Inside Track - Modern work http://approjects.co.za/?big=insidetrack/blog/tag/modern-work/ How Microsoft does IT Fri, 28 Aug 2026 17:57:25 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.4 137088546 How we deploy and manage enterprise devices at Microsoft Digital http://approjects.co.za/?big=insidetrack/blog/how-we-deploy-and-manage-enterprise-devices-at-microsoft-digital/ Thu, 27 Aug 2026 16:10:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25178 In a global organization such as Microsoft—with more than 220,000 employees connecting and working together from offices and remote workspaces scattered around the world—we enable our workers to stay productive from almost anywhere, on a wide range of devices. At Microsoft Digital, the company’s IT organization, we provide our employees with that flexibility while helping […]

The post How we deploy and manage enterprise devices at Microsoft Digital appeared first on Inside Track.

]]>

In a global organization such as Microsoft—with more than 220,000 employees connecting and working together from offices and remote workspaces scattered around the world—we enable our workers to stay productive from almost anywhere, on a wide range of devices.

At Microsoft Digital, the company’s IT organization, we provide our employees with that flexibility while helping keep the devices they use secure, compliant, and supportable at enterprise scale.

A photo of Fielder.

“Every digital experience depends on the readiness of the devices our employees use every day. Organizations that treat device management as a strategic lifecycle capability rather than a series of operational tasks are better positioned to adapt to change, reduce risk, and take advantage of new innovations with confidence.”

We balance employee experience, security posture, and operational efficiency as part of modern device management.

This IT playbook explains how we think about device readiness at Microsoft Digital, where we serve as Customer Zero for the company. It covers the tradeoffs we manage, the lifecycle patterns that hold up over time, and the signals we monitor to understand whether we’re reducing risk or quietly accumulating it.

We also share resources you can use to apply modern device management in your own enterprise.

“Every digital experience depends on the readiness of the devices our employees use every day,” says Brian Fielder, vice president of Microsoft Digital. “Organizations that treat device management as a strategic lifecycle capability rather than a series of operational tasks are better positioned to adapt to change, reduce risk, and take advantage of new innovations with confidence.”

Understanding device readiness and lifecycle

Effective device readiness must be sustained across the full device lifecycle, from planning and acquisition through operation, refresh, and retirement. In an enterprise environment, a device is considered ready only when we can:

  • Identify it and confirm ownership
  • Govern it through identity and policy
  • Keep it secure and compliant over time
  • Support and recover it when something goes wrong
  • Remove it cleanly when its role ends

When these conditions work together, device readiness becomes an operating advantage. We can move employees onto approved devices faster, enforce security and access requirements more consistently, and make lifecycle decisions with better data and less guesswork. The result is a device estate that is manageable, trustworthy, and productive at enterprise scale.

The device lifecycle model

At Microsoft Digital, we use the device lifecycle as a control system for readiness. We connect decisions, standards, and signals across the full lifecycle, so we can manage readiness over time rather than just check on it at isolated points. Each stage reinforces the next, and any issues show up early enough for us to correct them before they spread.

The stages serve specific functions:

  • Plan and standardize: Sets the device standards and guardrails that make the rest of the lifecycle workable at scale.
  • Acquire: Brings devices in as approved enterprise assets that can be tracked and managed from the start.
  • Onboard: Gets employees up and running quickly through automated setup and policy-driven enrollment.
  • Operate: Ensures devices are secure, up-to-date, and dependable over time.
  • Optimize: Uses telemetry to reduce friction and improve how the lifecycle performs.
  • Refresh or reassign: Keeps devices useful longer by replacing or repurposing them before they become a problem.
  • Retire: Removes devices cleanly so access is closed off, data is protected, and disposition is complete.

The device lifecycle is a durable operating model that we manage holistically. Weakness in any phase often appears after the original decision was made and far from the point where the issue began.

We describe each lifecycle stage using the following structure:

Chapter 1: Plan and standardize

In this stage, we define the standards, controls, and supported patterns that make the rest of the device lifecycle manageable. Good planning reduces downstream exceptions and gives later stages a more stable foundation.

Readiness question

Are our device standards enforceable in practice, and do they reduce downstream cost, risk, and fragmentation?

What good looks like

Clear, role-based device standards limit variance and make onboarding and support repeatable at scale. These standards are grounded in capabilities that our platforms and tools can enforce, not aspirational policy language.

Signals

Signals help us detect when a lifecycle stage is falling out of alignment with its intended outcomes, becoming harder to manage, or creating downstream cost and complexity. These signals include:

Exception rates that grow over time (more devices falling outside supported standards), which later shows up in higher support costs and weaker servicing consistency.

Policies that are documented but not enforced through device health and access controls, including modern management capabilities such as Intune compliance policies and Conditional Access. Some examples are minimum OS requirements, encryption standards, and Microsoft Defender health. Documented but unenforced controls create “paper compliance” instead of true operational compliance.

Device and OS coverage statements that become hard to verify. This could manifest as device counts, OS mix, and ownership mix becoming directional rather than telemetry-backed, which weakens credibility and decision making.

Microsoft Digital operating practices

These practices show how we design the operating model to make the target state durable and repeatable. They represent the baseline decisions we make around rollout control, visibility, and enforcement to help prevent drift before it emerges.

  • Early partnership with chip providers such as Intel, AMD, Qualcomm, and NVIDIA enables upstream testing, validation, and feedback on next-generation hardware. As Customer Zero for the Windows product group, our team in Microsoft Digital co-develops and is an early adopter of the Copilot+ PC experience, so readiness, performance, and security are tested and proven before fleet-wide deployment.
  • For Windows devices, readiness standards are anchored to enforceable hardware and security capabilities, including TPM 2.0, Secure Boot, Microsoft Pluton, Credential Guard, and Windows Hello for Business compatibility.
  • Devices are sourced from approved OEM catalogs and built to order, then validated against supported firmware, BIOS or UEFI, driver configurations, and setup experience. This approach reduces downstream support, servicing risk and providing white-glove device preparation while supporting a consistent, secure out-of-box experience.
  • Apple (macOS/iOS) readiness is anchored to managed enrollment, encryption (for example, FileVault on macOS), and phishing-resistant sign-in via Platform SSO and passkeys.
  • Android readiness requires Android Enterprise Work Profile support, verified device integrity (not compromised), and minimum OS and security patch levels enforced via MDM posture and Conditional Access.

Stakeholder lens

The following stakeholder groups shape planning, depend on its outcomes, and can detect misalignment quickly when expectations drift:

Being Customer Zero

Before broad deployment of new capabilities, enterprise endpoint teams and product groups align on an enterprise readiness contract that spans trust and safety, manageability, and recoverability. We validate identity-bound access and tenant trust boundaries early, so we don’t introduce unmanaged enterprise risk.

Key takeaways

Here are some tips as you approach your own device management planning process:

  • Device standards work best when they are enforceable through management, identity, and access controls.
  • Approved hardware catalogs, security baselines, and lifecycle expectations reduce downstream exceptions.
  • Early Customer Zero validation helps our team in Microsoft Digital test standards before they reach broad deployment.

Learn more

How we did it at Microsoft

Further guidance

Chapter 2: Acquire

In this stage of device lifecycle management, we bring devices into the environment as known, trackable enterprise assets. The goal is to make sure every device enters the lifecycle with the identifiers, registrations, and sourcing controls needed for clean provisioning and management.

Readiness question

Are devices known, owned, and visible before employees need them?

What good looks like

Procurement and asset registration are predictable and integrated, ensuring devices enter the environment as known enterprise assets, already associated with inventory systems and ready for automated provisioning.

Signals

These signals show where breakdowns in sourcing, registration, or asset control can create problems later in the lifecycle.

Procurement lead times cause day-one onboarding delays when devices arrive before they are ready for provisioning.

Inventory and asset records drift from reality, causing organizations to lose a single source of truth for device status, ownership, and lifecycle stage. This can create gaps in offboarding, recovery, and audit evidence.

Devices reach employees before registration is complete, such as when Autopilot or Apple Business Manager registration isn’t done before delivery. This forces catch-up work and introduces exceptions.

Microsoft Digital operating practices

These practices show how we design the operating model to make the target state repeatable:

  • Acquisition readiness and zero-touch deployment begin with an integrated sourcing and provisioning model. This model defines how we source and acquire devices globally, apply persona-based configuration, fulfill local language requirements, and preload the latest supported operating system and drivers.
  • When devices are delivered, they arrive asset-tagged, bundled, and preregistered with Windows Autopilot. This enables a consistent, secure, hands-off setup experience from first power-on.
  • Acquisition readiness is tied to asset registration and inventory accuracy. Corporate devices are registered at purchase, associated with enterprise asset identifiers, and tracked continuously from order through retirement.

Stakeholder lens

These groups influence acquisition decisions and depend on those decisions being accurate, timely, and supportable:

Being Customer Zero

Our early adoption program accelerates learning while preserving governance. We operate under explicit guardrails, including security posture, data boundaries, and regulatory requirements, so speed doesn’t bypass enterprise controls.

Key takeaways

Keep these principles in mind during the acquisition phase of the device lifecycle process:

  • Acquisition readiness starts before a device ships to an employee.
  • Asset tagging, inventory accuracy, and preregistration reduce provisioning exceptions.
  • Global sourcing works best when procurement, IT, and security share the same readiness criteria.

Learn more

How we did it at Microsoft

Further guidance

Chapter 3: Onboard

In this stage, we turn a device into a usable, trusted work endpoint through automated setup, enrollment, and policy enforcement. A strong onboarding experience helps employees become productive more quickly without weakening identity or compliance controls.

Readiness question

Can employees be productive on day one, experiencing minimal friction without bypassing identity, policy, or compliance?

What good looks like

Onboarding is fast, predictable, and largely hands-off for IT while remaining identity-bound and policy-driven. Day-one productivity comes through repeatable automation rather than exception handling.

Signals

These signals tell us when onboarding is becoming inconsistent, support-heavy, or harder to scale cleanly:

“Time to productive” increases or varies significantly (the onboarding path is no longer repeatable at broad scale).

Enrollment Status Page (ESP) failures increase (setup blocks, app install delays, and policy install failures).

Enrollment-related support calls or tickets rise during onboarding windows, indicating that friction is shifting from automation to human support.

Post-onboarding surveys and helpdesk ticket analysis show declining satisfaction or repeated “same issue” patterns.

Bring-your-own-device (BYOD) enrollment confusion increases as employees are unclear on what’s managed, what data is collected, or what happens when access is revoked.

Microsoft Digital operating practices

These practices show how the operating model makes the target state repeatable:

  • Devices are approved and certified before reaching employees. Corporate Windows and Apple devices are sourced from approved OEM catalogs and registered through Windows Autopilot or Apple Business Manager, then associated with user identities and asset systems.
  • For Windows devices, Autopilot registration occurs via OEM or partner APIs whenever possible; manual hardware hash registration is reserved for exceptions. Assigned Autopilot profiles define Entra ID join behavior, Intune enrollment, Out‑of‑Box Experience configuration, required applications, and baseline policies.
  • The Enrollment Status Page acts as a gate that can’t be bypassed. Devices cannot be used until required apps, updates, and policies are successfully installed. If setup fails, reset is blocked, and errors are captured for IT remediation.
  • Apple Business Manager is used exclusively for corporate‑purchased Apple devices; personally owned Apple and Android devices follow Intune BYOD enrollment paths. Android devices enroll using the Android Work Profile mechanism; Google Zero Touch is not used in this environment.
  • Before access to corporate resources is allowed, devices must meet certification requirements, including Intune enrollment, encryption (BitLocker or FileVault), supported OS versions, Defender for Endpoint health, and required hardware security capabilities. Conditional Access enforces these requirements at sign‑in.
  • Virtual onboarding options such as Azure Virtual Desktop are used for contractors, regulated roles, or temporary fallback access.

Stakeholder lens

These groups own setup, experience the outcome directly, and rely on tight alignment for onboarding to work smoothly:

Being Customer Zero

The readiness contract explicitly validates manageability, zero-touch onboarding readiness, and identity enforcement before capabilities advance beyond early internal cohorts.

Key takeaways

Here are some main points to remember about the onboarding phase of device management:

  • Onboarding should be automated, identity-bound, and policy-driven from first power-on.
  • Day-one productivity depends on reducing setup friction without weakening compliance controls.
  • Enrollment signals and support trends help identify where onboarding needs improvement.

Learn more

How we did it at Microsoft

Further guidance

Chapter 4: Operate

In this stage, we keep devices secure, current, and reliable through ongoing servicing and operational discipline. The aim is to maintain a stable experience over time while minimizing manual intervention and operational noise.

Readiness question

Can devices remain secure, reliable, and current over time without constant manual intervention, and can known vulnerabilities be remediated quickly without manual escalation?

What good looks like

Continuous servicing and support preserve productivity while minimizing operational noise and exposure windows.

Signals

These signals help us see when operations are getting noisier, less predictable, or more reactive than they should be:

Update compliance thresholds are missed, meaning more devices are at risk because of outdated patches or repeat failure patterns.

Rollbacks, pauses, or halted rollouts become frequent, which indicates that the ring and validation strategy isn’t catching issues early enough.

Helpdesk tickets trend upward for update failures or device remediation (operational noise is rising instead of staying quiet).

Firmware- or driver-related instability increases, which requires additional validation, staging, or rollback controls.

Zero-day response requires repeated emergency actions; this signals that baseline update hygiene isn’t consistently holding.

Microsoft Digital operating practices   

These practices show how we design the operating model to make the target state durable and repeatable:

  • Windows Autopatch: Provides a single, integrated update management experience in Intune. It combines Windows Update for Business policy-based controls with automated, telemetry-driven deployment across staged rollout waves, including built-in issue detection, pause, and rollback capabilities.
  • Windows Hotpatch: Helps reduce disruption by applying certain security updates without requiring a restart, which supports continuity for eligible devices.
  • Intune Vulnerability Agent: Extends vulnerability visibility and supports coordinated remediation through device management workflows.
  • Enterprise App Management: Gives us a structured way to manage application deployment, updates, and policy alignment across managed devices.
  • Update Compliance: Via Azure Monitor, it provides insight into installation rates and failure patterns, triggering remediation workflows when thresholds are crossed. Firmware and driver updates are validated with OEM partners and staged using the same ring-based deployment model.
  • Minimum OS requirements: Non-Windows devices must meet minimum operating system requirements, encryption standards, and endpoint protection requirements before they can access corporate resources. These are enforced by Intune compliance policies and Conditional Access.

Stakeholder lens

These groups keep the environment running smoothly and depend on that stability every day:

Being Customer Zero

We use a staged rollout approach to test new updates and features with progressively larger groups of users. This helps us identify issues early, validate performance and reliability at scale, and continuously improve quality before broad deployment across the company.

Key takeaways

Here are a few learnings for keeping your devices secure and reliable throughout the operational phase of the device management lifecycle:

  • Operating readiness depends on predictable servicing, staged rollout, and clear rollback controls.
  • Telemetry helps our team in Microsoft Digital detect update, firmware, driver, and vulnerability issues before they become widespread.
  • Quiet, consistent operations improve security posture while reducing disruption for employees.

Learn more

How we did it at Microsoft

Further guidance

Chapter 5: Optimize

In this stage, we use telemetry and operational insight to improve how the device lifecycle performs. Optimization helps us reduce friction, close recurring gaps, and make better decisions about where to invest effort.

Readiness question

Are fleet health, compliance, and cost improving or merely visible?

What good looks like

Telemetry and automation inform decisions that decrease friction, eliminate compliance gaps, and improve lifecycle efficiency.

Signals

These signals show when optimization has stalled and the environment is absorbing effort without reducing friction or risk:

Known vulnerabilities remain open longer than expected, increasing exposure to risk.

Compliance rates stop improving from one release to the next, despite ongoing remediation efforts.

Routine issues continue to require manual intervention instead of being handled through automation.

Devices repeatedly cycle in and out of compliance, indicating deeper issues in the environment.

Operational reviews spend more time addressing recurring problems and less time improving the overall service.

Microsoft Digital operating practices

These practices help us improve the environment over time and reduce operational overhead. They focus on measuring results, standardizing management, and automating routine work where possible.

  • Optimization investments are guided by metrics such as patch compliance, automation coverage, remediation success rates, and operational workload.
  • We standardized Windows devices on Microsoft Entra ID join and retired older management models such as Workplace join, Hybrid Azure AD join, and Active Directory join. This reduced complexity, simplified policy enforcement, and created a more consistent management experience across devices.
  • Windows Autopatch, Hotpatch, and automated remediation help us keep devices current while minimizing disruption for employees.
  • Intune firmware, driver, and Enterprise App Management capabilities extend the same update and deployment discipline beyond the operating system to hardware components and third-party applications.
  • Microsoft Security Copilot, Microsoft 365 Copilot, and Copilot in Power BI help our teams analyze Intune and Defender data more quickly, making it easier to identify issues and prioritize remediation efforts.

Stakeholder lens

Optimization in a cloud-native model depends on aligned ownership across engineering, security, and employee experience teams. Modern management gives us a standardized, policy-driven foundation.

Being Customer Zero

As Customer Zero for modern management, we validate optimization capabilities at enterprise scale and feeds insights directly to engineering. This helps ensure solutions are designed for real-world scenarios.

  • Modern Management transformation (Entra ID–based) simplified management and closed Conditional Access gaps.
  • Validation of Autopatch and Hotpatch improves update readiness and rollout quality before broad release.
  • AI-powered investigations unified Defender and Intune signals to accelerate issue triage and remediation.

Key takeaways

Here are some things to keep in mind as you consider the optimization aspect of device management:

  • Optimization turns lifecycle telemetry into decisions that reduce friction, risk, and operational load.
  • Cloud-native management gives our team in Microsoft Digital a consistent foundation for compliance and remediation.
  • AI-assisted investigation can help teams move faster from signal discovery to resolution.

Learn more

How we did it at Microsoft

Further guidance

Chapter 6: Refresh or reassign

In this stage, we decide whether a device should continue in service, move to a new owner, or be replaced. When done with intention, refreshing and reassignment extend an asset’s value while reducing avoidable support issues and lowering security risk.

Readiness question

Are devices refreshed or reassigned before they become performance or security debt?

What good looks like

Condition-based refresh and reassignment maximize asset value while minimizing disruption.

Signals

These signals help us see when device reuse, replacement, or support timing is slipping out of a manageable rhythm:

Hardware health telemetry trends indicate looming failures, including battery wear, thermal events, and disk health degradation, which creates unplanned downtime risk.

Firmware or driver update readiness becomes inconsistent across models (this increases the cost of servicing and support).

Refresh timing becomes reactive (devices are replaced after repeated failures instead of during planned lifecycle windows).

Reassignment or reuse requires more manual work (this signals that reset and reprovision flows aren’t consistently repeatable).

Microsoft Digital operating practices

These practices show how we make device refresh and reassignment consistent, scalable, and repeatable. They aren’t reactive steps we take when aging devices, inventory gaps, or fulfillment delays become visible. They’re the standard processes, controls, and decision points we use to keep devices moving through their lifecycle efficiently and to prevent those issues from occurring in the first place.

  • Windows lifecycle guardrails: Align firmware servicing and hardware support windows to a 48-month refresh baseline so devices remain within OEM-supported windows for security and firmware updates.
  • Condition-based refresh signals: Battery wear, thermal events, disk health, and firmware servicing status are monitored through telemetry to trigger proactive refresh actions before devices become performance or security debt.
  • Catalog discipline: Devices are sourced from the approved OEM catalog, with model selection tied to persona, lifecycle stage, and firmware support roadmap. This reduces drift between deployed inventory and supported hardware.
  • Defined recovery workflow: Reassignment is supported through a documented recovery workflow where applicable. Previously owned corporate Windows devices are returned to the out-of-box experience using WinRE-based reset initiated locally or through Company Portal, enabling redeployment to new owners through Autopilot. Recovery USB is the documented fallback when WinRE can’t be used.
  • Sustainability and cost outcomes: Where possible, devices are reassigned, repurposed, or returned through approved recycling channels. This extends asset value and supports our broader sustainability commitments.
  • Structured exception handling: Devices that fall outside refresh windows because of supply, persona, or business constraints follow a documented exception path with a defined review cadence so exceptions don’t become the norm.

Stakeholder lens

These groups help determine whether devices should be refreshed, reassigned, repaired, or retired:

Being Customer Zero

Our team in Microsoft Digital validates refresh and reassignment workflows at scale across device models, OEMs, and silicon partners before they reach employees. By partnering early with Windows product group, silicon partners, and OEM partners, we test Autopilot re-enrollment, WinRE-based recovery, and Company Portal reset flows in real conditions. We then turn lifecycle telemetry and friction points into direct product feedback as part of our Customer Zero commitment.

Key takeaways

Here are a few things we learned about device refresh and reassignment during our journey:

  • Refresh decisions should be driven by lifecycle signals, not simply device age.
  • Reassignment works best when reset, recovery, and reprovisioning workflows are documented and repeatable.
  • Lifecycle planning supports employee experience, cost management, and sustainability goals.

Learn more

How we did it at Microsoft

Further guidance

Chapter 7: Retire

In this stage, we close the lifecycle cleanly by removing devices from service in a controlled and auditable way. Retirement helps ensure that access is revoked, data is protected, and disposition is complete.

Readiness question

Can devices exit cleanly without leaving behind data, access, or audit gaps?

What good looks like

Offboarding is policy-driven, auditable, and integrated with identity, asset, and sustainability workflows.

Signals

These signals show where offboarding is leaving loose ends that can create exposure, confusion, or audit gaps later:

Orphaned devices appear (devices aren’t tied to an active person or remain enrolled after a lifecycle trigger).

Time to offboard grows (slow decommissioning creates prolonged access and data risk).

Wipe verification and audit artifacts are incomplete (this includes missing wipe confirmation logs, disposition certificates, or chain-of-custody records).

Devices remain enabled in Entra ID or continue to pass access checks after they should be decommissioned (these are access revocation gaps).

People repurpose devices informally, such as loaners or secondary devices, without clarity on what decommissioning means for audit and compliance versus reassignment.

Microsoft Digital operating practices

Offboarding triggers include employee exit, end of warranty, hardware health degradation, or compliance failure. These triggers launch automated workflows using Power Automate and ServiceNow, revoke access through Microsoft Entra ID and Conditional Access, and wipe devices through Intune or Configuration Manager. Data sanitization aligns with NIST 800-88 guidelines, and chain-of-custody controls support secure disposition.

Stakeholder lens

These groups help ensure retirement is controlled, auditable, and complete:

Being Customer Zero

Our team in Microsoft Digital validates retirement workflows at scale, including automated offboarding, access revocation, NIST 800-88 sanitization, and chain-of-custody controls across devices. By partnering with Microsoft Entra ID, Windows, and Intune teams, we surface real-world gaps such as orphaned devices, delayed wipes, and residual access. We then translate those gaps into product improvements that strengthen the retirement experience for customers and help keep our own audit and compliance posture durable.

