partner center
29 TopicsMicrosoft Partner Center account structure: Best practices for long-term success
About the author: David Starr is the founder and CEO of Cumulus26, where focus is on accelerating customer's Azure Marketplace journey from onboarding to business success. He is a former Principal Architect at Microsoft working on Azure Marketplace and a 6-time Microsoft MVP in Developer Tooling. Why account structure matters in Partner Center When first creating a Partner Center account, many Software Development Company (SDC) partners I’ve worked with dive straight into creating their transactable offers without first considering how their accounts are structured. This often leads to confusion about account setup, creating multiple “orphan” accounts, and support incidents that can delay the publication of your software to the Microsoft Marketplace--or even result in losing access to Partner Center. This article examines Partner Center account structures and the primary decisions to make when setting up your company’s accounts in the portal. We’ll cover the following. Initial considerations: Individual accounts. Understanding organizational account structures and configurations. Working with important identifiers used in account management and support scenarios. Setting up for long-term successful management of your accounts. This article ensures you’ll know how to structure your Microsoft Partner Center account so that it supports your organization’s needs today and can scale with you as you grow. Understanding Partner Center account management After initially creating your account, it’s tempting to skip user management and move on to other tasks in the portal. This can lead to the common mistake of failing to assign multiple account administrators right away. The predictable outcome is that if an account administrator leaves your organization, your staff could lose the ability to administer-- or even access-- Partner Center. This may sound intuitive upon reading it, so why mention it? It’s because I have worked with many publishers who failed to do this and were later unable to get the access they needed. This leads to time spent resolving support incidents, which can delay publishing your solution. Before diving into setting up an account, it’s helpful to understand there are three different accounts involved: Microsoft accounts, Azure Entra ID accounts, and Partner Center accounts. Although, the Microsoft account is essentially an extension of the Azure Entra ID account. In short, you must have an Azure Entra ID account to have a Partner Center account. These account types are shown in the image below. Each has its own features and capabilities. It is worth noting while you do need an Entra ID account, you do not need an Azure subscription, which allows creation of services like databases or virtual machines. This can be an important point for Azure administrators who provide accounts strictly for use with Partner Center. Setting up an Azure tenant in Partner Center Azure accounts for your organization are stored in tenants, which provide identity, security, and account management through Microsoft Entra ID. At least one tenant must be associated with Partner Center to manage the portal’s accounts. This allows those with accounts in the tenant to also have accounts in Partner Center. You may associate a pre-existing Entra ID account with Partner Center, or you may create one if needed. Regardless of which technique you use, you can manage users and permissions for Partner Center after configuring your tenant. User accounts After configuring your tenant, head over to the user management screen in Account settings, then select User management in the left side menu. As we mentioned earlier, the next account you’ll want to configure is another Global administrator. If you created the Azure tenant you are working with, you already have Global Administrator permissions in Partner Center. Otherwise, you may need to contact your Azure administrator to get the permissions you need. This is why it’s common (and good) practice for organizations with pre-existing Azure tenants to have an Azure administrator initially set up Partner Center. Adding another Partner Center administrator For this next step, there are three options for adding that new person to Partner Center: Create new user – Used if there are no other user accounts in the tenant. Add existing user – Use this if there are existing user accounts in the tenant. Invite outside user – May be used for inviting someone from outside your organization to manage Partner Center for you. Regardless of which method you choose, since you are adding a second Global administrator, give them that role during account setup. This is the first role listed in the account setup process as shown here. Configuring partner global and location accounts Now that you have at least two global administrators, you can turn your attention to setting up your organizational accounts. There are two types in Partner Center. Partner global account (PGA) Partner location account (PLA) Structuring your accounts There is one PGA per SDC and one or more PLAs. A PGA is an overarching account containing contact and other information for your organization. Each PLA account represents a different location for the organization. A single PLA is created when you first create a Partner Center account. This may be enough for some organizations, but for many SDCs it’s a good idea to consider how you will organize the company and its products in the future. See the image below for a typical example of PGA and PLA structures, the information associated with them, and their roles. Some organizations may want multiple PLAs to represent different sales centers or divisions within the SDC. It’s also a good idea for smaller SDCs to consider future growth at this stage. Think about how and where your company may eventually do business. However, you do not need multiple PLAs to sell your solution in multiple countries--you can sell worldwide even if you have only one PLA. Both PGAs and PLAs have unique identifiers, examples of which are shown in the below image. You may need to access these when working with Microsoft. To do so, go to: Account Settings > Identifiers > Microsoft AI Cloud Partner Program Managing publisher accounts and identifiers Each PLA has one or more publisher accounts, which are established when enrolling in the Microsoft Marketplace program. Each publisher also receives its own set of identifiers, and it’s common to be asked for these in customer support scenarios. When creating a new publisher, you get to specify your publisher account’s primary ID, but a second Seller ID is automatically assigned for you. To access publisher IDs, visit: Account settings > Identifiers > Publisher Tax and payment profiles-- used by Microsoft to bill on your behalf and to pay you for customer purchases-- are associated with publisher accounts. Publisher accounts are sometimes used by different billing departments or to organize products into logical groups. See the image below for a typical example. As you can see, the account structure is straightforward. If you consider it in advance of setting up Partner Center, you will be more likely to avoid configuration mistakes and be set up well for future growth. Organizing offers and plans for marketplace publishing We’ve seen how to structure user and organizational accounts to ensure a great Partner Center experience. When it’s time to set up your products to sell in the marketplace there are two more entities involved, offers and plans. Offers represent your base software product and plans are used to sell one or more SKUs of the product. For example, Cumulus26’s AMPup solution for marketplace publishers may be our offer, and has different plans for team, professional, and enterprise versions. To support global software sales, each plan is associated with one or more global markets. For example, a US-based publisher may sell software in Canada, the UK, and Germany. Selling markets are designated for each plan. Of course, each offer and plan receives its own ID. For each, you must specify the ID as you create each entity, and I recommend planning a logical naming convention for these IDs as you may need to navigate marketplace features using them at some point. Now you have a complete picture of Partner Center structures from PGAs all the way to plans as shown in the image below, which represents a single-region seller. This turns out to be the most common Partner Center account configuration due to its simplicity and the needs of most SDCs. Conclusion: Building for scalability and support There is a strong relationship between Microsoft Azure Entra ID and Partner Center accounts. For many SDCs the simplest path to successful user management is to start with an Entra ID Global Administrator setting up your initial Partner Center account. Don’t forget the important first step of adding a second Partner Center account administrator. You are now ready to model your organization and products in Partner Center, from PLAs and PGAs to offers and plans. You also understand the ID structures of each entity. You can refer to this article for help on where to find them when needed. With a solid understanding of Partner Center user and organizational account structures, you are ready to begin configuring your users and organization in Partner Center. To learn more and ask questions, attend the How to structure your Microsoft Partner Center account for long term success | Microsoft Community Hub session on November 4th. If you are unable to attend, the session will be recorded for viewing after.1.2KViews6likes0CommentsSecuring AI apps and agents on Microsoft Marketplace
Why security must be designed in—not validated later AI apps and agents expand the security surface beyond that of traditional applications. Prompt inputs, agent reasoning, tool execution, and downstream integrations introduce opportunities for misuse or unintended behavior when security assumptions are implicit. These risks surface quickly in production environments where AI systems interact with real users and data. Deferring security decisions until late in the lifecycle often exposes architectural limitations that restrict where controls can be enforced. Retrofitting security after deployment is costly and can force tradeoffs that affect reliability, performance, or customer trust. Designing security early establishes clear boundaries, enables consistent enforcement, and reduces friction during Marketplace review, onboarding, and long‑term operation. In the Marketplace context, security is a foundational requirement for trust and scale. You can always get a curated step-by-step guidance through building, publishing and selling apps for Marketplace through App Advisor. This post is part of a series on building and publishing well-architected AI apps and agents in Microsoft Marketplace. The series focuses on AI apps and agents that are architected, hosted, and operated on Azure, with guidance aligned to building and selling solutions through Microsoft Marketplace. How AI apps and agents expand the attack surface Without a clear view of where trust boundaries exist and how behavior propagates across systems, security controls risk being applied too narrowly or too late. AI apps and agents introduce security risks that extend beyond those of traditional applications. AI systems accept open‑ended prompts, reason dynamically, and often act autonomously across systems and data sources. These interaction patterns expand the attack surface in several important ways: New trust boundaries introduced by prompts and inputs, where unstructured user input can influence reasoning and downstream actions Autonomous behavior, which increases the