Security2026-10-048 min read

Microsoft Copilot Autopilot Agents Get a Mailbox and a Seat in the Org Chart. Put Them Through Joiner, Mover, Leaver

On 25 September 2026 Microsoft renamed its Scout agent to Autopilot and folded it into a rebuilt Copilot app. Each Autopilot agent runs under its own Entra identity and, in Frontier preview tenants, can hold a mailbox, a calendar, OneDrive storage and a place in the org chart, billed on usage. Here is how to govern an agent that looks like an employee.

Microsoft introduced Scout at Build 2026 as the first of a new category of always on agents it calls Autopilots. On 25 September 2026 it renamed Scout to Autopilot and folded it into a redesigned Copilot app with three modes, Home, Code and Autopilot. Copilot as most staff know it waits for a prompt. Autopilot runs in the background, works toward a goal it has been given, and takes action across Microsoft 365 without being asked each time. It is in private preview, so most organisations cannot switch it on yet, but the identity model Microsoft has chosen is already public and it is the part worth planning for now.

Each Autopilot agent runs under its own governed Microsoft Entra identity rather than a shared service account. Reporting on the preview describes a full Entra Agent ID user account with a productivity licence, which gives the agent its own email address, calendar, OneDrive storage, Teams presence and a position in the org chart. Mailbox and calendar access is currently limited to Frontier preview tenants, and some collaboration features need a separate, optional Entra user account and licence. Microsoft says the agent has its own permissions and audit logs, integrates with Purview for data protection, and can be configured so that sensitive actions require a human to sign off.

That is a better starting point than the shared service accounts and personal tokens most agent deployments use today, and it answers the attribution problem we described in our piece on UI operating agents and the audit trail gap. When an Autopilot sends an email or edits a file, the log can say which agent did it rather than which human lent it a session. But a distinct identity is only useful if you govern it like one. An agent with a mailbox, a licence and a manager field in the directory is, for every practical purpose in your identity platform, a new starter. Most identity processes were built on the assumption that new starters are people with an HR record.

Start with joiner, mover, leaver. Your provisioning flow for staff probably begins with an HR system event, and an agent has none. Decide who is allowed to create an Autopilot, which approval it needs, and who is recorded as its accountable owner. Then decide what happens when that owner changes role or leaves. An agent created by a sales manager, holding delegated access to the pipeline and sending mail to customers, should not keep running for six months after that manager has gone because no HR event fired for it. Tie every agent identity to a named human owner, review that link whenever the owner moves, and make orphaned agents a ticket rather than a discovery during an audit.

Access reviews need the same treatment. Under ISO 27001 Annex A 5.15 to 5.18 on access control, identity management, authentication information and access rights, and under SOC 2 CC6.1 to CC6.3 on logical access, provisioning and removal, an auditor will expect agent identities to appear in the same periodic review as human accounts, with the same evidence that someone looked at what each one can reach and confirmed it is still needed. If your Entra access reviews filter on employee type or on accounts linked to an HR record, check that agent accounts are not silently excluded. In Vanta, Drata or Secureframe, confirm the identity integration actually ingests Agent ID accounts, then tag them so they are not counted as people missing security training.

The mailbox deserves a threat model of its own. An agent that reads and sends email is a prompt injection target with a public address. A message crafted to look like an instruction from the owner can try to make the agent forward documents, accept a meeting, or reply to a supplier with changed bank details. Use the human sign off option for anything that sends mail outside the organisation, shares files externally or touches finance, and apply Purview data loss prevention and sensitivity labels to agent mailboxes exactly as you would for a staff member in the same team. Add agent addresses to your mail flow rules and conditional access policies on purpose, rather than discovering later which policies matched them by accident.

Billing is the other change. Autopilot runs on usage based Copilot Credits rather than a flat seat, and Microsoft has not published Autopilot pricing beyond that. An always on agent that keeps working toward a goal will consume credits whether or not anyone is watching, which makes a runaway agent a cost incident as well as a security one, the availability risk Mandiant flagged in its AI risk work. Set credit budgets and alerts per agent or per owning team before the preview reaches you, and treat sudden spend as a detection signal worth investigating, the same way you would treat an unusual login.

For AI governance, record each Autopilot in your AI system inventory under ISO 42001, with its owner, purpose, data access, approval gates and the date its access was last reviewed. That entry is also the starting point for EU AI Act deployer duties if an agent is ever pointed at decisions about people, such as screening candidates or prioritising customer complaints, since an agent that acts on a goal can drift into those uses without a new procurement decision. Our ISO 42001 and EU AI Act pages set out what that inventory needs to show.

A short list for this week. Decide who may create Autopilot agents once the preview arrives, and write it into your AI acceptable use policy. Extend your joiner, mover, leaver process so every agent identity has a named human owner and is reviewed when that owner changes. Confirm your access reviews and compliance platform include Agent ID accounts. Require human sign off for external email, external sharing and finance actions. Set credit budgets per agent. Our view is that giving agents their own identity is the right design, and Microsoft deserves credit for it. It also means the agent is now an employee as far as your directory is concerned, so give it an owner, a review date and an exit process before it gets a mailbox.

MicrosoftCopilotAutopilotScoutEntra Agent IDagent identityaccess reviewsPurviewusage billingISO 27001ISO 42001SOC 2EU AI ActVantaDrata

Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.

// Signal, not noise

Get the next post by email

One short email when something worth knowing ships. No spam, unsubscribe anytime.

Loading comments...

Add a comment

Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.

0/4000 · plain text · links are held for review

More from the blog