Elliot Margot Logo
  • Home
  • About
    Portrait of a Microsoft AI Specialist at work.
    Overview
    Abstract image of a strategic AI framework.
    Methodology
    Professional experience timeline visual.
    Experience
    Academic background and education visual.
    Education
    Certifications and diplomas visual.
    Certificates
    Letters of recommendation and testimonials visual.
    Testimonials
    Editorial photo of a resume on a warm wooden desk with fountain pen and coffee.
    Resume / CV
  • Work
    Projects portfolio hero visual.
    Projects
    Architectural tech stack hero visual.
    Tech Stack
    Open source coding and development visual.
    Open Source
    Blog header visual.
    Blog
  • Insights & Press
  • Community
    Copilot Studio Hub Discord community logo featuring Saphir the cat.
    Discord Community
    Agentic Weekly - the Microsoft AI weekly newsletter.
    Newsletter
    Microsoft AI Daily Brief - free daily digest of the Microsoft AI ecosystem.
    Microsoft AI Daily Brief
    Collaborative mentorship session visual.
    Free Mentorship
    Elliot at his workbench solving a steampunk problem - the clinic in spirit.
    Copilot Studio Clinic
    Conference stage spotlight with holographic AI agent diagrams floating above.
    Talks
My Cat SaphirContact
/
Elliot Margot Logo
/
My Cat Saphir

Navigation

  • Home
    • Overview
    • Methodology
    • Experience
    • Education
    • Certificates
    • Testimonials
    • Resume / CV
    • Projects
    • Tech Stack
    • Open Source
    • Blog
  • Insights & Press
    • Discord Community
    • Newsletter
    • Microsoft AI Daily Brief
    • Free Mentorship
    • Copilot Studio Clinic
    • Talks
Contact
  1. Community
  2. Agentic Weekly
  3. Edition 003
Agentic Weekly Edition 003 header
Edition 003

The week the capability and the controls shipped together

Week of May 18-24, 2026·6 signals·View on LinkedIn →

GPT-5.5 landed in Copilot Chat this week. So did the controls to govern it. The same May 19 Microsoft 365 Copilot wave that gave every user a sharper frontier model also gave admins per-group control over which model providers (Anthropic, xAI) their people can use, a natural-language SharePoint Admin Agent, and a stack of grounding and connector upgrades. Two days later Microsoft shipped one-call MCP governance for .NET, a published eval-gated CI/CD pattern for Foundry agents, and GA of Purview protections for Agent 365, while its enterprise CRO argued the barrier is no longer experimentation but execution. Capability and the brakes for it, shipped in the same breath.

This week's thread: Microsoft is shipping capability and the controls to govern it in the same release

Editions 001 and 002 tracked the build getting easier. This week the story matured: the new model and the governance for it arrived together. The May 19 Microsoft 365 Copilot wave put GPT-5.5 Instant and Thinking into Copilot Chat for everyone, and in the same release gave admins a switch to enable or deny Anthropic and xAI models per user and group, shipped a SharePoint Admin Agent for natural-language tenant management, and tightened grounding, connectors, and adoption-readiness tooling. Two days later, MCP tool-call governance became a single builder call in .NET, Microsoft published an eval-gated CI/CD reference for Foundry agents, and Purview protections for Agent 365 reached general availability. Read alongside the enterprise CRO's argument that execution, not experimentation, is now the differentiator, the pattern is clear: Microsoft has stopped shipping capability ahead of the controls and started shipping them as a pair. That is good news for anyone who has to put this in front of regulated users. Across model governance, MCP tool-call policy, eval-gated promotion, and data governance, the control plane filled in the same week the capability did. Capability is no longer the hard part. Governing and shipping it is.

On this page

  1. Signal of the week
  2. 1Microsoft 365 Copilot
  3. 2Governance + delivery
  4. 3Strategy
  5. Voices to follow
  6. Coming up
  7. Question

Signal of the week

GPT-5.5 Instant and Thinking land in Microsoft 365 Copilot Chat

The May 19 Microsoft 365 Copilot release brought OpenAI's GPT-5.5 Instant and GPT-5.5 Thinking into Copilot Chat across Android, Windows, iOS, Mac, and Web. Instant is the fast path: more accurate, concise responses with better performance on image analysis and STEM-related tasks, tuned for everyday quick answers like summarising a long email thread or checking a formula. Thinking is the deliberate path: a model built for multistep reasoning and structured analysis, aimed at planning, troubleshooting, and evaluating multiple options - breaking a complex project into actionable steps, comparing strategies, or explaining a technical process end to end. Both surface inside the same Copilot Chat experience users already have, with no separate app or license change called out in the release notes. The same wave added implicit grounding from Outlook email threads and in-chat PDF viewing, so the model upgrade lands next to real context-handling improvements rather than on its own.