blast radius when authentication or authorization gaps exist Tool and integration execution, where agents interact with external APIs, plugins, and services across security domains Dynamic model responses, which can unintentionally expose sensitive data or amplify errors if guardrails are incomplete Each API, plugin, or external dependency becomes a security choke point where identity validation, audit logging, and data handling must be enforced consistently as part of securing AI integrations—especially when AI systems span tenants, subscriptions, or ownership boundaries. Using OWASP GenAI Top 10 as a threat lens The OWASP GenAI Top 10 provides a practical, industry‑recognized lens for identifying and categorizing AI‑specific security threats that extend beyond traditional application risks. Rather than serving as a checklist, the OWASP GenAI Top 10 helps teams ask the right questions early in the design process. It highlights where assumptions about trust, input handling, autonomy, and data access can break down in AI‑driven systems—often in ways that are difficult to detect after deployment. Common risk categories highlighted by OWASP include: Prompt injection and manipulation, where malicious input influences agent behavior or downstream actions Sensitive data exposure, including leakage through prompts, responses, logs, or tool outputs Excessive agency, where agents are granted broader permissions or action scope than intended Insecure integrations, where tools, plugins, or external systems become unintended attack paths Highly regulated industries, sensitive data domains, or mission‑critical workloads may require additional risk assessment and security considerations that extend beyond the OWASP categories. The OWASP GenAI Top 10 allows teams to connect high‑level risks to architectural decisions by creating a shared vocabulary that sets the foundation for designing guardrails that are enforceable both at design time and at runtime. Designing security guardrails into the architecture Security guardrails must be designed into the architecture, shaping where and how policies are enforced, evaluated, and monitored throughout the solution lifecycle. Guardrails operate at two complementary layers: Design time, where architectural decisions determine what is possible, permitted, or blocked by default Runtime, where controls actively govern behavior as the AI app or agent interacts with users, data, and systems When architectural boundaries are not defined early, teams often discover that critical controls—such as input validation, authorization checks, or action constraints—cannot be applied consistently without redesign: Tenancy boundaries, defining how isolation is enforced between customers, environments, or subscriptions Identity boundaries, governing how users, agents, and services authenticate and what actions they can perform Environment separation, limiting the blast radius of experimentation, updates, or failures Control planes, where configuration, policy, and behavior can be adjusted without redeploying core logic Data planes, controlling how data is accessed, processed, and moved across trust boundaries Designing security guardrails into the architecture transforms security from reactive to preventative, while also reducing friction later in the Marketplace journey. Clear enforcement boundaries simplify review, clarify risk ownership, and enable AI apps and agents to evolve safely as capabilities and integrations expand. Identity as a security boundary for AI apps and agents Identity defines who can access the system, what actions can be taken, and which resources an AI app or agent is permitted to interact with across tenants, subscriptions, and environments. Agents often act on behalf of users, invoke tools, and access downstream systems autonomously. Without clear identity boundaries, these actions can unintentionally bypass least‑privilege controls or expand access beyond what users or customers expect. Strong identity design shapes security in several key ways: Authentication and authorization, determines how users, agents, and services establish trust and what operations they are allowed to perform Delegated access, constraints agents to act with permissions tied to user intent and context Service‑to‑service trust, ensures that all interactions between components are explicitly authenticated and authorized Auditability, traces actions taken by agents back to identities, roles, and decisions A zero‑trust AI agent architecture is essential in this context. is essential in this context. Every request—whether initiated by a user, an agent, or a backend service—should be treated as untrusted until proven otherwise. Identity becomes the primary control plane for enforcing least privilege, limiting blast radius, and reducing downstream integration risk. This foundation not only improves security posture, but also supports compliance, simplifies Marketplace review, and enables AI apps and agents to scale safely as integrations and capabilities evolve. Protecting data across boundaries Data may reside in customer‑owned tenants, subscriptions, or external systems, while the AI app or agent runs in a publisher‑managed environment or a separate customer environment. Protecting data across boundaries requires teams to reason about more than storage location. Several factors shape the security posture: Data ownership, including whether data is owned and controlled by the customer, the publisher, or a third party Boundary crossings, such as cross‑tenant, cross‑subscription, or cross‑environment access patterns Data sensitivity, particularly for regulated, proprietary, or personally identifiable information Access duration and scope, ensuring data access is limited to the minimum required context and time When these factors are implicit, AI systems can unintentionally broaden access through prompts, retrieval‑augmented generation, or agent‑initiated actions. This risk increases when agents autonomously select data sources or chain actions across multiple systems. To mitigate these risks, access patterns must be explicit, auditable, and revocable. Data access should be treated as a continuous security decision, evaluated on every interaction rather than trusted by default once a connection exists. This approach aligns with zero-trust principles, where no data access is implicitly trusted and every request is validated based on identity, context, and intent. Runtime protections and monitoring For AI apps and agents, security does not end at deployment. In customer environments, these systems interact continuously with users, data, and external services, making runtime visibility and control essential to a strong security posture. AI behavior is also dynamic: the same prompt, context, or integration can produce different outcomes over time as models, data sources, and agent logic evolve, so monitoring must extend beyond infrastructure health to include behavioral signals that indicate misuse, drift, or unintended actions. Effective runtime protections focus on five core capabilities: Vulnerability management, including regular scanning of the full solution to identify missing patches, insecure interfaces, and exposure points Observability, so agent decisions, actions, and outcomes can be traced and understood in production Behavioral monitoring, to detect abnormal patterns such as unexpected tool usage, unusual access paths, or excessive action frequency Containment and response, enabling rapid intervention when risky or unauthorized behavior is detected Forensics readiness, ensuring system-state replicability and chain-of-custody are retained to investigate what happened, why it happened, and what was impacted Monitoring that only tracks availability or performance is insufficient. Runtime signals must provide enough context to explain not just what happened, but why an AI app or agent behaved the way it did, and which identities, data sources, or integrations were involved. Equally important is integration with broader security event and incident management workflows. Runtime insights should flow into existing security operations so AI-related incidents can be triaged, investigated, and resolved alongside other enterprise security events—otherwise AI solutions risk becoming blind spots in a customer’s operating environment. Preparing for incidents and abuse scenarios No AI app or agent operates in a perfectly controlled environment. Once deployed, these systems are exposed to real users, unpredictable inputs, evolving data, and changing integrations. Preparing for incidents and abuse scenarios—including AI agent incident response—is therefore a core security requirement, not a contingency plan. AI apps and agents introduce unique incident patterns compared to traditional software. In addition to infrastructure failures, teams must be prepared for prompt abuse, unintended agent actions, data exposure, and misuse of delegated access. Because agents may act autonomously or continuously, incidents can propagate quickly if safeguards and response paths are unclear. Effective incident readiness starts with acknowledging that: Abuse is not always malicious, misuse can stem from ambiguous prompts, unexpected context, or misunderstood capabilities Agent autonomy may increase impact, especially when actions span multiple systems or data sources Security incidents may be behavioral, not just technical, requiring interpretation of intent and outcomes Preparing for these scenarios requires clearly defined response strategies that account for how AI systems behave in production. AI solutions should be designed to support pause, constrain, or revoke agent capabilities when risk is detected, and to do so without destabilizing the broader system or customer environment. Incident response must also align with customer expectations and regulatory obligations. Customers need confidence that AI‑related issues will be handled transparently, proportionately, and in accordance with applicable security and privacy standards. Clear boundaries around responsibility, communication, and remediation help preserve trust when issues arise. How security decisions shape Marketplace readiness From initial review to customer adoption and long‑term operation, security posture is a visible and consequential signal of readiness. AI apps and agents with clear boundaries—around identity, data access, autonomy, and runtime behavior—are easier to evaluate, onboard, and trust. When security assumptions are explicit, Marketplace review becomes more predictable, customer expectations are clearer, and operational risk is reduced. Ambiguous trust boundaries, implicit data access, or uncontrolled agent actions can introduce friction during review, delay onboarding, or undermine customer confidence after deployment. Marketplace‑ready security is therefore not about meeting a minimum bar. It is about enabling scale. Well-designed security allows AI apps and agents to integrate into enterprise environments, align with customer governance models, and evolve safely as capabilities expand. When security is treated as a first‑class architectural concern, it becomes an enabler rather than a blocker—supporting faster time to market, stronger customer trust, and sustainable growth through Microsoft Marketplace. What’s next in the journey Security for AI apps and agents is not a one‑time decision, but an ongoing design discipline that evolves as systems, data, and customer expectations change. By establishing clear boundaries, embedding guardrails into the architecture, and preparing for real‑world operation, publishers create a foundation that supports safe iteration, predictable behavior, and long‑term trust. This mindset enables AI apps and agents to scale confidently within enterprise environments while meeting the expectations of customers adopting solutions through Microsoft Marketplace. See the next post in the series: Designing AI guardrails for apps and agents in Marketplace | Microsoft Community Hub. Key resources See curated, step-by-step guidance to help you build, publish, or sell your app or agent (no matter where you start) in App Advisor, Quick-Start Development Toolkit Microsoft AI Envisioning Day Events How to build and publish AI apps and agents for Microsoft Marketplace Get over $126K USD in benefits and technical consultations to help you replicate and publish your app with ISV Success293Views5likes0CommentsGoverning AI apps and agents for Marketplace