Key takeaways

Here are factors to consider when you are setting up retirement and offboarding standards for the device lifecycle:

  • Retirement is a security and compliance process, not just an asset-management task.
  • Clean offboarding depends on identity, device management, inventory, wipe verification, and chain-of-custody controls working together.
  • Customer Zero validation helps us identify retirement gaps before they become audit or access risks.

Learn more

How we did it at Microsoft

Further guidance

Conclusion

Device readiness is not a one-time milestone. It is a lifecycle discipline that connects planning, sourcing, onboarding, operations, optimization, refresh, and retirement. At Microsoft Digital, we use that lifecycle to keep devices secure, employees productive, and operational decisions grounded in data.

A photo of Selveraj.

“Device readiness is ultimately about enabling people to do their best work wherever and however they choose to work. By treating the device lifecycle as a strategic capability, we’ve transformed this function from an operational necessity into a source of innovation, resilience, and future growth across our organization.”

When every stage has clear standards, measurable signals, and repeatable mechanisms, the device estate becomes easier to manage and safer to scale. That helps us reduce exceptions, improve employee experience, and strengthen enterprise security without relying on manual effort as the default path.

“Device readiness is ultimately about enabling people to do their best work wherever and however they choose to work,” says Senthil Selveraj, a principal group product manager in Microsoft Digital. “By treating the device lifecycle as a strategic capability, we’ve transformed this function from an operational necessity into a source of innovation, resilience, and future growth across our organization.”

Key takeaways

Here are some overall learnings that you should consider as you approach device management at your own organization:

  • Treat device management as a lifecycle discipline. Organizations can improve security, operational efficiency and the employee experience by connecting planning, deployment, support, and optimization into a single operating model.
  • Build standards that can be enforced through technology. Device requirements become more effective when identity, compliance, access, and security controls automatically validate and enforce them throughout the lifecycle.
  • Use automation to reduce friction while maintaining security. Automated provisioning, enrollment, updates, and remediation is essential, helping employees be more productive while ensuring devices remain compliant.
  • Make lifecycle thinking the control system for sustained readiness. When every stage of the device journey is connected through shared standards and measurable signals, organizations can manage readiness continuously instead of addressing issues only after they emerge.
  • Implement explicit constraints and guardrails. Clear standards, supported device configurations, and enforceable security requirements help reduce exceptions while making the environment easier to secure and manage at scale.
  • Rely on telemetry to guide decisions before problems become widespread. Monitoring device health, compliance, update status, and operational trends helps IT teams identify risk early and take proactive action instead of reacting to incidents.
  • Adopt a cloud-native management foundation to simplify operations. Standardized, policy-driven device management reduces complexity, improves visibility, and creates a consistent framework for compliance, servicing, and remediation across the enterprise.
  • Design every stage of the lifecycle with long-term sustainability and governance in mind. Clear processes for refresh, reassignment, and retirement help organizations maximize device value, reduce operational debt, and maintain strong security and compliance outcomes over time.

Try it out

Learn more

How we did it at Microsoft

Further guidance

The post How we deploy and manage enterprise devices at Microsoft Digital appeared first on Inside Track.

]]>
25178
From AI assistant to capable teammate: How Copilot Cowork is changing the way we work at Microsoft http://approjects.co.za/?big=insidetrack/blog/from-ai-assistant-to-capable-teammate-how-copilot-cowork-is-changing-the-way-we-work-at-microsoft/ Thu, 20 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25150 Most workdays don’t fall apart because employees lack ideas. Instead, challenges arise between intention and execution. What employees need is a way to set executional engines in motion so they can focus on higher-level work, stepping in only when necessary. At Microsoft, we’ve been working to close that gap with a new kind of agent: […]

The post From AI assistant to capable teammate: How Copilot Cowork is changing the way we work at Microsoft appeared first on Inside Track.

]]>
Most workdays don’t fall apart because employees lack ideas. Instead, challenges arise between intention and execution. What employees need is a way to set executional engines in motion so they can focus on higher-level work, stepping in only when necessary.

At Microsoft, we’ve been working to close that gap with a new kind of agent: Copilot Cowork. Rather than a strict instruction-and-response approach, Cowork has taken the leap to multi-step action across an employee’s Microsoft 365 environment.

From task assistants to true digital coworkers

For years, the promise of AI at work has centered on task assistance, like creating drafts quickly, delivering better summaries, and providing faster answers. But knowledge retrieval isn’t partnership.

A photo of Kerametlian

“Cowork really sheds light on the art of the possible when it comes to agents, without the need for employees to build them for themselves. It has ignited people’s imagination around what agents can do.”

Stephan Kerametlian, senior director, Microsoft Digital

In Microsoft Digital, the company’s IT organization, we’ve been pursuing deeper impact for AI. We want agents to work alongside our employees, take on multi-step tasks, and produce real outputs, all while keeping the humans that direct their work in the loop.

Copilot Cowork represents that shift. It behaves less like a chatbot and more like a capable teammate that plans, executes, and checks in as it goes along.

“Cowork really sheds light on the art of the possible when it comes to agents, without the need for employees to build them for themselves,” says Stephan Kerametlian, a senior director in Microsoft Digital. “It has ignited people’s imagination around what agents can do, and it helps them understand that they don’t need to be a developer to get high-quality outputs very quickly.”

Microsoft 365 Copilot agents

Copilot Cowork is just one of the agents available through Copilot. Each is most effective in a specific set of scenarios.

Using Copilot Cowork to move from conversation to action

We created Copilot Cowork for workflows that span multiple steps, people, and applications. While traditional chat experiences answer questions or generate content, Cowork can interpret a request, create a plan, gather relevant context, and carry work forward over time.

A photo of Malekar.

“Work IQ packages relevance, ranking, and context into something AI can actually act on. It understands who you work with, what you’re working on, and which content matters in a given situation, helping the AI identify the right material and infer the steps needed to deliver an outcome.”

Swapna Malekar, principal product manager, Microsoft Digital

This agent can develop documents, coordinate meetings, generate research, create web applications, and manage ongoing tasks. It also provides visibility into its progress and requests approval before taking sensitive actions.

Key capabilities of Copilot Cowork

Multi-step plan execution
Handles entire workflows by breaking complex requests into steps across apps​

Approval checkpoints
Allows for full oversight with approval before sensitive actions: pause, resume, or cancel anytime​

Scheduled and recurring tasks
Automates regular workflows by running prompts on a schedule​

Cloud-native execution
Enables continual progress in a sandboxed cloud environment when the employee’s device is unavailable​

Built-in skills

  • Executes on common productivity and enterprise tasks across Microsoft Word, Excel, and PowerPoint, including PDF document creation, editing, and formatting
  • Handles email, scheduling, and calendar and meeting management in Outlook and Teams
  • Offers support for up to 20 custom skills

Work IQ, Microsoft’s intelligence layer for enterprise context, is the foundation of these capabilities. It helps Cowork understand relevant files, meetings, chats, collaborators, and organizational signals so that the agent can identify the right information for the task at hand. Cowork then uses that context to determine the steps needed to deliver the requested outcome.

“Work IQ packages relevance, ranking, and context into something AI can actually act on,” says Swapna Malekar, a principal product manager in Microsoft Digital. “It understands who you work with, what you’re working on, and which content matters in a given situation, helping the AI identify the right material and infer the steps needed to deliver an outcome.”

Our employees are already using Cowork to tackle work that would otherwise require multiple prompts and applications. With a single request, they can create presentations, establish Teams chats for collaboration, schedule recurring follow-up activities, begin building strategy documents, and more.

Cowork can also pull together emails, chats, documents, and news sources into a briefing or transform existing content into an interactive web experience. Throughout the process, employees can refine the work, answer clarifying questions, and approve actions before Cowork moves forward.

Helping employees embrace this watershed moment

During early adoption efforts for Cowork, we learned that successful usage depends as much on behavior change as on technology. Employees who approached Cowork simply as a better chatbot often saw incremental gains.

A photo of Glattbach.

“Cowork introduces a new way of thinking about work, where you hand off a complex task, close your computer, and the work continues on your behalf. For adoption specialists, the goal is to help employees recognize where that capability fits naturally into their day.”

Petra Glattbach, senior business program manager, Microsoft Digital

People who learned to think in terms of outcomes uncovered far more value. Instead of asking for a draft, they delegated a process. Instead of requesting a summary, they assigned a research task with a defined deliverable.

Agent Launchpad is an instructional program we’ve designed to develop our employees’ agentic AI skills. This effort, alongside other readiness resources, is encouraging people to identify recurring workflows, experiment with multi-step requests, and refine their collaboration techniques over time.

“Cowork introduces a new way of thinking about work, where you hand off a complex task, close your computer, and the work continues on your behalf,” says Petra Glattbach, a senior business program manager in Microsoft Digital. “For adoption specialists, the goal is to help employees recognize where that capability fits naturally into their day.”

This process isn’t about replacing existing ways of working overnight. It’s helping employees recognize where a digital coworker can reduce manual effort, accelerate execution, and create more time for higher-value work.

Boosting our role as Customer Zero with Cowork

Based on our experience as Customer Zero, the most effective Cowork users start with a real business problem and then explore how an agent can help solve it to drive core business outcomes.

For Jody Ryan, principal cloud solution architect for Microsoft 365 Copilot AI Business Solutions, Cowork quickly became part of her daily workflow. She’s used it to build interactive HTML experiences, create adoption sites, and rapidly prototype customer-facing concepts during live conversations.

“Cowork has become a powerful partner in my day-to-day work, helping me turn information into action so I can be more present, proactive, and impactful with my customers.”

Jody Ryan, principal cloud solution architect, Microsoft 365 Copilot AI Business Solutions

In one scenario, Cowork helped her transform a customer discussion into a working web prototype that she refined in real time based on live feedback. Going from whiteboarding to prototype to Agent was a natural progression that helped her customers visualize the real impact of Microsoft’s agentic capabilities.

One of the greatest surprises for Ryan was how much she enjoyed the customizable approach to human-in-the-loop approval checkpoints. For example, Cowork will find a time for a meeting, build a deck, and draft the invite email, but then pause for her review before sending it out. It’s all about identifying patterns of work and enabling Cowork to be part of them.

“Cowork has become a powerful partner in my day-to-day work, helping me turn information into action so I can be more present, proactive, and impactful with my customers,” Ryan says.

Employees in all kinds of roles across Microsoft are echoing Ryan’s experience. People are feeling the genuine evolution that agents like Cowork represent.

The skills we’ve learned over the last three years have been leading to this moment. By demonstrating the tangible impacts of AI through adoption initiatives, celebrating wins, and setting employees free to explore and create AI solutions to business challenges, we’ve positioned ourselves to capitalize on this next leap into more advanced AI tools.

One of our most important lessons has been that cultivating an AI-ready workforce throughout our Frontier Transformation journey has built a sense of confidence and capability with AI. Now that true agentic partnership is a possibility, that journey has prepared our people to get the most value out of tools like this.

The next chapter in the agentic workplace

The response to Copilot Cowork within Microsoft has taken us through an inflection point where AI has moved beyond assistance and into genuine execution. Our internal adoption efforts clearly demonstrate that shift.

A photo of Fielder.

“When agents can reason over organizational knowledge and then take action on our behalf, they become a powerful force for productivity and a critical aspect of how we lead Frontier Transformation.”

Brian Fielder, vice president, Microsoft Digital

Within three weeks of its internal release, Cowork had 20,000 users. Employees are actively exploring new ways to use the agent, from streamlining meeting preparation and follow-up work to creating content, conducting research, and managing complex projects.

We’ve learned that different teams often have different uses for different agents. But Cowork is emerging as a tool that can accommodate efforts reaching across a wide array of apps, data sources, workflows, and scenarios.

That’s a big shift, and employees are excited. Interest has been so strong that we’re expanding our enablement efforts, including new, Cowork-focused learning experiences within Agent Launchpad.

As we continue to evaluate Cowork, product feedback is helping us improve reliability, strengthen connections to enterprise data and external systems, and refine the quality of outputs. Even though it’s still in the early stages, teams are finding that Cowork can reduce administrative burden and help work move faster.

“Work IQ is helping unlock a new era where AI can understand the context behind our work, not just the content,” says Brian Fielder, vice president of Microsoft Digital. “When agents can reason over organizational knowledge and then take action on our behalf, they become a powerful force for productivity and a critical aspect of how we lead Frontier Transformation.”

For us at Microsoft, Cowork is more than a new agent. It’s providing a glimpse into a new future of work, where digital coworkers help employees focus more of their time on the aspects of their job that matter most.

Key takeaways

Here are some things to consider as you prepare your organization to make the most of Copilot Cowork:

  • Start with the work, not the technology. The most successful AI adoption happens when employees apply agents to real business challenges, recurring tasks, and daily workflows. Cowork becomes most valuable when people connect its capabilities to their own work context.
  • Think in outcomes, not prompts. Multi-step agents introduce a new way of working. Instead of asking AI to complete one task at a time, employees can delegate an entire process and then collaborate with the agent as work progresses.
  • Learn from others. Social learning accelerates adoption. Sharing examples, use cases, and lessons learned helps employees discover new possibilities and build confidence using agentic AI in their own roles.
  • Keep a human in the loop. Approval checkpoints, visibility into progress, and ongoing guidance enable employees to delegate work while maintaining accountability and trust.
  • Context drives better outcomes. Work IQ helps agents understand the relationships between people, content, meetings, conversations, and organizational knowledge, allowing for more relevant actions and results.
  • Experiment continuously. AI capabilities are evolving rapidly. Rather than trying to keep up with every new development, regularly revisit the tools available and look for new opportunities to apply them to your work.
  • Treat agents as coworkers, not tools. The greatest gains come when employees view agents as collaborators that can take ownership of meaningful work, freeing people up to focus on judgment, creativity, and decision making.

Try it out

  • Ready to try Copilot Cowork? You can access the agent through the Microsoft Frontier program. Start today.

Related links

The post From AI assistant to capable teammate: How Copilot Cowork is changing the way we work at Microsoft appeared first on Inside Track.

]]>
25150
Empowering employees after the call: Enabling and securing Microsoft Teams meeting data retention at Microsoft http://approjects.co.za/?big=insidetrack/blog/empowering-employees-after-the-call-enabling-and-securing-microsoft-teams-meeting-data-retention-at-microsoft/ Thu, 13 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25075 Microsoft Teams meetings help our globally distributed and digitally connected employees create meaningful hybrid work experiences. When those meetings are recorded and transcribed, or their data becomes available to AI-powered digital assistants, their value extends far beyond the meeting itself. Once captured, meeting data becomes a source of organizational knowledge that helps employees catch up […]

The post Empowering employees after the call: Enabling and securing Microsoft Teams meeting data retention at Microsoft appeared first on Inside Track.

]]>
Microsoft Teams meetings help our globally distributed and digitally connected employees create meaningful hybrid work experiences. When those meetings are recorded and transcribed, or their data becomes available to AI-powered digital assistants, their value extends far beyond the meeting itself.

Once captured, meeting data becomes a source of organizational knowledge that helps employees catch up on discussions, revisit decisions, track commitments, and surface unresolved issues. AI-powered experiences such as Microsoft 365 Copilot and Work IQ can connect insights across meetings, helping teams understand how conversations, decisions, and workstreams evolve over time and ensuring important information doesn’t get lost.

Although these features have proven to be incredibly useful to our employees and our wider organization, there are also concerns about how retaining Microsoft Teams meeting data and AI insights might affect our security posture, records retention policy, and privacy. Just like any other company, we at Microsoft must balance these different factors accordingly.

At Microsoft Digital, the company’s IT organization, we’re leading cross-disciplinary conversations on this topic to help ensure that we get it right.

The value of Teams meeting data

Within a meeting, the Microsoft 365 Copilot sidebar experience helps our late-joining employees catch up on what they’ve missed, provides intelligent prompts to review unresolved questions, summarizes key themes, and creates notes or action items.

A photo of Jensen.

“The value of a meeting should not end when the meeting ends. Transcription and AI help transform conversations into durable knowledge—making decisions easier to find, commitments easier to track, and information easier to access for everyone who needs it.”

Chanda Jensen, senior product manager, Microsoft Digital

The benefits of AI in meetings extend beyond the live meeting experience as well. When meeting content is available after the meeting, AI can transform conversations into accessible organizational knowledge. Transcripts and underlying documentation—including, notes, decisions, and action items—enable participants to revisit discussions, catch up on missed meetings, verify decisions, and accelerate follow-up work.

Our Microsoft Teams meeting data retention efforts focus on three key categories of artifacts: Underlying documentations, transcripts, and the AI-generated artifacts that help power Microsoft 365 Copilot and Work IQ experiences.

Microsoft Teams meeting data and AI artifact retention

Meeting recordings

90-day Teams meeting expiration policy

  • Cloud video recording
  • Audio
  • Screen-sharing activity

Transcripts

90-day Teams meeting expiration policy

  • Transcript
  • Captions

AI-generated meeting artifacts

90-day Teams meeting expiration policy

  • Meeting summaries and intelligent recaps
  • Notes, decisions, and action items
  • Copilot interactions (queries and responses)
  • Insights and organizational knowledge derived from meeting content

Transcription provides the underlying documentation that makes these AI-powered experiences possible. By making transcription and AI capabilities available in meetings while preserving organizer, administrative, compliance, and sensitivity controls, organizations can choose how these capabilities are used while enabling users to benefit from more effective collaboration and knowledge retention.

“The value of a meeting should not end when the meeting ends,” says Chanda Jensen, senior product manager in Microsoft Digital. “Transcription and AI help transform conversations into durable knowledge—making decisions easier to find, commitments easier to track, and information easier to access for everyone who needs it.”

Policy considerations for meeting data retention

The value of these tools is clear, but data-retention obligations also play an important compliance role that organizations like ours need to consider.

A photo of Heade.

“When individuals generate recordings or other artifacts during meetings, we tend to think of them as an individual’s data, but they actually represent the company’s data. We want to empower individuals, but we have to remember the retention and volume impacts of these artifacts on the company can be substantial.”

Rachael Heade, director of records compliance, Microsoft Corporate, External, and Legal Affairs (CELA)

First, producing and retaining this kind of data can be complex if it isn’t governed properly. For us at Microsoft, this data represents day-to-day general business practices that elevate productivity, and factors such as security and privacy must be considered when managing it. Second, data-rich artifacts like video recordings require a lot of space, quickly eating up cloud storage budgets.

“When individuals generate recordings or other artifacts during meetings, we tend to think of them as an individual’s data, but they actually represent the company’s data,” says Rachael Heade, director of records compliance in Microsoft’s legal division. “We want to empower individuals, but we have to remember the retention and volume impacts of these artifacts on the company can be substantial.”

In light of these potential impacts, some organizations simply opt out of enabling Microsoft Teams meeting recordings.

Asking the right questions to assemble the proper guardrails

Leaders in Microsoft Digital and Corporate, External, and Legal Affairs (CELA), our legal division, are working to balance the benefits of Microsoft Teams meeting data retention with our compliance obligations, aiming to provide empowering experiences for our employees while also keeping company data safe.

“Organizations are always concerned about centralized control over the retention and deletion of data artifacts,” Heade says. “You have excited employees who want to use this technology, so how do you set them up so they can use it confidently?”

Like many policy conversations, getting this right starts with the governance team in Microsoft Digital and our internal partners asking employees from across the company who are responsible for data governance the right questions:

  • When should a meeting be recorded and when shouldn’t it?
  • What kind of data gets stored?
  • Who can initiate recording, and who can access it after the meeting?
  • How long should we retain meeting data?
  • Where does the data live while it’s retained?
  • How can we control data capture and retention?
  • What does this mean for eDiscovery management?

These questions help us think about the proper data-retention guardrails. Our IT perspective is only one part of the puzzle, so we’re actively consulting with CELA, corporate security, privacy, the Microsoft Teams product group, the company’s data custodians, and our business customers throughout this process.

A photo of Johnson.

“As an organization, this is about thinking through your tenant position and getting it to a reasonable state.”

David Johnson, tenant and compliance architect, Microsoft Digital

Our conversations have brought up distinctions that any organization should consider as they build policy around Microsoft Teams meeting retention:

  • The length of time a meeting’s data remains fresh, relevant, or useful
  • Consideration of the difference between AI-generated archival content versus the full meeting transcript
  • The different risks inherent with recordings compared to transcriptions
  • Establishing default policies while allowing limited variability and flexibility when employees require it

“As an organization, this is about thinking through your tenant position and getting it to a reasonable state,” says David Johnson, tenant and compliance architect in Microsoft Digital.

From sharing perspectives to crafting policy

Our policies around Microsoft Teams meeting data retention continue to evolve, but we’ve already implemented some highly effective practices, policies, and controls. Every organization’s situation is unique, so it’s important that you speak to your legal professionals to craft your own policies. But our work should give you an idea of what’s possible through the out-of-the-box features within Microsoft Teams.

The policies we’ve put in place represent a mix of technical defaults, meeting options, and empowering employees to make informed decisions about usefulness and privacy. They also build on the foundations of our work with sensitivity labeling, which helps secure data across our tenant.

Here are some of the practices we follow and features we use:

  • Transcript attribution opt-out gives employees agency and reassures them that we honor their privacy.
  • Recommending that employees “tell and confirm” before recording empowers and supports our people to speak up when they don’t believe the meeting should be recorded or don’t feel comfortable with this choice. Employees in the meeting can also stop the recording, if needed, or determine if automatic recording was set up but is not appropriate.
  • Visual indicators that a meeting is being recorded and that transcription has started, allowing users to request that a meeting stop being recorded or to leave the call.
  • User education, through an internal recording smart-use statement document, helps employees understand the implications of recording, when not to record, and when not to speak in a recorded call.
  • We do not use compliance recording. While compliance recording could enforce full consent collection, unmuting themselves, we decided that opt-outs and user notices provided sufficient agency to our employees.
  • We offer meeting labels that limit who can record, meaning only the organizer or co-organizer can initiate recordings for meetings labeled “highly confidential.”
  • Meeting labels are informed by content shared within the meeting. If content is shared in the meeting that has a higher label than the meeting itself, the organizer is prompted to re-label it.
  • Meeting labels are inherited and applied to all meeting artifacts, recordings, transcripts, and notes. This means that meeting knowledge remains protected, and any AI consumption of that recording will automatically inform the consumer of the sensitivity and required protections.
  • Only meeting organizers can download meeting recordings, keeping the meeting data contained and restricting sharing.
  • The default OneDrive and SharePoint meeting expiration is set to 90 days to ensure we minimize the risk of data leakage or cloud-storage bloat.
  • The default Meeting AI Archive is set to an 18-month retention policy. That allows questions and decisions from the meeting to be leveraged by the team for post-meeting insights but ensures that data is not kept forever.  
  • Deletion is applied in a consistent manner under the business general categories of our retention schedule. The schedule supports our designation of the Teams artifacts as productivity tools and resources, but not as official company records. This stance controls data volume, reduces review and production burden, and ultimately reduces risk (including security and privacy factors).

