Chiodo.

“I used to have this problem all the time. I upgrade one library, and then I’ve got to upgrade 17 other things, and something else breaks, and now my code is completely different.”

Rich Chiodo, principal software engineer, Python and Tools for AI

Flexibility leads to dependencies and risk

Python is a very flexible language, which is why it’s so popular among software developers. But that same flexible nature—it can be used across a wide range of scenarios—also means it forms deeply interconnected dependency chains. When one code library is updated, it can trigger changes across many others.

“I used to have this problem all the time,” says Rich Chiodo, a principal software engineer on the team responsible for Python Tools and AI. “I upgrade one library, and then I’ve got to upgrade 17 other things, and something else breaks, and now my code is completely different.”

A photo of Sheth.

“Developers avoid the upgrades because the dependency web is so complex. This means the vulnerabilities accumulate over time and can become a real security risk.”

Chintan Sheth, principal engineering manager, Viva Glint

Because the code is so interdependent and remediation is time-consuming, many developers skip updating their code packages, which can lead to security vulnerabilities.

Security compliance was often seen as a burden because it slows people down.

“Developers avoid the upgrades because the dependency web is so complex,” says Chintan Sheth, a principal engineering manager on the Viva Glint product team. “This means the vulnerabilities accumulate over time and can become a real security risk.”

A photo of Krishna Gollapelly.

“After my manager mentioned it, I reviewed the idea on the hackathon page, and it looked really interesting to me. So I jumped in, and we created a prototype and a demo video with a quick solution. That’s how it started.”

Shiva Krishna Gollapelly, senior software engineer, Microsoft Digital

Hacking our way to a solution

Like some of the best internally developed tools and processes, Python Dependency Remediation came out of a Microsoft hackathon project. These grassroots events allow our engineers to tackle interesting technical challenges in a collaborative, creative way.

“After my manager mentioned it, I reviewed the idea on the hackathon page, and it looked really interesting to me,” says Shiva Krishna Gollapelly, a senior software engineer in Microsoft Digital and the lead developer on the project. “So I jumped in, and we created a prototype and a demo video with a quick solution. That’s how it started.”

The fact that this solution came from a hackathon highlights the ideas-driven culture that we promote at the company.

“This really speaks to our special culture of innovation,” says Snigdha Bora, a principal group engineering manager for Employee Experience. “After this emerged from the hackathon, our developers realized it could solve a problem at scale—that it was worth taking through the full development cycle so we can release it for all of Microsoft, and maybe beyond.”

Solving the issue with one click (and AI)

Because the challenge was not detecting vulnerabilities but fixing them, we had to rethink how we addressed Python dependencies.

“The extension automatically finds the right updates and then fixes the vulnerabilities, so developers don’t need to do the research, the manual upgrades and fixes, run test cases, debugging—all those things that used to take so much time. With our solution, it’s just one button click and it does all of that automatically.”

Shiva Krishna Gollapelly, senior software engineer, Microsoft Digital

In the past, when engineers received a vulnerability notification, they would have to step outside their development workflow and address the issue. What was needed was a solution that could be enacted within their normal workflow—integrating remediation directly into the tools they were already using.

So, we created the Python Dependency Remediation extension for Visual Studio Code, a common Python development environment. Once installed, engineers can address vulnerabilities in the flow of their work.

A screenshot showing the extension detecting vulnerabilities in Python code.
The Python Dependency Remediation extension automatically detects vulnerabilities and then allows developers to fix them and update their code, right in the flow of their work.

“The extension automatically finds the right updates and then fixes the vulnerabilities, so developers don’t need to do the research, the manual upgrades and fixes, run test cases, debugging—all those things that used to take so much time,” Gollapelly says. “With our solution, it’s just one button click and it does all of that automatically, with the help of AI.”

The extension uses the APIs built into Visual Studio Code to connect with any AI model the user has access to. (If there is no AI model available, Gollapelly explains, the extension will still make the package updates but won’t do the remediation fixes to the code.) It also produces a report of the changes for the developer to review in case there’s a snag that needs troubleshooting.

“This tool removes a significant burden from our developers,” Bora says. “We are shifting the entire remediation process left, embedding it early in the development workflow. Developers can review the changes and move forward immediately, making the whole process more efficient.”

A photo of Saldivia.

“We’ve upgraded the library with new methods, calls, and structures. Now, let’s make sure everything works, check for errors in the code, etc. That’s the gap we’re bridging with AI.”

Angel Saldivia, software engineer, SharePoint

The result is that fixes and upgrades that used to take multiple hours of developer time now take minutes, and the code is much more reliable.

What the agent does in this solution is help close that loop, something that the engineer used to have to do.

“We’ve upgraded the library with new methods, calls, and structures,” says Angel Saldivia, a software engineer on the SharePoint product team. “Now, let’s make sure everything works, check for errors in the code, etc. That’s the gap we’re bridging with AI.”

From Customer Zero to global impact

One of the powerful things about working at Microsoft is that you get to help develop technology tools that can change the world. This is the case with Python Dependency Remediation as well.

A photo of Bora.

“We realized this technology had much broader value. There are hundreds of millions of Python users worldwide, so the impact could be massive.”

Snigdha Bora, principal group engineering manager, Employee Experience

As Bora explains, while the solution was being developed it was presented to Guido van Rossum, the creator of Python (and a Microsoft employee). He immediately saw the incredible potential of the concept.

“He suggested that we could take this solution to the world, not just to Microsoft,” Bora says. “We realized this technology had much broader value. There are millions of Python users, so the impact could be massive.”

To help make this happen, Microsoft Digital approached Graham Wheeler, a principal group engineering manager on the Python and Tools for AI team. Wheeler’s team is responsible for shipping Pylance, a development extension for Visual Studio Code used by more than 180 million developers worldwide.

A photo of Wheeler.

“One of the things we could do was provide a jumping-off point for this extension, so that when users installed Pylance they’d be prompted to also download Python Dependency Remediation. It can help raise awareness, because many users don’t actually do the dependency scanning and updating that they should.”

Graham Wheeler, principal group engineering manager, Python and Tools for AI

Wheeler and his team are in the process of incorporating the Python Dependency Remediation extension as an option during Pylance installation. This will open up a convenient vector for getting the tool in front of a huge audience, potentially revolutionizing Python development.

“One of the things we could do was provide a jumping-off point for this extension, so that when users installed Pylance they’d be prompted to also download Python Dependency Remediation,” Wheeler says. “It can help raise awareness, because so many users don’t actually do the dependency scanning and updates that they should. So, we’re helping with that challenge.”

Beyond Python, the AI-powered technology behind this extension might be applied to other dependency challenges as well. What started as a simple hackathon project could have huge ramifications for the future of software development.

“This solution can easily be adapted to other libraries, other programming languages,” Gollapelly says. “Whether you’re talking about C#, Angular, React, or another language, the concept is the same. The implications are vast.”

Key takeaways

Here are some points to keep in mind if you are thinking about tackling this kind of code-dependency issue at your organization:

  • AI can make the difference between simple awareness and actual resolution. We already had strong tools to detect Python vulnerabilities, but AI is what finally enabled remediation at scale across thousands of projects.
  • Python’s flexibility is both its strength and its biggest risk multiplier. Deep dependency chains mean that a single update can cascade into widespread breakage, with manual fixes slow and error-prone.
  • Automation embedded in the developer workflow is the breakthrough. By integrating directly into Visual Studio Code, Python Dependency Remediation allows developers to fix vulnerabilities with minimal friction—often in just one click.
  • AI dramatically compresses remediation time, from hours to minutes. Tasks that once required manual research, testing, and debugging are now handled automatically, improving both speed and code reliability.
  • The “shift left” approach is key to efficiency gains. Fixing dependency issues earlier in the development cycle reduces downstream complexity and keeps developers in the flow of their work.
  • This innovation has potential far beyond Microsoft—and beyond Python. With the potential for distributing the solution widely and adapting it to other languages, this breakthrough could reshape how developers everywhere manage dependencies.

Try it out

Related links

The post Taming our Python dependencies at Microsoft with AI appeared first on Inside Track Blog.

]]>
24491
How we approach cybersecurity risk management at Microsoft http://approjects.co.za/?big=insidetrack/blog/how-we-approach-cybersecurity-risk-management-at-microsoft/ Thu, 25 Jun 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24461 Cybersecurity risk management at Microsoft is an enterprise-wide discipline spanning governance, engineering, operations, and organizational culture. Through our international operations and diverse portfolio of products, services, and regulatory obligations, we’ve developed a mature, scalable framework designed to facilitate proactive risk identification, structured mitigation, and continuous oversight. This article presents our approach to cybersecurity risk management, […]

The post How we approach cybersecurity risk management at Microsoft appeared first on Inside Track Blog.

]]>
Cybersecurity risk management at Microsoft is an enterprise-wide discipline spanning governance, engineering, operations, and organizational culture. Through our international operations and diverse portfolio of products, services, and regulatory obligations, we’ve developed a mature, scalable framework designed to facilitate proactive risk identification, structured mitigation, and continuous oversight.

This article presents our approach to cybersecurity risk management, detailing the internal governance structures, lifecycle methodologies, regulatory compliance processes, and organizational practices that collectively promote transparency and accountability. This approach is built on two foundational components: a structured risk management lifecycle and a governance model that integrates cybersecurity risk into enterprise-level decision making.

Governance as the foundation

Microsoft’s cybersecurity risk management program is fundamentally structured around robust governance mechanisms. Central to this framework is the Cybersecurity Governance Council, a cross-functional body composed of the Chief Information Security Officer (CISO), Deputy CISOs (DCISOs), and representatives from legal and regulatory affairs. This council convenes twice weekly to evaluate emerging risks, validate mitigation plans, and ensure alignment with enterprise priorities.