Governing AI apps and agents Governance is what turns powerful AI functionality into a solution that enterprises can confidently adopt, operate, and scale—an essential part of AI governance for agents. It establishes clear responsibility for actions taken by the system, defines explicit boundaries for acceptable behavior, and creates mechanisms to review, explain, and correct outcomes over time. Without this structure, AI systems can become difficult to manage as they grow more connected and autonomous. For publishers, governance is how trust is earned—and sustained—in enterprise environments, enabling responsible AI operations. It signals that AI behavior is intentional, accountable, and aligned with customer expectations, not left to inference or assumption. As AI apps and agents operate across users, data, and systems, risk shifts away from what a model can generate and toward how its behavior is governed in real‑world conditions. Marketplace readiness reflects this shift, defined less by raw capability and more by control, accountability, trust, and adherence to AI compliance standards for publishing. You can always get a curated step-by-step guidance through building, publishing and selling apps for Marketplace through App Advisor. This post is part of a series on building and publishing well-architected AI apps and agents in Microsoft Marketplace. The series focuses on AI apps and agents that are architected, hosted, and operated on Azure, with guidance aligned to building and selling solutions through Microsoft Marketplace. What governance means for AI apps and agents Governance in AI systems is operational and continuous. It is not limited to documentation, checklists, or periodic reviews — it shapes how an AI app or agent behaves while it is running in real customer environments. For AI apps and agents, governance spans three closely connected dimensions: Policy What the system is allowed to do, what data it is allowed to access, what is restricted, and what is explicitly prohibited. Enforcement How those policies are applied consistently in production, even as context, inputs, and conditions change. Evidence How decisions and actions are traced, reviewed, and audited over time. Governance works when intent, behavior, and proof move together — turning expectations into outcomes that can be trusted and examined. These dimensions are interdependent. Policy without enforcement is aspiration. Enforcement without evidence is unverifiable. Governance in action Governance becomes real when responsibility is explicit. For AI apps and agents, this starts with clarity around who is responsible for what: Who the agent acts for — and how its use protects business value Ensuring the agent is used for its intended purpose, produces measurable value, and is not misused, over‑extended, or operating outside approved business contexts. Who owns data access and data quality decisions Governing how the agent consumes and produces data, whether access is appropriate, and whether the data used or generated is reliable, accurate, and aligned with business and integrity expectations. Who is accountable for outcomes when behavior deviates Defining responsibility when the agent’s behavior creates risk, degrades value, or produces unexpected outcomes — so corrective action is timely, intentional, and owned. When governance is left vague or undefined, accountability gaps surface and agent actions become difficult to justify and explain across the publisher, the customer, and the solution itself. In this model, responsibility is shared but distinct. The publisher is responsible for designing and implementing the governance capabilities within the solution — defining boundaries, enforcement points, and evidence mechanisms that protect business value by default. Marketplace customers expect to understand who is accountable before they adopt an AI solution, not after an incident forces the question. The customer is responsible for configuring, operating, and applying those capabilities within their own environment, aligning them to internal policies, risk tolerance, and day‑to‑day use. Governance works when both roles are clear: the publisher provides the structure, and the customer brings it to life in practice. Data governance for AI: beyond storage and access For Marketplace‑ready AI apps and agents, data governance must account for where data moves, not just where it resides. Understanding how data flows across systems, tools, and tenants is essential to maintaining trust as solutions scale. Data governance for AI apps and agents extends beyond where data is stored. These systems introduce new artifacts that influence behavior and outcomes, including prompts and responses, retrieval context and embeddings, and agent‑initiated actions and tool outputs. Each of these elements can carry sensitive information and shape downstream decisions. Effective data governance for AI apps and agents requires clear structure: Explicit data ownership — defining who owns the data and under what conditions it can be accessed or used Access boundaries and context‑aware authorization — ensuring access decisions reflect identity, intent, and environment, not just static permissions Retention, auditability, and deletion strategies — so data use remains traceable and aligned with customer expectations over time Relying on prompts or inferred intent to determine access is a governance gap, not a shortcut. Without explicit controls, data exposure becomes difficult to predict or explain. Runtime policy enforcement in production Policies are stress tested when the agent is responding to real prompts, touching real data, and taking actions that carry real consequences. For software companies building AI apps and agents for Microsoft Marketplace, runtime policy enforcement is also how you keep the system fit for purpose: aligned to its intended use, supported by evidence, and constrained when conditions change. At runtime, governance becomes enforceable through three clear lanes of behavior: Decisions that require human approval Use approval gates for higher‑impact steps (for example: executing a write operation, sending an external request, or performing an irreversible workflow). This protects the business value of the agent by preventing “helpful” behavior from turning into misuse. Actions that can proceed automatically — within defined limits Automation is earned through clarity: define the agent’s intended uses and keep tool access, data access, and action scope anchored to those uses. Fit‑for‑purpose isn’t a feeling — it’s something you support with defined performance metrics, known error types, and release criteria that you measure and re‑measure as the system runs. Behaviors that are never permitted — regardless of context or intent Block classes of behavior that violate policy (including jailbreak attempts that try to override instructions, expand tool scope, or access disallowed data). When an intended use is not supported by evidence — or new evidence shows it no longer holds — treat that as a governance trigger: remove or revise the intended use in customer‑facing materials, notify customers as appropriate, and close the gap or discontinue the capability. To keep runtime enforcement meaningful over time, pair it with ongoing evaluation: document how you’ll measure performance and error patterns, run those evaluations pre‑release and continuously, and decide how often re‑evaluation is needed as models, prompts, tools, and data shift. This is what keeps autonomy intentional. It allows AI apps and agents to operate usefully and confidently, while ensuring behavior remains aligned with defined expectations — and backed by evidence — as systems evolve and scale. Auditability, explainability, and evidence Guardrails are the points in the system where governance becomes observable: where decisions are evaluated, actions are constrained, and outcomes are recorded. As described in Designing AI guardrails for apps and agents in Marketplace, guardrails shape how AI systems reason, access data, and take action — consistently and by default. Guardrails may be embedded within the agent itself or implemented as a separate supervisory layer — another agent or policy service — that evaluates actions before they proceed. Guardrail responses exist on a spectrum. Some enforce in the moment — blocking an action or requiring approval before it proceeds — while others generate evidence for post‑hoc review, supported by audit logging for AI agents. Marketplace‑ready AI apps and agents could implement both, with the response mode matched to the severity, reversibility, and business impact of the action in question. These expectations align with the governance and evidence requirements outlined in the Microsoft Responsible AI Standard v2 General Requirements. In practice, guardrails support auditability and explainability by: Constraining behavior at design time Establishing clear defaults around what the system can and cannot do, so intended use is enforced before the system ever reaches production. Evaluating actions at runtime Making decisions visible as they happen — which tools were invoked, which data was accessed, and why an action was allowed to proceed or blocked. When governance is unclear, even strong guardrails lose their effectiveness. Controls may exist, but without clear intent they become difficult to justify, unevenly applied across environments, or disconnected from customer expectations. Over time, teams lose confidence not because the system failed, but because they can’t clearly explain why it behaved the way it did. When governance and guardrails are aligned, the result is different. Behavior is intentional. Decisions are traceable. Outcomes can be explained without guesswork. Auditability stops being a reporting exercise and becomes a natural byproduct of how the system operates day to day. Aligning governance with Marketplace expectations Governance for AI apps and agents must operate continuously, across all in‑scope environments — in both the publisher’s and the customer’s tenants. Marketplace solutions don’t live in a single boundary, and governance cannot stop at deployment or certification. Runtime enforcement is what keeps governance active as systems run and evolve. In practice, this means: Blocking or constraining actions that violate policy — such as stopping jailbreak attempts that try to override system instructions, escalate tool access, or bypass safety constraints through crafted prompts Adapting controls based on identity, environment, and risk — applying stricter limits when an agent acts across tenants, accesses sensitive data, or operates with elevated permissions Aligning agent behavior with enterprise expectations in real time — ensuring actions taken on behalf of users remain within approved roles, scopes, and approval paths These controls matter because AI behavior is dynamic. The same agent may behave differently depending on context, inputs, and downstream integrations. Governance must be able to respond to those shifts as they happen. Runtime enforcement is distinct