
Sign up to save your podcasts
Or


Take a business process from prompt to production by building agents, workflows, and apps in one place with Copilot Studio. Describe the agent you need and generate its instructions and reusable skills, choose the model, connect MCP tools and specialist agents, then test its quality at scale with Evaluations.
Trigger workflows from incoming email, classify submissions, hand work to your agents, and pause for human review on the decisions that need it. Track timing and paths for every step in the Activity tab. Then generate a full stack app on your Dataverse data so your team can filter, review, and approve every bid from one shared view.
Jack Rowbotham, Copilot Studio Senior Product Manager, shares how to automate a procurement process for bids from multiple vendors, using agents that reason, route, and recommend.
👥 Who it's for:
IT admins, Power Platform makers, solution architects, and developers building agentic solutions, plus operations and procurement teams automating reviews and approvals.
⏱️ Chapters:
00:00 Build agents, workflows, and apps in one place
01:04 Automate a multi-vendor bid review end to end
02:18 Build an agent from a prompt
03:28 Add models, MCP tools, and specialist agents
04:13 Test the bid agent in Preview
05:05 Evaluations
05:59 Automated workflows
07:42 Track every run in the Activity tab
08:13 Build an app from a prompt
09:10 Approve bids from the team app
09:37 Get started with Copilot Studio
Copilot Studio brings agents, workflows, and apps together in one place, all running on the GitHub Copilot harness. In this video, a supplier email triggers a workflow, a bid evaluation agent checks the bid against tender requirements, and the procurement team makes the final call in a shared app.
Describe the agent you want, including the requirements to assess, the logic to apply, and the live data source to connect to. Copilot Studio reasons over your prompt, maps out its build steps, and generates the agent's name, instructions, and skills for requirement coverage and evidence verification. Connect Work IQ for supplier emails and the Dataverse MCP server for bid data, keep Claude Sonnet as the reasoning model, ground the agent in an RFP example PDF, and add a Supplier Risk specialist agent.
Test the agent in the Preview tab and watch its chain of thought as it flags gaps in certification, cold-chain handling, and insurance minimums. Then run Evaluations with your own conversations, auto-generated tests, or a CSV file. Here, 18 test cases met the evaluation criteria 89% of the time.
In the Workflows tab, drag in an Outlook "When a new email arrives" trigger, a Classify step for RFP submissions, a Get Attachment connector, and an Agent step running the Bid Evaluation Agent. An if/else Human Review step brings in a person on flagged bids, and the Researcher agent and a recommendation agent finish the job before results land in Dataverse.
Finish in Apps by describing a Bid Management App connected to your Dataverse table, or to sources like SharePoint through connectors. Apply company branding with a follow-up prompt, then filter bids that need human review and approve decisions from the app.
Try it for yourself at copilotstudio.microsoft.com. Subscribe to Microsoft Mechanics for more videos like this.
🔗 Related links:
— Get started with Copilot Studio: https://copilotstudio.microsoft.com
► Unfamiliar with Microsoft Mechanics? Microsoft's Official Video Series for IT
— Subscribe: https://www.youtube.com/c/MicrosoftMechanicsSeries — Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog — Podcast: https://microsoftmechanics.libsyn.com/podcast
► Join us on social:
— https://twitter.com/MSFTMechanics — https://www.linkedin.com/company/microsoft-mechanics/ — https://www.instagram.com/msftmechanics/ — https://www.tiktok.com/@msftmechanics
Build a specialist AI agent without writing a line of code. Describe what you want in one prompt, and Copilot Agent Builder generates the name, instructions, skills, and knowledge setup for you — grounded only in the SharePoint sites, files, and Copilot Connectors you choose.
Teach your agent a Skill to handle recurring work, like drafting weekly status emails from your own template, then test it in Preview before you publish. Share it with people or groups and set exact permissions, track real usage in the new Monitor tab, and push your best agents into your org's Agent Store catalog.
Ned Friend, Group Product Manager for Copilot Agent Builder shares how to turn an agent into a tool your whole team can run, measure, and trust.
👥 Who it's for:
Team leads and managers who want trusted, repeatable answers for their team, plus IT admins and Microsoft 365 power users building specialist Copilot agents without code.
⏱️ Chapters:
0:00 Build specialist agents inside Copilot
0:34 Ground agents in trusted org knowledge
1:31 Create a new hire onboarding agent
2:15 Natural-language agent creation
2:41 Ground answers in SharePoint knowledge
4:13 Skills for repeatable tasks
4:53 Precise knowledge grounding
6:37 Preview and test before publishing
7:03 Share your agent with set permissions
7:39 See the new hire's agent view
8:22 Usage monitoring
8:41 Publish agents to your org catalog
Copilot Agent Builder lets you create a specialist agent by describing what you want it to do in plain language. Agent Builder interprets that prompt and automatically generates the agent's name, description, instructions, skills, knowledge sources, and suggested prompts, which you can review and edit directly.
Ground every answer in the exact knowledge you choose: SharePoint and OneDrive files, Outlook email and calendar, Microsoft Teams chats and meetings, or external business systems connected through Copilot Connectors. Turn on web search only when you want the agent to research beyond your organization, like competitor or customer research.
Add Skills to teach the agent repeatable, multi-step work — in this video, a weekly status update email built from a real template, matching its tone, sections, and formatting automatically. Preview and test the agent before publishing, then share it with people or groups and set whether they can use it or edit it.
Once your agent is live, the Monitor tab tracks total sessions, daily active users, average messages per session, average duration, and which knowledge sources get used most. For agents with strong adoption, publish them to the Built by your org section of the Agent Store for wider use across your organization.
Try Copilot Agent Builder for yourself — it's included with Copilot. Subscribe to Microsoft Mechanics for more videos like this.
► Unfamiliar with Microsoft Mechanics? Microsoft's Official Video Series for IT
— Subscribe https://www.youtube.com/c/MicrosoftMechanicsSeries
— Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
— Podcast: https://microsoftmechanics.libsyn.com/podcast
►Join us on social:
— https://twitter.com/MSFTMechanics
— https://www.linkedin.com/company/microsoft-mechanics/
— https://www.instagram.com/msftmechanics/
— https://www.tiktok.com/@msftmechanics
Govern every AI agent running across your organization with Agent 365. Track agents from Microsoft, Amazon, Google, and Salesforce in one registry, sync in agents you're already running on AWS Bedrock, Google Cloud, Databricks Genie, and Anthropic Claude, and lock down shadow AI with default blocks and Execution Container isolation.
Agent 365 inspects your environment for every agent Microsoft and partners have registered, then layers control on top. Reusable security policy templates apply Conditional Access, Access Packages, and Custom Security Attributes the moment you approve an agent, Tools governance blocks risky MCP servers and connectors org wide, and the Adoption Dashboard breaks down usage by group, job function, and license type for every manager in your org.
Jeremy Chapman, Microsoft 365 Director, shares how to bring every agent in your organization under one governed registry, and how to shut down shadow AI before it ever compromises your environment.
👥 Who it's for:
IT admins, security engineers, and identity teams governing AI agents across Microsoft 365, Entra, Purview, Defender, and Intune; solution architects designing agent access, tools, and security policy at scale; developers and DevOps teams building and registering agents and custom MCP servers in Copilot Studio, Agent Builder, and Foundry; and team leads, finance, and IT leaders tracking agent adoption, usage, and spend across the organization.
⏱️ Chapters:
00:00 Why you need an AI agent control plane 02:00 See every AI agent across your environment with the unified agent registry 02:50 Track local AI activity with OpenTelemetry and the Agent Map 03:16 Sync AI agents from AWS Bedrock, Google Cloud, Databricks and Claude with Registry Sync 03:55 Approve, publish and block AI agents across your organization 04:42 Manage MCP servers, plugins and connectors with Tools governance 05:18 Apply reusable security policy templates across Entra, Purview, Defender and Intune 06:06 Block shadow AI and isolate local agents with Microsoft Execution Containers 06:23 Track agent adoption and usage with the Agent 365 dashboard 07:06 Set spending limits and cost alerts for AI agents 08:02 Monitor AI agent costs and buy prepaid credits 09:07 Get started with Agent 365 today
