Instiq
Chapter 3 · Basic administration for Copilot and agents·v1.1.0·Updated 6/16/2026·~12 min

What's changed: Added per-section figures (cert-figure-retrofit). New AB-900 Chapter 3 (Domain 3 "Copilot and agent administration": capabilities = Copilot vs agents/monthly-PAYG/enable-disable/Researcher-Analyst-custom agents; Copilot admin = license assignment/PAYG billing policies/Copilot Analytics usage-adoption/prompt management; agent admin = user access config/creation/approval process/monitoring via M365 and Power Platform admin centers)

3.3Basic administrative tasks for agents

Key points

Understand configuring user access to agents, creating an agent, the agent approval process, and monitoring agents (usage, operational insights, lifecycle) using the Microsoft 365 admin center and the Microsoft Power Platform admin center.

Agents are powerful, so governing who can use them, whether they are approved, and whether they run safely is essential. Admins manage the whole lifecycle: access configuration, creation, approval, and monitoring.

3.3.1Access configuration, creation, and approval

First, configure user access to control which users/groups can use which agents (least privilege). Create agents tailored to org knowledge and processes. Before distributing across the org, run them through an approval process so unapproved agents are not used ungoverned—ensuring safety and governance.

3.3.2Monitoring agents and lifecycle

After deployment, monitor agents’ usage, operational insights, and lifecycle (create → publish → update → retire). Use the Microsoft 365 admin center and the Microsoft Power Platform admin center to govern agents built in tools like Copilot Studio. Remember the flow: "create → approve → monitor → retire."

TaskWhatWhere
Configure accessWho can use which agentControl with least privilege
CreateSpecialized to org knowledge/processesCopilot Studio, etc.
ApproveApproval process before distributionPrevent ungoverned use
MonitorUsage/operational insights/lifecycleM365 admin center / Power Platform admin center
Warning

Watch the mix-ups: (1) distribute agents only after an approval process (prevent ungoverned use). (2) Monitor using both the Microsoft 365 admin center and the Power Platform admin center. (3) Configure access with least privilege.

Exam point

Common: requirement → admin task. E.g., "control who can use an agent" = configure user access; "review before org-wide distribution" = approval process; "monitor agent usage/lifecycle" = M365 admin center / Power Platform admin center; "provide an org-specific agent" = create an agent.

Diagram of the agent administration lifecycle: create, test, publish, approve/govern, monitor.
Agent administration lifecycle

3.3.3Section summary

  • Agent lifecycle: configure access (least privilege) → create → approve → monitor
  • Run an approval process before distribution to prevent ungoverned use
  • Monitor using both the M365 admin center and the Power Platform admin center

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Before distributing agents org-wide, what should they go through to prevent ungoverned use of unapproved ones?

Q2. Which admin task controls which users/groups can use which agents?

Q3. Which admin centers are used to monitor agent usage, operational insights, and lifecycle?

Q4. Which admin task provides an agent specialized to org-specific knowledge or processes?

Q5. Which best represents the general agent management lifecycle?

Q6. Which principle best applies when configuring access to agents?

Check your understandingPractice questions for Chapter 3: Basic administration for Copilot and agents