from monitoring. Enforcement determines what is allowed to continue. Monitoring explains what happened once it’s already done. Marketplace‑ready AI solutions need both, but governance depends on enforcement to keep behavior aligned while it matters most. Operational health through auditability and traceability Operational health is the combination of traceability (what happened) and intelligibility (how to use it responsibly). When both are present, governance becomes a quality signal customers can feel day to day — not because you promised it, but because the system consistently behaves in ways they can understand and trust. Healthy AI apps and agents are not only traceable — they are intelligible in the moments that matter. For Marketplace customers, operational trust comes from being able to understand what the system is intended to do, interpret its behavior well enough to make decisions, and avoid over‑relying on outputs simply because they are produced confidently. A practical way to ground this is to be explicit about who needs to understand the system: Decision makers — the people using agent outputs to choose an action or approve a step Impacted users — the people or teams affected by decisions informed by the system’s outputs Once those stakeholders are clear, governance shows up as three operational promises you can actually support: Clarity of intended use Customers can see what the agent is designed to do (and what it is not designed to do), so outputs are used in the right contexts. Interpretability of behavior When an agent produces an output or recommendation, stakeholders can interpret it effectively — not perfectly, but reasonably well — with the context they need to make informed decisions. Protection against automation bias Your UX, guidance, and operational cues help customers stay aware of the natural tendency to over‑trust AI output, especially in high‑tempo workflows. This is where auditability and traceability become more than logs. Well governed AI systems should still answer: Who initiated an action — a user, an agent acting on their behalf, or an automated workflow What data was accessed — under which identity, scope, and context What decision was made, and why — especially when downstream systems or people are affected The logs should show evidence that stakeholders can interpret those outputs in realistic conditions — and there is a method to evaluate this, with clear criteria for release and ongoing evaluation as the solution evolves. Explainability still needs balance. Customers deserve transparency into intended use, behavior boundaries, and how to interpret outcomes — without requiring you to expose proprietary prompts, internal logic, or implementation details. For more information on securing your AI apps and agents, visit Securing AI apps and agents on Microsoft Marketplace | Microsoft Community Hub. What's next in the journey Governance creates the conditions for AI apps and agents to operate with confidence over time. With clear policies, enforcement, and evidence in place, publishers are better prepared to focus on operational maturity — how solutions are observed, maintained, and evolved safely in production. The next post explores what it takes to keep AI apps and agents healthy as they run, change, and scale in real customer environments. See the next post in the series: Quality and evaluation framework for successful AI apps and agents in Microsoft Marketplace | Microsoft Community Hub. Key resources See curated, step-by-step guidance to help you build, publish, or sell your app or agent (no matter where you start) in App Advisor Quick-Start Development Toolkit can connect you with code templates for AI solution patterns Microsoft AI Envisioning Day Events How to build and publish AI apps and agents for Microsoft Marketplace Get over $126K USD in benefits and technical consultations to help you replicate and publish your app with ISV Success323Views4likes0CommentsMeet customer business needs with flexible billing schedules in the marketplace
Co-authored by Trevor_Yeats Today, we’re announcing that Microsoft now offers flexible billing schedules through private offers to better align with customer needs. Flexible billing schedules are available globally to all marketplace-supported currencies. Watch these demo videos to learn more about flexible billing schedules. The value for your customers and for you With flexible billing schedules, customers can buy with confidence knowing that private offers can be customized for virtually any contract value and billing timeline to align with their requirements. Partners can tailor customer private offers and multiparty private offers to meet those requirements. This streamlines sales and accelerates deal velocity. With over 100 partners in our private preview, we’re excited to make this capability publicly available. Many of these partners have achieved remarkable success, closing deals worth millions of dollars. “Flexible billing in Microsoft marketplace has significantly improved how our sales teams engage with customers. It allows them to meet each organization's and customer's procurement needs, whether it's aligning with fiscal year budgets or accelerating project timelines from evaluations to implementations. Additionally, it helps with managing cloud commitment benefits. This flexibility has made it easier for our customers to purchase and deploy solutions faster, without waiting for specific budgets to become available. We can now set up flexible billing schedules to accommodate their needs.” Brett Ferancy, Global Alliance Leader, Abnormal AI Example use cases See below for some real-world examples of how partners and customers are leveraging flexible billing. Variable pricing with specific dates. In this example, the customer pays a setup fee at the start of billing, followed by variable pricing throughout the contract to match consumption patterns and budget cycles. 3-year deal $80M total Notes Immediate charge when billing starts $2M Setup fee – 1 st month 01 Jan 2025 $5M Year 1 installment #2 15 Jul 2025 $3M Year 1 installment #3 01 Jan 2026 $10M Year 2 installment #1 15 Jul 2026 $10M Year 2 installment #2 01 Jan 2027 $20M Year 3 installment #1 15 Jul 2027 $30M Year 3 installment #2 Variable quarterly billing. In this example, the customer pays a setup fee at the start of billing, followed by variable pricing each quarter. 1-year deal $10M total Notes Immediate when billing starts $2M Q1 01 Jun 2025 $3M Q2 01 Sep 2025 $2M Q3 01 Dec 2025 $3M Q4 Delayed start for billing. In this example, the customer gets the first two months free, followed by varied payments throughout the contract to match budget cycles 2-year deal $25M total Notes Immediate when billing starts $0M Free – 2 months 01 Mar 2024 $10M Year 1 fee 15 Jan 2025 $5M Year 2 installment 1 01 Jul 2025 $10M Year 2 installment 2 How it works To start using flexible billing for private offers: The software partner creates a private offer in the marketplace. Currently flexible billing supports SaaS flat rate offers, VM software reservations, and professional services. Partner must choose “Customize SaaS plans and Professional Services” or “Customize VM software reservations” when creating a new private offer. On the configure pricing page, under “billing frequency,” the partner will select “flexible schedule when the contract duration is 1-year or greater.” The software partner creates the billing schedule with up to 70 installments up to $100,000,000 USD, or any of the currencies supported by marketplace, over the length of the deal. There is also an option to book an immediate charge when billing starts or delay the first charge to a date in the future. Private offers can have up to ten included product plans. Each plan has its own billing frequency and may include a unique flexible schedule. A flexible schedule does not apply to all plans included in the private offer and must be set up independently. The software partner can also create a schedule in their customer’s local billing currency using the market pricing template. The customer accepts and purchases the private offer with the flexible billing schedule. For a multiparty private offer, the process is the same except: The software partner sends the private offer to the channel partner. The channel partner adds their price adjustment percentage aligned to the flexible billing schedule and passes it to the customer. Eligibility Any company who is part of the Microsoft AI Cloud Partner Program can sell on the marketplace through private offers with flexible billing. Details are provided in our documentation, but at a high-level: Be a member of the Microsoft AI Cloud Partner Program (it’s free to join) Sign the marketplace publisher agreement Publish your offer Sell private offers with flexible billing In addition, we have many support resources for partners depending on where they are on their marketplace journey. For example, software development companies can join ISV Success for tools and resources that help them publish their solution and maximize its reach on the marketplace. Get started with flexible billing on marketplace We invite you to start leveraging these new improvements to flexible billing today. Learn more by visiting aka.ms/flexbill-docs.2KViews4likes0CommentsMicrosoft Marketplace Partner Digest
In this edition of the Microsoft Marketplace Partner Digest, you'll find essential announcements, events, and key updates designed to drive your business forward, accelerate deal closures, and maximize your Marketplace success. Partner Center announcements As we kick off the new fiscal year, we're building upon a quarter that delivered valuable enhancements for both Marketplace partners and customers. We’ve focused on expanding partner-led growth across regions, simplifying SaaS transactions, and helping you improve co-sell outcomes. 🌍 Multiparty private offers expand across EMEA and APAC On May 27, Microsoft Marketplace expanded multiparty private offers to 30 countries in Europe, with availability in Australia, Japan, and South Africa coming July 15. Read the blog to discover how we are enabling new opportunities for channel-led growth through Marketplace. Why it matters Software companies gain more opportunities to reach new customers and drive growth without adding operational complexity. Channel partners differentiate their offerings with vetted software solutions while maintaining customer relationships. Recommended action Microsoft’s Jason Rook breaks down six practical steps to activate your channel strategy through Microsoft Marketplace, helping software companies recruit, enable, and scale partner-led growth. 📗Get the playbook 🌏 Resale enabled offers support expands to New Zealand Microsoft continues expanding channel-led sales opportunities by making resale enabled offers available through Microsoft Marketplace to customers in New Zealand as of May 26. Why it matters Channel partners can create and manage offers directly, without relying on software companies to build bespoke private offers. For software companies, resale enabled offers provide a scalable way to grow through trusted channel partners and expand into new markets. 