Microsoft just promoted agents from product to platform
If you're joining from Copilot Studio Blueprints, same newsletter, new format. Each week I filter the Microsoft AI ecosystem down to what shipped, what it means, and where to point your attention next. No hype, no release-note recaps. A nine-section map of the stack so you can scan the parts you care about.
This week's thread: agents are no longer the feature, they are the platform
For 18 months Microsoft shipped agent capabilities as additions to existing products: Copilot got a topic, Power Automate got a flow type, Defender got a hunting table. This week the model flipped. Cowork is now a Copilot product whose entire value proposition is 'agents that follow your team's playbook and execute on mobile.' Excel 'Edit with Copilot' is agent surface area pretending to be a ribbon button. Defender treats AI agents as first-class assets next to users and devices. Even the security incidents are about agents now (CVE-2026-35435 below). When the bug reports start being about your new abstraction, you've crossed a threshold.
Signal of the week
Copilot Cowork goes mobile, ships Skills, lights up first-party plugins
Charles Lamanna announced on May 5 that Copilot Cowork (Microsoft's Anthropic-Claude-powered productivity Copilot) is now in the Microsoft 365 Copilot mobile app for iOS and Android, has a new Skills primitive (reusable instruction sets that teach Cowork how to do recurring tasks), and ships first-wave plugins for Power BI, Loop, Viva, monday.com, HubSpot, Notion, LSEG, Miro, S&P Global, and Dynamics 365 (Sales, Customer Service, ERP). Frontier preview today. GA scheduled for July 2026.
Why it matters
This is the most consequential Microsoft 365 release of the year. It is the first time Microsoft is shipping a Copilot product that competes head-on with how knowledge workers actually use AI assistants today: sustained sessions, mobile-first, repeat-task patterns. Skills are the interesting primitive - not a Copilot Studio agent, not a declarative agent, not a Power Automate flow. They are a fourth thing. If your customers are using Cowork in Frontier, the playbook to write between now and July is 'which of our existing Copilot Studio agents should be Cowork Skills instead, and which Skills should escalate into agents.'
1Microsoft 365 Copilot
GPT-5.5 and Claude Opus 4.7 land in Excel "Edit with Copilot"
The May 5 M365 Copilot release notes added GPT-5.5 and Claude Opus 4.7 to Excel's 'Edit with Copilot' experience, alongside a new Chat/Edit switcher, a 'plan mode' for step-by-step reasoning before execution, change-tracking visibility, and the ability to invoke Python directly from Copilot.
Why it matters
Two notable shifts. First, Microsoft is now shipping multiple frontier models in the same end-user surface, letting Excel route by task. Second, 'plan mode' is the first time a Microsoft Copilot end-user surface exposes the agentic reasoning step explicitly to the user before execution. Expect the same pattern in Word, PowerPoint, and Outlook within the quarter. Hard question for makers: when an Excel power user has Claude Opus 4.7 one click away inside the ribbon, what does your Copilot Studio agent add over native Edit with Copilot?
- QuickVS Code 1.118 ships bigger Copilot agent workflows: remote control for CLI sessions, semantic codebase search, lower token usage, stronger enterprise controls.
- QuickAgent Builder (the no-code path inside M365 Copilot) got a creation-experience refresh rolling out late April / early May - clearer flow, faster setup. Worth a screenshot-update if you train customers on it.
2Copilot Studio
Multi-agent orchestration goes GA across Fabric, M365 Agents SDK, and A2A
Microsoft moved a stack of multi-agent capabilities to general availability: Copilot Studio agents can now coordinate with Microsoft Fabric data agents to reason over enterprise analytics at scale, plug into Microsoft 365 Agents SDK orchestration patterns, and communicate cross-vendor through the open Agent-to-Agent (A2A) protocol.
Why it matters
This is the moment 'multi-agent' stops being a demo. You can build a primary Copilot Studio agent that delegates analytics queries to a Fabric agent, hands off long-running execution to an M365 Agents SDK orchestrator, and exchanges messages with a non-Microsoft agent over A2A - all in production, all governed through the same Power Platform admin tooling. The architecture conversations get more interesting from here.
Authoring runtime moves to .NET 10 WebAssembly in production
The Copilot Studio team upgraded their .NET WASM engine from .NET 8 to .NET 10 and the .NET 10 build is already running in production. Highlights: automatic fingerprinting of WASM assets for cache busting, and WasmStripILAfterAOT enabled by default for AOT builds, shrinking the download payload.
