Forum Discussion
Difference between Copilot Agent settings and Microsoft Agent 365 Agent settings
Hello,
I am trying to better understand the distinction between the agent governance settings available in the Microsoft 365 admin center.
Currently, I can find seemingly similar agent access settings in two different locations:
- Copilot → Settings → Agents
- Agents → Settings → User Access (Microsoft Agent 365)
For example, both locations appear to provide controls such as :
- Who can access agents
- Whether access is granted to all users or specific groups
- Agent usage permissions
From an administrator perspective, it is not clear whether these are two different configuration scopes, two different management experiences, or simply two entry points to the same underlying policy.
So :
- What is the intended difference between the Copilot settings experience and the Agent 365 settings experience ?
- Which interface should be considered the primary administration location going forward ?
- Are the settings synchronized and backed by the same configuration objects ?
- Is one of these experiences planned to replace the other in the future ?
- What governance scenarios should be managed in Copilot settings versus Agent 365 settings ?
Thank you for your help.
1 Reply
You are seeing overlapping agent-access controls, but do not assume they represent independent policies. Microsoft currently documents Copilot > Settings > Data access > Agents for Copilot scenarios, while the centralized agent-settings documentation directs administrators to Agents > Settings > User access. Use the latter documented location for organization-wide access, and the Agent Registry for individual agent management. Copilot settings still cover broader Copilot-specific scenarios, including data access, billing, and product availability. Importantly, All users remains subject to existing app policies and user assignments; it is not blanket permission to use every agent. The documentation does not establish that both screens share identical backend configuration objects or guarantee a replacement date. Before relying on synchronization, compare the saved values and effective access using a small pilot group, following your change process. If the two views disagree, request tenant-specific confirmation from Microsoft support rather than assuming either overrides the other.
6:39 PM