The governance model is designed to facilitate bidirectional communication of risk intelligence. Information flows upward from engineering and operational domains to executive leadership, and downward from strategic oversight to operational execution. This exchange is essential for maintaining situational awareness and ensuring that risk mitigation efforts are both evidence-based and scalable.

At the operational level, DCISOs are accountable for reviewing, prioritizing, mitigating, and accepting risks within their domains. This domain-aligned ownership model ensures that accountability for cybersecurity risk is clearly defined and directly connected to enterprise decision making.

Once risks are identified, they are reviewed on a recurring basis and aggregated to inform enterprise-level prioritization. Risk acceptance decisions are tiered based on residual risk levels and aligned with Microsoft’s defined risk appetite. They are then governed and monitored to ensure consistency and appropriate oversight.

A pyramid with bidirectional arrow showing how risk information flows back and forth from foundational elements to senior leadership.

Foundational elements

Listening systems

  • Internal and external audits
  • Current and pending regulation
  • Incidents and media
  • Industry groups

Methodology

  • Risk management framework
  • Risk rating criteria
  • Risk universe

Tools

  • Power BI
  • Risk portfolio and accountability matrix
  • Risk assessments
  • NIST cybersecurity assessments

Risk domains

  • Cybersecurity
  • Quality and availability
  • Business resilience
  • Corruption
  • Digital safety and service misuse
  • Product safety
  • Sustainability
  • Global trade
  • Antitrust and regulation
  • Talent management
  • Data privacy
  • Supply chain
  • Financial
  • Facility security and people safety

Operational risk

  • Search, advertising, and news
  • Artificial intelligence
  • Cloud and AI
  • Commercial business
  • Consumer business
  • Security
  • Experience + Devices
  • Customer and partner solutions
  • Gaming
  • LinkedIn
  • Corporate, External, & Legal Affairs (CELA)
  • Finance
  • Human resources
  • Business development and corporate strategy
  • Marketing

Enterprise risk

  • Identify, assess, and prioritize risk to strategy
  • Senior leadership accountability and mitigation quality
  • Enable board risk governance

Microsoft’s security standards are published on an annual basis, establishing explicit requirements for risk entry, scoring, and mitigation. Adherence to these standards is mandatory for all teams, ensuring uniformity and accountability across the organization. The standards are subject to periodic revision in response to evolving threats, regulatory developments, and historical incident analysis.

The CISO GRC team synthesizes risk intelligence into a semi-annual enterprise risk management (ERM) report. The report is disseminated to senior leadership and the audit committee, elevating cybersecurity risk management from operational domains to the highest levels of organizational oversight.

Microsoft also defines and tracks key risk management metrics to measure and evaluate the effectiveness of its cybersecurity risk management program, providing visibility into risk posture over time and enabling informed decision making as part of governance and reporting processes.

A lifecycle approach to risk management

Microsoft’s risk management lifecycle is organized into four principal stages: identification, assessment, mitigation and remediation, and prevention and monitoring. Each stage is designed to ensure that risks are logged, actively managed, tracked, and validated.

Risk identification draws on a range of inputs, including threat intelligence, penetration testing, post-incident reviews, security research reports, red team exercises, and internal assessments. Risks are also surfaced through self-identification by teams, findings from defense operations, and structured self-assessments, such as the annual NIST Cybersecurity Framework (CSF) maturity review. The process is designed to be inclusive, allowing any employee or vendor with appropriate access to submit risks into a centralized system. This multifaceted approach aims to provide a comprehensive view of the threat landscape.

Upon identification, risks are entered into a centralized risk register, which provides early visibility and facilitates prompt action. The system is designed to be inclusive, permitting any employee or vendor with corporate access to submit risks. This democratized process reflects Microsoft’s commitment to broad-based risk identification across the organization.

Risk assessment is conducted by specialized teams employing structured methodologies, including impact and likelihood scoring, root cause analysis, and contextual evaluation informed by both internal signals and external intelligence. Assessment methodologies align with enterprise risk management practices and incorporate factors such as impact, likelihood, and management action and control opportunities to determine overall risk prioritization. Curators, who are Microsoft domain experts with risk management training, triage and assign risks to the appropriate DCISO area, thereby ensuring consistency and objectivity across all domains.

Risk mitigation and remediation strategies are tailored to the specific characteristics of each risk. Mitigation efforts may be prioritized and driven at an enterprise level through initiatives such as the Secure Future Initiative (SFI), or managed within specific organizational domains depending on scope and impact. These may involve deploying new controls, process adjustments, or implementation of technological solutions. Each risk is assigned an owner who is accountable for executing the mitigation plan and validating its effectiveness. Progress is monitored through workflow systems, and validation steps are employed to confirm the sustained efficacy of mitigations. Following mitigation, outcomes may inform updates to Microsoft security standards to strengthen systemic controls and prevent recurrence.

Prevention and monitoring constitute ongoing activities. Insights derived from mitigation efforts are also used to inform improvements delivered to customers, including secure-by-default configurations, product controls, and published guidance. Microsoft utilizes regression prevention techniques, continuous monitoring tools, and assurance systems to ensure the durability of mitigations over time. Insights derived from these activities are reintegrated into the identification process, thereby establishing a continuous improvement loop that is essential for maintaining resilience in a dynamic threat environment.

A graphic showing different aspects of the four stages of the cybersecurity risk management lifecycle.
The four stages of the cybersecurity risk management lifecycle include identification, assessment, remediation, and prevention and monitoring.

The risk register: Centralized oversight

The cybersecurity risk register functions as the central repository for Microsoft’s risk management program.

The workflow for risk management within the register encompasses seven defined stages: submission, triage, response, confirmation, information sharing, mitigation, and archiving. Each stage is governed by explicit service-level agreements to ensure accountability.

Risks are required to be triaged and scored within a specific timeframe following submission, and mitigation plans must be developed within a defined period after prioritization. Risk owners are required to provide regular, ongoing updates on the process of mitigation activities.

To support this workflow, roles within the risk register are clearly delineated:

  • Risk Submitter: Responsible for providing comprehensive descriptions and supporting documentation for identified risks
  • Risk Curator: Charged with validating, prioritizing, and assigning risks to appropriate domains
  • Risk Owner: Accountable for implementing and monitoring mitigation plans
  • Risk Viewer: Individuals such as auditors and senior leaders who access risk data for oversight and compliance purposes

In addition to these roles, DCISOs provide domain-level oversight and accountability for risks, including prioritization, acceptance, and escalation to enterprise governance structures.

Risk Submitter

The Risk Submitter is an individual, FTE or vendor who enters a new or existing risk into the Risk Register. Anyone with corp access can submit a risk, including Microsoft security experts. Responsible for submitting a clear, detailed, and understandable title, description, and supporting information for a risk.

Risk Curator

Delegated to take action by their DCISO, these are engineers, architects or analysts with respective domain knowledge and context who are responsible for triaging and prioritizing submitted security risks, ensuring the right DCISO area ownership alignment, identifying ownership, and tracking remediation.

Risk owner

The Risk Owner is an FTE, typically in a DCISO’s scope, that is responsible for updating mitigation status of a prioritized risk. This accountability continues until all mitigations are complete and the risk is deprioritized or archived.

Risk Viewer

The Risk Viewer is an FTE who requires read-only access to risk data to fulfill a business or compliance obligation. Where possible, their access is limited to PBI reports instead of direct access to the Risk Register itself.

Risks are reviewed on a quarterly basis, and prioritized lists are communicated to leadership to inform strategic decision making. The centralized risk register enables prioritized risks to be surfaced and reported to the CISO function and Enterprise Risk Management (ERM), supporting enterprise-level visibility and oversight. These prioritized risks inform the Secure Future Initiative (SFI), which drives systemic change across Microsoft.

Regulatory compliance integration

Microsoft’s cybersecurity risk management program is aligned with global regulatory frameworks, including ISO 27001, NIST SP 800-53, and the NIST Cybersecurity Framework, and is continuously updated to incorporate emerging requirements such as DORA and NIS2. These regulatory baselines inform both control implementation and risk evaluation, ensuring alignment between compliance requirements and operational risk management activities.

DCISOs are responsible for regulatory implementation and compliance within their respective domains. This encompasses oversight of regulated sectors such as healthcare, legal, and government, as well as emerging domains including artificial intelligence safety and privacy. The Cybersecurity Governance Council conducts regular reviews of regulatory risks and ensures that mitigation strategies are aligned with statutory and legal obligations.

A graphic showing details about how cybersecurity risk management at Microsoft is integrated with our enterprise risk management process.
Our cybersecurity risk identification and risk assessment and remediation practices are aligned with and connected to our enterprise risk management reporting system.

ERM reporting integrates cybersecurity risks alongside financial and operational risks, thereby ensuring that regulatory compliance is embedded across the organization’s overall broader risk posture. This integrated approach enables Microsoft to respond expeditiously to regulatory changes and maintain trust with customers, partners, and regulatory authorities.

What makes Microsoft’s approach unique

The scale and complexity of Microsoft necessitate a risk management methodology that is both rigorous and adaptable. Several practices distinguish Microsoft’s program from industry counterparts.

The Secure Future Initiative (SFI) establishes a structured mechanism for driving systemic change, prioritizing critical risks and aligning mitigation efforts across engineering, operations, and executive leadership. While not all risks are represented within SFI, the initiative functions as a strategic accelerator, publicly articulating the prioritized risks and corresponding mitigation efforts that drive enterprise-wide improvements.