Why it matters
Makers feel this every day. Web authoring boots faster, hot-reloads cleaner, ships less JavaScript-bridge cost per session. The kind of release that doesn't make a Build keynote but quietly raises the floor on developer velocity for everyone shipping Copilot Studio agents in 2026.
Real-time voice agents go GA for Dynamics 365 Contact Center (North America)
Microsoft's Copilot Studio blog confirmed real-time voice agents are now generally available in Copilot Studio, with the first production rollout in North America for Dynamics 365 Contact Center. Customers speak to the agent and receive a spoken response instantly, no segmented pipeline. Supported voices: Alloy, Echo, Shimmer, Ash. Microsoft says language support, additional regions, and Microsoft Teams Phone + other Copilot Studio channels are next on the roadmap.
Why it matters
The realtime model investments in Foundry now have a production landing zone in Copilot Studio. If your customers are on D365 Contact Center in North America, voice agents stop being a 'neat demo' and become a genuine deflection lever. For European customers, plan around the regional rollout - the feature is built and the docs are live, but production deployments wait for EMEA expansion. Pair with the new GPT-realtime-translate model when it lands locally and you have multilingual voice support without a multi-vendor stack.
- QuickNew read-only Analytics Viewer role and custom analytics metrics now available - addresses one of the longer-standing maker complaints about Copilot Studio access scoping.
3Agent 365
What is Agent 365?
Microsoft's control plane for AI agents. Launched May 1, 2026. One pane of glass to inventory, govern, observe, and secure every AI agent in your tenant - whether built in Copilot Studio, Foundry, the M365 Agents Toolkit, the Agent Framework, or by ecosystem partners (Adobe, SAP, Zendesk, Manus). Sold standalone at $15/user/month or bundled in the new Microsoft 365 E7 Frontier Suite at $99/user/month. Integrates with Microsoft Entra (identity), Microsoft Purview (compliance), and Microsoft Defender (security signals). If you have agents running in production, this is the layer that answers 'where are they, what are they doing, and who said they could do that?'
May update: registry expansions, risk flags, conditional access for agents
The May 4 Agent 365 update populated the registry with metadata-rich entries for every agent in tenant: name, description, publisher, platform, ownership, deployment status, Microsoft Graph permissions, data and tools access, security and compliance details, certifications, usage activity. Risk flags surface in the registry directly, powered by first-party signals from Defender, Entra, and Purview. Conditional access for agents is now configurable in the Microsoft Entra admin center.
Why it matters
Until last week the GA story was a slide. This week it is a working admin UI with real telemetry and real policy hooks. If you are scoping a customer engagement around agent governance, the registry view is the screenshot you put in the deck.
Tuesday May 12 - live AMA with the product team
The Agent 365 product and engineering team hosts a live 'Ask Microsoft Anything' on Microsoft Community Hub on Tuesday May 12 at 9am Pacific. Topics: licensing, governance, deployment, what to expect in next-quarter updates.
Why it matters
Most enterprises still haven't decided who owns Agent 365 - identity team, security team, M365 admins, or a brand-new role. The AMA is the fastest way to get product-team answers to deployment questions that don't have docs yet. Block the hour if you're scoping a rollout this quarter.
- QuickMicrosoft published the Agent 365 Getting Started Guide and a dedicated Adoption Resources page this week.
- QuickLicensing nuance: M365 E7 covers internal agents, but customer-facing or external agents still require a standalone Copilot Studio subscription with credit-based consumption billing. Same for autonomous agents acting outside the user OBO context. Flag this before scoping any E7 conversation.
4Microsoft Foundry
GPT-chat-latest (GPT-5.5 Instant) ships - 52.5% fewer hallucinations
OpenAI's GPT-5.5 Instant rolled out in Microsoft Foundry this week as GPT-chat-latest. According to OpenAI it produces 52.5% fewer hallucinations than GPT-5.3-chat and reduces hallucinated claims by 37.3% on conversations previously flagged for factual errors. Tool calling and structured outputs are tighter - relevant for function calling, RAG, and multi-step reasoning workflows.
Why it matters
Every Copilot Studio agent eventually grounds a response or calls a tool. A model that hallucinates 50% less and produces more reliable function calls is the difference between an agent that ships to production and one that gets stuck in test chat. Run your evaluation suite against the new endpoint this week and audit your custom guardrails - half of them may now be fighting a problem the model already solved.
