Updated: October 6, 2026 · Source-first reference130 documented agents & platforms · No paid rankings
AgentenCode evidence profileAutomation
✓ Editorially reviewedChecked: October 5, 2026

Agent profile · Automation

Microsoft Copilot Studio

Microsoft Copilot Studio is classified by AgentenCode as an enterprise agent builder from Microsoft. It belongs to the Automation category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.

MicrosoftAutomationOrganizations
ECOSYSTEM ASSOCIATION

This agent profile links to a curated provider view. Security controls are not inherited across products.

Automationeditorial classification
Microsoftprovider
15 primary sourcessource status
October 5, 2026last verification

AgentenTrust 2.0 · EU & governance evidence

Trust, privacy and control evidence for Microsoft Copilot Studio

Direct answer: AgentenCode currently documents 9 of 36 normalized trust controls for this profile. Missing fields remain Unknown and are never automatically interpreted as “no”.

Privacy contextPrivacy & data2 of 8 documentedResidency, training, retention, DPA, subprocessors and processing scope.
Security contextSecurity & access4 of 10 documentedEncryption, SSO, SCIM, RBAC, roles and credential handling.
Human controlHuman control1 of 10 documentedApproval, oversight, permissions and stop or rollback controls.
TraceabilityAudit & traceability2 of 8 documentedAudit logs, APIs, SIEM, observability, tracing and activity history.

Important: these numbers show evidence coverage, not a product rating. 0 of 10 means that no field-level public evidence is stored for those ten controls in the current dataset. It does not mean the product lacks those capabilities.

Field-level evidence

Documented controls and values from primary sources.

Documented yesDocumented valueUnknown remains unknown
High confidence

API · Rest

Yes — documented

Copilot Studio agents can be integrated through the REST-based Direct Line API.

Scope: copilot_studio_direct_line_integration · verified 2026-10-01 · Primary source ↗
High confidence

Governance · Audit logs · API

Yes — documented

Programmatic audit-log access is documented through the Office 365 Management API.

Scope: office_365_management_api · verified 2026-10-01 · Primary source ↗
High confidence

Governance · Audit logs · Available

Yes — documented

Copilot Studio activities are available as audit events in Microsoft Purview.

Scope: copilot_studio_tenant · verified 2026-10-01 · Primary source ↗
High confidence

Governance · Custom roles

Yes — documented

Custom Dataverse security roles are supported for Copilot Studio permissions.

Scope: power_platform_environment · verified 2026-10-01 · Primary source ↗
High confidence

Governance · Dlp

Yes — documented

DLP governance is documented.

Scope: power_platform_tenant · verified 2026-10-01 · Primary source ↗
High confidence

Governance · Human approval

Yes — documented

AI approval stages can be combined with human stages so people oversee and finalize critical or exceptional cases.

Scope: agent_flows_ai_approvals · verified 2026-10-03 · Primary source ↗
High confidence

Governance · RBAC

Yes — documented

Copilot Studio authoring access is governed with environment security roles.

Scope: power_platform_environment · verified 2026-10-01 · Primary source ↗
High confidence

Identity · Agent Identity · Provider

Microsoft Entra Agent ID

Microsoft Entra Agent ID is the documented identity provider.

Scope: new_agents · verified 2026-10-01 · Primary source ↗
High confidence

Identity · Agent Identity

Yes — documented

Agents receive a dedicated managed identity.

Scope: new_agents · verified 2026-10-01 · Primary source ↗
High confidence

Memory · Persistent

Yes — documented

Memory records interaction details and reuses them in future interactions; inactive user memories are deleted after 28 days.

Scope: copilot_studio_memory_preview · verified 2026-10-03 · Primary source ↗
High confidence

Memory · User Scoped

Yes — documented

Each agent keeps a separate memory store for every user; one user's context is not shared with another.

Scope: copilot_studio_memory_preview · verified 2026-10-03 · Primary source ↗
High confidence

Operations · Rate Limits Documented

Yes — documented

Copilot Studio documents agent request quotas in RPM/RPH for the Dataverse environment.

Scope: standard_harness_agents · verified 2026-10-03 · Primary source ↗
High confidence

Operations · Service Quotas Documented

Yes — documented

Microsoft publishes quotas and limits for standard-harness Copilot Studio agents.

Scope: standard_harness_agents · verified 2026-10-03 · Primary source ↗
High confidence

Orchestration · Handoffs

Yes — documented

Microsoft documents that Copilot Studio agents can hand off to other agents.

Scope: copilot_studio_agents · verified 2026-10-03 · Primary source ↗
High confidence

Privacy · Data residency · Available

Yes — documented

Geographic data residency is documented.

Scope: copilot_studio · verified 2026-10-01 · Primary source ↗
High confidence

Privacy · Data residency · Customer Region Selectable

Yes — documented

Customer-selectable geography is documented.

Scope: copilot_studio_environment · verified 2026-10-01 · Primary source ↗
High confidence

Protocols · Mcp · Client

Yes — documented

Copilot Studio agents can consume MCP servers.

Scope: copilot_studio_agents · verified 2026-10-01 · Primary source ↗
High confidence

Security · Customer-managed keys

Yes — documented

CMK is supported through the Power Platform implementation for Managed Environments.