👉 Learn more 📆 Custom contract lengths As of July 6, custom contract lengths for private offers are generally available. Partners can now create private offers with custom contract lengths of up to 10 years in Microsoft Marketplace. Why it matters Flexibility to better meet customer requirements Ability to configure contract durations from 1 to 120 months Define non-standard contract lengths, like 18 months or 45 months Support for both SaaS and professional services transactions 👉 Read the announcement ⚡ Auto activation for SaaS offers On May 18, Microsoft released the optional auto activation for SaaS offers, streamlining customer's Marketplace purchase and onboarding experience. What’s new Billing and subscription activation can now begin immediately when a customer completes a purchase Partners receive a real-time webhook signal to trigger onboarding Available for both public and private offers Default behavior For existing plans auto activation is off, unless you enable it When creating new plans auto activation is on, by default, unless you disable it Why it matters Reduces friction between purchase and onboarding Improves revenue predictability with immediate billing Enables a faster, more seamless customer experience Recommended action Evaluate your SaaS offers and enable auto activation where it aligns with your onboarding model. Make sure your sales and customer guidance reflect the updated experience. 👉 Learn more 🔔 Improve referral quality to accelerate co-sell deals Microsoft has updated how inbound co-sell referrals are reviewed and processed to improve speed and alignment with Microsoft account teams. What’s changing All referrals are now automatically checked for completeness and quality at submission. To avoid delays, ensure every referral includes: Solution area / play Estimated deal value Estimated close date (valid future date) Clear customer need and business context Customer contact (or consent to share later) Why it matters Submitting complete referrals helps you: Get faster seller engagement Reduce rework and follow-ups Improve acceptance rates Move deals forward more predictably Recommended action Audit your referral submission process and ensure these five fields are consistently included across all deals. 👉 Learn more about managing co-sell opportunities ⚠️ Review: Ensure the right contacts receive important partner communications Now is a great time to take care of digital housekeeping. Microsoft is reminding partners to review assigned Partner Center roles and email configurations to avoid missing critical notifications and account updates. Why it matters Having assigned roles like global admin or billing admin does not guarantee email delivery. If accounts aren’t configured correctly, you and your team may miss time-sensitive notifications. Missing communications can result in missed compliance deadlines or delayed actions that may impact your business. Recommended actions Verify your primary contact email is up to date Ensure role-based accounts can receive emails Add Microsoft system emails as safe senders Review role guidance on Microsoft Learn ✨ Bonus: Sign up for the monthly Microsoft AI Cloud Partner Program newsletter to stay informed of updates, incentives, and partner opportunities. It’s an easy way to get partner news delivered directly to your inbox. Events Recent events Marketplace as a FinOps platform Explore how Microsoft Marketplace helps simplify purchasing, centralize billing, and better align software investments to optimize cloud spending. As organizations scale cloud and AI investments, managing spend across tools and vendors becomes more complex. Tune in to learn practical ways to better understand the ROI of your organization’s cloud and AI investments. You will walk away with actionable insights to use Microsoft Marketplace as part of your FinOps strategy 📽️ Watch the recording The Marketplace playbook for channel-led sales Get step-by-step guidance and go-to-market resources to help you recruit and activate partners for channel-led sales through Microsoft Marketplace. Through resale enabled offers and multiparty private offers, software companies can empower partners to sell on their behalf to drive scale, reach new markets, and unlock new co-sell opportunities. In markets where both resale enabled offers and multiparty private offers are available, software companies can also scale through distributors, who can activate their broader channel networks. 📽️ Watch the recording Multicurrency transactions explained As Marketplace adoption continues to grow more partners are navigating sales that involve multiple currencies, local customer invoicing, and evolving seller of record responsibilities. Understanding how currency exchanges impact private offers, partner payments, and customer billing is critical to successfully managing Marketplace transactions across global geographies. 📽️ Watch the recording Upcoming events Channel growth in Australia ⌚Wednesday, July 15 at 9:30 AEST Microsoft Marketplace provides several ways for partners to collaborate and grow through the channel. With multiparty private offers launching in Australia on July 16, alongside resale enabled offers, this expansion helps partners strengthen customer relationships, fuel more partner-to-partner opportunities, simplify transactions, and find new growth opportunities. Leave with practical guidance on how these capabilities work together and how to put them into action. 📆 Save to your calendar MCAPS Start for Partners 📆 Wednesday, July 22 from 7:00 – 11:00 am PDT MCAPS Start for Partners gives software companies an early look at Microsoft’s FY27 priorities, investments, and growth opportunities. Learn how AI innovation and agentic applications are creating new customer demand, discover marketplace and co-sell opportunities to expand reach, and explore strategies to modernize, differentiate, and grow your business in the year ahead. 👉 Learn more and register today 🚀 Closing thoughts The last quarter delivered meaningful platform enhancements to make Microsoft Marketplace easier to scale, faster for customers to discover solutions and transact, and more effective for partners to manage business. 👍 Take the next step Explore new regions for multiparty private offers and resale enabled offers Review your strategy for activation of customer SaaS subscriptions Improve your co-sell submission quality Small changes in these areas can have a big impact on your pipeline, conversion, and overall Marketplace success.219Views3likes0CommentsDecember 2025
Microsoft Ignite 2025 - Marketplace highlights Microsoft Ignite was packed with announcements and insights for Marketplace partners. From new commerce capabilities to AI-driven innovations, here are some key takeaways: Global expansion of Microsoft Marketplace - Microsoft announced that the reimagined Microsoft Marketplace, which launched in the U.S. earlier this year, is now globally available. This expansion includes new APIs for distribution partners, enabling them to link their own cloud marketplace with Microsoft’s, opening significant opportunities for software companies in SMB and mid-market segments. 🎬 Watch a recorded webinar with TD SYNNEX on the power of distribution to accelerate SMB marketplace sales. Global availability of Resale Enabled Offers - This capability allows software development companies to and channel partners to resell software solutions directly through Marketplace, simplifying transactions, expanding reach, and scaling revenue. 👉 Read more about this announcement and get started Introducing App Accelerate - A unified offer that brings together incentives, benefits, and co-sell support across the Microsoft Cloud. App Accelerate provides end-to-end technical guidance, developer tools, and go-to-market resources so software development companies can innovate and scale. Previews are beginning now, with full availability planned for 2026. ✅ Sign up to receive updates Enhanced Partner Marketing Center - Discover, customize, and launch campaigns faster with intelligent search and AI-powered tools—all on one connected platform. The current Partner Marketing Center will remain available as the new and enhanced Marketing Center platform launches in early 2026 with 24 campaigns-in-a-box, aligned to FY26 solution plays. ✨ Get ready for the new era of partner marketing Frontier Partner badge – New customer-facing badges recognize top services, channel, and software development company partners that are driving AI transformation with customers and offer them an opportunity to differentiate themselves from the competition. 🛡️Differentiate your AI-first leadership Catch up on Microsoft Ignite sessions Ignite 2025 delivered powerful insights and announcements for Marketplace partners, and now you can catch up on the sessions you missed. Explore these recorded keynotes to learn about new capabilities, partner programs, and strategies to accelerate growth through Microsoft’s ecosystem. Ignite opening keynote Ignite partner keynote: Powering Frontier Partnerships Additionally, we’ve compiled recordings of relevant Marketplace partner and customer sessions so you can watch on-demand. Revisit Marketplace-focused sessions and resources. Just look for the ✨ icon below. Partner sessions: PBRK415 Grow your business with Microsoft AI Cloud Partner Program Find out how the Microsoft AI Cloud Partner Program helps you grow with new benefits, designations, and skilling opportunities. This session covers updates like the Frontier Partner Badge, Copilot specialization, and streamlined Marketplace engagement—all designed to accelerate your AI transformation journey. PBRK416 Accelerate Growth through Partner Incentives Explore how Microsoft is boosting partner growth with streamlined incentives, AI-first strategies, and new designations like Frontier Distributor. This session covers expanded investments in Azure Accelerate, Copilot solutions, and security practices—plus insights on how to capitalize on evolving programs and co-sell opportunities. PBRK417 Partner: Connect, Plan, Win – Enhancing Co-sell Engagement Discover how to enhance collaboration, optimize joint efforts, and drive success in shared initiatives. Gain insights into improving interactions with Microsoft sellers and leveraging opportunities, along with guidance on proactive co-selling to align your goals with Microsoft's for sustained growth. PBRK418 Partner: Benefits for Accelerating Software Company Success Learn about the resources and benefits available for software development companies across all stages of the build, publish and grow journey in MAICPP. Whether you’re developing a new agent solution or working toward a certified software designation, there are targeted skilling opportunities, technical resources, and GTM benefits to help. Tap into new investments for AI apps and agents and hear from your peers on how they’ve used rewards such as customer propensity scores and Azure sponsorship. PBRK419 SI & Advisory Partner Readiness: Accelerating the Journey to Frontier Understand how Microsoft is empowering our SI and advisory partners to accelerate frontier firm readiness for our Enterprise customers by driving AI transformation with agentic solutions and services. ✨PBRK420 Executing on the channel-led marketplace opportunity for partners See how Microsoft’s unified Marketplace drives partner growth with resale-enabled offers, creating scalable channel sales and co-sell opportunities. This session shares practical steps to build a sustainable Marketplace practice and leverage the partner ecosystem for greater reach and profitability. PBRK421 Enabling a thriving partner ecosystem: New CSP Authorization Criteria Dive into what’s new for Cloud Solution Providers, including updated authorization requirements and designations that help you stand out. This session covers steps to choose the right tier, build trust as a customer advisor, and prepare for growth with AI-driven solutions and Copilot offerings. PBRK422 The Future of Partner Support: Customer + Partner + Microsoft Discover ‘Unified for Partners,’ Microsoft’s new support model designed for CSP partners to deliver customer success at scale. This session introduces the Support Services designation, offering faster response times, financial incentives, and integrated tools to strengthen your support capabilities. PBRK423 Partner Execution at