Insights

Copilot Governance - 6 Lessons I Learned from EPPC Copenhagen

Nomondary Davidson, Senior Consultant

July 2026

6 key lessons I learned at the European Power Platform Conference (EPPC) 2026 in Copenhagen in terms of Copilot governance.

Photograph of Copenhagen with river, sail boats and buildings

Copilot is evolving fast. Governance can’t be an afterthought.  

I recently attended the European Power Platform Conference (EPPC) in Copenhagen and attended several sessions on the topic of governance. Here’s six practical, low-friction lessons I took away from the event that will help you and your organisation stay in control as you scale your Microsoft Copilot adoption.

1.   Plan for ongoing technical debt

As Microsoft rapidly expands Copilot and backfills security and governance features, some technical debt will be an ongoing reality if we continue to build. Organisations need to either migrate existing agents to the latest Copilot Studio capabilities, which require development effort, or accept maintaining two generations of agents in parallel, with different feature sets and maintenance overhead. Both options require build effort (now or later) which is a solid example of the technical debt taken on by creating Copilot agents.

2.    Consider your agent environment

By default, Copilot agent conversation transcripts are held for 30 days to preserve 24 hours of conversational context. This retention can increase storage and negatively impact performance for other workloads in the same environment,such as Power Platform or Dynamics 365, depending on which Copilot is being used.

Transcripts are held in a Dataverse table which includes all in-environment messages between agents and users, as well as agents-to-agent (A2A) exchanges. The retention period is enforced by a system-created bulk deletion job which can be modified. My recommendation? Tune the window based on context. Shorten it when agents collect personal data. Extend it to meet industry or regulatory record‑keeping requirements.

Separating agents into different environments is also beneficial. This allows each agent to be isolated or ringfenced from the others, enhancing both operational efficiency and security. Separation enables better auditing as the audit logs available in App Insights are generated for all agents within the same environment, which can make it difficult to pinpoint actions taken by individual agents. By assigning just one per environment, the audit logs are specific and accurate for that agent alone, avoiding confusion caused by combined logs for multiple agents.

3.   Voice agents demand even stronger governance

In one session I attended there was a lot of discussion around governance and voice agents. A key consideration is that when users use voice they tend to be chattier and use more slang compared to typed demands. Asa result, a voice conversation typically uses considerably more credits than a text agent because there’s simply more to process.

Voice agents use Microsoft Graph via its Teams voice integration. Because Microsoft Graph spans all Microsoft 365 services, it can access almost all the maker’s interactions across Outlook, Teams and more. Copilot text agents can also use Graph, but it isn’t enabled by default the way it is for voice agents.

Voice agents also tend to be more agreeable, so they require closer monitoring and stronger guardrails to ensure answer accuracy. When using voice agents, ensure tighter monitoring over accuracy of the output, as well closer auditing of your consumption costs.

For further information on AI voice agents, read our full 3-part blog series here.

4.   Enforce agent-to-agent (A2A) governance with DLP

Each A2A connection creates a custom connector. An easy way to govern what makers build is to block custom connectors in an environment’s DLP policy, so that they always need approval from the environment admin before release. A2A connections can be disabled by makers, but the change can take up to 24 hours to take effect. DLP policies are therefore an underestimated but effective way of controlling the sprawl of A2A connections.

5.   Entra IDs will enable better auditing and controls

It was mentioned at the conference that going forward, each Copilot agent will have its own Entra ID. This should improve auditing and make troubleshooting easier, as its data access will leave clear audit trails. You will be able to grant agents access to data just as we do for users, by assigning security roles and restrict them from certain tables or rows. Of course, this change will create more overhead: managing Entra IDs and tracking what work an agent performs to keep security roles accurate.

How can you prepare? Ensure your organisation is undertaking periodic reviews of each agent in each environment and have clear, explicit descriptors.

6.   Oversee agents as you would users

Microsoft Defender and Agent 365 block unsafe actions, such as sending emails with excessive sensitive information. To secure your agents, register your agent and turn on Copilot Studio real-time. This allows a connection between Copilot Studio, Microsoft Defender and Agent 365. Microsoft Defender can also integrate with other platforms such as Splunk and Dynatrace, which don’t natively understand Dataverse or Copilot outputs.

Forwarding agent traffic to Global Secure Access applies the same controls used for users to agents, such as network file filtering. Be sure to enable Global Secure Access for this security – this can only be done in the Power Platform Admin Centre by a Global Secure Access Administrator (editing features) or a Power Platform Admin (managing the environment or environment group).

Always enable App Insights for each agent before deployment as then makers can monitor them within Copilot Studio and at the environment level to see relationships between agents. App Insights is relatively inexpensive for the auditing it provides, so it’s always worth turning on.

Key Takeaways

The pace of Copilot’s evolution is incredible, but the above tips should serve as some practical measures all organisations should consider to keep agents under control. Treat agents like users by registering and protecting them with Copilot Studio real-time protection and Microsoft Defender, route their traffic through Global Secure Access for consistent policies and enable App Insights for end-to-end monitoring and auditing.

If you are a Robiquity customer, we will be diving even deeper into everything we learned at the European Power Platform Conference 2026 in our webinar - Straight from Copenhagen: Your EPPC Download - on the 6th of August. Find out more and register here.

Recent posts