Scope: managed_power_platform_environments · verified 2026-10-01 · Primary source ↗

Evidence-backed overview

What is Microsoft Copilot Studio?

Microsoft Copilot Studio is classified by AgentenCode as an enterprise agent builder from Microsoft. It belongs to the Automation category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.

Product-specific evidence for Microsoft Copilot Studio

This profile links 15 unique primary sources across the product profile, field-level evidence, trust controls and documented relations. The points below describe this product’s stored evidence rather than generic characteristics of Automatisierung.

Data Residency

Yes · Scope: copilot_studio · verified 2026-10-01.

Primary source ↗

Region auswählbar

Yes · Scope: copilot_studio_environment · verified 2026-10-01.

Primary source ↗

Customer-Managed Keys

Yes · Scope: managed_power_platform_environments · verified 2026-10-01.

Primary source ↗

Verschlüsselung at rest

Microsoft-managed keys by default · Scope: copilot_studio · verified 2026-10-01.

Primary source ↗

Audit Log API

Yes · Scope: office_365_management_api · verified 2026-10-01.

Primary source ↗

Audit Logs

Yes · Scope: copilot_studio_tenant · verified 2026-10-01.

Primary source ↗

AgentenCode treats this page as a reference profile rather than a ranking. Product facts are separated from editorial classification, and the profile is tied to a specific verification date. If a capability is not backed by sufficiently precise public evidence, it remains unknown instead of being inferred from marketing language or from similar products.

2primary sources
19field-level evidence claims
9documented trust controls
3history events

How to read the evidence

The field-level evidence layer records a value, a scope, a confidence level, a verification date and one or more primary sources. Scope matters: an enterprise-only security feature must not be generalized to every plan or deployment surface. The same rule applies to hosting, privacy, audit and protocol claims.

AgentenCode also keeps Unknown distinct from false. A missing claim means the public dataset does not currently contain sufficiently precise evidence for that field. A negative value is used only when a reliable primary source explicitly documents a restriction or non-availability.

Decision context

Provider and category

Microsoft Copilot Studio is documented under Automation and is associated with Microsoft. Category labels help navigation but do not replace product-specific evidence.

Verification status

The public profile is marked editorially reviewed and was last checked on October 5, 2026.

Trust coverage

9 of 36 normalized trust controls currently have field-level public evidence. The remaining controls are not treated as negative findings.

Source-first use

For procurement, security or legal decisions, use the linked primary sources and verify the plan, region and configuration that apply to your organization.

Capabilities, strengths and deployment checks for Microsoft Copilot Studio

Microsoft Copilot Studio is classified as Enterprise Agent Builder from Microsoft. The profile’s editorial layer is derived from the stored use cases, strengths and checks below; claims about security, privacy or governance remain separate and require field-level evidence.

Interne Assistenten

This use case is part of the stored profile for Microsoft Copilot Studio. The related strength is “Microsoft-Ökosystem”. In a production evaluation, the practical boundary to verify is: Dataverse- und Connector-Rechte prüfen.

Customer Service

This use case is part of the stored profile for Microsoft Copilot Studio. The related strength is “Low-Code plus Erweiterbarkeit”. In a production evaluation, the practical boundary to verify is: Autonome Trigger kontrollieren.

Business-Prozesse

This use case is part of the stored profile for Microsoft Copilot Studio. The related strength is “Connectoren und Aktionen”. In a production evaluation, the practical boundary to verify is: Lizenzierung und Verbrauchsmodelle kalkulieren.

Microsoft-365-Automation

This use case is part of the stored profile for Microsoft Copilot Studio. The related strength is “Governance-orientierte Bereitstellung”. In a production evaluation, the practical boundary to verify is: Dataverse- und Connector-Rechte prüfen.

What to verify before adoption

  • Dataverse- und Connector-Rechte prüfen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
  • Autonome Trigger kontrollieren. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
  • Lizenzierung und Verbrauchsmodelle kalkulieren. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
Editorial boundary: The use-case and strength descriptions are product-specific editorial context based on the stored profile. Trust, privacy and governance statements are only presented as facts when field-level primary-source evidence exists.

Verified history

The public history layer records only confirmed profile changes and verification events. Monitoring signals are not published as product facts until they have been reviewed.

  • October 5, 2026 · Verification Update
  • October 1, 2026 · Source Maintenance
  • September 30, 2026 · Verification Update
  • September 28, 2026 · Schema Upgrade

Official sources

This profile links 15 unique primary sources across the product profile, field-level evidence, trust layer and documented relations. Provider documentation remains authoritative when the product changes between verification cycles.

Frequently asked questions

What is Microsoft Copilot Studio?

Microsoft Copilot Studio is listed by AgentenCode as an automation agent or agentic product from Microsoft.

How much trust evidence is documented for Microsoft Copilot Studio?

The current trust layer documents 9 of 36 normalized controls. Missing controls remain unknown rather than being treated as false.

When was this profile last checked?

The current profile verification date is October 5, 2026. The linked primary sources remain authoritative if the product changes between checks.

Method note: AgentenCode does not certify GDPR or EU AI Act compliance. It documents evidence that can support a separate legal, security or procurement assessment.