Why it matters

Copilot Chat is the widest-reach surface in the Microsoft AI stack, so a frontier-model bump here changes the floor for the largest share of your users at once, not just the agent builders. The split matters for how you coach adoption: point people at Instant for the fast summarise-and-draft loop and at Thinking for the planning and analysis work where a wrong-but-fast answer costs more than a slow one. If you run a Copilot Champions program, this is the week to refresh the 'which model when' guidance, because the default experience your users open tomorrow is materially stronger than the one they closed on Friday.

Source →

1Microsoft 365 Copilot

Admins can now enable Anthropic and xAI models per user and group

Shipping in the same May 19 wave (Roadmap ID 557371): new admin controls let organizations enable Anthropic as a model provider, and xAI as a model provider, for specific users and groups rather than all-or-nothing for the tenant. The settings live in the admin center; admins review the Anthropic and xAI provider settings, then assign model access to chosen users or groups. xAI models are currently available in Microsoft Copilot Studio for US customers via admin opt-in. This is the governance counterpart to the GPT-5.5 capability drop - the same release that widened model choice also gave administrators the granularity to scope it.

Why it matters

Multi-model is now a governance decision, not just an architecture one. The moment you have Anthropic, OpenAI, and xAI models available, your security and compliance stakeholders will ask who can use which, and per-group assignment is the answer that lets you say yes to a pilot team without opening every model to the whole tenant. For regulated customers this is the unlock that makes 'bring Claude into Copilot' a scoped, auditable rollout instead of a tenant-wide policy fight. Wire model-provider access into your existing group-based governance now, before the first business unit asks for a model you have not yet scoped.

Source →

SharePoint Admin Agent brings natural-language tenant management to M365 Copilot

Also in the May 19 wave: Copilot in the SharePoint admin center now surfaces insights, recommendations, and contextual guidance grounded in your organization's SharePoint and OneDrive data, driven by natural language. Admins can ask it to identify inactive sites or sites with no recent activity, request guidance on optimizing storage, surface sites whose permissions are causing large exposure of sensitive data, or simply locate an admin setting by describing it. It is the Microsoft 365 Copilot answer to the same agentic-administration pattern dv-admin brought to Dataverse in edition 002 - the admin console becomes a conversation.

Why it matters

Two consequences. First, oversharing detection by natural language is a direct line to the single biggest Copilot rollout risk: agents and Copilot surfacing sensitive content because SharePoint permissions were never cleaned up. Being able to ask 'which sites are exposing sensitive data' turns a quarterly audit into a daily question. Second, the agentic-admin pattern is now spreading across surfaces (Dataverse, now SharePoint) - if you run a CoE, expect 'admin training' to keep shifting toward 'agent and prompt onboarding' for your platform admins.

Source →
  • QuickImplicit grounding in Outlook Copilot Chat (May 19) lets users pull emails and highlighted text straight into a Copilot Chat prompt; PDFs now open inside Copilot Chat instead of a separate viewer. Small UX moves that cut the context-switching tax on the most-used surface.
  • QuickGraph API enhancements for custom connectors (May 19): developers can now set icons, visibility, connection metadata, property descriptions, and semantic labels, so Copilot interprets and presents connector data more accurately. Worth a pass over any custom connector you have already shipped.
  • QuickOneDrive (May 19): file preview now surfaces ready-to-use Copilot actions - suggested prompts like summarise or generate FAQs - next to the Copilot button, to reduce the blank-prompt problem and drive adoption.
  • QuickViva Glint (May 19): Copilot Highlights reached GA with multilingual AI-generated survey summaries in Team and Executive Summary reports; Copilot in Glint also moved to Microsoft 365 Copilot access controls so governance runs through one control plane.
  • QuickAdoption tooling (May 19): the Copilot Dashboard Readiness page now gives personalized Copilot configuration recommendations, and analysts can publish Viva Insights Power BI reports to anyone in the org - both aimed squarely at the execution-and-adoption gap this edition's thread is about.

