A specialised form of Microsoft Copilot set up for one particular job, pairing instructions with knowledge and skills. You can create one in Copilot Studio, SharePoint or Agent Builder, and administrators control them from the Microsoft 365 admin center.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Agent in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Copilot
Licensed users get this workplace AI assistant, which grounds large language models in organisational data from Microsoft Graph and the Microsoft 365 apps. It respects existing permissions, so people see only what they could already open; without the licence, people use the web-grounded Microsoft Copilot Chat instead.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Job
A sequence of steps executed together on one agent or runner, or on the server for agentless work. While running, each occupies one of your parallel jobs.
- Pairing
Deployment pipelines link an item in one stage to its counterpart in the next. Deploying overwrites a linked item, but an unlinked item that just shares its name gets copied across as a duplicate.
- CRUD
Shorthand for create, read, update and delete, the four basic things you do with data. Data-plane roles in Azure Cosmos DB, for instance, authorise those operations on items.
- Copilot Studio
Microsoft's low-code tool for building workflows and AI agents. Its generative agents may hand each tool call they intend to make to an external threat detection service, Microsoft Defender for example, for checking.
- Agent Builder
A Microsoft Copilot tool where people describe a declarative agent in plain language, or fill in a Configure tab, and ground it in sources like SharePoint or Copilot connectors. If the agent later needs actions or workflows, a copy moves into Copilot Studio.
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
Related terms
- 168.63.129.16
Special platform address (WireServer) through which Azure delivers the VM agent channel, built-in DNS, DHCP and load balancer health probes. Traffic to it must stay open, or those platform functions stop working.
- Agent Dashboard
Gives leaders and analysts a picture of agent uptake and the credits those agents burn through, inside Viva Insights. It won't show data until a tenant has 50 or more Microsoft Copilot licences plus some agent usage.
- Agent endpoint
Fixed URL through which consumers call an agent by name. A version selector decides whether it always serves the newest version, without redeployment, or stays pinned to a single active version.
- Agent ID Administrator
Privileged role in Microsoft Entra for managing agent identities and blueprints across their lifecycle. Approving partner agent permissions and granting admin consent are beyond it.
- Agent identity blueprint
Template in Microsoft Entra Agent ID that holds credentials for one type of agent and obtains tokens for the agent identities created from it. Policies like Conditional Access set on it reach all those identities; Azure RBAC roles cannot be assigned to it.
- Agent instructions
System message of an agent defining its role, objectives, tone and boundaries; it also steers, though not deterministically, when tools get called.
- Agent memory
The past conversation and knowledge an AI agent draws from it, such as summaries, facts and user profiles, saved so the agent keeps context from one turn or session to the next. Azure Cosmos DB and Azure Managed Redis are common places to keep it.
- Agent risk
Condition in Conditional Access based on the risk level Microsoft Entra ID Protection assigns to agent identities, letting a policy stop high-risk agents from obtaining tokens.