Skip to main content

🤖🧑‍💼AG - Agent Builder Sharing

What this is 🤖

Copilot grew a build-your-own-agent button, and it does not check your job title. Anyone with a license can point an agent at a few SharePoint sites, type some instructions, and Publish to the whole company before their coffee goes cold ☕. IT finds out the way IT always finds out: in a ticket.

The problem isn't Marloes in Finance, who just shipped her first agent and is thrilled. It's the Share dropdown next to it, pre-set to the entire company. This page takes that option off the menu.

Why 🕵️

An agent is a chat interface bolted onto one person's access rights. Picture Clippy, except this Clippy can actually read your documents, all of them, and he is delighted to summarize the ones you forgot you could open. 📎

So when Marloes shares her "Q3 numbers helper" with everyone, she isn't sharing a document. She's mounting her SharePoint permissions as a company-wide search box. That board deck she can open because she's in Finance? Now three hundred colleagues can ask a cheerful chatbot to summarize it. Nothing got hacked. The permissions were always too broad. The agent just turned the filing cabinet nobody could find into a Google for it. 🔎

And you won't watch it happen. No "agents that overshare" dashboard, no approval step, no courtesy email to security. The author picks the audience from a dropdown, and Microsoft pre-selected "everyone" straight out of the box.

Two ways this bites:

Oversharing. Data that was always over-permissioned but mercifully undiscoverable is suddenly one polite prompt away.

Shadow agents. Load-bearing automations that live entirely inside one person's My Agents, undocumented, running great right up until that person is on a beach with no laptop and the thing throws its first error 🏖️. The first you hear of it is a ticket that just says "the AI is broken."

The recommendation

Turn org-wide sharing off. If an agent is meant for the whole company, an admin builds it in Copilot Studio and ships it from there, on purpose and on the record. Everyone keeps their personal helpers. Nobody self-appoints their side project as company infrastructure.

Two reasons the org-wide agents belong to the grown-ups:

Lifecycle. Copilot Studio agents live in the Power Platform: real dev, test, and production environments, packaged in solutions, promoted through pipelines. Agent Builder has exactly one environment, called "wherever Marloes was standing." Automation the business leans on belongs in the one with version history and a rollback button.

Ownership. An admin-built agent has an owner, a change log, and a home address. A self-built one has a person, and people go on holiday, change teams, and occasionally resign the Friday before a board meeting.

Agent Builder stays genuinely useful for the small stuff: summarize my inbox, draft from my notes. Anything the whole company relies on graduates to Copilot Studio.

🛠️ Configuration

Two control planes that don't talk to each other. Agent Builder is governed in the Microsoft 365 admin center. Copilot Studio is governed in the Power Platform admin center. Setting one does precisely nothing to the other, which is the trap most people fall in. Set both.

Agent Builder (Microsoft 365 admin center)

Where: Microsoft 365 admin center → AgentsSettings, then the Sharing section on the Agent settings page. These controls used to live over on the Copilot page and under Integrated apps, so if you're working from an older runbook, that's why the furniture moved.

Role: an admin role scoped to agent settings, or Global Administrator. Confirm the least-privileged one in your own tenant before handing anyone the keys.

SettingValueWhy
SharingNo usersStrips the "Anyone in your organization" option out of every user's Share dropdown. The default is "All users," which is the broadcast you came here to switch off.

Now the caveat the label conveniently omits: "No users" is not "no sharing." It removes the org-wide scope. It does not remove the Share button. Marloes can still share her agent with three named colleagues or a group she picks, and there is no single admin toggle that shuts that door. If you want to go further and stop people building agents at all, that's a Power Platform job (DLP data policies, switching off generative-AI agent publishing), and even there you get guardrails on what an agent may touch, not an off switch for creation. Microsoft sold you a dimmer, not a light switch.

Existing shares survive the change. Flipping this to "No users" on Tuesday does nothing about the agent Marloes broadcast last Thursday. Inventory what's already out there first, or you've bolted the barn door while the horse runs a SharePoint query down the hall. 🐴

Copilot Studio (Power Platform admin center)

This is where a company-wide agent should be born. An admin builds it, publishes it to the Microsoft 365 Copilot and Teams channel, and picks Show to the organization. That drops it into the org catalog for admin approval, and once approved it lands under Built by your org, a far better label than Built by whoever. Wrap the whole thing in a Managed Environment so the lifecycle and sharing controls actually bite.

Role: Power Platform Administrator. Licensing: Copilot Studio comes with Microsoft 365 Copilot, and whoever builds needs a Copilot Studio license on their name.

Caveats ⚠️

License fit (MKB lens). None of this is your problem until the customer buys Copilot. Microsoft 365 Copilot is a paid add-on that sits on top of Business Premium, not a feature hiding inside it, and Copilot Studio licensing stacks on top of that again. For most MKB tenants this is a "the day the Copilot licenses land" conversation. Have it before they land, not after the first agent has already introduced itself to the whole company.

Two planes, set both. Two switchboards, no shared wiring. Flip one and the other doesn't so much as blink. Set only the admin-center toggle and you've locked the front door while the back door quietly keeps its own hours. 🚪

Reversibility. Both switches are clean-revert tenant settings, which is the good news and the warning label. Nobody nudges Sharing from "No users" back to "All users" with a fat finger. That's a deliberate "let everyone back in," and it's almost always a tenant admin who took a vendor "support" call that went sideways. Alert on the change, then go find out who did it. 🚨

💼 Where the MSP comes in

Here's the part the customer can't do at 4pm between two other fires: decide what an agent is actually allowed to expose, sign off on what's safe to hand the whole company, and build the load-bearing agents in Copilot Studio like the software they are. That's a standing job, not a toggle you flip once and forget.

So own it, because nobody else will until it's a ticket. You run the governed agent layer, and the customer gets the Copilot they paid for without waking up to find a chatbot has been reading the salaries folder to the sales team since March. For an MSP with one eye on AI advisory, this is the door, already ajar.


Let Marloes build. Just don't let a dropdown quietly promote her side project to company infrastructure. 🤖