Balancing productivity with sensible data governance

At Microsoft, we apply different retention periods to different types of meeting data, based on their purpose and business value. Full meeting recordings and transcripts are governed by a default 90-day expiration policy, helping reduce privacy, security, and storage risks while ensuring employees can still benefit from recordings in the near term.

“The bottom line is that we rely on our employees to be good stewards of the company. Because we’ve got a good governance model in place for Teams and solid overall hygiene for our tenant, we’re well set up to deal with the evolution of the product and make these decisions.”

David Johnson, tenant and compliance architect, Microsoft Digital

Separately, AI-generated meeting knowledge—such as questions, decisions, and other insights extracted from meetings and used to support discovery and knowledge-sharing—can be retained for up to 18 months, allowing teams to benefit from the value of those insights long after the original transcript has expired.

These policies are designed to balance employee productivity with responsible data governance, ensuring that important information remains available when useful but is not retained indefinitely. They reflect the three core tenets we use to inform our governance efforts: empower, trust, and verify.

“The bottom line is that we rely on our employees to be good stewards of the company,” Johnson says. “Because we’ve got a good governance model in place for Teams and solid overall hygiene for our tenant, we’re well set up to deal with the evolution of the product and make these decisions.”

The net outcome of all of this work is that our organization is more confident in our approach to meeting knowledge, resulting in more meetings being recorded or transcribed and generating more valuable post-meeting artifacts.

We can’t specifically recommend that an organization follow our blueprint entirely, but asking questions similar to the ones we’ve outlined here can help you build a strong Teams data-governance foundation. With a firm grasp of the technology and close collaboration with key stakeholders, you can guide your own policy decisions and unlock more value for your employees.

Key takeaways

Here are some tips for approaching meeting data retention policies and practices at your company:

  • Face your fears and get comfortable with being a little uncomfortable. First establish your concerns about Teams data retention, then work toward optimizing your policy compliance.
  • Consider how to support your company’s compliance obligations while still allowing your employees to take advantage of the product’s data-retention features. Let those things live together side-by-side.
  • Connecting with your legal team is essential, because they’re the experts on assessing complex compliance questions. Leveraging legal expertise not only drives clarity on complex compliance questions but also allows you to surface opportunities and constraints around how and when to use meeting data features specific to your business or industry.
  • Investigate meeting labels and what policies you might want to apply to different meetings, based on sensitivity and other attributes.
  • Engage your security team to discuss how labeling and post-meeting protections can address any company security concerns.

Try it out

Related links

The post Empowering employees after the call: Enabling and securing Microsoft Teams meeting data retention at Microsoft appeared first on Inside Track.

]]>
25075
Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft http://approjects.co.za/?big=insidetrack/blog/keeping-the-enterprise-secure-by-default-secure-boot-certificate-updates-at-microsoft/ Thu, 13 Aug 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=25067 At Microsoft, we manage around 500,000 Windows client devices worldwide, from employee laptops to servers to meeting room systems. In an environment that large, it’s complex and challenging to maintain end-to-end security. Every one of those devices relies on Secure Boot, a Windows security capability that verifies firmware, boot loaders, and operating system components before […]

The post Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft appeared first on Inside Track.

]]>
At Microsoft, we manage around 500,000 Windows client devices worldwide, from employee laptops to servers to meeting room systems. In an environment that large, it’s complex and challenging to maintain end-to-end security.

Every one of those devices relies on Secure Boot, a Windows security capability that verifies firmware, boot loaders, and operating system components before startup. This system helps ensure all our Windows devices run only trusted software and protects us against threats that target the boot process.

When three Microsoft-issued Secure Boot certificates approached expiration in 2026, our team in Microsoft Digital, the company’s IT organization, knew we needed to take action early and get ahead of the update. By partnering with the Microsoft Office of the CISO and several of our product teams, we developed an approach that ensured secure-by-default devices from the firmware up.

Updating the foundation of device trust

Secure Boot sits at the foundation of Windows security. Without updated certificates, devices would lose the ability to receive future Secure Boot protections and other boot-level security improvements.

A photo of Quintana.

“We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.”

Luis Quintana, principal engineering group manager, Endpoint Security

To maintain protection, we needed to replace three legacy certificates with four new ones across a diverse device fleet. Replacing the certificates was straightforward. The real work was validating the update across thousands of device models and deployment scenarios.

Secure Boot certificates needing replacement

  • KEK: Microsoft Corporation KEK CA 2011 → Microsoft Corporation KEK 2K CA 2023
    Covers: Database updates (DB and DBX)
  • UEFI CA: Microsoft Corporation UEFI CA 2011 → Microsoft UEFI CA 2023 and Microsoft Option ROM UEFI CA 2023
    Covers: Third-party UEFI modules, bootloaders, and option ROMs
  • Windows Boot chain: Microsoft Windows Production PCA 2011 → Windows UEFI CA 2023
    Covers: Windows Boot Manager and boot components

We started early so we could test, validate, and gradually deploy the updates before the certificate expiration dates arrived. That approach helped us strengthen the security posture of our devices while minimizing disruption to employees and business-critical systems.

“Updating hundreds of thousands of devices without disrupting people and business operations is no small task,” says Luis Quintana, principal engineering group manager for Endpoint Security. “We manage a diverse fleet of devices and usage scenarios, so we needed an approach that could scale safely, provide visibility into our progress, and maintain confidence in device security.”

Leading the update across a complex device estate

We first began this work in 2024 by partnering with the Windows Servicing and Delivery team, which helped us identify device models the certificate renewal might affect. We tested those models end to end in our Client Test Lab, then deployed the update to a pilot group of around 35,000 devices using a controlled firmware release (CFR). That pilot achieved a 95% success rate, which gave us the confidence to scale up.

A photo of Dagdelen

“Intune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate. It helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.”

Kubilay Dagdelen, senior service engineer, Microsoft Intune

In February 2026, we kicked off the broader effort across our entire Windows 11 device ecosystem. Reporting and telemetry formed our essential starting point.

Microsoft Digital partnered with the Windows Autopatch, Intune, and Microsoft Defender for Endpoint teams to identify which devices already included the latest certificates because they were released after 2025, which devices needed the update, and which failed. In support of these efforts, the Autopatch team built fleet-wide reporting of Secure Boot status directly into Intune, turning raw telemetry into a live compliance dashboard.

“Intune was the glue that brought the process together, turning a collection of settings and instructions into something we could orchestrate,” says Kubilay Dagdelen, a senior service engineer on the Microsoft Intune team. “It helped us create a repeatable playbook that covered everything from reporting and targeting to rollout.”

A ringed approach across a range of devices

We started small, using telemetry signals to identify device cohorts based on their risk of failure. Starting from the simplest devices to update, we gradually scaled across models that carried more complexity, keeping backups and loaner machines ready to support global operations in case of disruption. After just 70 days, we had achieved 86% compliance across all our devices.

A photo of Savagur.

“This has been an opportunity to strengthen our security foundation. It’s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.”

Pandurang Savagur, senior product manager, Microsoft Digital

But we don’t just maintain employee devices. Our hardware estate spans meeting rooms, secure admin workstations, digital signage, and executive devices. These different device types demanded different Secure Boot approaches.

To tackle this challenge we established a virtual team, with members responsible for each of these surfaces holding weekly syncs and leadership updates. For example, our 15,000 meeting room devices run a custom Windows 11 image, so we partnered with OEMs to release firmware for them.

Meanwhile, cloud PCs on Azure infrastructure needed scheduled reboots to update, so we let employees choose when to restart. For our server cohort, where telemetry gaps made progress hard, Microsoft Defender for Endpoint delivered the independent visibility we needed.

“This has been an opportunity to strengthen our security foundation,” says Pandurang Savagur, a senior product manager on the Device Lifecycle team in Microsoft Digital. “It’s about going from reactive security to a secure-by-default baseline aligned with Zero Trust principles.”

Our Customer Zero experience: Expertise and process pathfinding

Our role as Customer Zero shaped how we approached this process. As both the creators and users of Microsoft technology, we have direct access to product teams as well as intimate knowledge of our tools’ capabilities.

A photo of the Evgrafova.

“Technology and culture matter equally here, and our Microsoft culture means we know what’s coming and can act proactively through direct access to our engineering groups.”

Yulia Evgrafova, principal security service engineer, Office of the CISO

Intune served as our execution engine, orchestrating policies and remediation scripts across more than 90% of our devices with precision. Autopatch and Defender added speed through visibility.

Thanks to the lessons we learned throughout our update journey, we’re in the process of incorporating capabilities we developed internally into each solution for public release. We’ve also established steps that can help you manage your own Secure Boot certificate updates.

“Technology and culture matter equally here, and our Microsoft culture means we know what’s coming and can act proactively through direct access to our engineering groups,” says Yulia Evgrafova, a principal security service engineer for our Office of the CISO. “On the technology side, we have the expertise to experiment and the privilege of reaching engineering teams directly.”

Secure by default and ready for what’s next

Thanks to thorough telemetry and a measured approach to rolling out the update, we’ve now reached 97% compliance globally, all while keeping our failure rate under one percent and our support burden low. Our devices now validate trusted firmware and boot components by default, keeping the list of trusted components current and closing gaps that attackers could exploit at startup.

This work continues as we collect logs on devices that need attention and remediate the stragglers, including meeting rooms and virtual machines. That long tail is the hard part, but it’s a natural component of any effort at this scale.

What we built here reaches well beyond one certificate update. Telemetry gave us the visibility to protect devices without disrupting people, and that aspect of this rollout will guide get compliant and stay compliant in the future.

“This effort serves as a playbook for many different initiatives that we’ll take on in the future,” Quintana says. “One of the biggest lessons is how we can balance experience and protection between Microsoft Digital and our security teams.”

Key takeaways

As you update your own Secure Boot certificates, keep the lessons we learned internally during this process in mind:

  • Start early and validate with pilots. Give yourself enough runway to test on representative hardware, because certificate updates touch the firmware layer and you don’t want surprises at scale.
  • Make telemetry your foundation. Reliable, fleet-wide visibility tells you which devices need updates, which have already succeeded, and where the real risks are before you deploy anything.
  • Deploy in phased rings. Start with low-risk devices and progress toward high-risk and older hardware, using guardrails at each stage to avoid boot failures and contain any issues.
  • Plan extra time for difficult device types. Older hardware, meeting room systems, servers, and end-of-support devices present the biggest hurdles, so identify them upfront and budget the effort they demand.
  • Build a virtual team culture. Bringing every stakeholder together, from security to leadership, gives each group a chance to shape the plan while also securing the budget and support that the effort requires.
  • Treat secure-by-default as the new standard. Secure Boot is no longer an opt-in position, so communicate early and enforce consistently. Remember that people need to know the change is coming and that you’re doing everything possible to make it happen smoothly.

Try it out

Related links

The post Keeping the enterprise secure by default: Secure Boot certificate updates at Microsoft appeared first on Inside Track.

]]>
25067
Implementing Agent 365: How we’re governing and managing AI agents at Microsoft http://approjects.co.za/?big=insidetrack/blog/implementing-agent-365-how-were-governing-and-managing-ai-agents-at-microsoft/ Thu, 06 Aug 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24764 Building readiness for Agent 365 at Microsoft At Microsoft, we’re on a Frontier Transformation journey to reimagine work and redefine processes through the power of agentic AI. Microsoft Digital, the company’s IT organization, operates a large and diverse population of agents, built across a broad range of tools and technical capabilities. With Microsoft Agent 365, […]

The post Implementing Agent 365: How we’re governing and managing AI agents at Microsoft appeared first on Inside Track.

]]>

Building readiness for Agent 365 at Microsoft

At Microsoft, we’re on a Frontier Transformation journey to reimagine work and redefine processes through the power of agentic AI.

Microsoft Digital, the company’s IT organization, operates a large and diverse population of agents, built across a broad range of tools and technical capabilities. With Microsoft Agent 365, we now have visibility into more than 500,000 agents.

This distributed control plane has brought agent inventory and governance into one place, giving us a clear view of agent categories, metadata, usage, and ownership information. Agent 365 has also improved our ability to track agent lifecycle and bring in new risk insights.

There’s more work to be done, but it’s already enabling enterprise-scale agent management at Microsoft. Agent 365 provides helpful information about our agent ecosystem, including the top platforms used to create them and the agents our employees use most. It presents this info in helpful, all-up views like the dashboards below.

We’re increasingly connecting agents to business-critical data, involving them in vital workflows, and using them to drive concrete business outcomes. This shift to agentic workflows has inevitably led to questions about operational readiness:

  • How do we further accelerate AI-powered innovation without losing visibility, trust, and control?
  • How do we create useful, powerful agents while governing them safely?

Agent 365 is becoming an essential vehicle for answering these questions as we enhance agent oversight and control for everyone involved in Frontier Transformation, from AI administrators to security professionals to business decision makers.

Agent 365: A response to the challenges of agentic governance

At Microsoft, we share many of the concerns of our customers about properly governing and managing the wide array of agents we build and surface across different platforms. We take a “self-service with guardrails” approach to our productivity estate, which means we give employees the ability to create new workspaces across their Microsoft 365 applications, while we secure assets by default and expand access based on employee needs.

The same is true for agent creation. As a result, the number of agents within our organization has grown rapidly.

A photo of Fielder.

“Agent 365 is giving us the confidence to let innovation happen everywhere while ensuring we always understand what agents are doing, how they’re evolving, and where IT needs to engage as a trusted partner in the process.”

Individuals and teams can create agents through a variety of platforms, including Microsoft 365 Copilot Agent Builder, Microsoft SharePoint, Microsoft Teams, Microsoft Copilot Studio, Microsoft Azure AI Foundry, and Agents Toolkit Software Development Kit (SDK). Each platform has its own tools, back-end systems, and ways to view inventory, usage, and risk.

As agents began operating across apps and runtime environments, the need for us to break down management and governance siloes became apparent. An effective method for managing this new class of enterprise asset was required.

We wanted one shared view of all agents in our organization, tightly connected to the people responsible for administration, governance, security, and business outcomes. That’s a challenging prospect—something that no organization has done before.

Microsoft created Agent 365 in response to these needs. In Microsoft Digital, we’ve been working alongside the Agent 365 product team to implement this suite of tools within our production tenant. We’re putting these core capabilities into practice, providing a unified way to observe, manage, govern, and secure agents as they scale across our organization.

“Agent 365 is giving us the confidence to let innovation happen everywhere while ensuring we always understand what agents are doing, how they’re evolving, and where IT needs to engage as a trusted partner in the process,” says Brian Fielder, vice president of Microsoft Digital.

This guide shares what we’ve learned so far:

  • How we’re using Agent 365 in Microsoft Digital
  • Where we’re supplementing it with additional practices
  • Lessons learned that can help you use Agent 365 more effectively, whatever your scale or AI maturity level

From product vision to production

As Customer Zero for Agent 365, it’s important that we’re candid about our journey. Much of the product’s value comes from how we’re incorporating it into our current processes, alongside existing tools.

Scale is also relevant. For smaller or simpler tenants, readiness comes faster. At an organization like Microsoft, with hundreds of thousands of agents, there are times when manual oversight isn’t enough.

We’re actively involved in co-developing the product, uncovering opportunities for capabilities like automation and programmatic solutions to support administration and governance at scale. As part of this process, we’ve partnered closely with the product team to provide continuous feedback and share learnings from our hands-on experiences.

A photo of Smith

“This has been a strong partnership—daily standups, tracking real issues, and embracing the feedback needed to make the product better. Microsoft Digital plays a critical role as our Customer Zero while operating at a scale like no one else.”

Today, we’re using core Agent 365 capabilities while actively sharing feedback with the product group in the following areas:

  • Centralizing an accurate inventory of all agents running in the tenant across Microsoft and third‑party platforms to provide a genuinely unified registry across all agent platforms.
  • Extending existing enterprise controls by integrating with Microsoft Entra for agent identity, Microsoft Purview for data security and compliance, Microsoft Defender for threat protection, and the Microsoft 365 admin center for operations—all enhanced for improved agent control and management.
  • Assisting processes to streamline the lifecycle for agents, including new lifecycle metadata like draft vs. published status, ownership tracking, and usage analysis.
  • Surfacing actionable insights and risk signals related to agent behavior, access, data usage, and runtime activity, helping IT prioritize attention and response.
  • Supporting enterprise scale through automation and APIs to help manage large, diverse agent deployments without relying on manual management.

While full lifecycle capabilities for certain agent platforms, risk signals, and enterprise-scale automation evolve, we continue to partner with the product group to close gaps while existing processes support current operations.

“This has been a strong partnership—daily standups, tracking real issues, and embracing the feedback needed to make the product better,” says Ray Smith, corporate vice president for the Agent 365 product group. “Microsoft Digital plays a critical role as our Customer Zero while operating at a scale like no one else.”

Chapter 1: Establishing a foundation of practice for agent administrators

A new opportunity to break down silos between roles

As we began scaling agents inside Microsoft, we discovered that the future of agent management would need to evolve from our current ways of working. We wanted a world where we could create and use agents broadly while keeping administration manageable and consistent.

Getting there required new patterns of practice for IT, especially for administrators operating across different focuses. Agent 365 unifies observability between enterprise roles, acting in concert with the broader Microsoft suite of administration, security, identity, and governance tools.

Here is a summary of the needs of different personas involved in the agent-building and management processes, grouped by office and broken down by role:

Office of the CIO

Developers and makers

Build, test, and deploy intelligent agents at scale

Products: Agent Builder, Copilot Studio, Microsoft Foundry

IT administrators

Control, govern, and monitor agents across the organization

Product: Microsoft 365 Admin Center

Agent users and business decisions makers

Get work done faster with AI-powered assistance

Products: Copilot and Teams

Office of the CISO

SecOps

Detect threats and secure agent activity in real time

Product: Microsoft Defender

Data and compliance

Protect data and enforce compliance policies

Product: Microsoft Purview

Identity manager

Manage identities and access agents and users

Product: Microsoft Entra

We’ve found that our most effective AI administrators come from existing Microsoft 365 backgrounds, because they already have deep expertise with mature tools and processes. Whether they’re generalists or specialists, your administrators will already be positioned to manage agents at scale and use their skills and experience with the tools and insights that Agent 365 delivers.

Shifting from siloed administration to coordinated responsibility

Up until this point at Microsoft, managing agents has been the responsibility of the platform administrators who control agent creation tools. SharePoint administrators manage SharePoint agents, Power Platform administrators manage Copilot Studio agents, and so on. Meanwhile, identity, security, and compliance teams handle their respective layers using Microsoft Entra, Microsoft Defender, and Microsoft Purview—often independently.

We know that this model has the potential to break down as agents become more powerful and more interconnected, and as new agent types begin to run autonomously with their own identities.

A photo of Clare

“With agents in action across multiple spaces, managing them is a special challenge. It was clear that we needed a silo-buster to govern this new ecosystem effectively.”

Within Microsoft Digital, we’re using Agent 365 to differentiate agent management from platform-specific administration without replacing existing expertise. Instead of creating a single, centralized agent manager that encroaches into each platform’s territory, Agent 365 gives us one shared view across platforms, so administrators can coordinate their work with the same data and context.

With this new, single pane of glass, we’re building shared responsibility and clear handoffs where they make the most sense. For example, our AI administrators manage the full lifecycle of Microsoft 365 Copilot Agent Builder agents. But when Copilot Studio is involved, they collaborate with Power Platform administrators to strategically manage those agents in their specific environment.

Agent 365 provides the connective tissue by providing details and common metadata as we move between platforms and administrators.

“With agents in action across multiple spaces, managing them is a special challenge,” says Jonathan Clare, principal service engineering manager in Microsoft Digital. “It was clear that we needed a silo-buster to govern this new ecosystem effectively.”

Evolving agent management from existing roles

One key insight we’ve uncovered from this work is that agent administration doesn’t require a new IT skill set. It builds on the same foundational experience we already use to manage products like Power Platform, SharePoint, Exchange, and Entra, or other identity-based systems.

A photo of Johnson

“We’re still iterating on the seams between administrators with different responsibilities. Agent 365 is providing the space for AI and identity administrators to work closely alongside their colleagues in security, compliance, and governance.”

The core skills of maintaining accurate inventory, ensuring visibility and access, managing lifecycle, and mitigating risk are already mature and deeply established in our organization. Agent 365 now gives us the broad insight we need to oversee all agents in one place.

From there, we can lean into our well-developed expertise and mature processes with newly enhanced tools, shared metadata, logging, and controls. This coordination gives each team in sequence a sense of clarity and partnership, rather than feeding effort up and down a chain of approval.

“We’re still iterating on the seams between administrators with different responsibilities,” says David Johnson, a principal PM architect in Microsoft Digital. “Agent 365 is providing the space for AI and identity administrators to work closely alongside their colleagues in security, compliance, and governance.”

As we progress, we’re developing a three‑part administrative model facilitated by the oversight that Agent 365 provides.

AI administrators, the primary users for Agent 365

  • Oversee complete agent inventory and usage at the tenant level
  • Manage the agent lifecycle with the platform coordination to cover a broad range of agent types
  • Provide the connective tissue between security, governance, identity, and platform administrators

Agent Identity administrators, new with Agent ID

  • Manage agent identities after provisioning and throughout the agent’s lifecycle
  • Manage lifecycle events tied to users, access changes, and deprovisioning
  • Build identity backed policies for agent workload management and risk mitigation

Security, compliance, and governance teams

  • Define the guardrails that apply to agents and agent blueprints, portable specifications for agents’ identities, capabilities, constraints, policies, data access, and lifecycles
  • Approve the kinds of data, tools, and permissions agents can request
  • Set agent evaluation and risk assessment criteria along with risk-aligned approval workflows
  • Align publishing and runtime decisions with risk tolerance and security policy

Agent 365 facilitates this model by providing comprehensive agent coverage. This acts as a shared coordination layer, bringing different administrator, security, identity, and governance roles into a unified space.

A diagram showing the relationship between AI administrators from within Microsoft Digital and the Office of the CISO that collaborate within Agent 365.
Agent 365 has been a “role buster” for our team, because deploying it effectively requires people from different administrative disciplines to come together and operate as one team. 

Agent 365 in practice: Agent publishing and workflows

We didn’t create Agent 365 to handle every IT workflow. Many approval, vetting, and escalation processes are specific to an organization’s risk posture and operating model. At Microsoft, we’re currently handling much of that logic using an existing risk assessment and publishing workflow while evaluating how Agent 365 capabilities can simplify those steps. An example of the type of risk we look for is when an agent could read sensitive data and write it to destinations with broad access, like external sites or apps.

There are several areas of risk we use Agent 365 to assess:

The levels of agent risk, color-coded from green to red, and how they align with different areas like data, compliance, security, and identity.
Agent 365 plays complementary roles in our agent risk assessment model while we continue to work with the product team to enhance and scale risk assessment features.