Scale with SME&C Explore growth opportunities in the high-potential SME&C segment. This session highlights investments in co-selling, AI-first strategies, and what it means to become ‘customer zero,’ with examples of frontier firms driving innovation at scale. ✨PBRK424 Marketplace Success for Partners—from SMB to Enterprise Learn how to build, publish, and monetize AI-powered solutions through Microsoft Marketplace. This session shares a proven approach to align your Marketplace strategy with your sales motion and unlock new revenue opportunities. PBRK272 Accelerate Secure AI: Microsoft’s Security Advantage for Partners Explore Microsoft’s integrated security solutions and learn how to help customers strengthen their defenses in the AI era. This session highlights partner opportunities, resources to grow your security practice, and what it takes to lead as a next-generation security partner. Customer Sessions: ✨Microsoft Marketplace: Your trusted source for cloud solutions, AI apps, and agents | STUDIO47 Hear from Cyril Belikoff, VP of Commercial Cloud & AI Marketing, sharing the reimagined Microsoft Marketplace—the gateway to thousands of AI-powered apps, agents and cloud solutions—all built to accelerate innovation and drive business outcomes. Discover how customers benefit from faster deployment, seamless integration with Microsoft tools, and trusted solutions, and how partners can scale their reach, accelerate sales, and tap into Microsoft’s global ecosystem. Azure Accelerate in action: Confidently migrate, modernize, and build faster Join Cyril Belikoff for a rapid Q&A that spotlights real-world customer success and the transformative impact of Azure Accelerate. Hear how customers like Thomson Reuters achieved breakthrough results with our powerful offering that provides access to Microsoft experts and investments throughout your Azure and AI journey. ✨BRK213 Microsoft Marketplace: Your trusted source for cloud and AI solutions Discover how the reimagined Microsoft Marketplace is reshaping the future of cloud and AI innovation. In this session, we’ll explore how Microsoft Marketplace—unifying Azure Marketplace and Microsoft AppSource—empowers organizations to become Frontier Firms by streamlining the discovery, purchase, and deployment of tens of thousands of cloud solutions, AI apps, and agents. ✨BRK215 Boost cloud and AI ROI using Microsoft Marketplace As organizations embrace an AI-first future, cloud adoption is accelerating to drive innovation and efficiency. This session explores practical strategies to optimize cloud investments—balancing performance, scalability, and cost control. Learn how Microsoft Marketplace enables rapid solution deployment while maintaining governance, compliance, and budget discipline. Build a resilient, cost-effective cloud foundation that supports AI and beyond. Community Recap Partner of the Year Award Winners Congratulations to the winners and finalists of the 2025 Microsoft Partner of the Year Awards in the Marketplace category! 🏆 Explore all winners and finalists Fivetran earned the top honor as Marketplace Partner of the Year for its innovation in automating data movement on Microsoft Azure, enabling enterprises to accelerate AI and analytics initiatives. Varonis Systems Inc. and Bytes Software Services were recognized as finalists for delivering exceptional solutions and driving customer success through Marketplace. What’s Coming Up AI-powered acceleration: Scale faster in Microsoft Marketplace 📆 Thursday, December 04, 2025, at 9:00 AM PST Microsoft Marketplace is no longer just a procurement convenience; it’s a strategic revenue engine. Dive into operational readiness, CRM-native automation, seller engagement, trust signals, and AI-enabled acceleration. Whether you're just getting started or looking to optimize your Marketplace motion, this session will provide you with information that will turn your first sale into a repeatable growth engine. Scale smarter: Discover how resale enabled offers drive growth 📆 Friday, December 05, 2025, from 11:00 - 12:00 PM GTM+1 Discover how resale enabled offers help software development companies to scale through the Microsoft Marketplace by simplifying transactions, expanding reach and accelerating co-sell opportunities. Chart your AI app and agent strategy with Microsoft Marketplace 📆 Thursday, December 11, 2025, from 8:30 - 9:30 AM PST Organizations exploring AI apps and agents face a critical choice: build, buy, or blend. There’s no one-size-fits-all—each approach offers unique benefits and trade-offs. Tune in for insights into the pros and cons of each approach and explore how the Microsoft Marketplace simplifies adoption by providing a single source for trusted AI apps, agents, and models. Office hours for partners: Marketplace resale-enabled offers 📆 Thursday, December 18, 2025, at 8:30 AM PST Tune in to explore resale enabled offers through Microsoft Marketplace. This recently announced capability enables software companies to expand into new markets globally, at scale, and without additional operational overhead. Dive deep into the workflow and requirements for these deals. Learn about reporting and best practices from those that are already selling globally with resale enabled offers. Microsoft Ignite will return to San Francisco next year 📆 November 17-20, 2026 Sign up now to join the Microsoft Ignite early-access list and be eligible to receive limited‑edition swag at the event. 💬 Share Your Feedback! We truly appreciate your feedback and want to ensure these Partner Digests deliver the information you need to succeed in the marketplace. If you have any feedback or suggestions on how we can continue to improve the content to best support you, we’d love to hear from you in the comments below!418Views3likes0CommentsMicrosoft Marketplace Partner Digest
What's new in Marketplace Convert more buyers into customers Microsoft recently expanded Marketplace listing capabilities with enhancements to free trials and the introduction of an option to request private offers, giving partners more ways to engage buyers at different stages of the purchasing journey. Customers can now discover and evaluate solutions through expanded trial experiences and transition more easily into paid subscription discussions by requesting custom pricing and terms directly from your Marketplace listings. ✨ Help customers evaluate your solution with free trials What's new On July 23 we announced the release of Marketplace enhanced trial capabilities. Customers can try solutions with confidence with the free trials in Microsoft Marketplace. Trials are available for multiple offer types, including SaaS, Azure virtual machines, Dynamics 365, and Power BI offers. New capabilities include: Custom meter trials: Partners can configure trials for SaaS solutions with metered pricing. Flexible trial durations: Partners can now configure SaaS trial durations from 1 to 180 days. Partner analytics: Partners can access SaaS trial analytics - including free trials initiated, active free trials, free trials converted, free trials not converted, and average trial duration - all within Partner Center Insights workspace. Customer discovery and management: Customers can better discover and manage trials. Upgrade to paid subscription during trial: Customers can upgrade to paid subscription at public pricing any time during a SaaS trial. Why it matters With enhanced trial capabilities in Microsoft Marketplace, partners can run self-service trials that make it easier for customers to try before they buy — whether for metered, per-user, or flat-rate pricing offers. Marketplace gives partners one place to manage trials end to end — from provisioning and mid-trial changes to insights — while improving offer discoverability through improved search, filters, and dedicated trial badges. Recommended action Review your Marketplace offers and trial strategy. For eligible SaaS offers, evaluate whether free trials can help you engage with more qualified buyers, faster. 📖 Learn more about free trials for SaaS ⚡ Customers can now request a private offer on Marketplace What’s new As of July 20, you can add a private offer request option directly on your Marketplace product pages. Customer requests are captured as Marketplace leads in referrals workspace and connected customer relationship management (CRM) integrations you’ve setup. This setting is disabled by default. You can easily activate it for applicable public offers. Why it matters More and more customers are seeking customized contracts and subscription pricing and terms tailored to their individual needs. This simple call to action reduces friction and helps you start the conversation with prospective buyers. Recommended action In the Marketplace offers workspace of Partner Center, update each of your offers for which you provide customers private offers. Enable the Request Private Offer setting and republish the offer. Events Recent events Multiparty private offers expand channel growth opportunities in Australia, Japan and South Africa Multiparty private offers continue to help software companies accelerate channel-led sales through Microsoft Marketplace. This past month, we hosted two region-focused Marketplace office hours sessions designed to help partners better understand local market opportunities, engage distributors and resellers, and scale Marketplace transactions through channel ecosystems in Australia and Japan. Whether you're looking to expand an existing Marketplace motion or explore new geographic opportunities, these sessions will provide practical guidance and market-specific insights to help you grow. See a list of currently supported countries/regions. Check out the recorded sessions: • Channel growth in Australia (English) • Channel growth in Japan (Japanese) Helping developers build, monetize, and scale AI solutions with Marketplace Discover how Microsoft Marketplace helps software companies access AI models and developer tools, accelerate application development, and reach customers through Microsoft's global commercial ecosystem. Learn how to monetize applications and agents without building and maintaining your own commerce and distribution infrastructure. Watch the recording Upcoming events Build AI-powered solutions, monetize through Microsoft Marketplace, and scale revenue through Microsoft expertise, skilling, and investments. Frontier Accelerate for Marketplace is an upcoming unified offering for software development companies to bring AI-powered solutions to market, drive customer acquisition and revenue growth, and scale through Microsoft Marketplace with technical guidance, skilling, and investments aligned to every stage of growth. 📆 Join us on August 26th before general availability to learn about the new offering, benefit alignment, migration guidance, and enrollment requirements. Next steps Turn insights into FY27 success — starting today. Ready to carry the momentum forward from MCAPS Start for Partners? Get everything you need to refine and execute your FY27 strategy in the Partner Activation Zone, including session recordings, ready-to-use playbooks, and tools to start building pipeline. Leverage your Marketplace Rewards benefits Discover use cases and how to leverage your Azure sponsorship. With Marketplace Rewards Azure sponsorships, eligible software development companies can increase sales through Microsoft Marketplace by using the sponsorships for customer deployments tied to Marketplace deals—and to offset infrastructure costs from eligible free trial offers. 📍Review the Marketplace Rewards Azure sponsorship policy guide for the latest278Views2likes0CommentsDesign tenant linking to scale selling on Microsoft Marketplace
