Securing Agents in Microsoft 365 Copilot
Eight controls, eight test cards, four read-only scripts. Document what stops an agent wiping a mailbox, control by control.
Team and org licence: $97
“Battle-tested in production environments.”
The situation
Your people are spinning up Copilot agents, and someone above you wants to know what stops one from wiping a mailbox, leaking data, or being hijacked by a poisoned document.
The documentation is scattered and reads like marketing. A probe that comes back ContentFiltered tells you a filter fired, not what it stopped. A settings screenshot is not evidence.
What you need is a defensible account you can hand a risk committee, and a way to gather that evidence control by control in your own tenant.
What this is
This is the audit instrument for exactly that. The centerpiece is a verification kit: eight per-control test cards, numbered T1 to T8, each naming what to test, the steps sourced to a named Microsoft or standards page, what a PASS looks like, what a FAIL means, and where to go to fix it.
Alongside it, a one-page board answer to the mailbox-wipe question, written so a CISO can read it straight into a minute. Four read-only assessment scripts turn the kit from a document into an instrument: they gather the evidence, you make the call.
It documents and structures your posture. It does not prove your agents are secure, and it is not a guarantee of any security outcome.
What is inside
- The verification kit, full T1 to T8: eight per-control test cards with sourced steps, PASS and FAIL criteria, a standards anchor, and result tables you fill once per run
- The mailbox-wipe board one-pager: the five load-bearing controls in the order they apply, and why the content filter and the runtime confirmation prompt are courtesies rather than controls
- Four read-only assessment scripts: agent inventory and sponsors, least privilege, DLP for Copilot presence and mode, plus an audit-signal KQL pack written against a measured record shape rather than a documented field list
- The free sample script, the run guide, and the required-reader-roles matrix naming the least-privileged read scope each script needs
- Per-script sample outputs, labelled constructed illustrations rather than captures of a live tenant
- The limits page, What this kit does not prove, which names every boundary a full green sheet does not establish
- The licensing dependency matrix, and a printable risk acceptance form for the checks you cannot run
- A SHA-256 checksum manifest, so you can confirm the files you received match the ones that shipped
- Twenty-two files. Every document ships as a typeset PDF and its Markdown source; the scripts ship as scripts
Who it is for
- Security and risk owners asked to sign off on a Copilot agent
- M365 and Copilot Studio admins who own the tenant-side controls
- AI governance leads who need evidence rather than a vendor screenshot
- Anyone who has to answer the mailbox-wipe question in writing
Who it is not for
- Anyone who wants software. There is no dashboard here, no connector, no automated pipeline
- Anyone hunting a script that performs, simulates, or enables a destructive or attacking action. Refusing to ship one is the entire point
- Non-Microsoft agent stacks. This is M365 Copilot specific
- Legal, compliance, or regulatory sign-off, and it is not a live assessment of your tenant
Not sure yet? Start free.
Agent Security Verification Checklist (Lite) is free and covers the same ground at a smaller scale. If it is useful, this is the full version.
Download Agent Security Verification Checklist (Lite)Questions people actually ask
Does this work if we are on E3 rather than E5?
Yes. M365 Copilot is a paid add-on that sits on top of a qualifying M365 licence, so the licence tier underneath changes what data Copilot can reach, not whether this material applies. Where an E5-only control is the cleanest answer to something, the material says so and gives the E3 route as well.
Is this current for the June 2026 GA wave?
Yes. Cowork went generally available worldwide on 16 June 2026 and brought a metered layer billed in Copilot Credits at $0.01 each. Everything here is written against that change rather than around it. Updates are included, so when the next wave lands you get the revision at no extra cost.
What if we have not enabled Cowork yet?
That is the common case and it is fine. The metered layer is additive and off by default until an admin enables it, so your bill today is still flat seats. Reading this before you switch it on is the cheaper order to do it in, because the decisions get harder to reverse once makers start building.
What do I actually get, and do I have to read a book to use it?
No. The buyable unit is the audit instrument, not a report you plow through. Twenty-two files: the T1 to T8 verification kit, the mailbox-wipe board one-pager, four read-only assessment scripts plus the free sample, a run guide, the required-reader-roles matrix, the per-script sample outputs, a checksum manifest, the limits page, the licensing dependency matrix, and the risk acceptance form. Every document ships as a typeset PDF and its Markdown source, so you can print and circulate it or paste it into your own audit materials. You can run the kit without reading a page of prose.
What access do the scripts need, and do they change anything?