Agent 365 gives you one place to govern every AI agent running across your organization, no matter where it was built or who owns it. In this demo, the unified agent registry surfaces agents from Microsoft Foundry, Copilot Studio, Agent Builder, and SharePoint, alongside agents from Amazon, Google, and Salesforce, each with its identity, owner, permissions, and usage history attached. Local AI running on managed devices shows up too, logged through standardized OpenTelemetry and mapped visually in the Agent Map so you can trace connections between agents, people, data, and tools. Registry Sync pulls in agents you're already running on AWS Bedrock, Google Cloud, Databricks Genie, and Anthropic Claude with nothing more than a connection string, and from the same registry you approve agents for broader use, publish or pin them to specific groups, automate ownership handoffs when an employee leaves, and block any agent you don't want in production.
From there, Agent 365 puts you in control of what agents can touch and how they're secured. The Tools view gives you one place to see every MCP server, plugin, and connector your agents rely on, block the risky ones, and approve or reject new tool requests as they come in. Reusable security policy templates apply Conditional Access, Access Packages, and Custom Security Attributes the moment you approve an agent, drawing on native signals from Microsoft Entra, Purview, Defender, and Intune so your identity, data security, SecOps, and device teams enforce the same controls. Shadow AI running as unsanctioned local agents gets blocked by default through Intune policy and isolated from user sessions with Microsoft Execution Containers. Team leads and managers track adoption and usage in the Agent 365 Dashboard, filtered by group, organization, job function, or license type. IT and finance teams set monthly spending limits, per user budget caps, and weekly usage alerts for Copilot Cowork and the Work IQ API, and can pre purchase discounted credits to keep spend predictable.
🔗 Related links: ► Get started at https://aka.ms/agent365
► Unfamiliar with Microsoft Mechanics? Microsoft's Official Video Series for IT
— Subscribe https://www.youtube.com/c/MicrosoftMechanicsSeries — Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog — Podcast: https://microsoftmechanics.libsyn.com/podcast
►Join us on social:
— https://twitter.com/MSFTMechanics — https://www.linkedin.com/company/microsoft-mechanics/ — https://www.instagram.com/msftmechanics/ — https://www.tiktok.com/@msftmechanics
An AI agent works inside your Windows 365 Cloud PC from a Teams chat on your phone — finding downloaded files, editing documents, and drafting emails with your laptop lid closed. Microsoft Scout, a new Autopilot agent powered by the open source OpenClaw project, runs on your own Cloud PC using your identity, your files, and your apps.
Developers get a Developer Optimized Cloud PC preloaded with GitHub, VS Code, and Node.js that runs Foundry Local for token-free AI coding, and input and output protection capabilities black out the screen when anyone tries to capture a sensitive file.
Bhavya Chopra, Windows 365 Partner Director, joins Jeremy Chapman, Microsoft 365 Director, to show how Windows 365 now covers every seat — end users, developers, admins, and the AI agents working alongside them.
👥 Who it's for: architects and IT teams deploying AI agents like Scout and Windows 365 for Agents, developers who want a pre-configured cloud coding environment with local AI, security and compliance teams enforcing data loss prevention on remote desktops, and admins managing Cloud PC connection health.
⏱️ Chapters:
0:00 What's new across Windows 365 Cloud PCs 0:59 Why Cloud PC adoption keeps accelerating 2:04 Healthcare and telecom Windows 365 case studies 3:14 Sign in to a full Windows desktop anywhere 4:10 Block screenshots with input and output protection capabilities 4:35 Pull table data from images with Click to Do 5:19 Resume your Cloud PC session on an iPad 5:52 Publish Cloud Apps with Windows 365 Flex 7:01 Give AI agents a dedicated Cloud PC 7:27 Run Microsoft Scout from a Teams chat 9:43 Code on a Developer Optimized Cloud PC 10:11 Run local AI with Foundry Local and Phi-4 11:57 Track Cloud PC connection health in Intune 13:03 Troubleshoot connection issues with an AI agent 14:03 What's next for Windows 365