2Governance + delivery

Microsoft ships one-call MCP governance for .NET

On May 21, @Jack Batzner announced Microsoft.AgentGovernance.Extensions.ModelContextProtocol, a Public Preview companion package for the official MCP C# SDK. It adds one-call governance to IMcpServerBuilder: policy enforcement, startup scanning, runtime tool-call governance, and response sanitization, wired into the builder pipeline you already use. It targets the questions every team building MCP servers eventually hits and usually answers with ad hoc filters: should every registered tool be callable by every agent, what happens when a tool description carries prompt-injection-style instructions, how do you fail closed when a tool definition changes in a risky way, and how do you stop unsafe tool output from flowing straight back into the model. Startup scanning runs before tools are exposed; runtime checks apply on each tool call. The stated goal is that the secure path is also the simple path.

Why it matters

MCP is the default integration surface across Copilot Studio, Foundry, and the wider stack, which makes MCP tool-call governance everyone's problem. Until this week the answer was custom filters every team rebuilt. Packaging prompt-injection defense, fail-closed tool-definition checks, and output sanitization into one extension method changes the economics: governance becomes the default the builder hands you, not the thing you bolt on after the security review. If you ship or consume MCP servers, this is the difference between a governed tool surface and an open one.

Source →

A reference CI/CD pattern for Foundry agents - release gates run on evals, not just tests

Microsoft published a reference architecture this week for shipping AI agents on Microsoft Foundry with the same CI/CD rigour teams apply to application code, using GitHub Actions and Azure DevOps pipelines and a public companion repository, foundry-agents-lifecycle. The critical shift it names: promotion happens at the agent-version level, and release gates are driven by evaluation outcomes, not just test results. The pattern is three staged Foundry projects. Dev: deploy the vNext version, run smoke tests and developer evals, gate on eval quality thresholds. Test/QA: scenario tests, human-in-the-loop validation, safety evaluation, gated on eval results plus human approval. Production: promote the version, enable the endpoint, run a post-deploy smoke test, gated on required reviewer approval. It covers both containerised hosted agents and declarative prompt-based agents.

Why it matters

This is the official delivery playbook for operationalizing agents at scale. Most teams bolt agents onto existing app CI/CD and discover a passing test suite says nothing about whether the agent still behaves, which is why eval-driven gates are the load-bearing idea. Promotion at the agent-version level, gated on evaluation outcomes rather than test results, is the pattern to copy before you invent your own - and it pairs directly with the model governance and MCP governance drops above to give you a control plane that spans build, ship, and run.

Source →
  • QuickMicrosoft Purview's what's-new lists general availability of data security and compliance protections for Microsoft Agent 365, plus GA of the new Data Security Posture Management (DSPM). The data-governance half of the same govern-as-you-ship story - if you are deploying agents into a regulated tenant, this is the Purview side of the control plane.
  • QuickDocs radar: Microsoft refreshed the Power Platform 'important changes coming' page on May 22 with an updated Visio-in-Power-Automate deprecation date, plus disaster-recovery and customer-managed-key migration guidance. If you track deprecations across client estates, re-check the page.

3Strategy

Microsoft's enterprise CRO: execution is the new differentiator, not experimentation

On May 21, @Deb Cupp, EVP and Chief Revenue Officer for Microsoft Global Enterprise, published a piece on the Official Microsoft Blog with a blunt thesis: organizations have stopped asking whether AI matters and started asking how to make it real - and that is where many get stuck. The barrier, she argues, is no longer experimentation but execution: scaling adoption, delivering consistent enterprise-wide impact, and getting repeatability across the business. Her two foundational elements are intelligence and trust - harnessing an organization's own work intelligence (its data, workflows, and expertise) and applying it through AI in ways that are flexible, secure, and governed.

Why it matters

This is the language your customer's executive sponsor is about to start using, because it came from the top of Microsoft's enterprise sales org. The practical consequence for delivery is concrete: when the framing shifts from 'can we build it' to 'can we execute at scale', your next steering committee should lead with adoption metrics, governance posture, and cost predictability - not feature counts and demo polish. Read it next to this week's governance drops: model governance, MCP tool-call policy, eval-gated promotion, and Purview for agents are exactly the execution muscle she is describing.

