Back to Blog
·VerseBlocks

Who is allowed to build an agent in your tenant

Power PlatformCopilot StudioGovernanceLicensing

In Copilot Studio, every user already has maker rights in the default environment. That's the out-of-the-box state. Microsoft ships it that way, and most tenants never touch it, a point Microsoft's Copilot Studio licensing documentation, updated 4 May 2026, states plainly. Add a Copilot Studio licence and a user can open the default environment and start building an agent the same afternoon, with nobody in IT aware it happened.

The same looseness runs through the rest of the agent surface. Anyone in the organisation can build a declarative agent in Microsoft 365 Copilot Agent Builder if the tenant holds a Microsoft 365 Copilot licence or has pay-as-you-go enabled for Copilot Studio, according to Microsoft's Agent Builder documentation, updated 19 August 2026. SharePoint agents need only Edit permission or higher on the site or document library, per Microsoft's SharePoint agent management documentation, plus the same tenant-level licensing or pay-as-you-go condition. A trial licence gets a user into the test chat panel and stops there. It permits creation and testing but blocks publishing, says Microsoft's Copilot Studio licensing documentation from 3 August 2026. Everything short of publishing is open by default, across three different products, to three different populations of users.

The controls that reach agent creation

Three admin surfaces change who can do this, and none of them sit in the same place.

Tenant settings come first. Developer environment assignments, Production environment assignments and Trial environment assignments, each named exactly that in the Power Platform admin center's tenant settings, updated 23 June 2026, control who can create and manage each environment type. Restrict them and you restrict who can spin up a new place for a Copilot Studio agent to live. Pair that with PowerShell. DisableEnvironmentCreationByNonAdminUsers narrows environment creation to Global admins, Dynamics 365 admins and Power Platform admins, per Microsoft's environment creation control documentation from 17 April 2024. Separate commands, disableDeveloperEnvironmentCreationByNonAdminUsers and DisableTrialEnvironmentCreationByNonAdminUsers, do the same for developer and trial environments specifically.

One preview setting has a catch. Copilot Studio authors grants agent-creation access to a specified security group under pay-as-you-go licensing, but it does not automatically revoke access from everyone outside that group, according to Microsoft's troubleshooting documentation for author access. It expands who can create agents. It doesn't shrink anyone else's access.

Inside an environment, the Environment Maker security role gates authoring. Microsoft's guidance on sharing Copilot Studio agents, updated 30 July 2026, says this role should go to anyone who needs to build agents, and it carries the ChatBotReaders privilege required just to chat with one. Strip a user of Environment Maker and they can't author, regardless of what the tenant setting allows.

Managed Environments is the third surface, and it comes with a licensing condition people skip past. It's an entitlement included with standalone Power Apps, Power Automate, Microsoft Copilot Studio, Power Pages and Dynamics 365 licences, and trial licences can license users inside a managed environment too, per Microsoft's managed environment overview from 23 February 2026. Inside one, Limit sharing governs how far an agent can spread once it's built. Solution checker enforcement, per Microsoft's solution checker documentation, runs at three levels, None, Warn or Block, applied the moment a solution containing an agent gets imported.

The setting that closes the original gap arrived with 2026 release wave 1. The Power Platform admin center gained agent-specific controls, including the ability to disable agent creation in the default environment outright and restrict deployment to managed environments only, according to Microsoft's governance administration release notes. Enhanced agent security controls reached general availability on 2 September 2026, letting admins define authentication and access policies for agents at the environment or environment group level, including requiring Microsoft Entra ID authentication or prohibiting anonymous access entirely inside a managed environment. Both are real, generally available controls. Neither is switched on by default.

Where Power Platform admin control stops

None of that reaches Microsoft 365 Copilot Agent Builder or SharePoint agents. The Copilot Agents section of the Microsoft 365 admin center manages declarative agents built in either surface, not Power Platform admin center settings, according to Microsoft's Microsoft 365 agents admin guide from 7 April 2026. The same guide is direct about the consequence. Creation runs on Microsoft 365 Copilot licensing and SharePoint permissions instead, nothing a Power Platform admin center setting touches.

That produces a specific hole. Lock down Production environment assignments so nobody outside a named group can spin up a new Power Platform environment, and a user still holding a Microsoft 365 Copilot licence and Edit rights on a SharePoint library can build an agent that afternoon anyway, because that restriction never touches Agent Builder or SharePoint. No tenant setting disables Agent Builder access or SharePoint agent creation. The only option left is removing the Microsoft 365 Copilot licence itself, which takes far more with it than agent creation.

Agent Builder does carry one real constraint. The No new privileges principle means an agent respects the permissions of whoever built it. If that person can't see a given SharePoint site, Teams channel or Outlook mailbox, the agent they build can't surface content from it either, per Microsoft's Agent Builder documentation. That's a data boundary. It says nothing about who was allowed to build the agent in the first place.

Disabling Publish Copilots with AI features stops Copilot Studio agents with generative features from going live, but it does nothing for creation, and nothing at all for the other two surfaces. No single native tenant setting turns off agent creation across Copilot Studio, Agent Builder and SharePoint at once, according to the same tenant settings documentation cited earlier. Anyone assuming one setting exists is planning around a control that does not exist.

What to restrict and what to just watch

Locking every one of these surfaces down defeats what the platform is for. Makers building without a ticket queue is the entire pitch of Copilot Studio and Agent Builder both, and an approval gate on every agent turns that into something closer to a traditional IT request process with extra branding.

Restrict environment creation broadly. Production environment assignments, Developer environment assignments and Trial environment assignments, backed by the PowerShell settings that lock creation to Global admins, Dynamics 365 admins and Power Platform admins, touch the fewest people and stop the largest share of unplanned Copilot Studio agents before they exist. That's the cheap, high-return control, and most tenants still run with all three assignments open to everyone.

Inside environments that already exist, govern rather than gate. Managed Environments is an entitlement most organisations already hold through their existing Power Apps, Power Automate, Copilot Studio or Dynamics 365 licences, so turning it on rarely means buying anything new. Once it's on, require Microsoft Entra ID authentication through the enhanced agent security controls that reached general availability on 2 September 2026, and let Solution checker run in Block mode rather than Warn. That governs agents where they get built instead of trying to pre-approve every one.

For Agent Builder and SharePoint, stop trying to restrict and start trying to see. The Power Platform admin center's Inventory experience can view and govern agents created across a tenant, according to Microsoft's Center of Excellence guidance. The older CoE Starter Kit is no longer actively maintained, and its core capabilities have moved into the admin center directly. The same guidance notes that Copilot Studio agents created inside Microsoft Teams environments were not discoverable through the CoE Starter Kit specifically. Removing a Microsoft 365 Copilot licence from a user is the only way to fully block Agent Builder and SharePoint agent creation, and it's too blunt to use as a first move. Watching who built what, and where, is the honest substitute until Microsoft gives that surface a tenant setting of its own.

Every environment that existed before an admin touched a single tenant setting still carried the default. Maker rights for any licensed user, no approval required. Nobody in IT chose that particular policy. Microsoft did, and it stays in force until somebody with the right role decides otherwise.