Realtime stack expands: GPT-realtime-translate, GPT-realtime-2, GPT-realtime-whisper
Foundry added three OpenAI realtime models this week. GPT-realtime-translate produces live translated speech as conversations unfold without segmented pipeline processing. GPT-realtime-whisper provides low-latency streaming transcription in parallel. GPT-realtime-2 is the next-gen base realtime model.
Why it matters
Voice agents are about to get noticeably better. Live multilingual customer support without the awkward pause-translate-resume pattern is suddenly feasible from a single API surface. If you have voice-enabled agents in Copilot Studio (or are planning them), this is the model lineup to test against this week.
- QuickMAI-Image-2-Efficient launched in Foundry: 22% faster generation and 41% cost reduction over the previous flagship in-house image model.
5Microsoft Agent Framework + Dev SDKs
Foundry Hosted Agents v2 becomes the production deployment path
The Microsoft Agent Framework devblog walked through the new path from local MAF prototype to production deployment via Foundry Hosted Agents v2. Built-in identity, automatic scaling, managed session state (sessions persist up to 30 days), observability, and versioning. Idle compute deprovisions after 15 minutes and seamlessly restores on the next request.
Why it matters
Until now, 'production deployment for an MAF agent' meant rolling your own container, identity layer, scaling logic, and session persistence - the part most teams got wrong on the first try. Hosted Agents v2 absorbs the boring infra into Microsoft's surface. If you have an MAF prototype sitting in a notebook, this is the week to push it past the demo.
Microsoft 365 Copilot Agent Evaluations CLI lands in public preview
The M365 Developer Blog announced a public preview of the Microsoft 365 Copilot Agent Evaluations CLI. The tool sends prompts to a deployed agent, captures responses, and scores them with Azure OpenAI LLM-judge evaluators. It plugs into the Microsoft 365 Agents Toolkit and ships with a Claude Code skill (microsoft-365-agents-toolkit@workiq) for creating and evaluating agents directly inside Claude Code.
Why it matters
Until now, M365 Copilot agent quality assessment has been 'build, deploy, hope, iterate when users complain.' A first-party CLI with deterministic test sets and LLM-judge scoring moves agent QA from vibes to discipline. The Claude Code skill is the most explicit signal yet that Microsoft expects developers to be using Claude Code for Microsoft agent work. Wire it into your CI before the customer asks for an agent quality SLA.
- QuickMAF GitHub activity this week: Foundry per-call x-client header support added; FIDES information-flow control prompt-injection defense work continues in Python.
6Power Automate + Power Platform
Reference previous prompts in Copilot for Power Automate Desktop
Copilot in Power Automate for desktop now supports contextual memory: build flows by referencing previously provided prompts in the same session. Part of the 2026 wave 1 lineup currently rolling out.
Why it matters
The single biggest Copilot-in-PAD complaint has been 'every prompt is a fresh start, even within the same flow build.' Contextual memory closes that loop. Combined with self-healing flows shipping in the same wave and the new MCP server for Process Intelligence, the Power Automate desktop story is meaningfully tighter than it was 90 days ago.
- QuickOther 2026 wave 1 PAD items rolling now: scheduled desktop flows directly from the portal, and version control for desktop flows. Both have been on the wishlist since 2023.
7Security & Governance
Three critical agent-framework CVEs in one week (Foundry EoP + Semantic Kernel RCE pair)
Microsoft disclosed three critical agent-framework vulnerabilities this week. CVE-2026-35435 (May 7) is an Azure AI Foundry elevation-of-privilege flaw affecting agents published from Foundry into Microsoft 365 - no patch as of disclosure, MSRC updating mitigation guidance. The same day, the Microsoft Security blog published research on CVE-2026-26030 (In-Memory Vector Store) and CVE-2026-25592 (arbitrary file write through SessionsPythonPlugin) in Semantic Kernel - both allow remote code execution by turning crafted prompts into shell commands.
Why it matters
Three critical agent-stack RCEs in a single week is not a coincidence. The Foundry CVE attacks the publish path; the Semantic Kernel CVEs attack the runtime. Together they say the security perimeter for agents is wherever you let untrusted text reach a tool call. Audit any Semantic Kernel agent in production this week (the Microsoft post includes Defender XDR detection queries). For Foundry-published M365 agents, restrict publishing scope to least privilege until the patch lands. The Microsoft security team is now publishing offensive research against their own frameworks - healthy, and a signal that the next 12 months of agent governance is going to be a sustained patch-and-mitigate cadence.
