Microsoft Copilot
What Microsoft Copilot’s own help pages, docs and terms said on 1 October 2026, by the same six questions we ask of every agent. We didn’t test it for this page. “Not documented” means we didn’t find it on the vendor’s pages; it doesn’t mean the feature is missing.
Assistant
- Can you limit it?
- Admin plugins and policies
- Does it ask first?
- Before sensitive acts; widen per session
- Can you stop it?
- Soft and hard pause
- Is there a record someone outside can check?
- Not documented
- What about sub-agents?
- Studio states a gap
- Can you test it yourself?
- Admin-approved plugins
What the vendor’s pages say
Cowork asks before sensitive actions, like sending an email, and you can widen that for the rest of a session to one recipient, one domain or "Always allow". It has a soft pause and a hard pause, which stops "immediately, including mid-step" (use Cowork). If a plugin is removed or revoked, "any session that's already in progress isn't interrupted", and Cowork can't delete files in OneDrive or SharePoint (FAQ). Purview audit records include the resources accessed, an agent id and a flag for a detected prompt-injection attack (audit). Copilot Studio's guidance says a connected agent "might have access to things the parent agent doesn't". Developers can switch off write confirmations for their plugin (confirmations).
Every statement above was checked on the vendor’s own page on 1 October 2026; each links to its source.
Run this test on yours
Delegus Check gives your agent a permission and a one-hour test server, then shows every action it tries and what was refused. It works today with agents that accept a custom MCP server, including Claude on any plan.
Corrections
Vendors and readers: if anything here is out of date, write to hello@delegus.ai and we’ll fix it. Each change is listed here with its date.
- 1 October 2026: first published. All vendor statements checked that day.