The culture of risk awareness is embedded throughout the organization. Risk identification is actively encouraged, and submissions are evaluated irrespective of origin, reflecting a commitment to democratized and proactive risk reporting. Internally, Microsoft advocates for a culture that celebrates the identification of risks and enables proactive reporting.

The governance cadence is highly disciplined; the Cybersecurity Governance Council convenes twice weekly, and DCISOs conduct reviews and confirm top risks every 90 days. These structured intervals ensure that risk management remains proactive, with clear accountability and continuous oversight.

The integration of operational and enterprise risk is seamless. The CISO GRC team synthesizes risk intelligence from across the organization and presents it in a unified ERM report, ensuring that cybersecurity risks are incorporated into strategic decision making, rather than isolated within technical silos.

Finally, Microsoft’s control ecosystem reinforces the durability of risk mitigation. Initiatives like the Secure Development Lifecycle (SDL), exception governance processes, and SFI collectively ensure that mitigations are implemented and sustained over time.

A blueprint for security leadership

Microsoft’s cybersecurity risk management program is a model of maturity, scalability, and transparency. The program integrates structured governance, rigorous processes controls, and a culture of accountability to ensure that risks are systematically identified, mitigated, and subject to continuous monitoring and improvement. For cybersecurity leaders seeking to understand risk management at scale, Microsoft offers a compelling blueprint: a proactive, integrated, and transparent framework that combines structured governance, rigorous process controls, and a culture of accountability.

Ultimately, cybersecurity risk management is not solely dependent on technical controls and frameworks; it is fundamentally about empowering individuals, building trust across teams, and connecting operational rigor with strategic clarity. If you are developing or refining your program, prioritize both structural and cultural elements, and build resilient processes around engaged teams. Security leadership presents significant challenges, but with the appropriate structure, culture, and rhythm, it can drive transformative outcomes.

Key takeaways

This article is not solely an account of Microsoft’s practices; it is a call to action for security leaders. If you are responsible for cybersecurity in your organization, here are five practical takeaways you can implement—regardless of your company’s size or industry:

  • Establish a structured governance cadence. Implement a regular schedule for risk management activities. While Microsoft’s Cybersecurity Governance Council convenes twice weekly, the essential principle is consistency. Monthly risk reviews and quarterly board updates can ensure sustained visibility and actionable oversight of cybersecurity risks.
  • Enable accessible risk reporting. Facilitate open channels for risk submission, allowing all stakeholders to contribute to risk identification. Democratizing risk reporting fosters transparency and organizational trust.
  • Integrate operational risk with strategic oversight. Elevate operational risks to enterprise-level reporting to ensure their inclusion in strategic decision making. Collaboration between security and enterprise risk teams is critical for comprehensive oversight. Risks that stay buried in technical teams rarely get the attention they deserve.
  • Implement structured risk lifecycle processes. Define clear roles, responsibilities, and timelines for each stage of the risk management lifecycle. Even in smaller organizations, a simplified version of this model can enhance accountability and progress tracking.
  • Proactively align with regulatory expectations. Maintain alignment with relevant standards and regulations, such as NIST, ISO, DORA, and NIS2. Regularly review emerging regulation requirements and collaborate with legal and compliance teams to ensure readiness.

Try it out

Related links

The post How we approach cybersecurity risk management at Microsoft appeared first on Inside Track Blog.

]]>
24461
Simplifying device registration at Microsoft with an agentic AI assistant http://approjects.co.za/?big=insidetrack/blog/simplifying-device-registration-at-microsoft-with-an-agentic-ai-assistant/ Thu, 25 Jun 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24507 When you’re busy at work, the last thing you want to do is spend hours getting a new device set up. In an ideal world, this process takes one, maybe two clicks—and then you’re off to the races. To make this ideal a reality, our team in Microsoft Digital—the company’s IT organization—created an agentic AI […]

The post Simplifying device registration at Microsoft with an agentic AI assistant appeared first on Inside Track Blog.

]]>
When you’re busy at work, the last thing you want to do is spend hours getting a new device set up. In an ideal world, this process takes one, maybe two clicks—and then you’re off to the races.

To make this ideal a reality, our team in Microsoft Digital—the company’s IT organization—created an agentic AI assistant that we’re now using to connect new devices to our network. We built the agent into GetConnected, the internal portal that 18,000 of our employees, vendors, and network administrators use each month to register their new devices to our network when they turn them on for the first time.

Our new workflow is simple, fast, and intuitive—and it’s a significant step up from our previous experience.

Creating the GetConnected AI assistant is part of the role we play as the company’s Customer Zero, where we test and use our technology and platforms first and then share our lessons learned with customers. In this case, we’re sharing how we used the Microsoft Agent Framework (MAF) to enhance onsite device management for our employees. GetConnected does not apply to remote device registrations.

A photo of Thompson.

“We’ve been looking across our set of services and capabilities to find places where we can do some experimentation leveraging AI. We wanted to be able to test our hypothesis around those AI investments and then be able to double down if it proved correct.”

Jason Thompson, principal PM manager, Microsoft Digital

Improving a highly trafficked internal tool using AI

Our employees use GetConnected to ensure their wired and wireless devices are registered on the network, as well as to extend device expiration dates and check on the status of their devices.

Heavy employee traffic and the repetitive actions users tend to take on GetConnected led us to realize that the tool was the perfect candidate for an agentic transformation. Our goal was to turn what was a five- or six-step process into something that could be completed in just one or two actions.

“We’ve been looking across our set of services and capabilities to find places where we can do some experimentation leveraging AI,” says Jason Thompson, a principal PM manager in Microsoft Digital. “We wanted to be able to test our hypothesis around those AI investments and then be able to double down if it proved correct.”

The team decided to start small, focusing on a couple of the most popular and crucial functionalities within GetConnected.

A photo of Dave.

“We’d seen previous projects that were very ambitious fail because they tried to achieve too much at one time. Based on customer feedback, we noticed that registration is the simplest, most common action that users were having trouble with. So we said, ‘Let’s do that first.’”

Aayush Dave, product manager, Microsoft Digital

It was also important to listen to our employees—our Customer Zero frontline users. They told us which actions in the experience mattered most to them.

“We’d seen previous projects that were very ambitious fail because they tried to achieve too much at one time,” says Aayush Dave, a product manager in Microsoft Digital. “Based on customer feedback, we noticed that registration is the simplest, most common action that users were having trouble with. So we said, ‘Let’s do that first.’”

Next up was deciding how the agent would appear in the portal. The Microsoft 365 Copilot model of a sidebar chat menu worked well for other workflows, so it seemed appropriate to approach the new GetConnected experience in a similar way. This enabled us to create a new experience alongside the existing workflow, so customers could still access the original process (should they need to) and compare the two experiences.

“Other teams might decide to automatically replace the UI with an agent,” says Faris Mango, a principal software engineering manager in Microsoft Digital. “But that’s hard, because now you’re forcing people to use the agent. If it’s not ready to be used at full capacity, they don’t have an alternative to accomplish what they intended. We wanted to avoid that situation.”

Testing out Microsoft Agent Framework (MAF)

To build the agent, we considered two paths.

The first was to directly call the Model Context Protocol using JavaScript, an option that would require significant amounts of coding on our part.

A photo of Sullivan.

“Some declarative agent systems do all of the things in the background, and you don’t get to turn all the little knobs. MAF gives you the flexibility to make the experience exactly what you want.”

Darron Sullivan, principal software engineer, Microsoft Digital

The second was to use Microsoft Agent Framework (MAF), which proved to be simpler and more customizable for our needs.

“Some declarative agent systems do all of the things in the background, and you don’t get to turn all the little knobs,” says Darron Sullivan, a principal software engineer in Microsoft Digital. “MAF gives you the flexibility to make the experience exactly what you want.”

The tricky part, however, was that MAF was fairly new at the time. In fact, the week that the team started developing the GetConnected agent was the same week that MAF was released in preview internally. As we were building out our agent, the framework was going through its own updates, which threatened to hinder our progress. Even one small change to the framework could break our tool’s entire functionality.

“They were moving really fast, and we were adopting new features and finding new bugs all the time,” Sullivan says. “You had to go through that rapid iteration and development, which is a challenge, but it was also pretty awesome because we’re working on the cutting edge.”

The upside was that we were able to provide valuable feedback to the MAF engineers, which in turn could supercharge the work we were doing on our agent. As a bonus, our partnership drove other teams to pursue similar projects.

“The knowledge sharing across our org was notable and crucial,” Dave says. “Our team was one of the first to start building a solution like this, and we presented in numerous architecture forums to share the components and frameworks we were using, and the teams we were working with. This brought the tide up for all boats in our organization, encouraging other teams to start kicking off similar projects as well.”

Building a seamless, discoverable interface

The agent currently has several key functions, the most prominent of which is to register a device on your behalf.

Previously, employees would have to fill in a long, complicated form that asked for a lot of technical details that they often didn’t know offhand, like type of device or the preferred network.

Instead of just selecting options and approving, the flow is more conversational. The user can start with a suggested prompt like “Help me register a device,” and the agent will ask for the required information (with examples for each field). If the user isn’t sure about something (for example, how to find a MAC address), they can ask follow-up questions, and the agent will pull in FAQ and help content to guide them.

Once all the required details are collected, the agent can complete the registration on the user’s behalf after the user approves it.

Once it has your approval, the chatbot submits the request and replies whether or not it was successful. Users can also ask the agent to show devices that are expired or will soon expire, then prompt the agent to renew those devices if desired.

A screenshot of the The GetConnected Portal homepage with the GetConnected AI Assistant asking the user how it can help.
The GetConnected AI assistant asks Aayush Dave, a product manager in Microsoft Digital, how it can help him in an interface that appears on the GetConnected portal homepage.