Microsoft Scout takes instructions from a Teams chat and carries them out inside your Cloud PC — locating a report in the Downloads folder that never synced to OneDrive, summarizing it, appending the summary to the file, saving it, then drafting an email with the document attached and holding it for review. It reports progress back in Teams the whole time, so nothing requires touching the physical device. For agent workloads that need isolation instead, Windows 365 for Agents provisions a dedicated Cloud PC with its own unique identity and scoped access, and the same agentic infrastructure powers Computer Use in Researcher.
Developer Optimized Cloud PCs skip the environment build entirely: sign in to a machine already loaded with GitHub, VS Code, and Node.js, then run Foundry Local against the Phi-4-mini small language model to generate an app and run it — CPU spikes visible in Task Manager and Windows Machine Learning profiling in VS Code confirm inference is local, with no cloud tokens spent to code or to run the finished app.
Input and output protection capabilities black out the Cloud PC screen the instant someone attempts a screenshot from the accessing device, and extends the same block to third-party screen recorders and key loggers. Alongside it, AI-enabled Cloud PCs running at least 8 vCPUs add Click to Do, which lifts text out of non-selectable images and graphical tables straight into Excel, plus Semantic Search across the desktop. Sessions roam: disconnect on a laptop, reconnect on an iPad, and apps and display settings come back as you left them. Windows 365 Cloud Apps with Windows 365 Flex publishes individual apps from a shared Cloud PC pool with user experience sync across Windows, macOS, iOS, Android, and the browser. And in the Intune admin center, new monitoring dashboards track connection health, failures, round trip times, and license utilization in near real time, while an admin agent in preview triages issues to a root cause — like a regional cohort set to TCP-only transport instead of UDP with RDP Shortpath.
🔗 Related links:
► Check out https://aka.ms/windows365
► See the latest Windows 365 updates at https://aka.ms/Windows365Turns5
► Unfamiliar with Microsoft Mechanics? Microsoft's Official Video Series for IT
- Subscribe https://www.youtube.com/c/MicrosoftMechanicsSeries - Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog - Podcast: https://microsoftmechanics.libsyn.com/podcast
► Join us on social:
- https://twitter.com/MSFTMechanics - https://www.linkedin.com/company/microsoft-mechanics/ - https://www.instagram.com/msftmechanics/ - https://www.tiktok.com/@msftmechanics
Build a fully working model-driven app from your existing Dataverse, SharePoint, or SQL data in under a minute — screens, navigation, and forms included. Generate new pages from a natural language prompt with Generative Pages, auto-populate records from any document in seconds with Automatic Form Fill, and embed Copilot to query your app data directly.
Layer in an Agent Feed to proactively surface decisions, missing data, and action items, then connect to Outlook and Microsoft 365 through Work IQ to act on your app data without leaving your inbox.
Jed Brown, Power Platform Group Product Manager, shares how to turn existing business data into a modern, AI-powered app.
► QUICK LINKS:
00:00 - Create apps using Power Apps
01:07 - Create an app from existing data
02:26 - Copilot + Form Fill Assist
03:46 - AI-generated pages from a prompt
04:53 - Agent feed for proactive intelligence
06:16 - M365 integration via Work IQ
06:46 - Wrap up
► Link References
Build your first Power App today at https://make.powerapps.com
► Unfamiliar with Microsoft Mechanics? Microsoft's Official Video Series for IT
- Subscribe https://www.youtube.com/c/MicrosoftMechanicsSeries
- Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
- Podcast: https://microsoftmechanics.libsyn.com/podcast
► Join us on social:
- https://twitter.com/MSFTMechanics
- https://www.linkedin.com/company/microsoft-mechanics/
- https://www.instagram.com/msftmechanics/
- https://www.tiktok.com/@msftmechanics
Unify identity and network access controls. Enforce least privilege access across every app and resource. Wire lifecycle workflows directly to your HR system to strip stale permissions on role changes, gate sensitive data behind biometric step-up verification, and replace your VPN with per-app, identity-scoped access that revokes tokens the moment risk spikes. Secure AI usage at every layer. Block confidential data from reaching public AI tools and stop adversarial prompt injections before your agents process them.
John Damon, Microsoft Entra Suite Senior Product Manager, shares how to lock down identity, network access, and AI usage from a single control plane.
