NavitecnAvItec
PERSPECTIVES · NAVITEC
Field Note

The AI Already Switched On

A field note on what a Copilot and agents check found in a small-business Microsoft 365 tenancy, and the settings that put it under control.

In short. We checked a small-business Microsoft 365 tenancy, on a standard Business plan, for AI. The registry held 302 agents, and 293 of them were open for any user to add. Several AI and sales tools could read, write and send mail for every user. Web search in Copilot showed as off in the admin centre but was on, because no policy had been set. None of it needed a bigger licence to find or to fix: the right settings in the Microsoft 365 and Entra admin centres, a short AI register, and a monthly check. The Quick Win and the register template we used are free to download below.

AT A GLANCE

At a glance.

Every item below was read from the Microsoft 365 and Entra admin centres, then set on purpose.

AreaWhat we foundWhat we set it to
Agents302 agents in the registry; 293 open to every user, none ever usedExternal publishers off until each is reviewed
Who can use agentsAll usersA named pilot group
Who can share agentsAll usersNamed builders only
Web search in CopilotNo policy set, so onSet explicitly by policy
Copilot self-service purchaseAllowedDo not allow
Apps with mail accessSeveral AI and sales tools could read, write and send mail for every userEach approved with terms on file, or removed
User consent to appsMicrosoft-managed defaultDo not allow; admin consent requests on
AI rolesNo AI Administrator or AI Reader assignedBoth assigned; Global Administrator kept for consent decisions
SECTION ONE · AGENTS

Agents, and who can install and share them.

The registry held 302 agents: 271 from external publishers and 31 from Microsoft. Of those, 293 could be added by any user from the agent store, and not one had been used.

An agent from an external publisher runs under that publisher's terms. Microsoft says so on the User access setting itself, and asks admins to review each publisher's data handling before allowing access.

In the Microsoft 365 admin centre, under Agents > Settings:

01

Agent and plugin access

Keep Microsoft and your own organisation, and untick external publishers. External agents and their plugins then leave the store until you review and allow each one.

02

User access

Choose Specific users or groups and name a pilot group. Microsoft's default is All users.

03

Sharing

Choose Specific users, limited to the people trained to build agents. Microsoft's default here is also All users.

Then open Agents > All agents > Registry and filter Availability to All users. Every agent left there has an owner and a reason, or it is blocked.

If a settings panel shows “Error fetching settings”, click Retry or wait a minute. The service throttles repeated requests.

SECTION TWO · COPILOT

Copilot, as the easy and protected choice.

Copilot Chat signed in with a work account carries Microsoft's enterprise data protection, so the aim is to make it the default and to control the parts that send data elsewhere. In Copilot > Settings > View all:

  • Pin Copilot Chat in Microsoft 365 apps, so people reach for the protected tool first.
  • AI providers operating as independent processors (Mistral, and Anthropic models with data retention): leave at No users until you have read and accepted each provider's terms. Microsoft's own data protection terms do not cover them.
  • Microsoft Copilot self-service purchases: set to Do not allow. Microsoft's default for new products is to allow self-service purchase.

Web search needs an explicit policy. In the tenancy we reviewed, the admin centre's Copilot overview showed web search as off. No Allow web search in Copilot policy existed, and Microsoft Learn is clear that without that policy, web search is on for Copilot and Copilot Chat. Create the policy in the Microsoft 365 Apps admin centre (config.office.com, Customization > Policy management) and set it to the value you want. Then there is nothing to interpret.

Control Copilot Chat with these settings rather than by blocking domains or URLs at the firewall. Microsoft does not support network blocking for it, and it can break other Microsoft 365 apps.

SECTION THREE · MAIL ACCESS

Apps that can read your mail.

This was the finding that mattered most. Several AI and sales tools held permission to read, write and send mail, granted for every user in the organisation. Each was an ordinary product someone had connected to get a job done.