Seamlessly integrating the agent into GetConnected required upgrading the existing user interface using Fluent.

These updates were needed to support the AI interface integration. Specifically, we introduced a custom header action to launch the AI side panel. Prior to upgrading, doing this would have required using Coherence components outside of their intended patterns.

A photo of Chambers.

“We used Fluent AI components to build the AI interface. This helped ensure a consistent Microsoft look and feel across the experience, built-in accessibility for scenarios like screen readers and mobile usage, and components that are designed for conversational and agent-driven interactions.”

Nathan Chambers, software engineer, Microsoft Digital

To stay consistent with the existing app architecture, we upgraded core dependencies like Fluent UI and Coherence to their latest versions. As part of upgrading Coherence across several major versions, it also required us to move the feedback experience to Centro to align with the updated patterns. We then needed to update other parts of the experience like navigation, FAQ, and release notes to match those newer component patterns.

“We used Fluent AI components to build the AI interface,” says Nathan Chambers, a software engineer in Microsoft Digital. “This helped ensure a consistent Microsoft look and feel across the experience, built-in accessibility for scenarios like screen readers and mobile usage, and components that are designed for conversational and agent-driven interactions.”

While making these upgrades, we ran tests to ensure the experience was accessible—for example, for screen reader users or others who might access GetConnected on their phones.

A photo of Mango.

“You can have an amazing, strong piece of software that is well built and focuses on security. But if you don’t have the traffic or people are not using it, it’s worthless.”

Faris Mango, principal software engineering manager, Microsoft Digital

Next, we wanted the agent to be as discoverable as possible. Without people actually navigating to it, there would be no way to show proof of concept. So, we built it so the agent automatically popped open via a side panel when someone loaded GetConnected.

“You can have an amazing, strong piece of software that is well built and focuses on security,” Mango says. “But if you don’t have the traffic or people are not using it, it’s worthless.”

We also wanted to gather early feedback from users. Before releasing it to the entire company, we had internal team members and frequent GetConnected users give the agent a try. Almost immediately, it was clear we had too many approval notices.

“At the beginning, we would have approvals for every single action. For example, if you wanted to see a device in different regions like Puget Sound, Latin America, or Canada, you had to do a separate approval for each region,” Dave says. “This was a very painful experience. So we removed all the approvals and pared it down to a one-click experience.”

Users also had issues with the approval language, which they said was hard to understand and looked like an error message. The next iteration took out much of the technical jargon, making the message more conversational and easier to read.

An agent experience driven by feedback

Our work as Customer Zero is never done. For GetConnected, we’re eager to keep collecting feedback. One major goal is to improve the agent’s performance, making it faster and more responsive.

Our feedback survey is tied directly to a performance dashboard, which tracks metrics like new and returning users, total unique users, conversions, and interactions. Each user submission generates a work item.

“When users leave feedback about something they don’t like, I feed that to the team, and then we sit down and figure out how we can improve that specific part of the experience,” Dave says.

With each update, we’re seeing the payoff of more users and more interactions. The traditional method of registering a device is also seeing a drop-off as more people lean on the agent for assistance.

“Before, you used to have to go into the system and change something about the experience manually. Now, our engineers are going to an AI model and telling it, ‘Hey, you’re doing this part wrong, please improve it.’”

Aayush Dave, product manager, Microsoft Digital

Looking ahead to more use cases

Building an agent has allowed the team to embrace an entirely new type of engineering.

“Before, you used to have to go into the system and change something about the experience manually,” Dave says. “Now, our engineers are going to an AI model and telling it, ‘Hey, you’re doing this part wrong, please improve it.’”

It’s also serving as a reminder to seek progress over perfection.

“AI is changing things so quickly,” Thompson says. “It’s better to do rapid prototyping and roll it out, and start getting the data in terms of how successful the experience is. Then you can let that guide you, in terms of how you iterate going forward.”

Because of the success we’ve had with the GetConnected device registration feature, we’re already exploring other capabilities, including bulk operations to accommodate our facilities managers who need to onboard many devices at once. As AI agents become mainstreamed in many workflows across our organization, we anticipate usage and functionality will continue to grow exponentially.

Key takeaways

If you want to create a similar agent to streamline processes or automate workflows in your organization, keep these tips in mind:

  • Transition gradually and maintain existing experiences. Until you’re confident users are happy with the new product, continue to give them access to original workflows. This allows them to compare experiences and provide contextual feedback.
  • Remove unnecessary steps for simpler processes. The user  need to formally approve every step along the way. Cut the cognitive load and focus on getting user signoff where it counts.
  • Check existing systems for compatibility. Before diving into design, ensure that your current systems can support your goals, and address any gaps early on to avoid running into limitations later.
  • Get feedback early and often. Release a minimum viable product to users to make sure it aligns with how they work, and fix any bugs before expanding its capabilities.
  • Maintain a low ego. Take user feedback to heart. Put their needs first, rather than what you think the product should be.

Try it out

Related links

The post Simplifying device registration at Microsoft with an agentic AI assistant appeared first on Inside Track Blog.

]]>
24507
Guiding our AI deployment with a set of employee councils http://approjects.co.za/?big=insidetrack/blog/guiding-our-ai-deployment-with-a-set-of-employee-councils/ Thu, 18 Jun 2026 16:05:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24374 The AI adoption curve gets steeper every day, as the technology continues to advance at lightning speed. At Microsoft Digital, the company’s IT organization, we’re using a set of employee councils and connected capability groups to guide and accelerate how we deploy and adopt AI across our enterprise. Our goal is to focus our energy […]

The post Guiding our AI deployment with a set of employee councils appeared first on Inside Track Blog.

]]>
The AI adoption curve gets steeper every day, as the technology continues to advance at lightning speed.

At Microsoft Digital, the company’s IT organization, we’re using a set of employee councils and connected capability groups to guide and accelerate how we deploy and adopt AI across our enterprise. Our goal is to focus our energy on the AI-enabled scenarios that matter most, reducing duplication, strengthening accountability, and making sure our investments create measurable value.

A photo of Campbell.

“Our AI decisions and direction must be grounded in business strategy. AI councils provide guidance and enablement for our organization, ensuring that our investments in AI generate tangible benefits to our business. It’s not just developing technology and then looking for a problem to solve with it—we start with the opportunity.”

Don Campbell, principal group technical program manager, Microsoft Digital

That focus matters, because AI success doesn’t come from usage alone. It comes from connecting strategy, enablement, data readiness, responsible AI, continuous improvement, change management, and measurement into one driving force.

That’s how we’re moving from experimentation to repeatable outcomes and from AI enthusiasm to AI accountability.

“Our AI decisions and direction must be grounded in business strategy,” says Don Campbell, principal group technical program manager in Microsoft Digital. “AI councils provide guidance and enablement for our organization, ensuring our investments in AI generate tangible benefits to our business. It’s not just developing technology and then looking for a problem to solve with it—we start with the opportunity.”

Our council-based approach is helping us accelerate our Frontier Firm transformation. The councils work together to set direction for AI adoption at Microsoft Digital, ensuring that our business needs drive solution development that can keep up with the pace of AI change. This work includes building visibility into all our AI solutions, including agents and Model Context Protocol (MCP) servers, while establishing governance and proven practices; developing training and learning pathways; and connecting teams together that are working on similar solutions across the enterprise.

We’re excited for a future where our employees use intelligent agents and human judgment together to work smarter, move faster, and unlock new value for Microsoft and our customers.

Why we use councils to guide internal AI efforts

Effective AI needs both enterprise guidance and business-owned direction. That’s why we’re using councils and connected capability groups as the operating model for our AI deployment.

Each group has a distinct role, and none of them work alone. Together, they help us connect the strategy for AI to the work currently happening across Microsoft Digital.

  • Our strategy council sets priorities by aligning AI work to business goals, identifying top scenarios, prioritizing investments, and keeping KPIs and value in focus.
  • Our enablement council uses our AI Center of Excellence to turn strategy into action through technical guidance, proven practices, ideation, learning, knowledge sharing, culture, and governance.
  • Our data council strengthens the AI foundation via data strategy, governance, access, quality, literacy, and prioritization.
  • Our process council drives continuous improvement through operational excellence, problem solving, prioritization, value realization, coaching, and learning.
  • Our compliance council applies Responsible AI principles to ensure compliance, inclusiveness, fairness, transparency, and reliability.
  • Measurement ties it all together by tracking both business outcomes and engineering artifacts, ensuring we can clearly demonstrate real-time value realization.  

These councils help us see across the business landscape through the lens of AI. They enable us to reduce duplication, scale what works, and make better decisions about where AI can create value. That allows our teams to keep moving fast without letting activity get ahead of accountability.

Aligning AI strategy to business value

Our strategy council helps us decide which AI-enabled scenarios deserve the most attention, which investments align to our business priorities, and how we’ll know whether the work is creating value. It gives leaders a practical way to look across the portfolio and keep our AI work tied to the outcomes we’re accountable for.

A photo of Wu.

“Business strategy defines the what and the why. AI defines the how, enabling execution of the strategy and delivering real value. We should use AI to advance our business strategy, not the other way around.”

Qingsu Wu, principal group product manager, Microsoft Digital

This is important, because broad experimentation is useful early on in your AI journey. It helps teams learn and build momentum. But experimentation has to mature into focus. Without that shift, organizations can end up with too many different agents, agent skills, MCP servers, and other artifacts, without a clear view of what’s actually impacting the business.

We’re using the strategy council to keep that from happening.