Defender XDR May update: AI agents become first-class assets
The Defender XDR May 2026 update promotes Sentinel to a top-level sidebar section, embeds Defender for Cloud, and (most significantly) adds AI agent inventory under Assets. Advanced hunting includes new identity-focused predefined scenarios; the AIAgentsInfo table picked up additional columns last month for deeper agent visibility.
Why it matters
AI agents stop being 'this special category we govern through Agent 365' and start being an asset class your SOC inventories alongside users and devices. Conversations with security teams shift from 'what is an agent' to 'show me your agent inventory and your hunting queries.' Vendor agents your business deploys are now inside Microsoft's security graph whether you knew it or not.
Microsoft Entra May 2026: Conditional Access for agents live, OBO flow GA
The 'What's New in Microsoft Entra: May 2026' post confirmed Conditional Access for agents is live, extending Zero Trust principles to agent identities. The on-behalf-of (OBO) flow for agents is now generally available. CA for OBO agents is evaluated against the user's identity token; M365 E3 (or equivalent) is required at the user level for the policy to apply.
Why it matters
This is the licensing detail that tripped up most early Agent 365 procurement conversations. CA for agents only works if your users have the right user-side license; Agent 365 itself does not grant E5-level Defender or Purview capabilities. Read the licensing fine print before you scope.
- QuickMicrosoft Purview Insider Risk is rolling out a feature in May-June that lets authorized reviewers view risky AI prompts and responses in plaintext. Worth flagging in any DLP review meeting this quarter.
8GitHub Copilot + VS Code
GitHub Copilot ships Autopilot mode
GitHub Copilot's new Autopilot mode enables fully autonomous agent sessions inside VS Code. Agents take a multi-step task and execute end-to-end, with the developer reviewing the diff rather than approving each step.
Why it matters
This completes the 'Copilot ladder' inside VS Code: from inline completions, through chat, through agent mode (single-step approvals), to Autopilot (autonomous). Each rung trades developer time for trust in the model. Autopilot only earns its keep if you have evals + guardrails wired up - see the M365 Copilot Agent Evaluations CLI two sections above for the matching toolchain.
VS Code adopts Claude Code's plugin format and ecosystem
VS Code is extending Claude support beyond the model picker - it now supports Claude Code's files, folders, and agent workflows: memory files, rules, agents, skills, hooks, and plugin formats. In addition to GitHub Copilot and OpenAI Codex agents.
Why it matters
Microsoft's 'AI relationship' with OpenAI is quietly becoming an 'AI portfolio.' If your team has been investing in Claude Code workflows, those investments now travel into VS Code without rework. If you've been all-in on GitHub Copilot, the next 18-month decision becomes 'do we let our developers use the agent ecosystem they prefer, or pick a winner?'
- QuickGitHub Copilot moves to usage-based billing on June 1, 2026, with updated model multipliers for PRUs.
9Others
Microsoft 2026 Work Trend Index: 58% producing work they couldn't do a year ago
Microsoft published the 2026 Work Trend Index on May 5. Headline numbers: 66% of AI users say AI lets them spend more time on high-value work; 58% report producing work they could not have completed a year ago, rising to 80% among 'Frontier Professionals.' 13% of AI users say they're rewarded for experimenting with AI in their jobs. The 'Transformation Paradox' attributes ~67% of AI impact to organizational factors versus ~32% to individual mindset.
Why it matters
The data is useful for client-facing decks but the methodology has limits - the 67/32 split comes from a single self-rated survey where the same respondent scored their own AI use, their org's culture, and the value they got. Cite the headlines, take the precise percentages with a pinch of salt.
Microsoft AI Steering Committee 2026 Checklist: Sovereignty
Jessica Hawk (CVP, Data, AI, Digital Applications Product Marketing) published the third installment in Microsoft's 'AI Steering Committee 2026 Checklist' series on May 7, this one focused on data sovereignty. Frames the EU AI Act August 2026 enforcement deadline as the next forcing function for AI governance maturity.
Why it matters
If you're advising a European customer on AI strategy, this checklist is paste-ready content for the executive-summary slide. Microsoft is publicly anchoring its sovereignty story around a Microsoft Sovereign Cloud + Agent 365 + Purview pattern. Use it, but cite it: clients respond well to 'Microsoft's own steering committee guidance says...' framing. The August 2026 EU AI Act deadline is now ~3 months out and most clients still haven't done their classification audit.