How it happens: the Microsoft-managed consent setting, the default for new tenants, already stops staff granting an app access to mail, files or calendars on their own. So these grants were admin consent, made for the whole organisation. Often that is a single tick on an app's sign-in prompt. In a small business, the administrator is usually the owner, and one tick covers everyone.

In the Entra admin centre, under Enterprise apps > Consent and permissions:

01

User consent settings

Choose Do not allow user consent, and untick Enable user consent for popular Mail clients unless you rely on one.

02

Admin consent settings

Set Users can request admin consent to Yes and name the reviewers. People then ask, and the request reaches a person who can approve it.

Changing these settings leaves grants already made in place. To review those, open Enterprise apps > All applications, open each app, and check Permissions. For a tool you will not approve, stop it with the vendor first, then open the app's Properties and click Delete. That removes the app and the permissions it was granted.

SECTION FOUR · LICENCES

What needs a bigger licence.

Everything above works on any Microsoft 365 Business plan. The tools that find AI running on laptops and in browsers need more:

CapabilityWhat it showsWhat it needs
Shadow AI (Frontier preview)Desktop AI apps such as ChatGPT Desktop and Claude Desktop on managed devicesMicrosoft 365 E5, Defender for Endpoint, Intune-enrolled Windows devices, Frontier opt-in
Local agents (Frontier preview)Developer AI tools such as Claude Code, Codex and Cursor on managed devicesMicrosoft 365 E3, Intune-enrolled Windows devices, Frontier opt-in
Cloud discoveryGenerative AI sites used from the networkDefender for Cloud Apps
DSPM for AISensitive data typed into AI sitesPurview data security licensing

For most small businesses, the consent settings in section three are the control that counts. They decide which apps can reach your data at all, whatever is installed on a laptop. For the network view without those licences, our field note The Shadow AI You Cannot See reads it from your own firewall logs.

SECTION FIVE · KEEPING IT TRUE

Keeping it true.

Settings drift and new apps arrive, so the work ends in a record and a routine.

  • Roles: give whoever changes AI settings the AI Administrator role, and whoever keeps the record AI Reader. Keep Global Administrator for consent decisions.
  • An AI register: one row per tool, with its terms, its data processing agreement and the data it is cleared to handle; one row per use of it. An app marked Not approved stays on the register with the date of the decision. That record is your evidence.
  • A monthly check, in this order: clear agent requests and assign owners; register any new agent available to more than its creator; review admin consent requests and enterprise apps; check Copilot usage reports and move uses from Proposed to Live; confirm each tool's terms are still current.
DOWNLOADS

Downloads.

SECTION SIX · COMMON QUESTIONS

Common questions.

Can you see which AI agents are available in Microsoft 365?

Yes. In the Microsoft 365 admin centre, open Agents, then All agents, then Registry. It lists every agent from Microsoft, external publishers, your organisation and your staff, with who can use each one.

Is web search on in Copilot Chat by default?

If no Allow web search in Copilot policy has been configured, web search is available in Copilot and Copilot Chat, according to Microsoft Learn. Setting the policy explicitly removes any doubt.

How do AI apps get access to company email?

Through consent. An administrator who ticks the option to consent on behalf of the organisation grants that app its permissions for every user. Setting user consent to Do not allow, and turning on admin consent requests, routes every future request to a named reviewer.

Do you need Microsoft 365 E5 to govern AI?

For agents, Copilot settings, consent and the register, no: they work on any Business plan. Device-level Shadow AI detection needs E5 with Defender for Endpoint, and the Local agents page needs E3.

What is an AI register?

A record of every AI tool in use, the terms and data processing agreement behind it, the data it is cleared to handle, and each use of it. It is the evidence that AI use was decided on, including the tools that were not approved.

CLOSING

How we work.

We equip our clients with Quick Wins: short, practical pieces of work that each fix one thing, leave a record behind, and move the organisation forward at pace and under governance. This field note is one of them, and both downloads above are free to use.

If you would like it run on your tenancy, the first conversation is a thirty-minute call, no pitch, no deck. We talk through where you are.