“Business strategy needs to lead the AI strategy,” says Qingsu Wu, a principal group product manager in Microsoft Digital and an influential member of the strategy council. “Business strategy defines the what and the why. AI defines the how, enabling execution of the strategy and delivering real value. We need to use AI to advance our business strategy, not the other way around.”

That principle shapes how we work. We use the strategy council to identify our top AI-enabled scenarios, clarify the value we expect to create with each one, and connect that work to a monthly operating rhythm. Product owners still manage delivery and the council keeps the portfolio focused, visible, and aligned.

Tuning strategy into repeatable execution

Our AI Center of Excellence (CoE) is at the heart of our approach to enablement. It helps us translate enterprise AI priorities into practical guidance and execution support for teams building AI-enabled solutions.

A photo of Khetan.

“We can see patterns that a single team can’t. We’re translating AI CoE strategy and enterprise priorities into clear execution plans that work in each organization’s context. That allows us to align priorities and make sure our biggest bets are actually landing.”

Ria Khetan, senior program manager, Microsoft Digital

The AI CoE extends the reach of the strategy council. It gives teams what they need to build, govern, reuse, and scale what matters, while the strategy council assists us in deciding where to focus.

That connective role is central to the broader council model. The strategy council identifies the top AI-enabled scenarios. The AI Center of Excellence connects strategy to execution across the organization, operating as a cross-functional coordination layer that sets direction and creates shared accountability.

“We can see patterns that a single team can’t,” says Ria Khetan, a senior program manager in Microsoft Digital, who is a member of the council. “We’re translating AI CoE strategy and enterprise priorities into clear execution plans that work in each organization’s context. That allows us to align priorities and make sure our biggest bets are actually landing.”

The COE helps teams move those scenarios forward with answers to important questions:

  • What initiatives are in flight?
  • What initiatives bring the most return on investment?
  • Where is there potential duplication?
  • Where do we need clearer guidance?
  • Where do we need stronger governance?

It also helps reduce fragmentation. When teams build in isolation, they can solve the same problem in different ways. They can choose different patterns, interpret standards differently, or create solutions that don’t scale beyond a single context. Enablement gives us a shared way to look across that activity and ask better questions.

“We use the CoE to bring consistency to how AI work gets done,” Campbell says. “It gives us a way to step back and ask whether we’re solving the right problems and whether we’re set up to scale.”

A photo of Uribe.

“High-quality, well-governed data is essential to accelerate AI implementation and adoption, and to ultimately unlock its full value. Data quality, accessibility, and governance are imperatives for AI systems to be reliable, scalable, and business-critical. Recognizing this principle is propelling our data strategy.”

Miguel Uribe, principal PM manager, Microsoft Digital

Building AI on trusted data

Our AI scale depends on trusted and reliable data. That makes our data council central to our council-based approach. This council makes sure our teams work with data that’s governed, discoverable, accessible, and ready for AI.

“High-quality, well-governed data is essential to accelerate AI implementation and adoption, and to ultimately unlock its full value,” says Miguel Uribe, a principal PM manager in Microsoft Digital and member of the data council. “Data quality, accessibility, and governance are imperatives for AI systems to be reliable, scalable, and business-critical. Recognizing this principle is propelling our data strategy.”

We’re applying a data mesh mindset to balance domain ownership with enterprise consistency. Teams stay close to the data that they know best. Shared standards for governance, quality, metadata, and compliance provide a framework to make that data useful across Microsoft Digital.

Microsoft Fabric and Microsoft Purview are key to that approach. Microsoft Fabric unifies our siloed data in a shared data mesh. Microsoft Purview enables governance and best practices to ensure that we manage our data responsibly through discovery, classification, protection, and monitoring.

Our goal is AI-ready data that’s available, complete, accurate, and high quality. Our data council also works with the AI Center of Excellence to strengthen data and AI fluency through learning pathways, operational practices, and community programs.

A photo of Laves.

“Our capacity to drive process improvements has been crucial to our AI transformation as a company. We’ve adopted a ‘CI before AI’ approach to ensure that we don’t end up automating inefficient processes.”

David Laves, director of business programs, Microsoft Digital

Improving the process before applying AI

AI works best when it’s applied to the right problem. That’s why continuous improvement is part of our council-based approach. Before teams automate a workflow or build an agent, we want them to understand the process, identify waste, and decide where AI can create measurable value.

“Our capacity to drive process improvements has been crucial to our AI transformation as a company,” says David Laves, director of business programs in Microsoft Digital and a member of the Continuous Improvement Center of Excellence. “We’ve adopted a ‘CI before AI’ approach to ensure that we don’t end up automating inefficient processes.”

Continuous improvement helps teams make sure the underlying work is worth scaling. That’s when a continuous improvement approach can help. It encourages practices like Gemba walks, Kaizen events, bowler cards, and monthly business reviews that allow our teams to understand where work gets stuck and where AI can help.

Continuous improvement keeps the council model grounded in real work. We’re applying it where the process is understood, the value is clear, and the outcome can be measured.

Scaling AI responsibly

Our compliance council encourages the application of Responsible AI, so our teams can move faster with confidence. As our AI work scales across Microsoft Digital, responsible AI has to connect directly to the same council ecosystem that guides strategy, enablement, data, process, and measurement. That connection helps teams understand what they’re accountable for before they build too far, too fast.

Our responsible AI work focuses on compliance, inclusiveness, fairness, transparency, reliability, privacy, security, and accountability. It’s grounded in the Microsoft Responsible AI Standard and supported by responsible AI champions who help teams apply those expectations in real development workflows.

This approach gives teams structure. It allows them to assess impact, identify risks, document decisions, and bring in the right reviewers. It also creates consistency, as more AI agents and solutions move from experimentation into enterprise use.

The goal is to enable AI project teams to move in the right direction with the right safeguards. Responsible AI gives the strategy council, the AI Center of Excellence, the data council, and product teams a shared standard for trust—to turn ambition into accountable execution. It also makes sure the AI systems we scale are worthy of the trust that employees, customers, and the company place in them.

Measuring our AI outcomes

Our councils choose the right AI work, support teams as they build, strengthen the data foundation, apply responsible AI, and improve processes before we scale. But we still need to answer the most important question: What changed because of the AI investment?

That’s why we have built a common value measurement framework across Microsoft Digital. Our teams use the framework to define expected value before they build. With it, they can establish a baseline, track results, and review what they learn with the right business and AI owners.

We organize AI value across six areas: Revenue impact, productivity and efficiency, security and risk management, employee and customer experience, quality improvement, and cost savings. Not every initiative needs to deliver value in every category. The point is to create a shared language that leaders and teams can use to compare investments, make tradeoffs, and understand progress.

Measurement also pushes us past simple savings claims.

If AI saves time, reduces cost, improves quality, or increases coverage, we want to know what happens next. Did teams reinvest that capacity? Did service improve? Did risk go down? Did quality increase?

AI accountability depends on that full loop. We define value, measure results, review progress, and adjust. Then we use what we learn to guide the next round of decisions.

Operating as one connected AI system

Our AI councils make a difference because each group has a different focus.

A photo of Wan.

“What got us here won’t get us to where we need to go next. We started with broad experimentation—getting teams excited and building—but now we’re evolving as an organization to think about scale, alignment to business goals, and making sure our investments are driving the right outcomes.”

Myron Wan, principal group product manager, Microsoft Digital

Strategy assists us in choosing the right priorities. Enablement helps our teams to build with shared patterns. Data readiness gives AI systems a trusted foundation. Responsible AI allows us to move faster with confidence. Continuous improvement makes sure we’re improving the work before we automate it. Measurement tells us whether the investment changed anything meaningful.

Together, this system means we can operate AI as a business-driven enablement system.

“What got us here won’t get us to where we need to go next,” says Myron Wan, a principal group product manager in Microsoft Digital. “We started with broad experimentation—getting teams excited and building—but now we’re evolving as an organization to think about scale, alignment to business goals, and making sure our investments are driving the right outcomes.”

There’s more work ahead. We need to keep scaling enablement, improving data readiness, increasing high-value use cases, showcasing measurable impact, and tightening alignment across teams.

We also need to keep asking the hard questions: Where should we invest? Where are we reducing risk? Are we reinvesting the value that AI creates?

Our council-based model allows us to answer those questions with discipline. It helps us connect AI ambition to business outcomes and move from experimentation to repeatable enterprise value. And it provides a practical model that other IT organizations can adapt as they guide their own AI deployment.

Key takeaways

Here are the core actions organizations like yours can take to align your AI efforts to business targets and scale them responsibly:

  • Start with business value. Use strategy to focus AI work on the outcomes that matter most.
  • Build a connected operating model. Bring strategy, enablement, data, responsible AI, process improvement, and measurement together.
  • Reduce duplication. Make your AI initiatives visible across teams so proven patterns can scale.
  • Strengthen the foundation. AI-ready data and responsible AI practices are core to enterprise scale.
  • Measure and reinvest. Track value, review progress, and use what AI gives back to create new capabilities.

Try it out

Related links

The post Guiding our AI deployment with a set of employee councils appeared first on Inside Track Blog.

]]>
24374
Digitally transforming Microsoft: Our IT journey http://approjects.co.za/?big=insidetrack/blog/digitally-transforming-microsoft-our-it-journey/ Thu, 18 Jun 2026 16:00:33 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=18521 The digital transformation of Microsoft spans the entire personal computing revolution, from the days of DOS and early Windows desktops, through our journey to the Azure cloud and into the era of AI and agents. Today, the company has grown into a global organization with more than 200,000 employees. They all rely on Microsoft Digital—the […]

The post Digitally transforming Microsoft: Our IT journey appeared first on Inside Track Blog.

