Copilot / AI / Governance / Enterprise AI
Microsoft 365 Copilot & Agents Architecture Podcast
Copilot and agents from an architecture perspective: Microsoft Graph, semantic index, grounding, governance and security, when do you choose Copilot, Copilot Studio or a custom agent?

11 episodesavg. 20 minLast update: 6 September 2026EnglishPodcast hosts Laura Bennett and Mark Sullivan
Now playing
Episode 1.10 - Threat Protection for AI: Detecting and Responding to Attacks on Copilot and Agents
0:000:00
Sign in to track your progress automatically in My Learning Journey.
All episodes
Also on SpotifyPractice what you learned
Apply the concepts from this episode right away in the Architecture Lab.
- Copilot or FoundryDecide between governed grounding and custom AI.
- Governance before a Copilot rolloutMake AI safe to switch on.
Knowledge check
Open the Architecture Lab Question 1 of 6
A user asks Microsoft 365 Copilot to summarize 'the latest project budget file.' Copilot must ensure it only surfaces content the user is already allowed to see. Which mechanism makes this possible?
Question 2 of 6
In the flow the podcast walks through, security trimming is step four, while the model only comes into play at step seven. Why is that order the whole point, and not incidental?
Question 3 of 6
After enabling Microsoft 365 Copilot tenant-wide, several users report that Copilot surfaces content from files they did not know they had access to. What is the root cause?
Question 4 of 6
A healthcare organization wants to expose clinical protocols that currently live outside Microsoft 365 through a Microsoft 365 Copilot connector, so Copilot can find them. What is the most important control to verify beforehand?
Question 5 of 6
While an organization is cleaning up SharePoint oversharing, the security team wants to limit Copilot's exposure to a defined list of sites in the meantime. How should Restricted Content Discovery (RCD) be positioned here?
Question 6 of 6
In the podcast's four architecture layers (experience, orchestration, grounding data, and identity/security/governance), the model sits in layer two. Why does the podcast emphasize layers three and four instead?
Learn more?
Go deeper on the same topic.
How-tos
How Microsoft partners can become a Frontier PartnerFrontier Transformation asks more of a partner than an AI page on the website. This is the route: your own organization first, then a knowledge foundation, agents around real workflows, governance from day one and a business model that holds up.How to publish an agent in the Microsoft ecosystemFrom your own organization's Agent Store to Microsoft Marketplace, a customer tenant and Microsoft Foundry: which route fits which goal, what each one requires, and where things go wrong in practice.How to secure AI workloads and agentsFrom an AI bill of materials to agent identity, governed RAG sources, prompt injection protection, and a release gate on GA and preview.
Use cases
Professional Services: global Microsoft 365 Copilot rollout with platform consolidationAn international professional services firm with more than 350,000 employees migrates to a unified Microsoft 365 platform with Copilot and builds its own agents in Copilot Studio, resulting in platform consolidation and reclaimed time.Technology: safe Copilot rollout with Purview DSPMA software vendor rolls out Microsoft 365 Copilot and uses Purview DSPM to gain visibility and policy over which sensitive data flows through AI prompts and responses.ISV: embedded generative AI for legal document automationA legal software vendor builds a fully embedded generative AI solution on Microsoft Foundry that automates document processing, data extraction, and draft generation for law firms.
Do you have a similar challenge?
Use the podcasts as inspiration, or share your own Data & AI challenge with us.