Agent 365 itself assists us with additional risk awareness:  

Real-time

  • Observability across agents
  • Surfacing signals from identity, security, and governance systems
  • Supporting the ability to act when risks or issues surface

Proactive

  • More intelligent risk insight during the agent permissioning and approval processes
  • Consistent agent publishing into the environment
  • Forthcoming capability: the ability to integrate with our existing agent review and publishing process that spans multiple teams, including administration, governance, and security

As you consider ways to collaborate across your own administrator teams, our silo-busting approach can act as a helpful guide.

Key takeaways

Use these practices to build your foundation for agent administration:

  • Clearly parse security, governance, AI administration, and identity responsibilities. Define collaborative channels and explicit handoffs between the teams that manage these domains.
  • Treat Agent 365 as an oversight and coordination layer. It isn’t a replacement for platform or identity administrator expertise, but it’s the best place to look at the big picture.
  • Determine your criteria for agent risk assessment and publishing approval. Collaborate with relevant security, privacy, HR, legal, and other teams to calibrate your risk tolerance.
  • Define your agent lifecycle expectations. Tie these back to any governance you may have in agent creation workloads like SharePoint and Copilot Studio.
  • Establish visibility first, then layer in approval workflows. Match them to your organization’s risk tolerance and operating model.
  • Avoid creating a bureaucratic choke point. Successful agent administration depends on partnership and choreography, not centralization, where one administrator does it all.
  • Invest in cross-collaboration. Strengthen virtual teams, especially across identity, security, and agent creation surfaces.
  • Expect your administrative model to evolve. As Agent 365 matures and new lifecycle and approval capabilities become available, new practices will emerge organically.

Learn more

How we did it at Microsoft

Further guidance

Chapter 2: Building a registry of agents to manage them at scale

A centralized source of truth for AI agents across the enterprise

As agents have proliferated across Microsoft, visibility has proven essential for robust governance. Without a clear understanding of all the agents that exist in our environment, including their origin and how people use them, it’s very difficult to make informed decisions or respond confidently when risks emerge. Establishing a thorough registry of agents and their key information is a critical step in governing the ecosystem.

Agent 365 provides that oversight.

Why an agent registry matters

An agent registry establishes the foundation for oversight, control, and compliance. As an organization introduces more agents, the environment can quickly become fragmented and difficult to track.

A comprehensive registry provides a single, authoritative inventory that makes every agent visible, tracks ownership, and captures key metadata. With that baseline, organizations can consistently govern, secure, and manage their agents with confidence.

A photo of Powers

“Managing agents begins with having a complete inventory with rich information, like their name, lifecycle status, type, ID, owner, where we created them, and where we’re using them. Once you have that level of clarity, everything else—security, compliance, lifecycle management—becomes much easier to manage.”

At the scale of a company like Microsoft, even small gaps in visibility can quickly become operational hurdles or compliance liabilities. Without that foundation, an organization faces substantial risks:

  • Ownerless agents remain active after employees leave the company.
  • Shadow or unsanctioned agents are difficult to detect.
  • Oversight is unreliable with respect to agent growth, usage, and impact.

“Managing agents begins with having a complete inventory with rich information, like their name, lifecycle status, type, ID, owner, where we created them, and where we’re using them,” says Mike Powers, an AI administrator in Microsoft Digital. “Once you have that level of clarity, everything else—security, compliance, lifecycle management—becomes much easier to manage.”

Agent 365 registry capabilities

Within Agent 365, the registry acts as a central inventory enriched with metadata. We use that metadata to meet compliance, security, and management standards, including:

  • Agent ownership and associated teams
  • Creation platforms and publishing surfaces
  • Lifecycle states like “draft” or “published”
  • User scope: who can discover and use the agent

In Microsoft Digital, we’re providing real-world feedback to the Agent 365 product group to enable even more types of metadata, like differentiation between system vs. user-created agents, and new agent types like AI teammates. We’re also using metadata surfaced from the platform where the agent was created, for example, the Power Platform environment ID for Copilot Studio agents and the Azure AI Foundry subscription details for Foundry agents.

Agent 365 amalgamates all of this metadata into a single view.

This structure matters because agents vary widely. Some are short‑lived experiments. Some belong to only one employee, while others are broadly shared. Treating them all the same doesn’t make sense.

From an administrative perspective, the registry gives us:

A summary view of total agent count

Insights around growth and adoption

Identification of agents without owners

Analytics on platforms used to make agents and their usage trends

Search, sort, and filtering with customizable columns to get detailed views across agent types

Robust inventory export capabilities to support collaboration with security, compliance, and business stakeholders

Establishing our Agent 365 registry

The agent registry is an out-of-the-box feature for Agent 365, so there’s nothing to deploy or configure. As Customer Zero, we’ve focused much of our early work on validating the registry for accuracy and completeness.

Agent 365 automatically ingests agent metadata from supported platforms. This technology is still new, so we’ve partnered with product teams across SharePoint, Power Platform, Azure AI Foundry, and other builder experiences to reconcile counts, ensure accuracy, and request additional relevant metadata.

For first-party tools, Agent 365 creates registry entries automatically. Third-party agents can also benefit from automatic registration if their creators use the Agent 365 SDK during development.

For pro‑code scenarios, Entra Agent ID is key. Registering an agent through Entra assigns it a formal identity, which lays the groundwork for consistent identity and lifecycle management and conditional access policies.

Acting on the registry

The registry is a living system. Ownership changes, while lifecycle states and usage signals update automatically.

That means the registry supports critical processes for administrators that include:

  • Passing audits for elements like tracking agent ownership
  • Presenting the tenant’s agent footprint and usage to business decision makers
  • Scoping agents to specific users, or excluding users based on regional or regulatory requirements
  • Highlighting high‑impact agents based on usage and runtime

A single view has been one of the most valuable outcomes for us, enabling informed operational decisions and peer-to-peer collaboration.

Looking ahead

The registry is also the prerequisite for future experiences, including broader agent discovery and publishing. Moving forward, it will provide the context we need to guide reuse, review, publishing, and eventual retirement to support intentional agent lifecycle practices over time. As a result, it will be easier to combat sprawl and ownerless agents.

In Microsoft Digital, our early Agent 365 efforts have focused on validating our agent registry to lay the foundation for comprehensive observability. It may be helpful for you to mirror this approach.

Key takeaways

Here’s what we’ve learned during the initial stages of building and operating our agent registry:

  • The registry isn’t just an inventory. It’s the foundation for agent governance and insights to help take more informed actions and avoid risk.
  • Establish accountability. Use the registry to ensure every agent has a clear owner and lifecycle state.
  • Dive deep for the most value. Analyze the Agent 365 inventory export files and compare them with any previous methods you used to gather information about agents, for example, Power Platform, SharePoint, or other bespoke methods, to ensure accuracy and consistency.
  • Break down silos using the agent registry. The information Agent 365 provides will break down administrative silos across IT, security, identity, and business teams for more informed and collaborative analysis and discussions about agent adoption.

Learn more

How we did it at Microsoft

Further guidance

Chapter 3: Visualizing agents to support oversight and action

Observability: Scaling beyond dashboards

At the scale of an organization like Microsoft, dashboards alone aren’t enough. We already have hundreds of thousands of agents in use across the company. At that scale, it would be impossible to review these agents individually. We rely on well-established governance in the form of guardrails, established software development lifecycle procedures, and risk-based app and agent management policies that trigger reviews when we detect risk.

Agent 365 helps us operationalize oversight using automation and rules engines, programmatic access via APIs and scripting, and bulk actions based on attributes like permissions, connectors, and usage patterns.

A simple user interface is essential for visibility, assessment, and decision‑making. Programmatic access is essential for execution. Effective agent administration requires both.

The lesson is that administering agents during Frontier Transformation requires a new approach that breaks out of traditional roles and inter-team hierarchies. By incorporating our experience into your own planning, you can use Agent 365 more effectively.

Why visualization matters

As agents spread across Microsoft, we learned that inventory alone isn’t enough. Knowing an agent exists is helpful, but understanding how people use it, how it connects to data and other agents to complete workflows, and where risks or concentration points emerge is what makes effective governance possible at scale.

In a Frontier Firm where almost anyone can create agents, observability is a core pillar of management. Like many organizations, we built agents first and only later confronted the challenge of seeing what existed. Agent 365 will help other organizations reverse that order by surfacing agent behavior continuously from the start.

A photo of Ceurvorst

“Just this first layer of visualizing our agent ecosystem in one central place is a big step toward flowing them into our business processes and demonstrating ROI more effectively.”

Visualization is helping us address questions we couldn’t answer before:

  • Where is agent growth accelerating?
  • Which agents are widely used?
  • Where do risk hot spots occur across connectors, data sources, and permissions?
  • What demands attention now, and what can wait?

“We’re uncovering so many new use cases for agents,” says Amy Ceurvorst, a director of business programs in Microsoft Digital. “Just this first layer of visualizing our agent ecosystem in one central place is a big step toward flowing them into our business processes and demonstrating ROI more effectively.”

The agent landscape changes quickly, and with Agent 365, we can look at usage at the individual agent level to track shifts over time. For example, Cowork (Frontier) is one of our newest agents, but in just a few weeks it became our most widely used.

In a recent review of Cowork adoption, Agent 365 allowed us to quickly analyze names, session activity, and locations for Cowork’s 58,000 active users in just a few minutes.

This is also where Agent 365 complements rather than replaces Viva Insights:

  • Viva Insights combines Agent 365 data with our organization’s people data to provide enhanced insights into agent usage across the organization.
  • Agent 365 provides oversight for the full agent estate: registry, publishing, ownership, lifecycle, and governance.

Both are important, but they serve different personas. Where Viva helps clarify usage for adoption leaders and change managers, Agent 365 helps determine what action IT should take next.

The Viva Insights Agent Dashboard extends the data in Agent 365 by translating agent inventory and telemetry into executive‑ready insights on adoption, usage patterns, and trends across the organization. By combining agent activity with organizational context, it helps leaders understand where people are using agents, how adoption is evolving over time, and where opportunities or risks may exist.

Together, Agent 365 and Viva Insights provide a governed, end‑to‑end view that supports informed decisions about scaling and governing agents to drive business impact.

From insight to action

One of our biggest lessons as Customer Zero is that visualization only matters if it leads to action. In Agent 365, insights increasingly surface as prioritized scenarios, such as risky, ownerless, or unused agents. We can then pair those insights with paths to response—for example, meeting compliance expectations by re-assigning or retiring ownerless agents.

A photo of Zimmer

“Agent 365 is saving us time by helping us analyze the kinds of issues that are common in agent management and bringing those to our administrators’ attention. It acts as a command center that surfaces those issues programmatically, so we’re able to prioritize the actions we need to take.”

Visualization in Agent 365 is about prioritization. For us, some of the most valuable scenarios include:

The goal is to focus attention where it counts.

“Agent 365 is saving us time by helping us analyze the kinds of issues that are common in agent management and bringing those to our administrators’ attention,” says Nate Zimmer, a senior product manager in Microsoft Digital. “It acts as a command center that surfaces those issues programmatically, so we’re able to prioritize the actions we need to take.”

Continuously clearing the fog

Observability is never finished. New agent types and creation tools continue to emerge. Agent 365 helps us embrace that reality by connecting signals across Microsoft 365, identity, security, and compliance for a continuously updated view of an evolving agent landscape.

We believe the Agent Map is going to be a differentiator in agent visualization, and we’re closely working with the product team to inform new, robust capabilities that will help us drill down to find hot spots, details on agent connectors, tools, and knowledge sources more easily.

For example, we use the large surface area provided by the Agent Map to search and filter for exactly what we want and then dive deeper into details.

Observability has been crucial for helping us guide agent usage at Microsoft. As you conduct Frontier Transformation at your organization, consider ways that observability has led to better oversight for our team, and incorporate them into your AI administrators’ discipline.

Key takeaways

Think about these lessons from Microsoft Digital as you considering using visualization for managing your agents:

  • Prioritize your attention. Use visualization to surface and remediate your greatest liabilities.
  • Scale through technology. Pair visualizations with the registry to operate at the right level of detail. Many visualization features also support targeted exports, for example, exporting just the users accessing a specific agent.
  • Prepare for new issues and risks. With greater visibility comes heightened awareness of issues. Expect visualization to surface new risks and new personas as agent adoption grows.

Learn more

How we did it at Microsoft

Further guidance

Chapter 4: Securing agents and aligning Agent 365 with organizational priorities

Melding agent oversight, identity, security, and governance

In Microsoft Digital, we’ve learned that securing agentic AI isn’t about inventing an entirely new security model. Instead, the focus should be on extending the identity, data, and threat protections we already trust, while also making risk visible in one place. Agent 365 plays a critical role by surfacing agent‑related security signals in a single view so that IT teams can see what matters quickly, even when remediation happens elsewhere.

The agentic security challenge

Up to this point, understanding agent risk has meant pulling information from multiple tools and manually stitching together context. Identity management lives in one place, data protection in another, and threat insights somewhere else. That makes it harder for IT administrators to spot patterns and gain insight.

A photo of Enjeti

“A lack of visibility creates real security risk, exposed data access, unmonitored behaviors, and unmanaged identities. Agent 365 helps us regain control by building a comprehensive inventory and risk profile of agents.”

Other factors compound the challenge:

  • People and teams are creating agents quickly, accelerating the need for manual reviews.
  • Agents can operate across apps, data sources, action types, data, and data destinations, and they carry the potential for other agents to expand the attack surface, complicating oversight and control.
  • Risk emerges at multiple stages, both during agent development (design time) and during execution (run time).

“This lack of visibility creates real security risk, exposed data access, unmonitored behaviors, and unmanaged identities,” says Prathiba Enjeti, a principal security manager for the Microsoft CISO organization. “Agent 365 helps us regain control by building a comprehensive inventory and risk profile of agents.”

Theoretically, existing agent governance policies and practices should mitigate these risks, but there are always exceptions. It’s easy to miss early warning signals, and teams may only detect issues after they have an impact.

Agent 365 helps us identify and remediate those issues.

Agent 365 as a security visibility layer

As we bring Agent 365 into our operational workflows, it connects with Microsoft Purview, Microsoft Entra, and Microsoft Defender, surfacing relevant agent‑specific risk insights in a cohesive experience. That reduces fragmentation and supports more informed, coordinated decisions.

You can see how Agent 365 capabilities apply to different members of the agent administration and management ecosystem.

A three-part Venn diagram featuring areas where Agent 365 breaks down silos between different agent administration roles: IT, identity, and security.
Agent 365 facilitates coordination between different administrator roles.

Rather than replacing those tools, Agent 365 ingests identity signals from Entra, data signals from Purview, and runtime behavior from Defender. In practice, we think about agent security in two main categories:

  • Buildtime risk: These signals surface when people create or configure agents. Examples include overly broad permissions, insecure configurations, or missing responsible AI safeguards. Seeing these early helps reduce downstream risk and rework.
  • Run-time risk: As agents operate, they can expose data unexpectedly, become susceptible to vulnerabilities like prompt injection, or lose protection as data moves across systems. Run-time visibility becomes even more important as agents begin working together.

Agent 365 doesn’t eliminate these risks, but it does have the capacity to make them more visible, traceable, and easier to prioritize and mitigate. Follow‑up actions still happen in Entra, Purview, and Defender, but now those administrators benefit from improved oversight and coordination.

What we’ve learned so far

Internally, broader visibility has helped us uncover issues we had difficulty tracking before, like ownerless agents spanning multiple platforms or unexpected data handling behaviors. While more broadly available agent oversight might seem intimidating because it widens scrutiny, we’ve found that additional data and insights have accelerated alignment and improved decision making.

With Agent 365, we now have better conversations through shared context and metadata. As a result, IT, security, and business teams can discuss adoption trends and mitigate risk using the same information instead of chasing it across tools.

Key takeaways

You can follow the lessons we’ve learned while further securing agents using Agent 365:

  • Oversight is not a replacement for security.  Use Agent 365 as a central visibility layer, not a substitute for existing security tools and practices.
  • Creation and operation both contain risks. Expect security signals at both build time and runtime.
  • Build a practice of consolidation. Prioritize investigation using consolidated signals, even when remediation happens elsewhere.
  • Choreograph the tools between teams and functions. Integrate Agent 365 into existing security operations rather than creating parallel workflows.

Learn more

How we did it at Microsoft

Further guidance

Conclusion: Turning visibility into confidence as agents scale

As we reflect on the early days of Agent 365, visibility is the foundation for everything that follows. As Customer Zero, our priority has been to understand the full extent of agents across our environment.

The real value will come when we can drill down further. How are people using agents? What risk patterns repeat? What building and usage trends emerge as Frontier Transformation progresses?

A photo of Tiwari

“When we started, I thought the hardest part would be the technology, but it turned out to be building the weekly rhythm where IT, security, identity, product, and business unit teams could look at the same picture, make decisions from the same facts, and act together. My advice to every IT leader is to establish that governance rhythm before your agent count grows faster than your ability to manage it.”

As we mature in our use of Agent 365, it will give us greater ability to move from simple metrics like volumes of agents to more meaningful measures of impact. It will also help us see trends in our environment by segmenting low-use experimental agents from business‑critical digital workers so we can move beyond isolated usage to scaled adoption.

It’s important to be clear about where we are on this journey. Our operating model for Agent 365 isn’t complete. Much of our current focus is still on seeing clearly by surfacing trends, comparisons, and emerging patterns we couldn’t identify before.

“When we started, I thought the hardest part would be the technology, but it turned out to be building the weekly rhythm where IT, security, identity, product, and business unit teams could look at the same picture, make decisions from the same facts, and act together,” says Garima Tiwari, a principal product manager for Agent 365 Customer Zero in Microsoft Digital. “My advice to every IT leader is to establish that governance rhythm before your agent count grows faster than your ability to manage it.”

That visibility is already paying dividends by revealing duplication, ownerless agents, and cross‑platform risks that would otherwise remain uncovered. Over time, those insights will increasingly feed automation, lifecycle workflows, and deeper integrations across identity, security, and governance.

Looking ahead, our next steps are about translating this oversight into action at scale. That will include preparing for broader agent discovery, refining lifecycle management, and enabling new personas, such as managers who are responsible for selecting, creating, and overseeing digital workers. It will also encapsulate learning as new agent types, tools, and usage patterns emerge. Change is constant in a Frontier Firm environment; readiness is something you build continuously, not something you check off once.

A photo of Kerametlian

“Agent 365 represents a new operating model for AI at scale. By bringing visibility, governance, and security together, it helps organizations move beyond experimentation and toward a future where agents are trusted and embedded in everyday work, all without slowing innovation.”

Our overall message in this guide is straightforward: You don’t need to have every answer on day one. What matters most is establishing the conditions for safe evolution as agents scale. Think about clear administration practices, a reliable registry, effective observability, and security signals you can trust. Here at Microsoft, Agent 365 has become an important part of that foundation.

“Agent 365 represents a new operating model for AI at scale,” says Stephan Kerametlian, a senior director in Microsoft Digital. “By bringing visibility, governance, and security together, it helps organizations move beyond experimentation and toward a future where agents are trusted and embedded in everyday work, all without slowing innovation.”

We’ll continue sharing what we learn as Customer Zero. As your organization moves through its own Frontier Firm transformation, we hope these lessons help you build the confidence to innovate quickly, supported by comprehensive insights, thoughtful governance, and security that scales with your ambition.

Key takeaways

Here are the essential top-level learnings that we’ve developed from our Customer Zero experience with Agent 365 so far. They can help guide your own readiness and implementation journey:

  • Agent governance is becoming a team sport. Agents touch on identity, permissions, data access, workflow automation, compliance, and business outcomes. That means agent governance requires cross-team alignment.
  • Start with visibility, not perfection. You don’t need a fully mature operating model on day one. What matters most is creating shared visibility and data about what agents exist, how people use them, and where risks or opportunities are emerging.
  • Treat agent management as an evolution of IT practice. Managing agents builds on familiar disciplines like identity, lifecycle, access control, and security rather than replacing them.
  • Clearly define roles and handoffs. Effective agent governance depends on clear coordination between security teams, AI administrators, identity administrators, and platform owners. Think choreography, not hierarchy.
  • Use registries and metadata to enable an increased understanding of agents. A reliable agent registry with ownership, lifecycle state, and usage data is foundational. Without it, agent sprawl, duplication, and ownerless agents become unavoidable as adoption grows.
  • Rely on visualization to focus attention where it matters most. Visualization is about surfacing patterns, hotspots, and trends so IT can prioritize action, especially in large or complex environments.
  • Plan for continuous learning, not a finished state. Agent ecosystems evolve quickly. New agent types, tools, and usage patterns will continue to emerge. Readiness is an ongoing capability that improves as oversight, automation, and governance mature together.

Try it out

Related links

The post Implementing Agent 365: How we’re governing and managing AI agents at Microsoft appeared first on Inside Track.

]]>
24764
Unlocking the value of Microsoft 365 Copilot and agents at Microsoft http://approjects.co.za/?big=insidetrack/blog/unlocking-the-value-of-microsoft-365-copilot-and-agents-at-microsoft/ Thu, 30 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24946 In Microsoft Digital, our company’s IT department, we get to share our internal learnings on deploying and using Microsoft 365 Copilot and agents with many of our enterprise customers. During in-person briefings, I often remind our customers that generative AI systems like Copilot and Copilot Cowork are still quite new, and that they upend decades […]

The post Unlocking the value of Microsoft 365 Copilot and agents at Microsoft appeared first on Inside Track.

]]>
In Microsoft Digital, our company’s IT department, we get to share our internal learnings on deploying and using Microsoft 365 Copilot and agents with many of our enterprise customers.

During in-person briefings, I often remind our customers that generative AI systems like Copilot and Copilot Cowork are still quite new, and that they upend decades of human-computer interaction patterns. For over 40 years, we’ve trained knowledge workers to memorize patterns in the GUI to support their productivity.

With Copilot and agents, you can type nearly anything as a prompt and instantly get a detailed response, or create an agent to autonomously complete a business process on your behalf. It’s a very new way of working, and it’s no surprise that many knowledge workers—and even engineers themselves—are still adapting.

More than anything, our customers are looking for one key insight: They want to know how we measure and define the business value of Copilot and agents at Microsoft, especially through the lens of increased productivity and cost savings. After all, AI systems represent a significant investment for our customers, and leaders want to have confidence that they’ll yield sufficient ROI to justify the cost, knowing that the payback period isn’t immediate.

Six steps to proving value

So, how do you prove the value of AI-powered tools in the enterprise? There are six main steps that I share with customers that I believe are critical, based on the empirical evidence we’ve gathered in Microsoft Digital.

Graphic showing the six steps for measuring Copilot and agent value: identifying pain points, measuring processes, investing in enterprise AI skilling, deploying Copilot by cohorts, measuring identified processes, and recapturing value from time saved.
This graphic shows the six main steps for measuring Copilot and agent value in an organization.

Our big mistake? We didn’t instrument all the arduous business processes that slow us down and impact effectiveness before our deployment, so that we could more easily prove the value of AI across our enterprise after deployment.

Here are further details on the six measurement steps to keep in mind:

  1. Before you deploy, talk to people who are doing the frontline work in your organization. These should be hands-on managers or influential individual contributors (ICs), not executives or mid-level managers who are abstracted away from the work (although these individuals can be useful in helping identify the right SMEs to talk to).