They change nothing. Every script inspects posture only: every Graph call is a GET, there is no write cmdlet anywhere in the bundle, and the only file any of them writes is a local findings CSV on your own machine, and only when you ask for one. The three Graph scripts need the delegated read scopes AgentIdentity.Read.All, Directory.Read.All and Application.Read.All, and because those are admin-consent scopes, a one-time tenant-wide admin consent is the real gate rather than a reader role. The DLP check uses View-Only DLP Compliance Management, and the KQL needs Reader on the Application Insights resource and on the Log Analytics or Sentinel workspace. Nothing needs a ReadWrite scope or an admin write role. The required-reader-roles matrix ships free in the Lite bundle, so you can check that claim before you spend anything.
How long does it take?
You can run the full kit against one agent in an afternoon. The four assessment scripts each run in minutes and hand you a finding you decide on. Because model output is non-deterministic, the two behavioral checks, the prompt-injection probe and the human gate, have to be run several times: one follow-through in five is a FAIL, not a fluke. Those two are active tests that send live prompts and can trigger agent actions, so point them at a non-production or explicitly consented agent rather than blind at production.
What did the August 2026 tenant run establish?
A process claim, not an assurance claim. Every PowerShell script in the bundle was run end to end against a purpose-built Microsoft 365 E5 tenant, with seeded canaries and ground truth recorded out of band before each run, from 15 to 18 August 2026. One tenant, one operator, and that operator is the author. It found defects in the scripts, and they were fixed before this went on sale. That is the whole of the claim: nobody outside has looked at any of it, and it says nothing about whether your agents are safe. Three limits travel with it. The KQL pack was evaluated against records captured from that tenant rather than executed in Log Analytics. The sample outputs stay constructed illustrations. And the two dates do not merge: documentary claims are current as of July 2026, only the tenant measurements are August. The item-by-item bound list is in the limits page, which ships free in the Lite bundle.
What can I do with it, and what does the Team licence add?
One purchase covers your own use inside your organization: run the kit and the read-only scripts against your own tenants, adapt the checklists into your internal audit materials, and share the completed outputs and the board one-pager internally. What you may not do is redistribute or resell the source files outside your organization. The $97 Team tier is the same kit plus the 30-page source-cited dossier, the filterable threat-to-standards crosswalk, a citation workbook, an incident runbook, sample audit-log artifacts, and an internal-use organization licence with no headcount limit. If you are rolling this out across a team, buy that one instead. Full terms are at kesslernity.com/license.
Buying this with a company card?
Most buyers expense it. Your receipt email carries a Generate link that opens an invoice generator: add your billing address, put your legal company name and any reference your finance team needs in the Additional notes box, and download the PDF. If you have an EU VAT number, enter it at checkout and no VAT is charged. Here is the approval email, so you do not have to write one.
Subject: Approval request: Securing Agents in Microsoft 365 Copilot ($69, one-time) Hi [Manager], I would like to expense a one-time $69 purchase: Securing Agents in Microsoft 365 Copilot by Kesslernity. What it is: Eight controls, eight test cards, four read-only scripts. Document what stops an agent wiping a mailbox, control by control. What we get: - The verification kit, full T1 to T8: eight per-control test cards with sourced steps, PASS and FAIL criteria, a standards anchor, and result tables you fill once per run - The mailbox-wipe board one-pager: the five load-bearing controls in the order they apply, and why the content filter and the runtime confirmation prompt are courtesies rather than controls - Four read-only assessment scripts: agent inventory and sponsors, least privilege, DLP for Copilot presence and mode, plus an audit-signal KQL pack written against a measured record shape rather than a documented field list - The free sample script, the run guide, and the required-reader-roles matrix naming the least-privileged read scope each script needs Why it is worth it: it is a one-time purchase with future updates included, and it costs less than an hour of any consultant we would otherwise ask. The author publishes the open-source Copilot prompt library that Microsoft's CMO for AI at Work cited as "battle-tested in production environments". A downloadable invoice is available from the purchase receipt for expenses. [Your name]
Securing Agents in Microsoft 365 Copilot
Eight controls, eight test cards, four read-only scripts. Document what stops an agent wiping a mailbox, control by control.
Get it for $69Licensed, not sold. The full License & Terms apply. Kesslernity is an independent publisher: this is independent analysis, not affiliated with, sponsored by, or endorsed by Microsoft. It is practitioner guidance, not professional, legal, or financial advice.
Often bought alongside
Copilot Agent Pack, Vol. 1
Six governed Copilot Studio agents, finished for governance rather than for a demo.
$49→Agent Instruction Block Design Guide
Write agent instructions that behave. The fiftieth user gets the same result you did on day one.
$19→Govern Your Agents
One agent, two governance problems. Naming the Swarm plus the Agent Instruction Block guide.
$47→