Designing tenant linking and Open Authorization (OAuth) directly shapes how customers onboard, grant trust, and operate your AI app or agent through Microsoft Marketplace. This post explains how to design scalable, review‑ready identity patterns that support secure activation, clear authorization boundaries, and enterprise trust from day one. Guidance for multi‑tenant AI apps Identity decisions are rarely visible in architecture diagrams, but they are immediately visible to customers. In Microsoft Marketplace, tenant linking and OAuth consent are not background implementation details. They shape activation, onboarding, certification, and long‑term trust with enterprise buyers. When identity decisions are made late, the impact is predictable. Onboarding breaks. Permissions feel misaligned. Reviews stall. Customers hesitate. When identity is designed intentionally from the start, Marketplace experiences feel coherent, secure, and enterprise‑ready. This post focuses on how software development companies (like ISVs) can design tenant linking and consent patterns that scale across customers, offer types, and Marketplace review—without rework later. You can always get curated step-by-step guidance through building, publishing and selling apps for Marketplace through App Advisor. This post is part of a series that focuses on AI apps and agents that are architected, hosted, and operated on Azure, with guidance aligned to building and selling solutions through Microsoft Marketplace. Why identity across tenants is a first‑class design decision Designing identity is not just about authentication. It is about how trust is established between your solution and a customer tenant, and how that trust evolves over time. When identity decisions are deferred, failure modes surface quickly: Activation flows that cannot complete cleanly Consent requests that do not match declared functionality Over‑privileged apps that fail security review Customers who cannot confidently revoke access These are not edge cases. They are some of the most common reasons Marketplace onboarding slows or certifications are delayed. A good identity and access management design ensures that trust, consent, provisioning, and operation follow a predictable and reviewable path—one that customers understand and administrators can approve. Marketplace tenant linking requirements A key mental model simplifies everything that follows: separate trust establishment from authorization. Tenant linking and OAuth consent solve different problems. Tenant linking establishes trust between tenants OAuth consent grants permission within that trust Tenant linking answers: Which customer tenant does this solution trust? OAuth consent answers: What is this solution allowed to do once trusted? AI solutions published in Microsoft Marketplace should enforce this separation intentionally. Trust must be established before meaningful permissions are granted, and permission scope must align to declared functionality. Making this distinction explicit early prevents architectural shortcuts that later block certification. Throughout the rest of this post, tenant linking refers to trust establishment, not permission scope. Microsoft Entra ID as the identity foundation Microsoft Entra ID provides the primitives for identity-based access control, but the concepts only become useful when translated into publisher decisions. Each core concept maps to a choice you make early: Home tenant vs resource tenant Determines where operational control lives and how cross‑tenant trust is anchored. App registrations Define the maximum permission boundary your solution can ever request. Service principals Determine how your app appears, is governed, and is managed inside customer tenants. Managed identities Reduce long‑term credential risk and operational overhead. Understanding these decisions early prevents redesigning consent flows, re‑certifying offers, or re‑provisioning customers later. Marketplace policies reinforce this by allowing only limited consent during activation, with broader permissions granted incrementally after onboarding. Importantly, activation consent is not operational consent. Activation establishes the commercial and identity relationship. Operational permissions come later, when customers understand what your solution will actually do. OAuth consent patterns for multi‑tenant AI apps OAuth consent is not an implementation detail in Marketplace. It directly determines whether your AI app can be certified, deployed smoothly, and governed by enterprise customers. Common consent patterns map closely to AI behavior: User consent Supports read‑only or user‑initiated interactions with no autonomous actions. Admin consent Enables agents, background jobs, cross‑user access, and cross‑resource operations. Pre‑authorized consent Enables predictable, enterprise‑grade onboarding with known and approved scopes. While some AI experiences begin with user‑driven interactions, most AI solutions in Marketplace ultimately require admin consent. They operate asynchronously, act across resources, or persist beyond a single user session. Aligning expectations early avoids friction during review and deployment. Designing consent flows customers trust Consent dialogs are part of your product experience. They are not just Microsoft‑provided UI. Marketplace reviewers evaluate whether requested permissions are proportional to declared functionality. Over‑scoped consent remains one of the most common causes of delayed or failed certification. Strong consent design: Requests only what is necessary for declared behavior Explains why permissions are needed in plain language Aligns timing with customer understanding Poor explanations increase admin rejection rates, even when permissions are technically valid. Clear consent copy builds trust and accelerates approvals. Tenant linking across offer types Identity design must align with offer type; a helpful framing is ownership: SaaS offers The publisher owns identity orchestration and tenant linking. Microsoft Marketplace reviewers expect this alignment, and mismatches surface quickly during certification. Containers and virtual machines The customer owns runtime identity; the publisher integrates with it. Managed applications Responsibility is shared, but the publisher defines the trust boundary. Each model carries different expectations for control, consent, and revocation. Designing tenant linking that matches the offer type reduces customer confusion. When consent actually happens in Marketplace lifecycle Many identity issues stem from unclear timing. A simple lifecycle helps anchor expectations: Buy – The customer purchases the offer Activate – Tenant trust is established Consent – Limited activation consent is granted Provision – Resources and configurations are created Operate – Incremental operational consent may be requested Revoke – Access and trust can be cleanly removed Making this sequence explicit in your design—and in your documentation—dramatically reduces confusion for customers and reviewers alike. How tenant linking shapes Marketplace readiness Identity tends to leave a lasting impression as it is one of the first architectural design choices encountered by customers. Strong tenant linking and consent design leads to: Faster certification (applies to SaaS offer only) Fewer conditional approvals Lower onboarding drop‑off Easier enterprise security reviews These outcomes are not accidental. They reflect intentional design choices made early. What’s next in the journey Tenant identity sets the foundation, but it is only one part of Marketplace readiness. In upcoming guidance, we’ll connect identity decisions to commerce, SaaS Fulfillment APIs, and operational lifecycle management—so buy, activate, provision, operate, and revoke work together as a single, coherent system. Key Resources See curated, step-by-step guidance to help you build, publish, or sell your app or agent (no matter where you start) in App Advisor Quick-Start Development Toolkit can connect you with code templates for AI solution patterns Microsoft AI Envisioning Day Events How to build and publish AI apps and agents for Microsoft Marketplace Get over $126K USD in benefits and technical consultations to help you replicate and publish your app with ISV Success254Views2likes0CommentsUnlocking the power of Partner Center reporting: Why these insights matter for Marketplace success
For publishers in the Microsoft commercial marketplace, having the right data at the right time is essential. Understanding how customers engage with your offers, how revenue flows through billing and payout cycles, and how subscriptions or usage evolve over time directly influences your go‑to‑market decisions, financial planning, and customer management strategies. During a recent Microsoft webinar focused on Partner Center reporting, David Najour from the Marketplace Fast Track team walked partners through how these reporting tools work—and more importantly, why they are a critical part of operating effectively in the marketplace. This article distills the heart of that session, shifting away from step‑by‑step walkthroughs and instead exploring the purpose of each reporting workspace, how they support publisher operations, and the real value they bring to your marketplace business. To get the full depth and demos, we still recommend watching the complete session—but this overview will help you understand the strategic value these reports offer. Why Microsoft built reporting Workspaces into Partner Center Partner Center is the operational hub for managing your relationship with Microsoft—from listing offers to managing customers to getting paid. Because marketplace transactions involve multiple processes (ordering, invoicing, usage, payouts), Microsoft organizes reporting into two dedicated workspaces: Insights and Earnings. Each workspace answers a different business question and serves a different operational audience. The Insights workspace is your business intelligence engine—designed to provide a multidimensional view of how your marketplace business sales are performing. Meanwhile, the Earnings workspace is your financial source of truth, detailing what Microsoft owes you, what has already been paid, and what adjustments or deductions apply. Together, they create a full picture of both commercial health and financial outcomes. The Insights workspace: Your commercial visibility engine The Insights workspace houses the dashboards publishers rely on to understand how offers are performing across customers, geographies, channels, and billing models. It is the foundation for growth analysis, forecasting, customer intelligence, and product decision‑making. Far more than a collection of numbers, it is a structured lens into how your marketplace business behaves over time. Revenue reporting: The unified story of Marketplace performance The Revenue dashboard is often regarded as the centerpiece of Insights, because it gathers data from orders, usage, customer activity, invoicing, and payout progression into a single view. For publishers, this unified model provides the clearest indication of which offers are gaining traction, who your most valuable customers are, and how different sales channels or billing models shape revenue flow. It also reflects the nuances of marketplace billing—for example, the distinction between Enterprise Agreement (EA) and Microsoft Customer Agreement (MCA/MCA-E) customers. EA transactions become eligible for payout once billed, whereas MCA-E transactions only qualify after the customer pays their Microsoft invoice. This difference directly influences Publisher’s payout timing and makes the Revenue dashboard an indispensable tool for evaluating earnings. More information about the Insights revenue dashboard can be found here: Revenue dashboard in Microsoft Marketplace analytics - Partner Center | Microsoft Learn Order intelligence: Understanding your subscription footprint SaaS publishers depend on subscription lifecycle clarity. The Orders dashboard provides visibility when subscriptions start and end, whether they are set to auto‑renew, and how quantities or reservations evolve. Because the auto‑renew indicator is only visible here across Partner Center reporting, this dashboard becomes essential for managing renewals, reducing churn, and supporting customer success motions. More information about the Insights orders dashboard can be found here: Partner Center Orders dashboard in Microsoft Marketplace analytics - Partner Center | Microsoft Learn For teams focused on retention, forecasting, and renewal management, the Orders dashboard is one of the most operationally valuable tools available. Usage Insights: Making sense of consumption‑based models For metered or usage‑based offers, understanding consumption trends is foundational. The Usage dashboard enables publishers to see real metered activity and interpret how consumption translates into billed revenue. This helps teams identify adoption patterns, detect anomalies, and support customers before usage drops—or before a period of increased consumption turns into a surprise invoice. More information about the Usage Insights dashboard can be found here: Usage dashboard in Microsoft Marketplace analytics - Partner Center | Microsoft Learn Customer intelligence: Connecting the dots The Customer dashboard links transaction activity to the organizations purchasing your solutions. Because customer identifiers remain consistent even when names change, this dashboard becomes vital for mapping revenue to specific organizations, and their customer details More information about the Customer dashboard can be found here: Customers dashboard at Microsoft Marketplace analytics on Partner Center - Partner Center | Microsoft Learn The Earnings workspace: Your source of financial truth While Insights helps publishers understand the “why” behind commercial performance, the Earnings workspace answers a different but equally critical question: What has Microsoft actually paid us, and what is eligible for payout? This workspace is relied on heavily by finance and accounting teams because it contains the authoritative record of payments Microsoft has sent or will send, complete with: Payment IDs that match bank remittance statements, Payout dates and statuses, Withholding tax details (when applicable), and Store service fee taxes or adjustments. Earnings also reflect Microsoft’s payout policy: it includes EA transactions and only MCA-E transactions that customers have fully paid. Unpaid MCA-E transactions remain outside the Earnings view until it becomes eligible. This helps prevent reconciliation errors and clarifies why revenue totals in Insights may exceed what’s visible in the Earnings dashboard at any given point. For any publisher reconciling revenue to payouts—or managing financial reporting cycles—this workspace is indispensable. More information about the Earnings dashboard can be found here: Earnings in Partner Center - Partner Center | Microsoft Learn Why these reports matter for Marketplace publishers Marketplace success depends on understanding both the commercial and financial sides of your business. Microsoft designed these reporting capabilities to help publishers: Make data‑driven product and sales decisions With clear revenue, usage, and customer insights, teams can pivot offers, target high‑value accounts, and optimize go‑to‑market activities based on real patterns—not assumptions. Support customers through their lifecycle Subscription and usage analytics make it easier to identify renewal opportunities, anticipate support needs, and maintain strong customer relationships. Strengthen financial control Earnings reporting provides the clarity needed to reconcile payouts, communicate with internal finance teams, and verify tax or fee deductions with confidence. Align internal teams around a single source of truth Whether you’re in sales, marketing, engineering, finance, or operations, these dashboards provide shared visibility into the same metrics and definitions, reducing confusion and improving cross‑team decision‑making. The bottom line: Better reporting leads to better Marketplace outcomes Partner Center reporting is more than a backend tool—it’s the intelligence layer that helps publishers understand performance, forecast revenue, support customers, and confidently manage financial operations. The marketplace introduces unique billing and payout considerations, and these reports translate that complexity into actionable insight. If you want to see how these dashboards work in practice, with live examples and Q&A discussion, be sure to watch the full webinar session available on Microsoft Marketplace Community site. The live demonstrations provide additional context and are especially useful for teams new to marketplace reporting or looking to optimize their internal processes. Watch the recording here: Office hours for partners: Microsoft Partner Center reporting - Microsoft Marketplace Community270Views2likes0CommentsWelcome to the FY26 Q1 Partner Digest!
Stay up to date on the latest Microsoft Marketplace news, tools, and resources to help you grow your business. Subscribe to the Partner Digest label to never miss an update. 🚀 Noteworthy Highlights Introducing Microsoft Marketplace: Growth starts here. Turn your agents and other cloud-based innovations into sales, at scale, with Microsoft Marketplace. Learn more Updated Agreement: The Microsoft AI Cloud Partner Program Agreement has been updated, effective September 22, 2025. Review now Partner Center Security: Multifactor authentication (MFA) is now required for Partner Center access. API enforcement beings April 2026. Learn more App Advisor Enhancements: Six new features help software developers build, publish, and sell apps faster and smarter on the Microsoft Marketplace. Explore now Fabric Extensibility Toolkit: Software companies can help customers bring apps to Fabric, speed development, and integrate workloads. Get started today Azure AI Foundry Updates: Now featuring GPT-5, OpenAI gpt-oss, Foundry Local support, and a new Browser Automation tool to help you build intelligent agents using natural language. Learn more Partner Center AI assistant: Now localized and smarter than ever with support for additional languages, providing quick answers to your day-to-day questions. Learn more Microsoft AI Cloud Partner Program Concierge: Your go-to resource for all program related desk engagements, streamlined and more impactful than ever. Learn more 🌟 Microsoft partner resources: New for FY26 MCAPS Start recap Microsoft kicked off FY26 with a bold vision for partner growth in the AI era. Nicole Dezen outlines how partners can lead with innovation and scale impact. Explore strategic solution areas, expanded MAICPP investments, and GTM support.👉 Read the full post New benefits & resources New AI-powered benefits and tools are here to help partners thrive. Julie Sanford details how to get Azure credits, Copilot seats, and custom GTM materials to accelerate agentic AI adoption.👉 Read the full post Blog Series & Playbooks: Catch up on our Cloud and AI Platforms blog series. Part one: Capturing the market opportunity Part two: Migrations & Modernizations Explore the latest Cloud and AI platforms and Agentic AI partner playbooks which includes key skilling resources, investments, win formulas and more. Unlock your Microsoft AI Cloud potential with Partner Skilling Hub: Visit our skilling hub for the latest training resources to earn designations and specializations. Explore the most recent skilling blog for key skilling-related announcements. Incentives ISV Success Advanced Package: Top-performing partners with Certified Software Designations can qualify for financial incentives to build AI solutions or migrate customers to Azure. The package supports every stage of ISV Success. Learn more. Migration Incentives: New end-customer migration incentives are now available to help software companies and advanced specialized system integrators securely and efficiently move software companies’ end customers to modern applications running on Azure. See Azure Incentives > ISV Engagements tab in the incentive guide for details. 🗓️ Events & Office Hours June-September recaps June: The Microsoft Marketplace Ecosystem Opportunity Explore how AI is reshaping solution development and customer engagement in this conversation with Cyril Belikoff, Microsoft’s new leader for Marketplace. Learn how the marketplace is simplifying procurement and accelerating growth. A “lightbulb moment” for the industry and the critical role partners play in delivering innovation on Microsoft’s platform. 👉 Watch the recording July: Marketplace Rewards FY26 Learn how channel partners can benefit from multiparty private offers and new rewards tier thresholds to unlock $200K in sponsorship. 👉 Watch the recording August: Co-Sell Blueprint & Certified Designations Gain real-world co-sell strategies and learn about Microsoft’s Customer Engagement Methodology from industry experts. Plus, get the latest on Certified Software Designation benefits for FY26. 👉 Watch the recording from Ultimate Partner session on Co-sell 👉 Watch the recording on Certified Software Designations and download the slide deck 📖Explore Microsoft Customer Engagement Methodology (MCEM) September: Migrate and Modernize Summit Our Sep 23-24 event is now available online to help services partners learn how agentic AI can boost their agility by moving to the cloud quickly and effectively. Catch the replay. Upcoming Events Microsoft AI Tour for Partners is back- Join a free, one-day event to accelerate your AI journey with sales best practices, growth opportunities, hands-on labs, and technical deep dives. Discover upcoming events in cities around the globe. Join the Fabric Global Hack (Sept 15–Nov 3, 2025) to build data and AI solutions with Microsoft Fabric, collaborate globally, and compete for prizes up to $10,000. Participants get 50% off Fabric certifications. Join us at the Azure Dev Summit from October 13-15, a Microsoft-sponsored event designed for developers, architects, and technology leaders. Explore the latest in Azure, .NET, and Microsoft AI, gain insights from inspiring speakers, and connect with peers driving innovation. Participate in AgentCon 2025 by Global AI Community—a global series of one-day conferences designed exclusively for developers building the future with autonomous AI agents. 🔥 Microsoft Ignite 2025 Microsoft Ignite 2025 will empower you to get the edge you need to drive impact in the era of AI. Join us in San Francisco or attend virtually from November 18-21 to bolster your knowledge, build connections, and explore emerging technologies. Hear from Microsoft executives and other leaders on their vision for AI. Explore the latest in Cloud and AI platforms, AI business solutions, and Security. Celebrate the winners and finalists of Partner of the Year Awards 👉 Register now and stay up to date with event news at Microsoft Ignite Unplugged. __________________________________________________________________________________________________________________________________________________________________ Stay tuned to the https://techcommunity.microsoft.com/t5/marketplace-blog/bg-p/MarketplaceBlog for upcoming recaps and new office hour announcements. 💬 Share Your Feedback! We truly appreciate your feedback and want to ensure these Partner Digests deliver the information you need to succeed in the marketplace. If you have any feedback or suggestions on how we can continue to improve the content to best support you, we’d love to hear from you in the comments below!208Views2likes0Comments