► QUICK LINKS:
00:00 - Identity and network controls
00:45 - Lifecycle Workflows
01:28 - Verified ID with Face Check
02:15 - Request access for direct reports
03:17 - Global Secure Access + Token Revocation
04:32 - Secure AI usage
06:20 - Network DLP / ChatGPT Block
07:12 - Prompt Injection Protection
08:31 - Wrap up
► Link References
Check out our related deep dives at https://aka.ms/EntraSuitePlaylist
For more information, go to https://aka.ms/EntraSuite
► Unfamiliar with Microsoft Mechanics?
As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.
• Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries
• Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
• Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast
► Keep getting this insider knowledge, join us on social:
• Follow us on Twitter: https://twitter.com/MSFTMechanics
• Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
• Enjoy us on Instagram: https://www.instagram.com/msftmechanics/
• Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
Qualify a lead, close a case, or walk into a renewal meeting fully briefed, all from the sales and service agents built into Dynamics 365. Ask a question and pull a grounded answer straight from your CRM and your calendar. Hand a prompt to Copilot Cowork and walk away with updated records, a finished presentation, and a drafted email, ready before your next meeting. Auto-fill a case description as you work, and walk into every quality review already scored against your team's framework.
Eric Boocock, Dynamics 365 Principal Program Manager, shares how these agents move with you from first prospect touch to case resolution, right inside the apps you work in every day. Along the way, he explains the mechanics of how everything works and your options to customize the experience with your own skills and instructions.
► QUICK LINKS:
00:00 - Agentic platform in Dynamics 365
01:03 - Sales Qualification & Opportunity Agents
01:44 - Case Management & Quality Evaluation Agents
02:25 - Sales Agent in action
04:30 - Copilot Cowork
05:44 - Automate repeated tasks
07:33 - Power behind agentic platform
08:50 - Custom skills via Power Apps + Dataverse
09:57 - Wrap up
► Link References
Get started at https://aka.ms/AgenticCXPlatform
► Unfamiliar with Microsoft Mechanics?
As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.
• Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries
• Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
• Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast
► Keep getting this insider knowledge, join us on social:
• Follow us on Twitter: https://twitter.com/MSFTMechanics
• Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
• Enjoy us on Instagram: https://www.instagram.com/msftmechanics/
• Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
Control what you're billed on. Tokens are the currency of AI, and how you design your app determines how many you spend. Compress conversation history instead of resending it raw, cap output tokens with matching prompt instructions, and cache static context so each reuse costs a fraction of the first request. Route each prompt to the right model by complexity, or set Model Router in Microsoft Foundry to handle that automatically — balanced, quality, or cost mode.
Then optimize the whole stack. Run Agent Optimizer to test your prompt, model, and tool configurations together and surface better setups. Use Toolbox to dynamically select only the tools each request needs and cut input token overhead by 90%.
April Gittens, Microsoft Principal Cloud Advocate, joins Jeremy Chapman, Microsoft 365 Director, to share how to seize control of AI token spend through smarter app design.
► QUICK LINKS:
00:00 - Tokenomics foundation
01:06 - Token cost basics
02:11 - Context Window creep
03:46 - Reduce unnecessary tokens
04:29 - Trim context costs
05:21 - Cap output tokens
06:27 - Cache for savings
07:54 - Model cost tradeoffs
09:15 - Model Router
09:42 - Toolbox in Microsoft Foundry Toolbox
11:18 - Agent Optimizer
12:44 - Other cost drivers
13:57 - Wrap up
► Link References
Check out the tools in Microsoft Foundry at https://ai.azure.com
For more about managing AI costs go to https://aka.ms/FoundryTokenomics
► Unfamiliar with Microsoft Mechanics?
As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.
• Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries
• Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
• Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast
► Keep getting this insider knowledge, join us on social:
• Follow us on Twitter: https://twitter.com/MSFTMechanics
• Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
• Enjoy us on Instagram: https://www.instagram.com/msftmechanics/
• Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
The speed that AI can now discover and exploit vulnerabilities means that our defenses also need to adjust. For the devices that you manage where you can afford to tighten deployment timelines, we'll explain updated recommendations and show you how to speed up patching.
It starts with assessing your risk exposure for unpatched devices using the new Autopatch report in Microsoft Intune, then tightening deferral policies on the devices where it makes sense, using Hotpatch to activate protection on install — without requiring reboots. Windows Autopatch automates your update deployments using rings to progressively apply updates to the device groups that you help define, including updates for Windows, Microsoft 365 Apps and the Edge browser. And to keep internal resources protected, you can enforce access controls using Conditional Access to block non-compliant devices.
Jeremy Chapman, Microsoft 365 Director, shares what's changed along with the approaches you can take to help counter the growing number of AI-discovered vulnerabilities and stay protected.
► QUICK LINKS: 00:00 - AI and Windows patch management
01:13 - Updated patching deferral thresholds
01:46 - Hotpatch on by default
02:05 - Windows Autopatch report
02:30 - Ring-based deployment + M365 Apps servicing profile
02:50 - Conditional Access for non-compliant devices
03:16 - Wrap up
► Link References
For what you can do beyond patching, go to https://aka.ms/securenow
► Unfamiliar with Microsoft Mechanics?
As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.
• Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries
• Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
• Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast
► Keep getting this insider knowledge, join us on social:
• Follow us on Twitter: https://twitter.com/MSFTMechanics
• Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
• Enjoy us on Instagram: https://www.instagram.com/msftmechanics/
• Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
Apply Zero Trust controls to every AI agent in your environment across identity, tool usage, and data access. Extend Conditional Access in Microsoft Entra to evaluate every agent authorization request in real time against the same risk signals as human users. Assign each agent its own managed identity with Entra Agent ID and scope permissions with Access Packages. Govern your MCP catalog as a software supply chain — unapproved tools don't run, and approved servers lock behind Azure API Management.
Log every agent tool call, API access, and data lookup into Microsoft Sentinel for continuous anomaly detection. Purview Insider Risk Management auto-assigns risk levels so you can investigate fast or revoke access entirely. DLP and sensitivity labels in Microsoft Purview restrict what agents can reach and auto-inherit to everything they generate, and Data Access Governance maps exactly what each agent can access before a prompt fires.
Jeremy Chapman, Microsoft 365 Director, shares how to put these controls into practice across every managed, self-hosted, and shadow agent in your estate.
► QUICK LINKS:
00:00 - How AI changes Zero Trust
01:20 - Zero Trust principles
02:27 - How to apply Zero Trust principles
03:40 - Conditional Access for Agent Identities
04:59 - Entra Agent ID + Access Packages
06:07 - Runtime Observability
06:58 - DLP, Sensitivity Labels + Data Access Governance
07:47 - MCP catalog
08:36 - AI apps & experiences
09:24 - Wrap up
► Link References
Watch the rest of this series at https://aka.ms/ZTMechanics
For additional resources, check out https://aka.ms/GoZeroTrust
► Unfamiliar with Microsoft Mechanics?
As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft.
• Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries
• Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
• Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast
► Keep getting this insider knowledge, join us on social:
• Follow us on Twitter: https://twitter.com/MSFTMechanics
• Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/
• Enjoy us on Instagram: https://www.instagram.com/msftmechanics/
• Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics
From the publisher's feed

4,348 Listeners

379 Listeners

3,062 Listeners

2,011 Listeners

888 Listeners

65 Listeners

959 Listeners

179 Listeners

191 Listeners

203 Listeners

510 Listeners

222 Listeners

684 Listeners

273 Listeners

1,448 Listeners