For each role, identify three to five everyday pain points that could benefit from Copilot or agents. These could be operational, business, or technological processes, all of which can be improved by thoughtful applications of AI. This phase provides a great chance to use Six Sigma skills or other continuous improvement (CI) methodologies to evaluate your processes and identify waste, then consider how a combination of CI and AI could make them more efficient.

  1. Once identified, instrument and measure each of the processes to get baseline data on the average time it takes to complete them. Then the hard work begins—you need to think deeply about how AI could make those processes better. This could be through defining a series of step-like prompts that take away the toil. It could be through further AI-powered automation to make some of the steps go away. It could be applications of AI that validate outputs to ensure that rework is minimized. More and more, it could be an agent that completes the work on the employee’s behalf.

If you lack detailed telemetry for the process in question, you have two options. The first is preferable: Build end-to-end telemetry, so you have observability throughout the process in question. While this is always the best way to reliably measure productivity gains at scale, there is also a second option: Identify a cross-section of ICs and measure them the old-fashioned way as they complete the process in question—with a stopwatch. Take the average of several people to get a better sense of how much time is typically needed to complete the task. Then consider how AI could make that process more efficient, while also improving the resulting business outcomes.

  1. Concurrent with your investigation into ways that AI can improve productivity and reduce toil, you need to invest in enterprise AI skilling, ideally by role. The fact is, engineers are going to use AI differently than operations staff, who are going to use it differently than sales and marketing pros. Yes, there are common skills for each, but the best training is tailored to the role, grounded in the experience of using Copilot or agents to address challenges or opportunities that commonly arise in their day-to-day work.

It’s also important to ensure your employees understand the strengths and weaknesses of current AI models. No model is perfect, and understanding where reasoning errors can occur will help them avoid accepting AI-generated output that may be inaccurate. Human discernment and observability is a critical step in validating AI outputs.

A best practice is to gate access to generative AI; require employees to engage in both general and role-specific training prior to their provisioning to ensure they immediately unlock value in their work.

  1. After you’ve trained your employees and given them the skills to succeed with AI and agents in the enterprise, begin your deployment in earnest. For tools like Copilot, we recommend deploying in cohorts by role, focusing on employees who will immediately see the greatest benefit. At Microsoft, we started with our sales team and then gradually deployed to the remaining employee population over the course of several months. This enabled us to scale up our skilling programs, governance strategies, and support function in anticipation of increased volumes. For agents, deploy to support the biggest pain points first, then monitor and observe agent performance before scaling to additional business or operational processes.
  2. Post-deployment, give it a few weeks, then return to those same processes you identified in the first step and measure the average time savings. If time savings aren’t as significant as you hoped with either Copilot or agents, go back to process evaluation and employee skilling and continue to refine your approach.

This whole process is intentionally iterative—you’re not likely to get it exactly right on the first attempt. But if a process that used to take 30 minutes can now be completed in 10, you’ve obviously made a big difference that will save a lot of time when extrapolated across an entire fiscal year. Even better if that end-to-end process is now being completed by an autonomous agent, with a human reviewing and validating the output.

After you’ve succeeded in one domain, identify different role leaders and find another batch of processes that could be improved with a combination of continuous improvement and AI. There’s really no limit to the scope of ways you can positively impact your employees if you maintain a sharp focus on continually improving their experience with Copilot and agents.

  1. The final step: Reclaim the value from those productivity savings and apply it to new business challenges or opportunities. Let’s be clear—most enterprises aren’t investing in AI solely to give their people back time. They’re trying to do more with less, enabling their workers to be more productive and generate more value for the company.

In this crucial final phase, you need to be thoughtful and deliberate about how you’ll use the time saved with AI. If your people are saving two hours per week on average, how will they use that time? There are innumerable ways you could redeploy that time to address new business challenges or opportunities. The key is to be intentional in maximizing value, so it aligns with your team and your company’s goals and ambitions. Then report those savings to the appropriate members of the leadership team, to help them understand how their AI investments are paying off.

There you have it—you now possess the tools to quantify the value of your generative AI investments in the enterprise, using them to recapture value and drive more business impact thanks to the power of Copilot and agents.

Boosting AI adoption with structured change management

As you can see from the graphic above, it’s important to surround the AI value measurement process with structured change management and ongoing employee skilling. In Microsoft Digital, we’ve learned that even the most useful or intuitive technologies won’t see widespread adoption without a deliberate and sustained change management effort that’s localized to meet the disparate needs of a global organization.

In our case, that meant cultivating and supporting a community of Copilot Champions who have become the backbone of our global change management strategy. This community is now 10,000+ strong and even has its own Viva Engage forum, where our Copilot enthusiasts answer employee questions and share useful prompts.

Unfortunately, just doing AI skilling once won’t be enough. The pace of change with Copilot and agents is simply too great to do one training effort and then move on. Building an AI-forward culture takes time, and ongoing opportunities to learn and improve skills are one of the best ways to help your employees build the AI habit.

The Microsoft 365 Admin Center has an “AI adoption score” that can help you see—by cohort—how successfully people are building that habit. Having employees who use Copilot three times per week in any way is enough to build an AI-focused workforce, enabling your company to unlock the value of AI in the enterprise.

The promise of generative AI is significant, and there’s no doubt that you’ll see qualitative benefits in your organization even if you don’t instrument every process. But in an era of tight IT budgets, having the quantitative data necessary to calculate the ROI of your investments in Copilot and agents will make it far more likely that you’ll get financial support from your executive team to deploy and succeed at scale.

Key takeaways

Here are some key things to remember as you embark on your own Copilot and agent value measurement efforts:

  • Start at the beginning. Work with influential individual contributors and frontline managers to identify operational, business, and technological pain points, then measure those processes to understand their impact. Carefully consider how AI could accelerate each of those processes through structured prompts, workflow automation, and other techniques.
  • After you identify time savings, be thoughtful in applying that reclaimed capacity to new business opportunities or challenges. The point isn’t to just save time or lower costs—it’s to unlock productivity, so your employees can do more with less and create new ways for your business to thrive.
  • Generative AI skilling is not a one-time event—it’s an ongoing investment in your people to help them seize this generational opportunity with AI. Beyond general AI skills, consider how role-based training could help you accelerate the aptitude of specific employee groups in your organization.

Try it out

Related links

The post Unlocking the value of Microsoft 365 Copilot and agents at Microsoft appeared first on Inside Track.

]]>
24946
AI for Knowledge Management: Keeping support content up-to-date at Microsoft http://approjects.co.za/?big=insidetrack/blog/ai-for-knowledge-management-keeping-support-content-up-to-date-at-microsoft/ Thu, 16 Jul 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24648 Our AI agents and self-help channels are often our employees’ first stop for support, and like anyone, they expect the answers they get to be correct. This makes accurate content essential. If our content is stale, even the best agent or search engines will return wrong answers, which is frustrating to everyone. “Knowledge management today […]

The post AI for Knowledge Management: Keeping support content up-to-date at Microsoft appeared first on Inside Track.

]]>
Our AI agents and self-help channels are often our employees’ first stop for support, and like anyone, they expect the answers they get to be correct.

This makes accurate content essential. If our content is stale, even the best agent or search engines will return wrong answers, which is frustrating to everyone.

A photo of Olkies.

“Knowledge management today is about making sure people can find the right answers the moment they need them. When knowledge stays current, employees get unblocked faster and productivity improves, making the overall support experience far more efficient.”

Silvina Olkies, senior director, Service Management, Microsoft Digital

That means the knowledge bases that get tapped for answers need be accurate, and for that to happen, they need to be updated frequently and without delay.

Internally here at Microsoft, that’s where our team got involved.

We’re Microsoft Digital, the company’s IT organization, and our team saw an opportunity to use AI to dynamically and proactively update our knowledge management systems.

Our first step was—in partnership with our Global Help Desk—to strengthen our self-serve help and reduce the number of steps users need to take to find the right answers. It’s a process that many of our own customers can apply to their knowledge management transformation.

“Knowledge management today is about making sure people can find the right answers the moment they need them,” says Silvina Olkies, a senior director of Service Management in Microsoft Digital. “When knowledge stays current, employees get unblocked faster and productivity improves, making the overall support experience far more efficient.”

The challenge: Fragmented knowledge, manual reviews

For our Global Help Desk, the challenge wasn’t just the volume of content, but also its condition. Support knowledge is spread across thousands of self-service articles, agent-facing systems, and SharePoint sites, all constantly evolving.

A photo of Verdeck.

“If the knowledge isn’t accurate and current, the experience breaks down immediately. Bad content leads to bad answers.”

Kevin Verdeck, senior IT service manager, Microsoft Digital

In today’s fast-changing AI-powered world, it doesn’t take long for knowledge to become incomplete, out of date, or redundant. This shows up in the inaccurate answers employees might receive.

In an environment increasingly powered by search and AI, weak knowledge equals weak results.

“If the knowledge isn’t accurate and current, the experience breaks down immediately,” says Kevin Verdeck, a senior IT service manager in Microsoft Digital. “Bad content leads to bad answers.”

At our Global Help Desk, keeping that content current required a manual review process.

Our teams analyzed usage data, depended on support agents to report missing or outdated content, and worked through recurring review cycles that relied on subject-matter experts to help confirm whether articles were still accurate. This took significant time and coordination, and even then, some issues were identified only after employees had already hit a dead end.

The result was a system that was reactive and hard to scale.

When employees couldn’t find answers, issues were pushed to advanced support. Poor knowledge quality created poor outcomes, while those responsible for fixing it were struggling with maintaining it.

“One five-member team was reviewing 1,900 self-service KB articles and 1,700 agent-facing KB articles every six months, and that didn’t even include the many SharePoint sites,” Verdeck says. “It was basically their full-time job doing regular reviews.”

Turning raw data into knowledge

Our team in Microsoft Digital set out to build AI for Knowledge Management, a centralized system that could scale across multiple repositories, cut the manual work of keeping content current, reduce reliance on busy content owners, and prepare knowledge for people and AI to use.

A photo of Guddewala.

“When you have a large volume of data, it’s a silent gold mine. The sheer brilliance lies in taking that data, making it sing, and letting it tell you exactly where the treasure is.”

Ankit Guddewala, software engineer II, Microsoft Digital

An AI pipeline solution made sense because we wanted to fix the issue at scale.

The real opportunity was to turn every resolved support ticket into a signal that looked at what the employee was asking for (nature of the issue or request), whether the answer was already documented, and how the AI and human agents handled it. So, we began with our large amounts of support ticketing data and systems as the starting point.

“When you have a large volume of data, it’s a silent gold mine,” says Ankit Guddewala, a software engineer in Microsoft Digital. “The sheer brilliance lies in taking that data, making it sing, and letting it tell you exactly where the treasure is.” 

The stages to complete the work happen as follows:

  1. Ingest the raw support data: The team pulls in large volumes of incident data from our ticketing systems.
  2. Clean and structure noisy data: Tickets can include conversation notes, incomplete details, inconsistent writing styles, and abandoned issues. We use the AI enrichment layer to turn those details into structured fields, such as reported versus actual problems and remediation steps.
  3. Find patterns across incidents: We cluster tickets to help identify recurring issues and avoid cluttering the knowledge base with one-off scenarios.
  4. Compare patterns against existing knowledge: We use the system to search current articles and rank how closely the resolution aligns to current content to determine what steps to take next. For example:
    • Below 40 percent: Create knowledge
    • 40 to 80 percent: Update existing knowledge with missing details
    • Above 80 percent: No update needed
  5. Notify the appropriate knowledge managers: Subject-matter experts are notified by email so they can validate the change(s) and add more detail if needed.

“Our goal is to free people from the manual work of maintaining content so they can focus on improving its quality. With the right human-in-the-loop balance, AI can do the heavy lifting while people make sure the final knowledge is accurate and useful.”

Namrata Ladda, product manager II, Microsoft Digital

The result is far less time spent reviewing thousands of articles during every review cycle. We keep humans in the loop to validate the output. Their feedback helps tune the AI model, so it improves over time.

“Our goal is to free people from the manual work of maintaining content so they can focus on improving its quality,” says Namrata Ladda, a product manager in Microsoft Digital. “With the right human-in-the-loop balance, AI can do the heavy lifting while people make sure the final knowledge is accurate and useful.”

Impacts and what’s next on the journey

Using our new AI for Knowledge Management platform, our Global Help Desk teams can identify knowledge gaps without waiting for someone to report them. They’re using AI to generate structured article drafts so humans can focus on quality, not search through data.

The Global Help Desk projects the solution will save them an estimated 16,000 hours annually; result in a 10 percent reduction in support tickets; and reduce the number of advanced support escalations. This leaves everyone on the team more time to directly help employees more quickly, when needed.

“Turning our knowledge base from a static thing into a living knowledge base is a big step forward,” Ladda says. 

Other Microsoft teams, including HR, have expressed interest in leveraging the content management platform. Once the product has completed internal testing, AI for Knowledge Management will be released to all company employees and customers.

“This solution moves knowledge management from manual maintenance to an intelligent capability that helps organizations scale and apply what they know more effectively,” Olkies says.

Key takeaways

Here are some actions your organization can take right away to strengthen your own knowledge foundations:

  • Start with knowledge. Treat your knowledge base as the source of truth that determines whether AI and self-help succeed.
  • Audit how knowledge is maintained. Look beyond publishing workflows to understand how gaps and outdated content show up in real usage.
  • Spot and remove manual bottlenecks. Identify where people are spending the most time searching and reporting knowledge and target those steps for automation.
  • Use AI to maintain, not just serve, content. Apply AI to identify gaps and refresh out-of-date information.

Try it out

Related links

The post AI for Knowledge Management: Keeping support content up-to-date at Microsoft appeared first on Inside Track.

]]>
24648
Digitally transforming Microsoft: Our IT journey http://approjects.co.za/?big=insidetrack/blog/digitally-transforming-microsoft-our-it-journey/ Thu, 18 Jun 2026 16:00:33 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=18521 The digital transformation of Microsoft spans the entire personal computing revolution, from the days of DOS and early Windows desktops, through our journey to the Azure cloud and into the era of AI and agents. Today, the company has grown into a global organization with more than 200,000 employees. They all rely on Microsoft Digital—the […]

The post Digitally transforming Microsoft: Our IT journey appeared first on Inside Track.

]]>
The digital transformation of Microsoft spans the entire personal computing revolution, from the days of DOS and early Windows desktops, through our journey to the Azure cloud and into the era of AI and agents.

Today, the company has grown into a global organization with more than 200,000 employees. They all rely on Microsoft Digital—the company’s IT organization—to provide the tools, technologies, and solutions that empower them to accomplish more every day.

The need for digital transformation

The history of information technology is one of constant evolution, and the pace of change has never felt greater than it does right now. The AI capabilities and other groundbreaking innovations unveiled in the last few years show the potential to radically transform our world and change the way we think about and operate all IT services.

When the world pivoted to remote online work and collaboration because of the COVID-19 pandemic, it was just one example of how digital transformation doesn’t always happen in a straight line or on a predictable schedule. Our company’s history of shaping and adapting its IT organization to the latest challenges faced by employees and partners is no different; marked by big bets and strategic shifts that reflect our ever-changing world.

Mapping our IT journey

Timeline graphic shows the four eras of Microsoft IT (On-Premises IT, Cloud and Culture, Modern Engineering, and AI) along with major milestones in each era.
The four eras of digital transformation of IT at Microsoft : On-Premises IT, Cloud and Culture, Modern Engineering, and the Era of AI.

Today, Microsoft Digital is the team that powers, protects, and transforms the digital employee experience across all devices, applications, and hybrid infrastructure at the company. Using our deep knowledge and experience in enterprise IT, we’re pivoting to help lead the company’s AI transformation while also sharing our journey with customers so they can take advantage of this generational opportunity to reshape their businesses and IT operations.

To understand where we’re going, it helps to take a look at where we’ve been. This article explores the details of the major eras of our IT history and then shifts to examine the trendlines and technological innovations that are shaping Microsoft now.

On-Premises IT (founding to 2009)

It’s useful to break the history of our IT operations into different eras. For the first three decades or so from its founding in 1975, Microsoft operated with on-premises IT systems. This era was characterized by the setup, operation, and maintenance of onsite physical technology—servers, datacenters, and other hardware infrastructure.

During this time, IT roles were narrowly defined. IT team members functioned primarily as “order-takers,” with limited influence over strategic decisions.

Because funding was inconsistent, our IT organization had limited growth opportunities and relied on vendors for development work. Gaps were filled in with “shadow IT,” where internal teams would sometimes procure their own hardware or software without formal IT approval or standards.

We established security as an early priority for the company. Cofounder Bill Gates launched the Trustworthy Computing initiative more than two decades ago, an effort emphasizing the importance of security, privacy, and reliability across Microsoft products and services both internally and externally.

Our On-Premises IT era established the foundation that would become crucial to the company’s future digital transformation.

All in on the cloud: The Cloud and Culture era (2010-2018)

Image showing Ballmer presenting at an event, with Windows Azure and Azure DevOps logos overlaid on the photo.
Former Microsoft CEO Steve Ballmer led the shift to the cloud that began in the early 2010s.

Cloud computing marked the next significant shift in the history of IT at Microsoft. It began in 2010 under the leadership of CEO Steve Ballmer, signaling a major break with the previous era of physical IT infrastructure and an important step toward today’s distributed-computing world.

The launch of the cloud computing platform then known as Windows Azure heralded this new era, as we transitioned away from an IT philosophy focused on the Windows desktop client toward a more platform-agnostic view. Cloud computing offered extensive advantages for customers and for our own IT environment, in terms of cost, performance, security, and scalability.

We started our journey by moving productivity workloads (Exchange and SharePoint) to the cloud. Then, we shifted new development to Azure and optimized modern applications to run in the cloud. We also moved existing applications targeted for migration to virtual machines. Today, more than 98% of our IT workloads run on Azure.

Cultural transformation

Another important shift during this era was the profound cultural transformation at Microsoft sparked by new CEO Satya Nadella, who rose to the top job at the company in 2014. Nadella had previously run the Microsoft cloud computing and enterprise group, so he was already steeped in the idea of transformational change at the company.

A photo of Nadella.

“Achieving our mission requires us to evolve our culture. It all starts with a growth mindset—a passion to learn and bring our best every day to make a bigger difference in the world.”

Satya Nadella, CEO, Microsoft

Before Nadella’s ascension, Microsoft had long been known for its extremely competitive, “know-it-all” culture. Employees succeeded by showcasing their own individual achievements and how their accomplishments exceeded their peers.

Nadella changed this ethos by championing a growth mindset, encouraging employees to be “learn-it-alls” rather than “know-it-alls.” The shift included placing new importance on how employees contributed to the success of others, a value that was incorporated into individual performance reviews. Nadella made this transformation his personal mission and directed leadership to propagate the new philosophy at all levels across the organization.

“Achieving our mission requires us to evolve our culture,” Nadella says. “It all starts with a growth mindset—a passion to learn and bring our best every day to make a bigger difference in the world.”

The combination of the shift to cloud computing infrastructure and overhauling the company culture helped set the stage for the major technological innovations to come.

A new vision: The Modern Engineering era (2018-2023)

For years, IT at Microsoft had been order takers, doing what the business requested with limited ability to impact strategic priorities. That changed as we shifted to become a modern engineering organization. With support from our executive leadership, IT was elevated to become a peer engineering function at Microsoft.

Rather than simply taking orders, the team was empowered to lead with a strong vision for the future. In fact, leading with vision is the primary hallmark of our Modern Engineering era. As we moved into this era, we needed a clearly articulated view of our goals as an IT organization aligned to the needs of our business partners, as well as the resources needed to achieve them.

Role transformation

Transitioning to become a modern engineering organization required Microsoft Digital to adapt our legacy approach to IT.

Operating an engineering organization in a cloud environment meant new roles, new skills, and a new mindset. With no need to manage physical hardware, our modern IT professionals were freed to work more closely with business partners, requiring greater strategic acumen. The team was now focused on DevOps, Agile program management, and user-centric design principles.

User-centric, coherent design

Our design philosophy puts the user—an employee or guest—at the heart of every decision we make at Microsoft Digital.

The goal of this approach is to make tasks that might have previously caused friction to become simpler. Instead of dealing with disconnected systems, user-centric design introduces consistent and logical flow between services. This makes it easier for people to access services, learn how to use them, and then put them to good use.

Microsoft also embraces coherent design across all our products. A familiar look and feel, along with consistent usage patterns, accelerates employee usage and adoption. 

Embracing work-from-anywhere capability

During the pandemic, when our workforce was still fully remote, our organization was already starting to think about what the new hybrid workplace would look like when people started returning to the office. We identified three key dimensions of the employee experience:

  • Physical spaces: We partner with Global Workplace Services to plan and deploy meeting spaces with amazing digital capabilities that support an inclusive approach to hybrid productivity.
  • Digital capabilities: We keep employees productive and their digital environment safe and secure, no matter where they’re located or how they connect.
  • Culture: A strong partnership with HR ensures that digital experiences support our company culture.

Managing shadow IT with a culture of trust

Shadow IT is the unknown and unmanaged set of applications, services, and infrastructure that are developed and managed outside standard IT policies. Shadow IT typically crops up when engineering teams are unable to support the needs of non-engineering partners, a situation that could arise from a lack of available capacity or the need for specialized domain solutions. 

While earlier eras of our IT history focused on trying to prevent shadow IT, we are now concentrating on managing it. We use Azure best practices to optimize shadow IT and Microsoft 365 governance policies to ensure that our corporate security, privacy, and accessibility standards are met. We empower our employees to create whatever they need within our tenant, including PowerApps, SharePoint sites, Teams channels, or agents, mitigating the need for “shadow” solutions while also providing visibility into how our employees are using our own technology.

Learn how optimizing our Microsoft Azure usage is helping us manage our Shadow IT.

The Era of AI (2023 to present)

The latest chapter in the history of our organization’s digital transformation is defined by the integration of AI and agents into IT operations. AI is revolutionizing how Microsoft does IT at enterprise scale, driving efficiency and innovation across the board. From the apps, workflows, and services that power our employee experience to the network, infrastructure, and devices that enable employee productivity, our AI-focused investments provide a solid foundation for the innovations that we are constantly implementing. As we look at the future of Microsoft Digital, we’re focused on four key priorities: security, service fundamentals, acting as Customer Zero, and AI-powered innovation. We’re working to excel in all four domains with the help of our industry-leading AI capabilities.  

A photo of Fielder.

“Our mission is to power and protect Microsoft, and that starts with an unwavering commitment to the Secure Future Initiative.”

Brian Fielder, vice president, Microsoft Digital

Securing our future

Security is our highest priority. The Microsoft Secure Future Initiative aligns every team with a shared approach, common priorities, and consistent milestones to harden our security posture across all products and services.  

“Prioritizing security above all else is critical to our company’s future,” Nadella says. “Every task we take on—from a line of code to a customer or partner process—is an opportunity to help bolster our own security and that of our entire ecosystem. If you’re faced with a tradeoff between security and another priority, your answer is clear: Do security.”

