Microsoft 365 Copilot and its agents are paid for in three different ways, and each one bills to a different place: per-user seats on the Microsoft 365 invoice, prepaid Copilot Credits allocated to Power Platform environments, and pay-as-you-go charges on an Azure subscription. This guide explains the three cost shapes, the controls Microsoft provides for each, and a chargeback model built on them, checked against Microsoft's documentation in September 2026.
Indirect prompt injection arrives through the documents, email, web pages and tool results an AI system reads, not through the user. OWASP's 2026 Top 10 now says no reliable prevention exists and that defence is architectural. This article explains where injected instructions enter, what model-level defences can and cannot do, and the trust boundaries on data that still hold when the model is fooled.
Microsoft Copilot respects existing permissions, which means it finds existing oversharing faster than any user ever did. This guide explains where excess access comes from, what SharePoint Advanced Management and Microsoft Purview actually do about it, why Restricted SharePoint Search is retiring, and a phased remediation plan, with every status checked against Microsoft's documentation in September 2026.
Once an AI agent can write to systems, send email or move money, "a human approves it" is not a design. This guide classifies agent actions by consequence and reversibility, maps each class to an approval pattern, and sets out what the audit record must hold to survive a review, grounded in what Microsoft 365 Copilot, Copilot Studio, Microsoft Foundry and Purview actually provide as of September 2026.
Once you have decided to extend Microsoft 365 Copilot, there are three ways to do it, and they are not interchangeable. Copilot connectors change what Copilot knows, declarative agents change how it behaves, and custom engine agents replace its engine. This guide compares the three on licensing, governance and who carries the risk, with every claim checked against Microsoft's documentation in September 2026.
Copilot Studio and Microsoft Foundry are not competitors — they sit at different levels of abstraction, and three changes in 2026 have quietly retired most of the advice written about choosing between them. A decision framework built on who owns the runtime, where the data already lives, and who operates the agent on day ninety, with the cost shapes, governance asymmetries and interop paths verified against Microsoft's own documentation.
Microsoft's AI portfolio is not five versions of the same product — it is a layered enterprise architecture with an experience layer, two build platforms, a control plane, and the identity, data and threat controls underneath. A practical architecture guide to what each platform is for, which workloads belong where, how agent identity and authority actually flow, and what has to be true before an organization scales any of it.