- QuickCGI earned Microsoft's Copilot Modern Work specialization on May 4, the latest signal that Microsoft's enterprise AI strategy is 'deputize the large services firms' rather than direct sales. Expect more in the lead-up to Build 2026.
Voices to follow
- Microsoft EVP - Copilot, Agents & PlatformCharles Lamanna
Executive Vice President for Copilot, Agents, and Platform at Microsoft. He owns the strategy behind Copilot Studio, Agent 365, and the Power Platform, so when the agent stack's direction shifts, it usually shifts because of a decision his org made.
Microsoft EVP - Copilot, Agents & Platform - Microsoft Principal Cloud Advocate - Power Platform + agentsDaniel Laskewitz
Principal Cloud Advocate at Microsoft, ex-Power Platform MVP and co-founder of Forward Forever. One of the clearest voices on multi-agent systems and Power Platform governance - the bridge between the maker community and the product teams.
Microsoft Principal Cloud Advocate - Power Platform governance + agents - Microsoft Principal Cloud Advocate - Power Platform Advocacy LeadApril Dunnam
Principal Cloud Advocate and Team Lead for the Power Platform Advocacy team at Microsoft, and the face of Agent Academy. If a Copilot Studio feature or governance update ships, April has usually broken it down within 48 hours.
Microsoft Principal Cloud Advocate - Power Platform + AI Demystifier - Microsoft Software Engineer - CoworkBas Brekelmans
Software Engineer at Microsoft, started the Copilot Cowork project and previously CTO of Copilot Studio. The clearest voice on why Microsoft chose multi-model, MCP, and A2A architecture across the agent stack.
Microsoft Software Engineer, Cowork - ex-CTO Copilot Studio - Microsoft Principal PM - Copilot Studio (Power CAT)Henry Jammes
Principal Program Manager for Copilot Studio on the Power CAT team at Microsoft. Deep on agent-building mechanics, governance, and the release roadmap - a first-party source on what Copilot Studio can actually do.
Microsoft Principal PM - Copilot Studio (Power CAT) - Microsoft Principal Cloud Developer Advocate - AISeth Juarez
Principal Cloud Developer Advocate at Microsoft on AI. One of the most watchable explainers of Foundry, the Agent Framework, and GitHub Copilot for developers - deep technical content that stays accessible.
Microsoft Principal Cloud Developer Advocate - AI - Microsoft Partner Director - Foundry Agent ServiceJeff Hollan
Partner Director of Product at Microsoft, leading the Foundry agent platform: Agent Service, the Agent Framework, and the SDKs. The clearest source on how agents actually go from prototype to a hosted production runtime.
Microsoft Partner Director - Foundry Agent Service + Agent Framework - Microsoft CVP - Security, Compliance, Identity & PrivacyVasu Jakkal
Corporate Vice President for Microsoft Security. Defender's AI agent posture risk, the Agent 365 security integration and the wider security-for-AI story all ship out of her organisation.
Microsoft CVP - Security, Compliance, Identity & Privacy
Coming up
- Tuesday May 12, 9am PT · Live AMA with the Agent 365 product team on Microsoft Community Hub.
- Wednesday May 13, 8am PT · Mike Tholfsen hands-on webinar: Study & Learn agent in M365 Copilot, going globally available alongside the session.
- June 1, 2026 · GitHub Copilot moves to usage-based billing, with updated model multipliers.
- June 2-3, 2026 · Microsoft Build, San Francisco + online. 90+ hands-on sessions; agent stack and Copilot Studio tracks confirmed.
- July 2026 · Copilot Cowork general availability.
- August 2026 · EU AI Act enforcement begins for high-risk AI systems. European customers should have their classification audit done before this date.
This week's question
If Cowork ships with Anthropic Claude under the hood, Excel offers Claude Opus 4.7 next to GPT-5.5, Foundry hosts both, VS Code embraces Claude Code's plugin format, and Microsoft's own developer blog tells you to use a Claude Code skill to evaluate Microsoft 365 agents - has Microsoft's 'AI relationship' with OpenAI quietly become an 'AI portfolio?' And what does that mean for the architecture decisions you're making for 18-month engagements that assume one model provider?
Get Agentic Weekly in your inbox
Every Monday morning. Unsubscribe any time.