Source →

Voices to follow

  • Microsoft Software Engineer - CoworkBas Brekelmans

    Software Engineer at Microsoft, started the Copilot Cowork project and previously CTO of Copilot Studio. The clearest voice on why Microsoft chose multi-model, MCP, and A2A architecture across the agent stack.

    Microsoft Software Engineer, Cowork - ex-CTO Copilot Studio
  • Microsoft EVP - Copilot, Agents & PlatformCharles Lamanna

    Executive Vice President for Copilot, Agents, and Platform at Microsoft. He owns the strategy behind Copilot Studio, Agent 365, and the Power Platform, so when the agent stack's direction shifts, it usually shifts because of a decision his org made.

    Microsoft EVP - Copilot, Agents & Platform
  • Microsoft Partner Director - Foundry Agent ServiceJeff Hollan

    Partner Director of Product at Microsoft, leading the Foundry agent platform: Agent Service, the Agent Framework, and the SDKs. The clearest source on how agents actually go from prototype to a hosted production runtime.

    Microsoft Partner Director - Foundry Agent Service + Agent Framework
  • Microsoft Principal Group PM - DataverseJulie Koesmarno

    Principal Group Product Manager at Microsoft, leading the Dataverse as Agent Data Platform team. Follow her to see where the governed data layer, MCP surface, and coding-agent plugins are heading before they ship.

    Microsoft Principal Group PM - Dataverse as Agent Data Platform
  • Microsoft Principal Cloud Advocate - Power Platform + agentsDaniel Laskewitz

    Principal Cloud Advocate at Microsoft, ex-Power Platform MVP and co-founder of Forward Forever. One of the clearest voices on multi-agent systems and Power Platform governance - the bridge between the maker community and the product teams.

    Microsoft Principal Cloud Advocate - Power Platform governance + agents
  • Copilot Studio MVPLisa Crosbie

    6x Microsoft MVP, Practical AI for Business with Copilot and Agents at Barhead. Calm, hands-on voice on production-grade agent design - the one to follow when you want patterns you can ship, not just demo.

    6x Microsoft MVP - YouTuber + International Speaker - ~21K followers
  • Microsoft VP - Product, Microsoft FoundryYina Arenas

    Vice President of Product for Microsoft Foundry. She owns the developer surface where hosted agents, the agent catalogue and the Foundry tooling story get decided, and she posts the roadmap thinking behind them.

    Microsoft VP - Product, Microsoft Foundry
  • Microsoft Principal Cloud Advocate - Power Platform Advocacy LeadApril Dunnam

    Principal Cloud Advocate and Team Lead for the Power Platform Advocacy team at Microsoft, and the face of Agent Academy. If a Copilot Studio feature or governance update ships, April has usually broken it down within 48 hours.

    Microsoft Principal Cloud Advocate - Power Platform + AI Demystifier

Coming up

  • June 1, 2026 · GitHub Copilot moves to usage-based billing, with updated model multipliers for PRUs. Another consumption meter to wire an alert to.
  • June 2-3, 2026 · Microsoft Build 2026, San Francisco + online. Expect the next wave of agent governance, Foundry, and MCP announcements - and likely the formal enterprise positioning of the execution theme above.
  • July 2026 · Copilot Cowork general availability.
  • August 2026 · EU AI Act enforcement begins for high-risk AI systems. Roughly three months out, and governance tooling like this week's drops is part of how you get ready.

This week's question

Microsoft shipped a stronger model and the controls to govern it in the same week, and its CRO says execution is now the differentiator. If capability is no longer your bottleneck, which control are you missing first - per-group model governance, MCP tool-call policy, an eval-gated promotion path, or Purview for your agents?

#Microsoft365Copilot#CopilotStudio#MCP#AgentGovernance#MicrosoftAI#Foundry#Purview
← All editions

Get Agentic Weekly in your inbox

Every Monday morning. Unsubscribe any time.

Elliot Margot

© 2026 Elliot Margot. Microsoft AI Specialist & Power Platform Solutions Architect.

Working atWitivio

Site Map

HomeAboutResume / CVProjectsTech StackFree MentorshipContactSitemapPrivacy PolicyImpressum

Contact Me

Ready to build? Let's architect your next big leap.

Get in Touch