]]>
The digital transformation of Microsoft spans the entire personal computing revolution, from the days of DOS and early Windows desktops, through our journey to the Azure cloud and into the era of AI and agents.

Today, the company has grown into a global organization with more than 200,000 employees. They all rely on Microsoft Digital—the company’s IT organization—to provide the tools, technologies, and solutions that empower them to accomplish more every day.

The need for digital transformation

The history of information technology is one of constant evolution, and the pace of change has never felt greater than it does right now. The AI capabilities and other groundbreaking innovations unveiled in the last few years show the potential to radically transform our world and change the way we think about and operate all IT services.

When the world pivoted to remote online work and collaboration because of the COVID-19 pandemic, it was just one example of how digital transformation doesn’t always happen in a straight line or on a predictable schedule. Our company’s history of shaping and adapting its IT organization to the latest challenges faced by employees and partners is no different; marked by big bets and strategic shifts that reflect our ever-changing world.

Mapping our IT journey

Timeline graphic shows the four eras of Microsoft IT (On-Premises IT, Cloud and Culture, Modern Engineering, and AI) along with major milestones in each era.
The four eras of digital transformation of IT at Microsoft : On-Premises IT, Cloud and Culture, Modern Engineering, and the Era of AI.

Today, Microsoft Digital is the team that powers, protects, and transforms the digital employee experience across all devices, applications, and hybrid infrastructure at the company. Using our deep knowledge and experience in enterprise IT, we’re pivoting to help lead the company’s AI transformation while also sharing our journey with customers so they can take advantage of this generational opportunity to reshape their businesses and IT operations.

To understand where we’re going, it helps to take a look at where we’ve been. This article explores the details of the major eras of our IT history and then shifts to examine the trendlines and technological innovations that are shaping Microsoft now.

On-Premises IT (founding to 2009)

It’s useful to break the history of our IT operations into different eras. For the first three decades or so from its founding in 1975, Microsoft operated with on-premises IT systems. This era was characterized by the setup, operation, and maintenance of onsite physical technology—servers, datacenters, and other hardware infrastructure.

During this time, IT roles were narrowly defined. IT team members functioned primarily as “order-takers,” with limited influence over strategic decisions.

Because funding was inconsistent, our IT organization had limited growth opportunities and relied on vendors for development work. Gaps were filled in with “shadow IT,” where internal teams would sometimes procure their own hardware or software without formal IT approval or standards.

We established security as an early priority for the company. Cofounder Bill Gates launched the Trustworthy Computing initiative more than two decades ago, an effort emphasizing the importance of security, privacy, and reliability across Microsoft products and services both internally and externally.

Our On-Premises IT era established the foundation that would become crucial to the company’s future digital transformation.

All in on the cloud: The Cloud and Culture era (2010-2018)

Image showing Ballmer presenting at an event, with Windows Azure and Azure DevOps logos overlaid on the photo.
Former Microsoft CEO Steve Ballmer led the shift to the cloud that began in the early 2010s.

Cloud computing marked the next significant shift in the history of IT at Microsoft. It began in 2010 under the leadership of CEO Steve Ballmer, signaling a major break with the previous era of physical IT infrastructure and an important step toward today’s distributed-computing world.

The launch of the cloud computing platform then known as Windows Azure heralded this new era, as we transitioned away from an IT philosophy focused on the Windows desktop client toward a more platform-agnostic view. Cloud computing offered extensive advantages for customers and for our own IT environment, in terms of cost, performance, security, and scalability.

We started our journey by moving productivity workloads (Exchange and SharePoint) to the cloud. Then, we shifted new development to Azure and optimized modern applications to run in the cloud. We also moved existing applications targeted for migration to virtual machines. Today, more than 98% of our IT workloads run on Azure.

Cultural transformation

Another important shift during this era was the profound cultural transformation at Microsoft sparked by new CEO Satya Nadella, who rose to the top job at the company in 2014. Nadella had previously run the Microsoft cloud computing and enterprise group, so he was already steeped in the idea of transformational change at the company.

A photo of Nadella.

“Achieving our mission requires us to evolve our culture. It all starts with a growth mindset—a passion to learn and bring our best every day to make a bigger difference in the world.”

Satya Nadella, CEO, Microsoft

Before Nadella’s ascension, Microsoft had long been known for its extremely competitive, “know-it-all” culture. Employees succeeded by showcasing their own individual achievements and how their accomplishments exceeded their peers.

Nadella changed this ethos by championing a growth mindset, encouraging employees to be “learn-it-alls” rather than “know-it-alls.” The shift included placing new importance on how employees contributed to the success of others, a value that was incorporated into individual performance reviews. Nadella made this transformation his personal mission and directed leadership to propagate the new philosophy at all levels across the organization.

“Achieving our mission requires us to evolve our culture,” Nadella says. “It all starts with a growth mindset—a passion to learn and bring our best every day to make a bigger difference in the world.”

The combination of the shift to cloud computing infrastructure and overhauling the company culture helped set the stage for the major technological innovations to come.

A new vision: The Modern Engineering era (2018-2023)

For years, IT at Microsoft had been order takers, doing what the business requested with limited ability to impact strategic priorities. That changed as we shifted to become a modern engineering organization. With support from our executive leadership, IT was elevated to become a peer engineering function at Microsoft.

Rather than simply taking orders, the team was empowered to lead with a strong vision for the future. In fact, leading with vision is the primary hallmark of our Modern Engineering era. As we moved into this era, we needed a clearly articulated view of our goals as an IT organization aligned to the needs of our business partners, as well as the resources needed to achieve them.

Role transformation

Transitioning to become a modern engineering organization required Microsoft Digital to adapt our legacy approach to IT.

Operating an engineering organization in a cloud environment meant new roles, new skills, and a new mindset. With no need to manage physical hardware, our modern IT professionals were freed to work more closely with business partners, requiring greater strategic acumen. The team was now focused on DevOps, Agile program management, and user-centric design principles.

User-centric, coherent design

Our design philosophy puts the user—an employee or guest—at the heart of every decision we make at Microsoft Digital.

The goal of this approach is to make tasks that might have previously caused friction to become simpler. Instead of dealing with disconnected systems, user-centric design introduces consistent and logical flow between services. This makes it easier for people to access services, learn how to use them, and then put them to good use.

Microsoft also embraces coherent design across all our products. A familiar look and feel, along with consistent usage patterns, accelerates employee usage and adoption. 

Embracing work-from-anywhere capability

During the pandemic, when our workforce was still fully remote, our organization was already starting to think about what the new hybrid workplace would look like when people started returning to the office. We identified three key dimensions of the employee experience:

  • Physical spaces: We partner with Global Workplace Services to plan and deploy meeting spaces with amazing digital capabilities that support an inclusive approach to hybrid productivity.
  • Digital capabilities: We keep employees productive and their digital environment safe and secure, no matter where they’re located or how they connect.
  • Culture: A strong partnership with HR ensures that digital experiences support our company culture.

Managing shadow IT with a culture of trust

Shadow IT is the unknown and unmanaged set of applications, services, and infrastructure that are developed and managed outside standard IT policies. Shadow IT typically crops up when engineering teams are unable to support the needs of non-engineering partners, a situation that could arise from a lack of available capacity or the need for specialized domain solutions. 

While earlier eras of our IT history focused on trying to prevent shadow IT, we are now concentrating on managing it. We use Azure best practices to optimize shadow IT and Microsoft 365 governance policies to ensure that our corporate security, privacy, and accessibility standards are met. We empower our employees to create whatever they need within our tenant, including PowerApps, SharePoint sites, Teams channels, or agents, mitigating the need for “shadow” solutions while also providing visibility into how our employees are using our own technology.

Learn how optimizing our Microsoft Azure usage is helping us manage our Shadow IT.

The Era of AI (2023 to present)

The latest chapter in the history of our organization’s digital transformation is defined by the integration of AI and agents into IT operations. AI is revolutionizing how Microsoft does IT at enterprise scale, driving efficiency and innovation across the board. From the apps, workflows, and services that power our employee experience to the network, infrastructure, and devices that enable employee productivity, our AI-focused investments provide a solid foundation for the innovations that we are constantly implementing. As we look at the future of Microsoft Digital, we’re focused on four key priorities: security, service fundamentals, acting as Customer Zero, and AI-powered innovation. We’re working to excel in all four domains with the help of our industry-leading AI capabilities.  

A photo of Fielder.

“Our mission is to power and protect Microsoft, and that starts with an unwavering commitment to the Secure Future Initiative.”

Brian Fielder, vice president, Microsoft Digital

Securing our future

Security is our highest priority. The Microsoft Secure Future Initiative aligns every team with a shared approach, common priorities, and consistent milestones to harden our security posture across all products and services.  

“Prioritizing security above all else is critical to our company’s future,” Nadella says. “Every task we take on—from a line of code to a customer or partner process—is an opportunity to help bolster our own security and that of our entire ecosystem. If you’re faced with a tradeoff between security and another priority, your answer is clear: Do security.”

The Secure Future Initiative is built on three core principles: Secure by design, secure by default, and secure operations. As the company’s IT organization, we work relentlessly to fulfill the key pillars of the Secure Future initiative across all our systems, including:

  • Safeguarding identities and secrets
  • Protecting tenants and isolating production systems
  • Securing networks and engineering systems
  • Enhancing threat detection
  • Expediting response and remediation

“Our mission is to power and protect Microsoft, and that starts with an unwavering commitment to the Secure Future Initiative,” says Brian Fielder, vice president of Microsoft Digital.