The Secure Future Initiative is built on three core principles: Secure by design, secure by default, and secure operations. As the company’s IT organization, we work relentlessly to fulfill the key pillars of the Secure Future initiative across all our systems, including:

  • Safeguarding identities and secrets
  • Protecting tenants and isolating production systems
  • Securing networks and engineering systems
  • Enhancing threat detection
  • Expediting response and remediation

“Our mission is to power and protect Microsoft, and that starts with an unwavering commitment to the Secure Future Initiative,” says Brian Fielder, vice president of Microsoft Digital.

Secure Future Initiative | Microsoft

Foundations: Service fundamentals

The second pillar is to maintain the highest standards of service fundamentals. These are the essential capabilities and practices that enable us to deliver reliable, secure, and compliant services companywide. Adhering to the highest standards of service fundamentals ensures that our organization continues to play a critical role in running the company’s business and enabling innovation, agility, and resilience in a fast-changing and competitive environment.

Customer Zero

The third pillar is acting as Customer Zero for Microsoft’s most important products and services, like Copilot Studio, Microsoft Teams, and Agent 365. In Microsoft Digital, we take pride in being the first customer for a wide variety of Microsoft products and services, relentlessly focusing on our own employee experience to create products that enable every person on the planet to achieve more.

Being Customer Zero means forging a deep partnership between our IT organization and product engineering groups to envision the right experiences, co-develop innovative solutions, and then listen to and act on insights gathered from our employees. We work together to stay grounded in the way our employees use our products every day, so your employees can benefit from our insights prior to external product launches.

Read about how we’re improving our employee experience through our Customer Zero focus.

AI-powered innovation

The final pillar of this era is innovating with AI to transform the digital experience at Microsoft. By doing all the fundamental work detailed above—security, foundations, and Customer Zero—extremely well, we gain the confidence and earn the trust necessary to embed AI across our full portfolio of services. We do this over three key dimensions: core IT services, employee experiences, and corporate functions.

Core IT services: Transforming and securing our network and infrastructure

We’re focused on using AI to infuse data-driven intelligence into every part of our infrastructure and network operations. This allows us to optimize operations and increase security while simultaneously improving outcomes.

Examples include:

  • Network observability and governance: Ensuring data accuracy, eliminating non-compliant hardware and software, and real-time updates
  • Securing endpoints: Device management, asset management, and patching
  • Zero Trust networking: Isolating device classes and limiting attacker’s movements across the network
  • Network access: Azure VPN, identity management, and Secure Access Workstation (SAW) infrastructure security

Learn how we’re transforming our enterprise IT operations at Microsoft.

Core IT services: Tenant management

We manage one of the most complex tenants anywhere. Governance today is a somewhat fragmented experience, with no clear mechanism for IT to safely enable self-service asset creation for sites, Teams, groups, Power Apps, and so on. These unmanaged assets increase the risk of over-sharing sensitive data and compromise the health and security of our IT environment.

In the world of AI, security through obscurity is no longer a viable option. This means data hygiene, permission management, and data protection are essential to providing trustworthy AI tools that don’t overexpose sensitive content, while still providing quality responses.

Read about one way we’re improving security by protecting elevated-privilege accounts at Microsoft.

Core IT services: Support

We’re using generative AI to transform the way our employees interact with our support services. IT issues will be either auto-remediated or resolved remotely and instantly through conversational, personalized, and contextualized solutions, often without a human agent’s intervention.

We’ll accomplish this with a focus on the following:

  • User experience: Our employees are using the AI-powered Employee Self-Service Agent to access personalized, accurate, and cost-effective issue resolution. Future goals include implementing a seamless transition to a human agent while the user stays within the agentic Copilot experience.
  • Human agent experience: Operational efficiency and automation are being integrated into the Service Operations Workspace. The service includes chat and incident summarization that recommends best next actions and drafts contextual answers to queries.

Find out how we’re transforming IT support at Microsoft with AI and the Employee Self-Service Agent.

Defragmenting the employee experience

The second dimension where we’re implementing our AI vision to make a difference is our employee experience. Our vision is to deliver a unified, connected, and personalized experience where users can access employee data, tools, and insights from one place.

A photo of Alaparthi

“We see AI as the key to unlocking the full potential of our employees, delivering personalized experiences that empower us to work smarter, faster, and happier—unleashing the innovation and collaboration necessary for our success.”

Vijaya Alaparthi, principal group product manager, Microsoft Digital

One of the key ways we’re doing this is with Microsoft 365 Copilot, which functions as a “UI for AI” across our employee tools and services. An example is our Employee Self-Service Agent, an AI-driven tool based on Copilot that helps employees more efficiently find context-specific answers to their questions using natural language queries.

“We see AI as the key to unlocking the full potential of our employees, delivering personalized experiences that empower us to work smarter, faster, and happier—unleashing the innovation and collaboration necessary for our success,” says Vijaya Alaparthi, a principal group product manager in Microsoft Digital.

To achieve our vision, we’re building a workplace where AI defragments the employee experience by:

  • Providing contextual support in the flow of work
  • Reducing the number of sites and apps an employee must remember
  • Using Microsoft 365 Copilot as the “UI for AI,” making it simple for employees to find information, take action, and even fully automate certain repeatable tasks

Corporate functions growth

Our third major priority in Microsoft Digital is to improve how we support the company’s corporate functions organizations, including legal and real estate and facilities.

A photo of West.

“With AI, we have so many new ways to innovate. From optimizing building occupancy, to streamlining commute services, to automating contract and document management, we have incredible potential to make our corporate functions more efficient and impactful.”

Becky West, principal group product manager, Microsoft Digital

This is a particular challenge, as these teams are being asked to do more with less today; Microsoft can no longer afford to grow operational costs at the same rate as in the past.

AI is playing a fundamental role in transforming the business workflows of our corporate functions partners while improving operational efficiency, user productivity, regulatory and corporate compliance, and data-driven decision making. It’s revolutionizing the way they operate by automating repetitive and time-consuming operational tasks.

“With AI, we have so many new ways to innovate,” says Becky West, a principal group product manager in Microsoft Digital. “From optimizing building occupancy, to streamlining commute services, to automating contract and document management, we have incredible potential to make our corporate functions more efficient and impactful.”

Some of the corporate functions taking advantage of AI capabilities and related increased efficiencies include:

  • Real estate and facilities: In supporting the technology needs for more than 500 company buildings worldwide, we are poised to use AI and related innovations to implement cost savings in the areas of workspace systems, facilities management, and space management.

Find out how we’re transforming facility operations at Microsoft with AI maps.

  • Travel and expense: Our plan is to work for near-elimination of the traditional expense reporting process through AI-based and touchless experiences, driving simplification and productivity gains.

Check out how OneExpense transformed our employee expense reporting.

  • Legal: Our vision for integrating AI into Corporate, External, and Legal Affairs (CELA) includes more discoverable legal findings, better corporate document management with the Docufy platform, enhanced engagement with Microsoft Philanthropies, and accelerated support for business-critical functions such as immigration, contracting, and insider trading compliance.

Read how AI is revolutionizing the way we support corporate functions at Microsoft.

Agentic AI: Becoming a Frontier Firm

This era of AI in IT has quickly morphed into a world in which agents are having major impacts across the enterprise. Microsoft Digital plays a central role in helping the company embrace this change and transform into a Frontier Firm: an organization that has deeply embedded AI and agents into its operations, products, and culture

As a Frontier Firm, we go beyond simply adopting AI as a discrete tool or additional technology. We’re actively integrating intelligent systems, rich data platforms, and human knowledge into a unified operating model, where automation, decision making, and innovation combine to spark acceleration at scale. Agentic AI is a core enterprise capability for us, powering everything from employee productivity to customer experiences and strategic decisions.

As Microsoft progresses into this agentic AI future—where autonomous or semi-autonomous AI agents understand context, take actions, and collaborate alongside humans—Microsoft Digital has played a lead role in deploying these capabilities internally. We’ve led the early adoption of tools like Microsoft 365 Copilot, Azure AI services, and custom-built agents that help us automate repetitive tasks, surface insights, and orchestrate workflows across systems while enforcing strict governance policies. Examples include AI-powered agents that assist in IT service management, network monitoring, and enterprise knowledge retrieval, which allow employees to focus on higher-value work and maximize their individual impact.

As AI agents continue to grow in power and functionality and become more deeply integrated into the daily workflows of knowledge professionals, Microsoft IT will maintain our leadership role and operate at the bleeding edge of this technological revolution. 

A catalyst for change and growth

Microsoft’s digital transformation is a story of evolutionary change, resilience, and adaptation across multiple eras of information technology. From our origins as a traditional IT organization to becoming a modern engineering organization focused on driving AI-powered innovation, we in Microsoft Digital remain a catalyst for change within the company and our industry.

With our insights born from customer and employee obsession, we’re committed to streamlining IT operations while prioritizing security, revolutionizing user services, and facilitating corporate functions growth and development. All with the overarching goal of making Microsoft employees everywhere more productive while showing our customers and partners what’s possible as we move forward together into the future of IT.

Key takeaways

Our IT digital transformation story offers valuable lessons for organizations in the midst of their own IT journey. They include:

  • Be vision-led: A clear, articulated vision is crucial for driving transformation.
  • Foster a growth mindset: Encourage continuous learning and adaptability among employees (“learn-it-all” culture).
  • Invest in people: Upskill and reskill your workforce to keep pace with technological advancements and emphasize diversity of skills and experience.
  • Insist on security: Prioritize security in all aspects of operations to safeguard data and maintain trust.
  • Focus on collaboration and partnership: Create successful hybrid work environments to foster strong partnerships across functions.
  • Seek continuous improvement: Learn from the past and use those lessons to shape the future.
  • Embrace AI: Take advantage of AI tools and technologies to drive efficiency, innovation, and security.

Try it out

Related links

The post Digitally transforming Microsoft: Our IT journey appeared first on Inside Track.

]]>
18521
Meet ‘Eddie,’ our agent for putting new PCs in the hands of our employees http://approjects.co.za/?big=insidetrack/blog/meet-eddie-our-agent-for-putting-new-pcs-in-the-hands-of-our-employees/ Thu, 18 Jun 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24121 For many years, our process for getting new work PCs to employees at Microsoft remained largely unchanged: Decentralized and variable, with data spread across systems, refresh cycles differing by team and geography, and manual steps required throughout the journey. “The legacy system was highly fragmented, with more than 50 device options, localized processes, data scattered […]

The post Meet ‘Eddie,’ our agent for putting new PCs in the hands of our employees appeared first on Inside Track.

]]>
For many years, our process for getting new work PCs to employees at Microsoft remained largely unchanged: Decentralized and variable, with data spread across systems, refresh cycles differing by team and geography, and manual steps required throughout the journey.

A photo of Das.

“The legacy system was highly fragmented, with more than 50 device options, localized processes, data scattered across different systems, manual touchpoints, and limited visibility into order status. This created a lot of friction across the company, as well as higher costs.”

Aniruddha Das, principal PM manager, Microsoft Digital

But as our organization scaled globally, this system became increasingly complex and inefficient.

Across more than 200,000 employees in over 100 countries and regions, our device procurement and inventory management devolved into a patchwork of systems and practices. There was no top-level management, no consistent lifecycle model, and no standardized experience for employees needing to order a new device.

“The legacy system was highly fragmented, with more than 50 device options, localized processes, data scattered across different systems, manual touchpoints, and limited visibility into order status,” says Aniruddha Das, a principal PM manager in Microsoft Digital, the company’s IT organization. “This created a lot of friction across the company, as well as higher costs.”

Working in partnership with Procurement, we built myDevice—a companywide program that centralizes primary-device procurement and lifecycle workflows within a single managed platform. myDevice brought together previously distributed data and processes, giving us reliable visibility into each employee’s primary device and enabling predictable, data-driven refresh planning at scale—along with the operational insights needed to run the end-to-end experience.

A photo of Singhal.

“We’ve moved from a fragmented device procurement experience with many touchpoints to one conversation with one agent. Basically, we can tell our employees that their next device is just a conversation away.”

Mukul Singhal, partner engineering manager, Microsoft Digital

Beyond solving some of these basic data challenges, we also needed to address harder, at‑scale problems in the broader procurement experience: helping employees confidently pick the right device without getting overwhelmed by options, aligning eligibility and catalog choices to an employee’s role and location, and more.

With the new Employee Device Information (EDI) agent—affectionately referred to as “Eddie”—our employees will soon be able to use an AI chat interface to quickly explore recommended device options based on their job role and work needs, compare different models, and order a new device with a single click. This streamlined approach will reduce frustration, save time, and cut our costs as we automate a formerly manual process.

“We’ve moved from a fragmented device procurement experience with many touchpoints to one conversation with one agent,” says Mukul Singhal, a partner engineering manager in Microsoft Digital. “Basically, we can tell our employees that their next device is just a conversation away.”

Creating a unified approach with myDevice

The transformation began about three years ago, when our Procurement partners brought their vision for myDevice to us in Microsoft Digital. The stated goal was to standardize employee device procurement, inventory, and lifecycle management across the company.

A photo of Pearson.

“Our decentralized process was an industry outlier, and we realized we needed to pivot toward a standardized global process. We wanted to give our employees a single entry point, with consistent guidance across the enterprise.”

Angela Pearson, senior procurement program manager, Microsoft Procurement

Built on top of our internal ServiceNow platform, myDevice brought together previously disconnected workflows into a single consistent experience for employees. It introduced a common catalog of devices, standardized refresh cycles, and centralized ordering and fulfillment processes.

It was evident that such a system was badly needed.

“Our decentralized process was an industry outlier, and we realized we needed to pivot toward a standardized global process,” says Angela Pearson, a senior procurement program manager in Microsoft Procurement. “We wanted to give our employees a single-entry point, with consistent guidance across the enterprise. That was the first big win.”

Purchasing devices for a global workforce the size of Microsoft is not an insignificant budget item. And our fragmented system meant higher costs for the organization.

“The decentralized procurement model allowed teams to move fast, but it also led to inefficiencies,” Das says. “Devices were often purchased at the end of the fiscal cycle, because there was budget, but they didn’t always match real requirements and would sometimes go unused.”

This list maps out the evolution of our device procurement program here at Microsoft:

Legacy state

  • Distributed experience: Inconsistent, inefficient processes across countries and business groups
  • Zero visibility: Lack of proper asset tracking, accounting, or device management
  • High friction and high cost: Significant manual effort required across multiple touchpoints

Foundation: myDevice 1.0

  • Unified global experience: One consistent process across all geographies and divisions
  • Persona-based: Guided buy for productivity needs based on job role
  • Streamlined workflows: Optimized automated processes reducing manual touchpoints
  • Enhanced visibility: Improved data management and asset tracking entering the company

Future vision: myDevice 2.0

  • Next-gen interface: AI-driven, seamless employee interaction
  • Supply chain resiliency: Built to weather disruption
  • AI-assisted workflows: Intelligent automation across backend systems and processes

Creating a solution at the scale required for myDevice was a challenge. Relevant data was spread across systems, refresh cycles were inconsistent, and key processes, such as determining which devices should be refreshed, were often manual and time-intensive.

“The data was distributed across multiple systems, and each group was doing their own cycle,” says Amit Raghuwanshi, a principal software engineering manager in Microsoft Digital. “Bringing all the relevant data together was a huge task and big part of the solution.”

Three scenarios for device procurement

Our employees interact with three different workflows that involve obtaining a new primary work device:

  • New hire provisioning
  • Device refresh (for aging machines)
  • Replacement for damaged devices

Each of these core scenarios now follows a standardized process, replacing the ad hoc methods that previously varied by team and geography.

A photo of Bagade.

“If a new hire’s device arrives a week after they join the company, that’s not a good experience. We want them to have it on day one.”

Ashok Bagade, principal product manager, Microsoft Digital

Establishing a clear device lifecycle was a big step. For example, Microsoft employees are eligible for a new PC (called a refresh) every four years. Now, with myDevice, roughly 20,000 employees each quarter automatically get a refresh invite, presuming available budget. This takes the burden off IT, admins, and other support staff who were previously tasked with managing this process manually.

The myDevice system is also improving the process for new hire device procurement. The goal has always been for each new Microsoft employee to have a computer waiting for them on their first day, but the gaps in the previous system often made meeting this standard difficult.

“If a new hire’s device arrives a week after they join the company, that’s not a good experience,” says Ashok Bagade, a principal product manager in Microsoft Digital. “We want them to have it on day one. Today, we are only able to do that around 70% of the time. We want to take that rate up to 98%.”

To make that happen, we’re in the process of shifting from a build-to-order device model to an inventory-based model. This means that our suppliers will have a stockpile of our most frequently requested PCs on hand, based on data we have compiled. This approach is designed to reduce the device procurement time from four to six weeks down to less than two weeks, Bagade says.

By centralizing and standardizing device management, myDevice created the foundation for the next phase of transforming this process: intelligence.

Adding AI for a seamless procurement experience

The second part of reimagining our employee device procurement at Microsoft was on the front end, which is the digital interface our people experience when they need to choose their new device.

Even with a unified platform in place, the experience of selecting and ordering the device could be time consuming and disjointed. Employees could browse a list of available computers, but choosing the right one still required research and consultation with colleagues and led to cognitive overwhelm.

“The challenge we saw is that people take a long time to complete their purchase because they don’t know which device to select,” Bagade says. “They get a bunch of options, and they’re not sure which one is right for them.”

So we built EDI (or “Eddie”), an AI-powered agent created with Microsoft Copilot Studio, that makes the process much more efficient. Eddie is transforming a static workflow into a conversational experience.

Screenshot showing the EDI agent comparing two devices.
The Employee Device Information (EDI) agent—“Eddie”—recommends devices for our employees based on their role, work needs, location, and other factors.

With Eddie, employees get a guided, conversational buying experience instead of a form-led journey. The agent validates the employee’s eligibility, captures the required inputs, and then offers role-aligned device choices directly in the chat—complete with comparison details and a clear selection path. Once confirmed, the employee submits the request and receives a trackable ServiceNow reference, which reduces follow-ups and helps employees stay informed on the process end-to-end.

“Eddie not only gives a consistent purchasing experience—it also guides you,” Bagade says. “You can ask questions and, through that conversation, narrow down your options.”

The agent is underpinned by a multi-agent architecture where specialized components handle different aspects of the process—catalog browsing, comparison, recommendations, and ordering—coordinated by an orchestration layer.

“With Eddie, the agent validates the information and, in many cases, executes the change. It can literally happen in minutes.”

Aniruddha Das, principal product manager, Microsoft Digital

Reducing complexity and increasing visibility

EDI also addresses operational pain points that extend beyond purchasing. One early challenge focused on correcting primary device records, which is an essential but previously manual process.

“Before we developed this solution, something as simple as correcting an employee’s primary device required multiple tickets and human validation,” Das says. “It could take weeks—and in some cases months—to resolve. With Eddie, the agent validates the information and, in many cases, executes the change. It can literally happen in minutes.”

Another critical improvement is visibility. Previously, once a device request was submitted, it effectively disappeared into a system that offered limited transparency.

“After placing a request, employees had no way to check on the status—it went into a black hole,” Das says. “Now, Eddie can look at the same data that Procurement has and provide answers immediately.”

Bottom-line impacts of myDevice and EDI

  • 23% reduction in primary work device spend (saving roughly $20 million annually)
  • Average cost per device reduced from $1850 to $1670
  • 50,000+ employees equipped globally in the last fiscal year
  • Reduced from 50-plus device models due to role-based recommendations
  • Eliminated end-of-fiscal-year spending spikes through predictable quarterly planning
  • Improved sustainability through increased device reuse and recycling

Looking ahead: From systems to conversations

With myDevice and EDI in place, we’re now focused on the next phase: transforming device management into a fully conversational, intelligent experience. The vision is to move beyond portals entirely and toward an agent-first model where employees interact with systems through natural language.

A photo of Raghuwanshi.

“Our view for the future is that you won’t need to visit a UI or a system to accomplish a task, you’ll just start talking to an AI agent.”

Amit Raghuwanshi, principal software engineering manager, Microsoft Digital

This includes expanding capabilities such as predictive refresh cycles, deeper personalization, and tighter integration with supply chain and inventory systems. Efforts are also underway to reduce fulfillment times through innovations like centralized inventory management and forecasting.

At the same time, the experience will continue to evolve toward greater simplicity.

“Our view for the future is that you won’t need to visit a UI or a system to accomplish a task, you’ll just start talking to an AI agent,” Raghuwanshi says.

For employees, that shift means less friction, faster decisions, and a more intuitive experience.

A photo of Adams

“We know how busy our employees are, and we don’t want them spending time on lower-priority tasks. When it’s time to acquire a new device, the experience should be seamless from start to finish, without added complexity or cognitive burden. We’re making steady progress toward that reality.”

Anna Adams, director of hardware programs and operations, Microsoft Procurement

For our organization, it represents a broader transformation—one where AI not only improves existing processes but fundamentally reshapes our workflows and the way that work gets done across all functions.

This means that our employees have one less process that they have to puzzle through and figure out, which allows them to focus on their higher-value work.

“We know how busy our employees are, and we don’t want them spending time on lower-priority tasks,” says Anna Adams, director of hardware programs and operations in Microsoft Procurement. “When it’s time to acquire a new device, the experience should be seamless from start to finish, without added complexity or cognitive burden. We’re making steady progress toward that reality.”

Key takeaways

If you’re planning on revamping how your organization approaches employee device procurement, consider what we learned over the course of our journey:

  • Unify before you optimize. We discovered that fragmented, decentralized processes don’t scale, and that a standardized platform for procurement, lifecycle management, and device visibility was worth the investment of time and resources to implement.
  • Design for simplicity. Moving from multiple touchpoints to a single conversational interface dramatically reduces friction in any organizational process.
  • Use AI to guide decisions, not just automate tasks. Employees often struggle with too many choices when it comes to device selection. Embedding persona-based AI recommendations helps users quickly make the right decision.
  • Establish and enforce a clear lifecycle model. Standard refresh cycles and automated triggers eliminate guesswork, improve planning, and ensure devices are refreshed based on actual need.
  • Pair process change with supply chain strategy. Align your new process with inventory forecasting and sourcing models to reduce fulfillment times and improve first-day readiness for employees.
  • Design for an agent-first world. Plan for a future where employees “talk to systems” through AI agents, with predictive insights and seamless execution built in.

Try it out

Related links

The post Meet ‘Eddie,’ our agent for putting new PCs in the hands of our employees appeared first on Inside Track.

]]>
24121
Intelligence on tap: How Work IQ enables AI and agents at Microsoft http://approjects.co.za/?big=insidetrack/blog/intelligence-on-tap-how-work-iq-enables-ai-and-agents-at-microsoft/ Thu, 11 Jun 2026 16:00:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=24006 Improving agentic workplace results with Work IQ Adding deeper contextual intelligence to Microsoft 365 Copilot responses Enterprise knowledge is perhaps a company’s most valuable asset, but for AI and agents, it can be difficult to take advantage of. Years of emails, documents, chats, meeting recordings, and workflows have created enormous volumes of rich data, scattered […]

The post Intelligence on tap: How Work IQ enables AI and agents at Microsoft appeared first on Inside Track.

]]>

Improving agentic workplace results with Work IQ

Adding deeper contextual intelligence to Microsoft 365 Copilot responses

Enterprise knowledge is perhaps a company’s most valuable asset, but for AI and agents, it can be difficult to take advantage of. Years of emails, documents, chats, meeting recordings, and workflows have created enormous volumes of rich data, scattered across systems and teams in a fragmented way. This data captures how work actually happens, but harnessing it broadly—especially in ways that support better decision making—has traditionally been almost impossible.

Enter the power of agentic AI tools.

In the modern agentic workplace, employees and teams here at Microsoft and elsewhere are finally able to take advantage of all that rich, unstructured knowledge. Microsoft 365 Copilot and AI agents can now access all this data and not simply retrieve information but also reason over it—learning how work gets done and then providing rich contextual responses and guidance.

A photo of Fielder.

“By giving AI the ability to reason across the vast repositories of unstructured data that our enterprise possesses, Work IQ fundamentally changes what’s possible for Copilot, agents, and employees alike.”

We’ve given this new, dynamic way of leveraging your enterprise data to boost productivity a special name: Work IQ.

Work IQ represents a big step forward.

For us, it’s enabling the concept of “intelligence on tap” across our enterprise, making our organizational knowledge and work context accessible in real time, grounded in the signals employees generate every day. This transforms unstructured data from a challenge into a strategic resource—one that can support workflows at scale.

“Work IQ represents the next phase of the agentic workplace of the future—and it’s here,” says Brian Fielder, vice president of Microsoft Digital. “By giving AI the ability to reason across the vast repositories of unstructured data that our enterprise possesses, Work IQ fundamentally changes what’s possible for Copilot, agents, and employees alike.”

A photo of Hasan

“It’s not really a brand-new capability, but more an evolution of what users already know, which is access to the grounding data in their Microsoft tenant. The difference is that Work IQ adds an additional layer to provide more context, allowing for richer and more relevant results.”

Internally here at Microsoft, Work IQ is having a tangible effect on how we work every day. A few simple scenarios that illustrate the power of Work IQ—described in greater detail in Chapter 3—include:

  • Helping our employees understand which emails require their immediate attention, so they can focus on what matters
  • Connecting meeting transcripts to the people involved in a meeting, accelerating actions through a deeper understanding of the participants and their work patterns
  • Enabling our employees to create, organize, and publish Microsoft 365 content more quickly and with higher quality

This is just the beginning. As AI continues to permeate our business workflows, nearly every day-to-day task at Microsoft will be simplified, expedited, and improved by the intelligence of Work IQ. This includes the agents that are managing routine business and operational processes, giving them critical business context that helps their reasoning abilities.

This guide explores the ways that Work IQ is impacting how work gets done at Microsoft, and how Microsoft Digital—the company’s IT organization—has played a key role as Customer Zero, validating how Work IQ behaves under real enterprise conditions. It also examines the challenges and considerations that IT organizations will face as we enter an era where AI agents have access to unstructured data to complete workflows.

Chapter 1: Understanding Work IQ

Providing deeper insights through the power of context

Before we can fully explore the implications of Work IQ, it’s important to start with a clear understanding of what it is.

Work IQ is not a new application or service that users interact with directly. Rather, it’s a shared intelligence layer that continuously interprets work happening across the tenant. Understanding this distinction is critical, because it explains why Work IQ shows up everywhere Microsoft 365 Copilot works—and why it must be treated as foundational infrastructure, not as optional, add‑on functionality.

“It’s not really a brand-new capability, but more an evolution of what users already know, which is access to the grounding data in their Microsoft tenant,” says Aisha Hasan, a principal product manager in Microsoft Digital. “The difference is that Work IQ adds an additional layer to provide more context, allowing for richer and more relevant results.”

Work IQ is built on three layers:

  • Data: It unifies signals from files, emails, meetings, chats, and business systems.
  • Memory: It builds persistent understanding of how people and teams work.
  • Inference: It combines models, skills, and tools to reason and act.

At a high level, Work IQ consists of the systems that collect and interpret signals from everyday work. These signals come from many familiar Microsoft 365 applications—Word, Outlook, PowerPoint, Teams, SharePoint, and more—as well as structured data sources (such as those contained in Power Apps and Dynamics 365 resources).

The fact that Work IQ unifies unstructured and structured data into a shared ontology is a key differentiator from traditional search tools. This combination, referred to as semantic unification, means that it can combine the authoritative data contained in structured sources with the intent, nuance, and narrative found in unstructured data.

Work IQ draws from a broad range of work data from your Microsoft tenant. The unstructured data includes:

  • SharePoint sites, files, and other content
  • OneDrive activity that reflects individual work and collaboration patterns
  • Teams content, including chats, channels, and meeting data
  • Outlook emails and attachments

In addition, calendar signals—such as meeting participation, recency, and frequency—add time-based context that helps Work IQ understand priority and relevance of different data. This is what it means to go beyond simple information retrieval.

SharePoint

Example signals: Site membership, document libraries, file creation and sharing, co-authoring activity, linked workflows

Why they matter for context: Reveals shared projects, authoritative content locations, and how teams collaborate over time

OneDrive

Example signals: Individual file creation, sharing behavior, recent edits, collaboration spikes

Why they matter for context: Provides insight into personal work-in-progress and early-stage collaboration patterns

Email

Example signals: Conversation threads, reply frequency, recipients, attachments, urgency signals

Why they matter for context: Shows decision-making flows, stakeholder relationships, and which conversations truly drive work

Teams chat

Example signals: Channel discussions, mentions, reaction patterns, topic recurrence

Why they matter for context: Captures informal collaboration, fast-moving decisions, and cross-team interaction

Teams meetings

Example signals: Transcripts, speakers, shared files, action items, follow-up artifacts

Why they matter for context: Turns live discussions into durable knowledge that can inform future work and agent reasoning

Calendar

Example signals: Meeting frequency, recency, attendance, role of participants

Why they matter for context: Adds time-based priority and relevance, helping agents understand what matters now versus later

When all these are combined, it provides rich context that allows Work IQ to reason across all our employees’ work in a way that would be impossible if each signal were evaluated independently.

In practice, this means that when an employee asks a question about a current work project in Copilot, the tool’s response is not simply informed by the model’s capabilities or general source material. Responses are shaped by Work IQ’s understanding of the employee’s role, recent work, collaboration patterns (who they work with), and the larger enterprise context and conversations surrounding the question.

How our employees interact with and understand Work IQ depends on their role in the organization.

Our personas and their relationship with Work IQ

AI agents using Work IQ behave similarly. They use the intelligence to ground their reasoning in real organizational data, ensuring that their actions and recommendations are aligned with how work is happening inside the tenant. Although there are differences in how they are configured, all agents in a Microsoft tenant can be set up to take advantage of the power of Work IQ.

The impact of Work IQ on our company has been dramatic—we’re seeing agentic responses and actions that go deeper than surface-level answers. Our ability to reason over both our structured and unstructured data is producing richer, more nuanced contextual results that are boosting our productivity.

As your organization assesses your level of AI readiness, think of Work IQ not as an abstract concept but as critical infrastructure. It’s the key to connecting enterprise knowledge, trust, and productivity in a single, shared foundation.

Work IQ versus Microsoft Graph

Work IQ does not replace what we call the Microsoft Graph, the general term for unified, API-enabling, secure, permission-aware access to Microsoft 365 data, insights, and services. While the Microsoft Graph provides our employees with access to all their work data, Work IQ turns those signals into meaningful context that AI can reason over. In other words, Graph answers the general question “what info exists,” while Work IQ interprets what that information means and weaves it into responses to make them better.

Key takeaways

As you prepare for Work IQ, these points can help frame how to think about its role in your organization:

  • Work IQ is foundational infrastructure, not a user-facing feature. It operates as a shared intelligence layer across the tenant, continuously interpreting signals from everyday work.
  • Work IQ draws its power from context, not isolated data. By combining signals from email, meetings, documents, calendars, and collaboration patterns, it enables Copilot and agents to reason about work in a way that goes beyond simple search or retrieval.
  • Better agentic outcomes depend on Work IQ being in place. When agents and Copilot are grounded in Work IQ, their responses and actions align more closely with real enterprise work, delivering better relevance and measurable productivity gains.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 2: Establishing trust: How we govern Work IQ

Building on an existing foundation of solid governance and security

Like all Microsoft products, Work IQ was built with security foremost in mind. As the IT team at Microsoft, it is our responsibility to work in tandem with the product groups to ensure that all data that Work IQ has access to is well governed and secure.

The fact that Work IQ does not introduce new data into Microsoft 365 makes meeting this commitment easier. Embedded directly into the Microsoft 365 intelligence stack, Work IQ inherits the same compliance, security, and access controls that already govern the tenant.

A photo of Johnson.

“With great power comes great responsibility, and it’s up to your IT team to think about what it means to give your users full access to all this Work IQ data. It can greatly accelerate what people can build and what they can do.”

For Microsoft 365 Copilot–native agents, Work IQ is enabled to provide governed, context‑aware access to Microsoft 365 work data without requiring developers to build or manage individual data connectors.

As our governance experts note, this represents an inherent trade-off. Giving an agent access only to certain isolated data types reduces risk but also limits its value. Granting access through Work IQ means an agent can reason across everything the employee can access. This simplifies enablement but also requires stronger confidence in governance foundations.

Microsoft 365 intelligence stack

A graphic showing four layers of intelligence from bottom to top: Microsoft tenant, Microsoft Graph, Work IQ, and Microsoft 365 Copilot and AI agents.
Work IQ sits on top of our Microsoft Graph, reasoning over all that data and, in turn, informing the results we’re getting from Copilot and AI agents.

As our governance experts note, this represents an inherent trade-off. Giving an agent only access to certain isolated data types limits risk, but it also limits its value. Granting access through Work IQ means an agent can reason across everything the employee can access. This simplifies enablement but also requires stronger confidence in governance foundations.

“With great power comes great responsibility, and it’s up to your IT team to think about what it means to give your users full access to all this Work IQ data,” says David Johnson, a principal PM architect in Microsoft Digital. “It can greatly accelerate what people can build and what they can do. At the same time, organizations will want to think about the downstream implications of access.”

Exposing underlying governance issues

Our overall solution was to anchor Work IQ to our governance and security policies that already existed for our data. Sensitivity labels, data protection rules, and data-loss prevention policies remain the primary guardrails, as they do for all data across our enterprise. All these controls live at the data layer.

A critical aspect of this governance model is how sensitivity labels propagate through Work IQ experiences. In Microsoft 365, the label that is applied to a source document determines the label of any derived outputs, including summaries, insights, or AI-generated responses. This ensures that users have immediate context about the information’s sensitivity and how it should be handled. The label effectively travels with the data, reinforcing both user awareness and policy enforcement.

Labels also play a key role in controlling access beyond simple permissions. Even if a user has baseline access to a location, sensitivity labels can further restrict whether content can be extracted, shared, or surfaced through AI experiences. In some cases, organizations can configure policies so that content with specific labels is not returned at all in Work IQ or Copilot responses. This gives IT teams an additional layer of control to prevent exposure of particularly sensitive information.

These labeling principles extend across collaboration scenarios as well. For example, meeting labels determine the classification of all downstream artifacts—including recordings, transcripts, and notes. Sensitive discussions remain governed consistently, even as Work IQ helps make them more discoverable and actionable.

For example, even with Work IQ enabled, a document labeled Highly Confidential cannot be exposed through Copilot to someone without access, even if it is referenced in a Teams meeting transcript or included in an AI-generated summary. Copilot may understand that the document played a role in a particular decision, but it cannot extract or reveal its contents beyond what permissions allow.

This distinction—discoverable versus extractable—proved critical in our deployment of Work IQ. The intelligence layer makes data relationships visible, but it does not override protection. In one internal scenario, a sensitive document was found to be accessible through a Copilot query. The root cause was not Work IQ, but a missing sensitivity label—the AI tool simply honored what governance allowed. We treated the incident as a governance signal and corrected labeling at the source.

Remember that Work IQ can only access data that:

  • Exists inside your Microsoft 365 tenant or is explicitly connected via approved connectors
  • The current user already has permission to access
  • Is allowed by tenant‑level admin policy, compliance, and sensitivity controls

The security and governance considerations also extend to how new agents are released across our enterprise. For example, an agent created for use within one internal team has lighter governance controls than one that is published to our internal Microsoft agent portal, which offers companywide access. The latter requires additional review, approval, and monitoring as part of our due diligence for governance and security.

Ultimately, Work IQ adheres to all of the security and governance policies and procedures in our tenant, preserving the trust that our security-first approach creates and maintains.

Key takeaways

The following are important considerations for data governance and security when you consider adopting Work IQ for your organization:

  • With Work IQ, governance and security are top-line priorities. We made sure that Work IQ would always inherit the same compliance, access controls, and data protection policies that already govern Microsoft 365 data.
  • Work IQ doesn’t introduce new data access—it changes how existing access functions. By packaging tenant data into a single intelligence layer, it facilitates easier agent builder access to the data you already have in your Microsoft 365 tenant.
  • The distinction between discoverable and extractable data is central to safe AI deployment. Copilot and other agents can understand how work information is connected and referenced without exposing protected content beyond existing permissions.
  • IT admins and leaders should consider the ramifications to their tenant. Work IQ makes agents more powerful and context-aware by opening up access to vast quantities of Microsoft 365 data, but IT professionals should always think through downstream effects on data security and governance.
  • Work IQ surfaces governance gaps instead of masking them. When issues arise—such as misapplied sensitivity labels—the solution is not to restrict intelligence, but to strengthen data governance at the source.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 3: How our employees experience Work IQ day to day

Transforming the way work happens at Microsoft

To understand how Work IQ shows up and impacts the workflows of people across our organization, we spoke to several Microsoft employees. They explained how Work IQ makes a difference in the results they’re getting from Copilot and other agentic AI tools and how the intelligence is supercharging their work.

Work IQ in Outlook    

Outlook email and calendars are the space where many of our employees feel the heaviest cognitive load of their day‑to‑day work. It’s also where Work IQ is surfacing some of the most innovative ways to help employees accomplish more.

A photo of Marzynski.

“You open your Outlook in the morning and Copilot—by drawing on Work IQ context and through features like priority scoring and summarization—can help you see which messages need your attention first.”

Rather than treating messages and meetings as isolated items, Work IQ allows Copilot in Outlook to reason across email signals, conversation history, meeting patterns, and calendar behavior to deliver responses that reflect how work actually unfolds.

This means Copilot goes beyond keywords or unread status indicators to determine importance. Through Work IQ, it understands the context of each conversation—which threads are more urgent and relevant to your work and which are less vital.

“You open your Outlook in the morning and Copilot—by drawing on Work IQ context and through features like priority scoring and summarization—can help you see which messages need your attention first,” says Matthew Marzynski, a principal product manager for core experiences in Microsoft Digital. “Copilot is now beginning to offer proactive nudges to help you stay on top of what matters, surfacing what’s changed and what you need to focus on.”

The deeper context also aids Outlook in generating rich summaries of lengthy threads, which can highlight owners, decisions made, and next steps. This allows employees who are added to the thread or who have been away to quickly catch up on complex conversations without manually digging through seemingly endless past messages or related documents.

Marzynski frames Work IQ as an invisible intelligence layer that quietly reshapes how Outlook behaves over time. His core thesis is simple: Users never have to think about Work IQ; they just observe that Outlook is more helpful than before, and that their work gets easier.

“There are no complex commands to learn or rules to create. The intelligence works behind the scenes as you use Outlook,” he says. “Your inbox just gradually feels more relevant. Outlook adapts to how you work, rather than the reverse, and becomes more like an assistant instead of a filing cabinet of communications.”

Work IQ in Teams + Researcher Agent

Another immediate and tangible way our employees experience Work IQ is in Microsoft Teams meetings. The value begins the moment a meeting is recorded. Transcripts, speaker contributions, shared content, and AI‑generated summaries are automatically captured and folded into the attendees’ ongoing work context—without requiring manual note‑taking or follow‑up documentation.

Ray Peer is a senior product manager in Microsoft Digital who observed the power of Work IQ in a recent project he completed with our internal legal team. According to Peer, the team was struggling to find specific content in their data lake, which contains tens of thousands of documents, articles, and other content items.

A photo of Peer.

“Based just on what people shared in that meeting, and what it knows about their work and about SIPOC diagrams, Researcher was able to generate a fully formed, detailed solution for me. That’s the intelligence layer at work.”

So, he facilitated a Teams meeting for a free-form process‑mapping discussion with a few members of Microsoft Legal. Days later, he put the meeting transcript into the Copilot Researcher agent and asked it to generate a structured SIPOC (Suppliers, Inputs, Process, Outputs, Customers) diagram and accompanying documentation.

He was amazed by the results.

“Based just on what people shared in that meeting, and what it knows about their work and about SIPOC diagrams, Researcher was able to generate a fully formed, detailed solution for me,” Peer says. “That’s the intelligence layer at work. It reasoned over what we said—there were no visuals shared or anything—and it came up with something that I could cut and paste into the final format. I used to have to do that manually, and it took hours.”

Work IQ connected the meeting transcript to the people involved, the SharePoint sites they used, and similar work done elsewhere in the organization. Copilot was able reason across different tools and unstructured data, rather than just treating the meeting transcript as a static artifact.

Note that this works differently from third‑party meeting tools, because the data never leaves the tenant. Work IQ treats Teams meetings as part of a continuous Microsoft 365 workstream—honoring permissions and sensitivity labels throughout—so conversations can become durable inputs for future work without adding risk or effort for employees.

Work IQ in SharePoint

In SharePoint, Work IQ is helping employees create, organize, and publish content by drawing on the rich context of their Microsoft 365 data. Rather than starting from a blank page or text block, content development is sped up as Copilot draws on their relationships, collaboration history, and metadata to help produce sites and documents.

A photo of Crewdson.

“Copilot will recommend text changes, but also layout suggestions, image and graphic options, and other helpful assistance. It makes it easy to create more compelling content, more rapidly.”

For example, when you ask Copilot to create a new section in a SharePoint site—such as a project overview, status update, or other material—Work IQ enables the tool to look deeper than the prompt itself. When generating the content, it can draw on documents you’ve recently edited, your emails and Teams conversations, and related work happening across the organization. The output you get from Copilot is highly relevant and grounded in real work.

Sam Crewdson is a principal product manager at Microsoft Digital who has been a part of the SharePoint team for more than two decades. He’s excited about what Work IQ is enabling users to accomplish in the product using Copilot, as well as other agentic tools like Knowledge Agent (a domain-specific agent that can drill down on SharePoint sites and libraries).

“Copilot in SharePoint is now able to not only help you produce better written content, it’ll also offer more contextual and visual help,” Crewdson says. “Copilot will recommend text changes, but also layout suggestions, image and graphic options, and other helpful assistance. It makes it easy to create more compelling content, more rapidly.”

Another emerging scenario Crewdson described is conversational agentic authoring in SharePoint. In these workflows, employees refine their SharePoint pages by interacting directly with an agent—asking it to add sections, adjust tone, or suggest visuals. Over time, these agents will reduce repetitive setup steps and help teams move from draft to publish faster.

Across these experiences, Work IQ is helping shift SharePoint from a manual content creation tool to an application where agents automate everyday content tasks based on your overall work context and related Microsoft 365 data.

Key takeaways

Here are some things to remember when thinking about how Work IQ can impact your employee workflows:

  • Work IQ reduces cognitive load in Outlook by understanding work context. By recognizing decision‑driven threads, collaboration patterns, and urgency over time, Copilot helps employees focus on what truly needs their attention without relying on manual rules or keyword searching.
  • Email and calendar intelligence improves prioritization, summaries, and follow‑through. Work IQ allows Copilot to highlight owners, decisions, and next steps in long threads and nudge users toward timely action, based on how they typically work with colleagues.
  • Teams meetings become durable inputs for future work when powered by Work IQ. Copilot and the Researcher agent can reason across meeting content, people, and related SharePoint work—creating structured outputs while honoring tenant security and permissions.
  • Work IQ helps Copilot speed up and enrich content creation in SharePoint. By drawing on Microsoft 365 data, Copilot can generate more relevant content for your SharePoint sites and offer helpful layout and graphics suggestions that accelerate the site development process.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 4: Work IQ beyond Microsoft 365

Integrating Work IQ across the enterprise

As organizations adopt Copilot and other AI agents at scale, the question arises: How does Work IQ show up in different contexts? Is it something that only impacts your work in Microsoft 365 applications, or does it also play a role in external applications and other areas of your IT enterprise?

Based on our experience here at Microsoft, the answer is that Work IQ shows up differently depending on where it’s consumed, and those differences matter for admins, agent developers, and other IT professionals.

For most of our employees, Work IQ operates entirely behind the scenes inside Microsoft 365. It is not something users configure, enable, or interact with directly. By reasoning over your entire Microsoft 365 data graph, Work IQ improves the results that Copilot generates in apps like Outlook, Teams, Word, SharePoint, Copilot Chat, and GitHub Copilot.

In this mode, Work IQ is:

You don’t “implement” Work IQ—it’s already present in first-party Microsoft products by default. If you have enabled Copilot, you are getting the benefits of Work IQ across all of these applications. 

Similarly, any agents you build for Microsoft 365 apps (such as using Agent Builder in Microsoft 365 Copilot) are scoped for use specifically in these apps, rather than outside of them. These agents do not require separate connectors, such as APIs or Model Context Protocol (MCP) servers, to access Work IQ. In fact, Work IQ MCP is a great tool to make your context ubiquitous to whichever agentic experience can be imagined.

Extending Work IQ beyond Microsoft 365: explicit by design

Implementation works somewhat differently outside of native Microsoft 365 experiences. When it comes to custom agents, line‑of‑business applications, or Azure‑hosted solutions, Work IQ does not show up automatically. In these contexts, it is intentionally enabled by our builders and governed by our administrators.

In these scenarios:

  • Developers access Work IQ through APIs or MCP servers
  • Admins explicitly control which capabilities are enabled or disabled
  • Work IQ provides rich enterprise context without duplicating data
  • Permissions and governance remain enforced at the tenant level

For us, this design is deliberate and has advantages. Rather than asking our developers to configure dozens of individual connectors for mail, calendars, files, and meetings, Work IQ offers them a single-entry point for enterprise context. Builder tools like Microsoft Foundry and Copilot Studio allow our teams to take the same Work IQ intelligence that Copilot uses and apply it to workflows that live outside Microsoft 365. Examples include automating newsletters, generating insights for account teams, or powering custom agents to handle specific scenarios.

The key distinction is accountability. Inside Microsoft 365, Work IQ is ambient. Outside it, Work IQ is a conscious architectural choice, one that requires actions upfront to enable.