Secure Future Initiative | Microsoft

Foundations: Service fundamentals

The second pillar is to maintain the highest standards of service fundamentals. These are the essential capabilities and practices that enable us to deliver reliable, secure, and compliant services companywide. Adhering to the highest standards of service fundamentals ensures that our organization continues to play a critical role in running the company’s business and enabling innovation, agility, and resilience in a fast-changing and competitive environment.

Customer Zero

The third pillar is acting as Customer Zero for Microsoft’s most important products and services, like Copilot Studio, Microsoft Teams, and Agent 365. In Microsoft Digital, we take pride in being the first customer for a wide variety of Microsoft products and services, relentlessly focusing on our own employee experience to create products that enable every person on the planet to achieve more.

Being Customer Zero means forging a deep partnership between our IT organization and product engineering groups to envision the right experiences, co-develop innovative solutions, and then listen to and act on insights gathered from our employees. We work together to stay grounded in the way our employees use our products every day, so your employees can benefit from our insights prior to external product launches.

Read about how we’re improving our employee experience through our Customer Zero focus.

AI-powered innovation

The final pillar of this era is innovating with AI to transform the digital experience at Microsoft. By doing all the fundamental work detailed above—security, foundations, and Customer Zero—extremely well, we gain the confidence and earn the trust necessary to embed AI across our full portfolio of services. We do this over three key dimensions: core IT services, employee experiences, and corporate functions.

Core IT services: Transforming and securing our network and infrastructure

We’re focused on using AI to infuse data-driven intelligence into every part of our infrastructure and network operations. This allows us to optimize operations and increase security while simultaneously improving outcomes.

Examples include:

  • Network observability and governance: Ensuring data accuracy, eliminating non-compliant hardware and software, and real-time updates
  • Securing endpoints: Device management, asset management, and patching
  • Zero Trust networking: Isolating device classes and limiting attacker’s movements across the network
  • Network access: Azure VPN, identity management, and Secure Access Workstation (SAW) infrastructure security

Learn how we’re transforming our enterprise IT operations at Microsoft.

Core IT services: Tenant management

We manage one of the most complex tenants anywhere. Governance today is a somewhat fragmented experience, with no clear mechanism for IT to safely enable self-service asset creation for sites, Teams, groups, Power Apps, and so on. These unmanaged assets increase the risk of over-sharing sensitive data and compromise the health and security of our IT environment.

In the world of AI, security through obscurity is no longer a viable option. This means data hygiene, permission management, and data protection are essential to providing trustworthy AI tools that don’t overexpose sensitive content, while still providing quality responses.

Read about one way we’re improving security by protecting elevated-privilege accounts at Microsoft.

Core IT services: Support

We’re using generative AI to transform the way our employees interact with our support services. IT issues will be either auto-remediated or resolved remotely and instantly through conversational, personalized, and contextualized solutions, often without a human agent’s intervention.

We’ll accomplish this with a focus on the following:

  • User experience: Our employees are using the AI-powered Employee Self-Service Agent to access personalized, accurate, and cost-effective issue resolution. Future goals include implementing a seamless transition to a human agent while the user stays within the agentic Copilot experience.
  • Human agent experience: Operational efficiency and automation are being integrated into the Service Operations Workspace. The service includes chat and incident summarization that recommends best next actions and drafts contextual answers to queries.

Find out how we’re transforming IT support at Microsoft with AI and the Employee Self-Service Agent.

Defragmenting the employee experience

The second dimension where we’re implementing our AI vision to make a difference is our employee experience. Our vision is to deliver a unified, connected, and personalized experience where users can access employee data, tools, and insights from one place.

A photo of Alaparthi

“We see AI as the key to unlocking the full potential of our employees, delivering personalized experiences that empower us to work smarter, faster, and happier—unleashing the innovation and collaboration necessary for our success.”

Vijaya Alaparthi, principal group product manager, Microsoft Digital

One of the key ways we’re doing this is with Microsoft 365 Copilot, which functions as a “UI for AI” across our employee tools and services. An example is our Employee Self-Service Agent, an AI-driven tool based on Copilot that helps employees more efficiently find context-specific answers to their questions using natural language queries.

“We see AI as the key to unlocking the full potential of our employees, delivering personalized experiences that empower us to work smarter, faster, and happier—unleashing the innovation and collaboration necessary for our success,” says Vijaya Alaparthi, a principal group product manager in Microsoft Digital.

To achieve our vision, we’re building a workplace where AI defragments the employee experience by:

  • Providing contextual support in the flow of work
  • Reducing the number of sites and apps an employee must remember
  • Using Microsoft 365 Copilot as the “UI for AI,” making it simple for employees to find information, take action, and even fully automate certain repeatable tasks

Corporate functions growth

Our third major priority in Microsoft Digital is to improve how we support the company’s corporate functions organizations, including legal and real estate and facilities.

A photo of West.

“With AI, we have so many new ways to innovate. From optimizing building occupancy, to streamlining commute services, to automating contract and document management, we have incredible potential to make our corporate functions more efficient and impactful.”

Becky West, principal group product manager, Microsoft Digital

This is a particular challenge, as these teams are being asked to do more with less today; Microsoft can no longer afford to grow operational costs at the same rate as in the past.

AI is playing a fundamental role in transforming the business workflows of our corporate functions partners while improving operational efficiency, user productivity, regulatory and corporate compliance, and data-driven decision making. It’s revolutionizing the way they operate by automating repetitive and time-consuming operational tasks.

“With AI, we have so many new ways to innovate,” says Becky West, a principal group product manager in Microsoft Digital. “From optimizing building occupancy, to streamlining commute services, to automating contract and document management, we have incredible potential to make our corporate functions more efficient and impactful.”

Some of the corporate functions taking advantage of AI capabilities and related increased efficiencies include:

  • Real estate and facilities: In supporting the technology needs for more than 500 company buildings worldwide, we are poised to use AI and related innovations to implement cost savings in the areas of workspace systems, facilities management, and space management.

Find out how we’re transforming facility operations at Microsoft with AI maps.

  • Travel and expense: Our plan is to work for near-elimination of the traditional expense reporting process through AI-based and touchless experiences, driving simplification and productivity gains.

Check out how OneExpense transformed our employee expense reporting.

  • Legal: Our vision for integrating AI into Corporate, External, and Legal Affairs (CELA) includes more discoverable legal findings, better corporate document management with the Docufy platform, enhanced engagement with Microsoft Philanthropies, and accelerated support for business-critical functions such as immigration, contracting, and insider trading compliance.

Read how AI is revolutionizing the way we support corporate functions at Microsoft.

Agentic AI: Becoming a Frontier Firm

This era of AI in IT has quickly morphed into a world in which agents are having major impacts across the enterprise. Microsoft Digital plays a central role in helping the company embrace this change and transform into a Frontier Firm: an organization that has deeply embedded AI and agents into its operations, products, and culture

As a Frontier Firm, we go beyond simply adopting AI as a discrete tool or additional technology. We’re actively integrating intelligent systems, rich data platforms, and human knowledge into a unified operating model, where automation, decision making, and innovation combine to spark acceleration at scale. Agentic AI is a core enterprise capability for us, powering everything from employee productivity to customer experiences and strategic decisions.

As Microsoft progresses into this agentic AI future—where autonomous or semi-autonomous AI agents understand context, take actions, and collaborate alongside humans—Microsoft Digital has played a lead role in deploying these capabilities internally. We’ve led the early adoption of tools like Microsoft 365 Copilot, Azure AI services, and custom-built agents that help us automate repetitive tasks, surface insights, and orchestrate workflows across systems while enforcing strict governance policies. Examples include AI-powered agents that assist in IT service management, network monitoring, and enterprise knowledge retrieval, which allow employees to focus on higher-value work and maximize their individual impact.

As AI agents continue to grow in power and functionality and become more deeply integrated into the daily workflows of knowledge professionals, Microsoft IT will maintain our leadership role and operate at the bleeding edge of this technological revolution. 

A catalyst for change and growth

Microsoft’s digital transformation is a story of evolutionary change, resilience, and adaptation across multiple eras of information technology. From our origins as a traditional IT organization to becoming a modern engineering organization focused on driving AI-powered innovation, we in Microsoft Digital remain a catalyst for change within the company and our industry.

With our insights born from customer and employee obsession, we’re committed to streamlining IT operations while prioritizing security, revolutionizing user services, and facilitating corporate functions growth and development. All with the overarching goal of making Microsoft employees everywhere more productive while showing our customers and partners what’s possible as we move forward together into the future of IT.

Key takeaways

Our IT digital transformation story offers valuable lessons for organizations in the midst of their own IT journey. They include:

  • Be vision-led: A clear, articulated vision is crucial for driving transformation.
  • Foster a growth mindset: Encourage continuous learning and adaptability among employees (“learn-it-all” culture).
  • Invest in people: Upskill and reskill your workforce to keep pace with technological advancements and emphasize diversity of skills and experience.
  • Insist on security: Prioritize security in all aspects of operations to safeguard data and maintain trust.
  • Focus on collaboration and partnership: Create successful hybrid work environments to foster strong partnerships across functions.
  • Seek continuous improvement: Learn from the past and use those lessons to shape the future.
  • Embrace AI: Take advantage of AI tools and technologies to drive efficiency, innovation, and security.

Try it out

Related links

The post Digitally transforming Microsoft: Our IT journey appeared first on Inside Track Blog.

]]>
18521
Microsoft CISO advice: Governing security at scale with Security Development Lifecycle http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-governing-security-at-scale-with-security-development-lifecycle/ Thu, 18 Jun 2026 15:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24347 Microsoft first mandated use of Security Development Lifecycle (SDL) in 2004. Now, SDL underpins our Secure Future Initiative (SFI) and supports SFI’s goals of secure by design, secure by default, and secure operations.​​ The SDL is a proven, adaptable approach we apply to building secure products and services. In this video, Tony Rice, principal security […]

The post Microsoft CISO advice: Governing security at scale with Security Development Lifecycle appeared first on Inside Track Blog.

]]>
Microsoft first mandated use of Security Development Lifecycle (SDL) in 2004. Now, SDL underpins our Secure Future Initiative (SFI) and supports SFI’s goals of secure by design, secure by default, and secure operations.​​ The SDL is a proven, adaptable approach we apply to building secure products and services.

In this video, Tony Rice, principal security program manager in the Office of the CISO, discusses the teams and organizational systems that help define and adapt security requirements that are applied across the enterprise. You’ll hear about how teams work together to embed security into engineering workflows and scale assurance through automation, secure defaults, and data driven KPIs. We seek to continuously monitor and improve security by applying both automated controls and use of human-driven security reviews.

“This isn’t just about ticking boxes. It’s about making sure that security is embedded in every stage of development and operation,” says Rice.

Watch this video to hear Tony Rice describe how Microsoft uses governance and automation to apply its Secure Development Lifecycle (SDL) at enterprise-level scale. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=oyciotF-qGA.)

Key takeaways

Here are some practices to socialize in your organization as you seek ways to embed “security first” thinking in your organization:

  • Inventory, deeply and regularly. Create and review regularly an accurate, complete and categorized inventory of development assets at your company. This practice provides the foundation for automation without knowing what we have.
  • Invest in scaling assurance functions. Having security policies is not enough. It takes time, attention, and effort to define processes and build technical control automation.
  • Shift left. “Shifting left” means not waiting until a service or feature is nearly done to consider security requirements. Consider ways to integrate meeting security requirements in the work developers do every day.
  • Have humans review. Prioritize human-driven security reviews on the ​businesses most critical scenarios and assets.
  • Measure your organizational progress. The best way to know if you are succeeding is to measure your progress against your organization’s security requirements. Incremental improvements in measurement and remediation drives real security outcomes.

Try it out

Related links

The post Microsoft CISO advice: Governing security at scale with Security Development Lifecycle appeared first on Inside Track Blog.

]]>
24347
From data sprawl to AI-driven seller insights at Microsoft http://approjects.co.za/?big=insidetrack/blog/from-data-sprawl-to-ai-driven-seller-insights-at-microsoft/ Thu, 18 Jun 2026 15:15:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24357 Sellers at Microsoft have access to a wide range of data to help them understand their business, identify risks, and focus on opportunities. Over time, new systems and reporting tools expanded the amount of data available to them. At first glance, helping sellers improve the way they work looks like a data challenge because we […]

The post From data sprawl to AI-driven seller insights at Microsoft appeared first on Inside Track Blog.

]]>
Sellers at Microsoft have access to a wide range of data to help them understand their business, identify risks, and focus on opportunities. Over time, new systems and reporting tools expanded the amount of data available to them.

At first glance, helping sellers improve the way they work looks like a data challenge because we tend to believe more data equals better decisions. However, when we explored how they use data to prepare for customer meetings and internal business reviews, we saw a different pattern.

The amount of data they had available to them had increased—but so had the manual effort needed to turn it into useful and actionable insights. In fact, our sellers were spending more time looking for relevant information than they were spending engaging with customers to improve their experience.

As part of our Customer Zero approach at Microsoft, we apply our technologies internally and use that experience to understand what works at scale so we can pass that knowledge onto our customers. In this case, our discoveries unearthed a deeper issue with how our sellers interact with data in their day-to-day work.

Too much data, not enough insight

The increased amount of data available to our sellers gave them more options but also more information to process. It also introduced fragmentation.

A photo of Toomey.

“I think the big feedback pain point we got was that we have way more data than our sellers were used to. You give us a gigantic well of data, but how I use that data to execute my job is fragmented.”

Michael Toomey, revenue insights lead, Finance Data and Experience

A significant portion of our sellers’ time went into finding, interpreting, reconciling, and analyzing the information before any actual decisions or customer interactions were taking place. In some cases, sellers were navigating hundreds of reports and dashboards across multiple systems. In others, they were exporting data into spreadsheets, building their own analyses, and assembling presentations manually. They told us they were overwhelmed by the amount of data they had access to.

“I think the big feedback pain point we got was that we have way more data than our sellers were used to,” says Michael Toomey, a revenue insights lead on our Finance Data and Experience team. “You give us a gigantic well of data, but how I use that data to execute my job is fragmented.”

This tedious manual user experience didn’t match the fast pace of our work. Sellers needed to move quickly, and we needed a way to empower them to find the data and insights they needed to be able to make actionable decisions immediately.

Instead of continuing to expand the amount of data available to our sales force, we concentrated on making the existing data easier to access, understand, and use.

Beginning with a trusted data foundation

The starting point was the data itself. Our sales organization draws from many systems, each of which has its own structure, definitions, and refresh cycles. Without alignment across these systems, even seemingly simple seller questions could produce different answers depending on the data source. This created more work as our sellers hunted down which answer was the correct one.

We consolidated all this data into a unified model on Microsoft Fabric, creating a shared data foundation across the organization. It included standardized definitions, consistent metrics, and common hierarchies. Data from more than 70 systems was brought together into one governed environment.

This step required coordination across teams and ongoing attention to evolving data governance. It established trust in our data that made it easier to streamline the user experience for our sales teams down the line.

Streamlining how sellers work with data

With a consistent data foundation put into place, we turned our attention to how sellers could most effectively access and use the information.

Instead of asking sellers to navigate a portal of reports, we designed role-based dashboards that reflect how people actually work. Individual dashboards are curated based on role, workflow, and responsibilities, helping our sellers quickly find what they needed without searching across systems. We transformed the work surrounding actionable insights, too: Power BI surfaces intelligent insights to our sellers’ dashboards every morning, automatically giving them their priorities for the day and providing an overview of their funnel.

Before this transformation, building PowerPoint presentations for customers and summarizing reports were routine but tedious parts of the preparation process for our sellers before they spoke to customers. These preparatory steps have been streamlined or automated wherever possible, reducing seller time spent on repetitive manual tasks.

Empowering sellers using AI

With the data organized and cleaned and the user experience transformed, we introduced AI to overhaul how our sellers interact with the information available to them.

“A lot of what we’re trying to do is get to a native Microsoft 365 Copilot experience where we meet people where they’re working every day. And then work is optimized to be able to reason over our day to pull the data in.”

Michael Toomey, revenue insights lead, Finance Data and Experience 

To find the information they’re looking for, sellers can now ask questions in natural language and receive answers directly in the tools they already use. Insights powered by Power BI Copilot, Fabric, and AI Foundry are delivered proactively, helping sellers prioritize their day, generate summaries, and assemble materials for meetings without working through each step manually.

Insights that previously required a great deal of time to uncover are surfaced directly. The relevant reports are automatically routed to sellers based on their job description and client base. Sellers can also subscribe to continuously updated reports and have them surfaced each morning to their inbox.

These capabilities are available in the tools our people already use, which means they don’t have to spend time learning new product suites. The information they’re looking for can be surfaced through tools like email or within Microsoft Teams, which means sellers can stay focused on their work without needing to switch between systems.

Processes that once took hours can now be completed in minutes.

“A lot of what we’re trying to do is get to a native Microsoft 365 Copilot experience where we meet people where they’re working every day. And then work is optimized to be able to reason over our day to pull the data in,” Toomey says.

What changed

The most visible shift we’ve observed is how sellers spend their time. Less effort goes into finding, assembling, and reconciling information, and more attention is directed toward understanding customer needs and making decisions that actively move the business forward.

After deploying this model across our sales organization, we saw meaningful improvements in both efficiency and effectiveness, including:

  • 100,000 seller hours saved annually
  • 30% reduction in data ingestion costs
  • 10x faster insight generation
  • 1,500 reports retired and consolidated

We credit our success to building a trusted data foundation; a streamlined, intuitive user experience; and embedding AI into the flow of work to help our sellers surface insights and information with a few clicks instead of spending hours sifting through irrelevant inputs.

We learned that executive sponsorship and active change management were essential to transforming the department successfully. Concentrating on consistency and departmental alignment around a set of trusted, verified, well-governed data and shepherding people through shifting how they worked with the data were just as important as adding AI into the process.

Looking ahead

At the heart of our trusted data foundation is the semantic layer, the place where our business definitions, metrics, and data quality are standardized across the organization. It’s now the engine that powers our agents. Because those definitions live in one governed place, our agents can reason over our data products with confidence, and we can trust what they surface.

That foundation is already bearing fruit. A new generation of personal and role-based agents at Microsoft is taking on the workflows that were consuming our sellers’ time, such as meeting preparation, pipeline reviews, and customer insight generation. These processes are now running on the governed data infrastructure we built. Everything draws from the same source of truth, so everything our agents work with is consistent, reliable, and ready to act on.

This return on our platform investment is bringing us closer to becoming a Frontier Firm where our people spend less time searching for the answers and more time acting on them.

Key takeaways

If you’re looking to transform how your teams interact with data and AI, consider these lessons from our experience:

  • Start with a trusted data foundation: Standardize your definitions, governance, and ownership before layering on AI.
  • Simplify before you scale: Reduce fragmentation and rationalize your reports to eliminate unnecessary complexity.
  • Design for real workflows: Focus on how y our people work, not just how your data is organized.
  • Embed AI into the flow of work: Deliver insights where your people already are instead of requiring them to search across systems or learn a new product suite.

Try it out

Related links

The post From data sprawl to AI-driven seller insights at Microsoft appeared first on Inside Track Blog.

]]>
24357