Work IQ does not “open up new data” when used externally. It ports intelligence, not raw access, applying the same rules no matter where it’s consumed. At the same time, it gives organizations flexibility to decide when and how far that intelligence should travel.

This continuum—from implicit use inside Microsoft 365 to explicit use beyond it—also clarifies our roles:

  • Our end users benefit without needing to learn anything new
  • Our IT teams retain centralized control at the tenant level
  • Our builders gain a faster path to context‑aware solutions

Work IQ works best when treated as a shared intelligence foundation, not a feature toggle. It is present by default where trust is already established, and it can be incorporated deliberately where your organizational requirements or innovation needs demand more reach.

Model Context Protocol servers and Work IQ

For organizations that move beyond native Microsoft 365 experiences and begin building custom agents, Model Context Protocol (MCP) servers are the primary mechanism for connecting those agents to Work IQ. While Work IQ is always available inside Copilot, MCP servers are what make much of that same intelligence accessible to agent builders.

At a high level, MCP servers are an open-standard technology (not proprietary to Microsoft) that act as governed tool interfaces to enterprise context. Each Work IQ MCP server represents a scoped slice of Microsoft 365 signals—such as email, calendar, Teams activity, or SharePoint content—and exposes them in a form that agents can reason over. Rather than wiring individual connectors or APIs for each workload, builders can rely on MCP servers to assemble relevant context automatically, while still honoring permissions, sensitivity labels, and tenant policies.

When we’re building agents, Work IQ becomes explicit, and MCP servers are how our builders declare their intent. This includes determining which types of enterprise context the agent needs, how broadly it should reason across work signals, and where governance boundaries apply.

From an IT perspective, MCP servers also provide a critical control point. Our administrators decide which Work IQ MCP servers are enabled in the tenant and which of our builders are allowed to use them. This ensures that extending intelligence beyond Microsoft 365 remains a deliberate choice rather than an accidental one.

Using these servers to connect with your enterprise data also represents real—but manageable—risk. They make existing permissions more actionable, which can amplify the impact of overshared content or weak data hygiene. The best practice is to treat these servers as governed infrastructure: enable them selectively at the tenant level, start with the minimum set required for defined agent scenarios, restrict usage to approved builders, and pair expansion with regular permission reviews and labeling discipline.

Your readiness plan should be to ensure that governance is in place, then selectively enable MCP servers where agents require deeper context. The servers are the bridge that lets agent builders tap into Work IQ safely, allowing you to bring enterprise intelligence into custom solutions without breaking the trust model that makes Copilot effective at scale.

Key takeaways

Here are some things to remember when thinking about how Work IQ shows up across your organization—especially if you plan to extend this intelligence into custom agents and applications:

  • Work IQ is foundational inside Microsoft 365 and intentional outside it. Within Copilot experiences, Work IQ operates implicitly, while custom agents introduce a conscious decision to consume that intelligence through MCP servers.
  • Governance principles don’t change when extending Work IQ, but they become more visible. MCP servers enforce existing permissions, labels, and tenant policies, making it critical that governance foundations are solid before agents rely on deeper context.
  • Agent builders declare intent through MCP server selection. Choosing which Work IQ MCP servers to use defines what enterprise signals an agent can reason over and how broadly it reflects real work patterns.
  • Preparing to extend Work IQ beyond Microsoft 365 is about readiness. Organizations that are already ready for Copilot can selectively enable MCP servers to unlock richer agent scenarios without introducing new security or compliance risk.

Learn more

How we did it at Microsoft

Further guidance for you

Chapter 5: Working with Work IQ: The Customer Zero impact

Change management lessons from our experience with an ambient intelligence layer

Work IQ wasn’t rolled out across our organization as an abstract platform decision or deployment milestone. Its development has been one aspect of our overall transformation into an AI-first Frontier Firm.

Along the way, Work IQ has been shaped by our long‑standing Customer Zero mission at Microsoft Digital: Using our own products at enterprise scale first, learning directly from how employees experienced it, and allowing those lessons to shape how the technology is refined and extended to customers.

In our tenant, Work IQ benefits emerged gradually through incremental improvements to relevance, context, and intelligence across Microsoft 365. These gains were driven by advances in AI that made it possible to interpret everyday work signals more effectively.

There was no formal product implementation or adoption campaign when we launched Work IQ at Microsoft. As ambient infrastructure, Work IQ is an unseen part of all employee workstreams—nearly every experience benefits from it. At the same time, the power of Work IQ depends on everyone in our organization being effective stewards of their own unstructured data, preserving security, governance, and relevance.

Enablement and adoption

To fully realize the value of Work IQ, we have found that organizations must invest in the foundational behaviors that make their organizational knowledge accessible. One of the key steps in this effort is enabling and encouraging the use of meeting transcripts. Work IQ depends on the artifacts of daily work to build context, and without transcripts, a significant portion of meeting insights and decisions remain inaccessible to the intelligence layer.

Making transcription a standard part of our employees’ everyday collaboration proved essential. Transcripts create a durable, searchable record that Work IQ can connect to documents and actions, helping employees quickly understand what happened, even if they weren’t present. When paired with existing governance controls like sensitivity and meeting labels, organizations can capture this data securely while unlocking great value from this collective knowledge.

This is actually a cultural shift.

We gave our teams clear guidance and encouraged meeting transcription as part of their normal workflow. When paired with the enhancements to meeting recaps in Microsoft Teams, this becomes a powerful tool for preserving and leveraging organizational knowledge.

Of course, Copilot adoption and training efforts were also a vital part of our getting the most from Work IQ. Our employees needed demonstrations of all the things that Copilot could help them accomplish, along with encouragement to jump in and try it out for themselves. Our data shows that internal AI usage has grown significantly over time—from a few thousand users to hundreds of thousands across the company—in large part due to:

  • Employee-driven champions programs
  • Scenario‑based learning efforts
  • Timely and consistent internal communications

Usage also grew internally as our product teams continually refined our AI tools, aided by our collection of user feedback on agentic answers to identify low-quality output and irrelevant detail.

Another major insight we captured was the importance of persistent memory to the Copilot and Work IQ experience. Through our work as Customer Zero, we collected a large volume of feedback from employees indicating that this was a priority—users should not have to repeatedly explain who they are or what they are working on.

The experience was subsequently improved, and Work IQ now helps enable Copilot to remember user history and tailor responses accordingly—delivering summaries for communicators and deeper technical detail for engineers, for example.

Our Customer Zero efforts also validated a critical governance principle for us. As intelligence improved, some teams were surprised by how much context Copilot could surface. In every case, investigation showed that the underlying data access already existed. Work IQ did not change permissions or expose new data—it made existing relationships more visible. This reinforced the importance of strong data hygiene, sensitivity labeling, and permission management as prerequisites for trusted intelligence.

Ultimately, our work as the company’s Customer Zero validated that Work IQ is best understood as shared infrastructure. Its value compounds when organizations focus on readiness—governance, learning, and trust—and allow intelligence to scale naturally across work, rather than treating it as a feature to deploy.

When these conditions are in place, Work IQ quietly raises the quality of Copilot and agent experiences without adding complexity for users or additional burden for IT.

Key takeaways

As you consider how Work IQ might take shape in your own organization, consider these observations from Microsoft Digital’s Customer Zero experiences with this new intelligence layer:

  • Meeting transcription is the key. Making sure all meetings are transcribed is essential for Work IQ, so it can build context on how work happens in your organization. This is a technical and cultural change that you need to facilitate and encourage.
  • Awareness and learning are keys to usage and feedback. Our internal Copilot adoption grew when employees were shown practical scenarios and encouraged to experiment, supported by champions programs and ongoing internal communication.
  • Change management drives results. Use employee champions, role-based immersive learning, and timely internal communications to help your employees understand what Work IQ is and how it can help your enterprise maximize the value of AI.
  • Treating Work IQ as shared infrastructure unlocks compound value. When governance, learning, and trust were in place, intelligence could reason across all our rich unstructured data —improving Copilot and agent experiences without adding additional work for users or IT.

Learn more

How we did it at Microsoft

Further guidance for you

Where we’re heading: Work IQ, Fabric IQ, and Foundry IQ

Combining different layers of intelligence to transform the workplace

While impactful on its own, Work IQ is just part of larger story of how we’re using the power of rich data and agentic AI to transform how we work at Microsoft.

A photo of Jangir

“While Work IQ can access your Microsoft 365 data, Fabric IQ will connect to your organizational data, such as analytics. Foundry IQ can leverage both, plus other domain data, to help developers build powerful agentic solutions.”

Work IQ is one layer. It allows our AI tools to reason over unstructured data so this powerful resource can be a part of our larger enterprise intelligence system. But it also includes two other aspects of this three-layer system—Fabric IQ and Foundry IQ. Combined, these three capabilities enable organizations to take full advantage of your knowledge estate to forge the AI-powered workplace of the future.

“While Work IQ can access your Microsoft 365 data, Fabric IQ will connect to your organizational data, such as analytics,” says Naveen Jangir, a principal architect in Microsoft Digital. “Foundry IQ can leverage both, plus other domain data, to help developers build powerful agentic solutions.”

Here’s how these capabilities work together in complementary roles to impact how work gets done at Microsoft:

  • Work IQ handles unstructured data—like documents, emails, PDFs, and web content—by extracting meaning and context from human language.
  • Fabric IQ operates over structured data—like tables, databases, metrics, events, and transactions—to bring consistency and analytic rigor to our work.
  • Foundry IQ provides the knowledge-grounding layer, where entities, relationships, and ontologies allow reasoning to stay aligned with enterprise truth.

While each component is powerful on its own, the deeper value is what becomes possible when they are used together.

The intent is to enable agents that can reason across all enterprise knowledge, regardless of where it originated or how it was stored. An agent should be able to read a policy, connect it to operational data, understand who and what is involved, explain its conclusions, and take an action (if desired) through a shared ontology based on organizational context.

That kind of capability can’t emerge just from information retrieval. It requires shared meaning across systems, content, and data types.

A graphic showing the overlap of the three intelligence layers to produce more powerful agentic results.
Work IQ combines with the Fabric IQ and Foundry IQ intelligence layers to create a shared business ontology that enables the completion of more complex agentic tasks.

This is where the role of Work IQ becomes especially important. We have found that unstructured data contains some of the most critical institutional knowledge an organization has, but it rarely arrives in a form that is ready to be reasoned over. Documents reference people, systems, processes, and timelines in ways that make sense to humans, but not to machines. They can also fall out of date or represent a draft state that was never meant to be presented as verified information.

Work IQ bridges this gap by transforming the raw text into structured understanding, without stripping away nuance.

A photo of Alaparthi.

“Work IQ is already helping us change the way that work gets done. Instead of hunting for information or stitching context together manually, our employees can focus on decisions, creativity, and outcomes—because the intelligence is already there, working with them every day. It’s an integral part of preparing our organization for our agentic AI future.”

The crucial mechanism for that transformation is entity extraction, paired with a shared ontology. When a document mentions an employee, a system, a regulation, or a product, Work IQ identifies that reference as something concrete and reusable. Over time, those entities become the connective tissue between unstructured content, structured records in Fabric IQ, and the semantic backbone that Foundry IQ relies on to ground reasoning in the agents we create.

We can already see signs of this promised future at Microsoft today. Take a tool like our Employee Self-Service Agent, which we launched late last year. What before was a collection of static HR documents becomes a living knowledge system: policies are parsed, roles and eligibility criteria are extracted, and guidance is grounded in an understanding of employee role and location. The agent can answer a question and explain why the answer applies, because it understands both the document and the organizational context behind it.

This is why Work IQ is such a strategic capability. Improving document quality, normalizing metadata, resolving entities, and establishing governance are not one-off hygiene tasks. They expand what future agents will be able to do safely and reliably. The more coherent your unstructured data becomes, the less guesswork agents must do and the more context they can absorb.

“Work IQ is already helping us change the way that work gets done,” says Vijaya Alaparthi, a principal group product manager in Microsoft Digital. “Instead of hunting for information or stitching context together manually, our employees can focus on decisions, creativity, and outcomes—because the intelligence is already there, working with them every day. It’s an integral part of preparing our organization for our agentic AI future.”

For us, the direction forward is clear. The better your data foundation, the more capable—and trustworthy—your agents become. As unstructured and structured knowledge converges, intelligence stops being a set of isolated features and becomes a system.

Organizations that invest in technology like Work IQ to harness their unstructured data as enterprise knowledge are the ones that will deploy the most capable agents going forward and will be best positioned to take advantage of the agentic future.

Key takeaways

If you want your organization to be able to use Work IQ to propel your own agentic transformation, consider what we’ve learned on our journey:

  • Work IQ transforms unstructured enterprise data into actionable intelligence. By reasoning over emails, documents, meetings, and chats, it unlocks institutional knowledge that was previously fragmented and underused.
  • The intelligence operates as foundational infrastructure, not a user-facing feature. Work IQ runs continuously behind the scenes across Microsoft 365, improving Copilot and agent responses wherever they appear without configuration.
  • Context is what makes Copilot feel truly intelligent. By combining signals from collaboration patterns, conversations, documents, and more, Work IQ enables agents to respond based on how work actually happens, not just what information can be retrieved.
  • Security and governance remain intact because Work IQ inherits existing controls. It doesn’t create new access to data; it reveals relationships while fully honoring permissions, sensitivity labels, and compliance policies.
  • Employees experience Work IQ as reduced cognitive load, not added complexity. Inbox relevance, richer summaries, and clearer follow-through improve naturally over time.
  • Using Work IQ beyond Microsoft 365 is a deliberate, governed choice. MCP servers allow builders to bring enterprise context into custom agents while giving IT teams clear control over scope, access, and risk.
  • Work IQ is the foundation for the next generation of agentic intelligence, especially when combined with Fabric IQ and Foundry IQ. The more coherent and well-governed your unstructured data is today, the more capable, explainable, and trustworthy your future agents will become.

Learn more

Try it out

Get a closer look at Work IQ.

The post Intelligence on tap: How Work IQ enables AI and agents at Microsoft appeared first on Inside Track.

]]>
24006
Streamlining finance cash collection at Microsoft with AI http://approjects.co.za/?big=insidetrack/blog/streamlining-finance-cash-collection-at-microsoft-with-ai/ Thu, 04 Jun 2026 15:45:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23944 When it comes to running a business, getting paid on time is critical. Our Global Collection team in the Microsoft Treasury division makes sure payments are seamlessly executed in our fast-moving global enterprise environment. However, our case managers were often losing valuable time figuring out things like who the right contact was for a given […]

The post Streamlining finance cash collection at Microsoft with AI appeared first on Inside Track.

]]>
When it comes to running a business, getting paid on time is critical.

Our Global Collection team in the Microsoft Treasury division makes sure payments are seamlessly executed in our fast-moving global enterprise environment. However, our case managers were often losing valuable time figuring out things like who the right contact was for a given customer, which issues were likely to be challenged by a customer, and where an exception should be routed next. This information was spread across systems or buried in handoffs.

To solve these challenges, our team built a human-led, AI agent-assisted support system to reduce preparation time and streamline their processes.

“Building the AI assistance wasn’t the hard part,” says Kathy Brustad, a director in the Global Treasury and Financial Services division at Microsoft. “The hard part was reimagining the collection experience with AI front and center, and bringing the underlying infrastructure up to speed to get it there.”

In this post, we explain how we did it so you can learn from our experience.

A photo of Brustad.

“We have over 1,000 collectors around the world who perform collections for Microsoft. They had multiple systems they had to go to in order to find out things like the totality of the customer’s invoice and what conversations a different team had with the customer. The information was fragmented.”

Kathy Brustad, director, Global Treasury and Financial Services

Stitching together information across systems

Our AI agent is focused on helping our case managers prioritize high-value work by:

  • Predicting late payments and possible customer disputes
  • Summarizing customer case interactions for use by case managers
  • Routing customer emails to the right collections manager faster and with greater precision Automatically matching payments to invoices
  • Automatically responding to customer inquiries

“We have over 1,000 collectors around the world who perform collections for Microsoft,” Brustad says. “They had multiple systems they had to go to in order to find out things like the totality of the customer’s invoice and what conversations a different team had with the customer. All of this information was fragmented. We didn’t have a single view of how much a customer owed us.”

We started by consolidating these dispersed tools and systems into an SAP and Microsoft Dynamics 365 environment, creating a single source of truth for all relevant customer, invoice, and payment data.

On that foundation, we layered on Microsoft’s IQ intelligence platform to infuse semantic understanding and business context. That standardized our workflows by simplifying templates and worklists to reduce complexity and put consistent global practices into place. Routine communications became fully automated.

We then applied AI to improve payment matching accuracy from 40% to 90%, generate customer response drafts, and intelligently route cases to reduce time-consuming back‑and‑forth.

Copilot assistance was embedded directly into the daily workflow of our case managers to reduce administrative load by providing inline knowledge suggestions, summarizing calls, and automatically drafting replies. With these standardized automated workflows, we could apply 98% of payments within 48 hours.

“In a nutshell, this is the collection story: We have various agents and models deployed to assist our human agents with all the activities they have to do, saving hundreds of thousands of hours that we spent on manually tracking things before.”

Kathy Brustad, director, Global Treasury and Financial Services

Moving faster on ‘act ready’ work

Deploying the agent was only the starting point. The harder work was helping our collection team change established ways of working. Brustad described the shift as learning to “run it in a different way,” moving from manual, fragmented preparation toward workflows where prioritization, context gathering, and routing were increasingly supported within the system.

To make that shift possible, the team introduced a change management work stream program and role-based training focused on real, day-to-day scenarios alongside the rollout. By anchoring the work in clear business pain points and showing tangible improvements, our team saw how the new approach made their work easier. Each morning, the agent prioritized each case manager’s workload according to urgency and past client behavior so case managers could immediately focus on the accounts that were the most pressing.

A graphic shows the different actions taken by our Global Collections team, all but two of which are now assisted by AI.
This graphic shows all the typical actions executed by our Global Collections team. The majority of these steps are now assisted by an AI agent in our newly reimagined collection experience. 

We reduced repetitive communications using automatically drafted responses and automated statements.

“In a nutshell, this is the collection story: We have various agents and models deployed to assist our human agents with all the activities they have to do, saving hundreds of thousands of hours that we spent on manually tracking things before,” Brustad says.

After deploying this system to our case managers, we saw measurable improvements in both productivity and speed, including:

  • Hundreds of thousands of hours unlocked annually in order to do more human-led high-value work rather than routine administrative tasks
  • 40% reduction in call preparation time
  • 2X growth in automatic cash applications
  • 2.5X acceleration of customer inquiry resolution time

Operationally, the team also saw up to 60% reduction in inquiry handling time through inline suggestions, summarized calls, and automatically drafted replies. To ensure these improvements were real and repeatable, we emphasized observability in our evaluation approach. Our team tracked dollars collected through collections and hours worked to create productivity metrics.

Data, trust, and good governance

When introducing AI systems or agents into finance workflows, leaders often ask two questions:

  1. Can we trust the outputs?
  2. Can we govern the process?

“The biggest takeaway is to know your own process very, very well. You need to understand where all the bottlenecks and pain points are. Start from there to design the new agent-enabled process instead of saying, ‘I’m going to just inject the agent into my existing process.’”

Kathy Brustad, director, Global Treasury and Financial Services

For us, trust came from getting the basics right in the form of right-sizing our enterprise data, standardizing our workflows, and establishing clear ownership for each part of the work. When we tested early and included frontline users throughout the process, outcomes improved.

“The biggest takeaway is to know your own process very, very well,” Brustad says. “You need to understand where all the bottlenecks and pain points are. Start from there to design the new agent-enabled process instead of saying, ‘I’m going to just inject the agent into my existing process.’”

Embed custom agent assistance directly into the moments where time disappears, such as prioritization, preparation, routing, and drafting so adoption feels natural and can be measured. You can prove impact with a small set of metrics like cycle time, throughput, dollars collected, and hours saved, and iterate from there.

Key takeaways

Modernizing collections is about fixing the fundamentals first, before you add AI into the mix. As you begin to streamline your own finance workflows, keep these lessons in mind:

  • Fix fragmented workflows before adding intelligence: AI delivers the most value when it’s layered on top of standardized processes and a unified data foundation rather than disconnected systems and ad hoc handoffs.
  • Embed assistance where time is actually lost: Copilot-style support works best when it shows up directly in prioritization, preparation, routing, and drafting to reduce friction without changing how people work.
  • Focus AI on highROI decisions, not just automation: Predicting late payments, flagging likely invoice disputes, and surfacing context can help teams spend time where it matters.
  • Design around the practitioner’s day: When work arrives prioritized and prepped, case managers spend less time chasing context and more time resolving exceptions.
  • Measure what matters to prove impact: Cycle time, dollars collected, throughput, and hours saved provide a clear, repeatable way to track productivity gains and cashflow velocity.
  • Pair generative AI with strong governance: Trust comes from clear ownership, standardized workflows, quality data, and ongoing human oversight.

Editor’s notes:

  • SAP is an enterprise finance system that many organizations use to manage invoices, payments, and financial records in a single, centralized platform.
  • All metrics cited are based on Microsoft internal data gathered during the writing of this article. They’re best read as directional signals from that period, and they may change as systems, processes, and behaviors evolve. Microsoft makes no warranties, express, implied, or statutory.

The post Streamlining finance cash collection at Microsoft with AI appeared first on Inside Track.

]]>
23944
Microsoft CISO advice: Securing AI with full stack red teaming http://approjects.co.za/?big=insidetrack/blog/microsoft-ciso-advice-securing-ai-with-full-stack-red-teaming/ Thu, 04 Jun 2026 15:30:00 +0000 http://approjects.co.za/?big=insidetrack/blog/?p=23971 At Microsoft, we approach security for AI systems holistically using a full stack red teaming that goes beyond just testing an AI model. Corporate Vice President of red teaming at Microsoft Craig Nelson describes what he looks for with this method, “I’m interested in the model, but I’m also interested in how that model connects […]

The post Microsoft CISO advice: Securing AI with full stack red teaming appeared first on Inside Track.

]]>
At Microsoft, we approach security for AI systems holistically using a full stack red teaming that goes beyond just testing an AI model.

Corporate Vice President of red teaming at Microsoft Craig Nelson describes what he looks for with this method, “I’m interested in the model, but I’m also interested in how that model connects with underlying additional data. And then how that model also executes automation from the back end.”

In this video, Nelson explains why securing AI requires more than testing the model alone.

Watch this video to see Craig Nelson describe how Microsoft approaches full stack red teaming. (For a transcript, please view the video on YouTube: https://www.youtube.com/watch?v=68MmP084rXA.)

Key takeaways

When you apply full stack red teaming to AI, here are some key questions to answer:

  • How are AI models connecting to data sources?
  • What backend automation do we allow AI to execute?
  • What security credentials do we require?
  • Do we have logs you need to understand how the model works with our backend infrastructure?

The post Microsoft CISO advice: Securing AI with full stack red teaming appeared first on Inside Track.

]]>
23971