Module 7 – Security, monitoring & governance
This module equips learners with the knowledge and best practices needed to secure, monitor, and govern Microsoft Copilot Studio environments at scale.
Participants will learn how to balance innovation and control, implement zoned governance models, enforce data loss prevention (DLP) and compliance policies, and manage the security of both agents and users.
Topics Covered
Balancing Innovation and Governance
The importance of governance in AI and Copilot deployment
Balancing citizen development and enterprise oversight
How governance enables safe innovation without stifling productivity
Building governance frameworks aligned with corporate IT and security policies
Common governance challenges in scaling Copilot adoption
The Agent Controls Model
Understanding the Agent Controls Model: policies, permissions, and oversight
Key governance layers: user, environment, tenant, and data
How agent-level controls support compliance and operational transparency
Tracking agent performance and telemetry for security auditing
Zoned Security, Governance, and Operations
Overview of Governance Zones (1–3):Zone 1: Citizen Development (low-risk, innovation sandbox)Zone 2: Partnered Development (moderate risk, departmental use)Zone 3: Pro Development (high governance, enterprise-critical)
Mapping organizational maturity to governance zones
Getting Started with Zones – setting up secure, scalable environments
How to manage transitions between zones while maintaining compliance
Security and Administration Controls
Overview of security architecture in Copilot Studio and Power Platform
Security, agent, and user management strategies:Assigning roles and permissionsEnabling secure authentication (Azure AD, Entra ID)Monitoring user actions and agent activity logs
Designing an effective environment strategy for production, test, and development
Understanding Copilot Studio security roles and least-privilege access design
Data Loss Prevention (DLP) and Policy Management
Overview of DLP Policies in Power Platform and Copilot Studio
The role of DLP connectors and data classification in controlling data flow
How to manage connectors across risk profiles (Business vs. Non-Business)
DLP policies and rules per environment — and when they can be safely relaxed
Designing DLP frameworks that balance flexibility and compliance
Practical examples: blocking external connectors, auditing data access
Securing Copilot Studio Usage at Scale
Strategies for secure scaling across large organizations
Controlling adoption through environment boundaries and sharing rules
Using analytics and reports to monitor agent performance, cost, and usage
Automating governance checks and policy enforcement through CoE Starter Kit
Prompt Injection Mitigations – preventing manipulation of agent behavior through malicious inputs
DDoS Protection for Anonymous Chatbots – safeguarding public-facing Copilots against overload attacks
Data Residency and Compliance Management
Understanding data residency and storage in Microsoft Copilot Studio
Managing data movement restrictions across geographies and tenants
Compliance with GDPR, SOX, HIPAA, and other global standards
Designing for multi-region governance and local data processing
Tools and best practices for monitoring data movement and access patterns
Module 8 – Application Lifecycle Management
This module focuses on implementing Application Lifecycle Management (ALM) practices for Copilot Studio.
Learners will explore how ALM ensures structured development, testing, and deployment of Copilot agents across environments while maintaining governance, consistency, and control.
Participants will gain practical insights into using Power Platform ALM, Azure DevOps, GitHub Actions, and Power Platform Pipelines to manage agent updates and continuous delivery in enterprise environments.
Topics Covered
Understanding ALM Strategy
Defining an ALM strategy for Copilot agents within Microsoft 365 and Power Platform
Why ALM is essential for enterprise-scale development and governance
The benefits of structured lifecycle management:Version controlTesting and quality assuranceControlled deployment across environmentsReduced risk and rework
Aligning ALM practices with organizational change management and security policies
What Is ALM and Why It’s Important
Overview of Application Lifecycle Management (ALM) conceptsDevelopment → Testing → Staging → Production cyclesManaging agent versions and configurations
How ALM supports collaboration between makers, developers, and administrators
Common pitfalls in unmanaged agent updates or direct publishing
Real-world ALM examples in Copilot Studio agent deployment
What “Publish” Really Does in Copilot Studio
Understanding the Publish process in Copilot Studio
What happens behind the scenes when publishing an agentVersion creation, environment packaging, and synchronization
How publishing differs from exporting/importing solutions in Power Platform
Best practices for publishing safely without disrupting production agents
Integrating publishing into your broader ALM workflow
Power Platform ALM for Copilot Studio
Overview of Power Platform ALM capabilities relevant to Copilot Studio
How solutions encapsulate Copilot agents, connections, and data configurations
Managing Copilot components as part of broader Power Platform solutions
Understanding environments and their role in ALM:Development, Test, UAT, and ProductionEnvironment permissions, data boundaries, and DLP alignment
Tracking agent versions, dependencies, and solution history
ALM with Azure DevOps
Integrating Azure DevOps with Power Platform and Copilot Studio
Managing Copilot solution source control and version tracking
Automating deployment pipelines through Azure DevOps YAML templates
Example workflows:Export → Validate → DeployTrigger-based deployments for agents or connectors
Using Azure DevOps Boards for ALM governance and change tracking
GitHub Actions for Microsoft Power Platform
Introduction to GitHub Actions for CI/CD with Power Platform
Setting up a GitHub repository to manage Copilot Studio solutions
Example automation:Exporting a solution from Dev → Importing to Test or ProdRunning validation checks before deployment
Comparing Azure DevOps Pipelines vs. GitHub Actions for ALM workflows
Security and permission considerations for GitHub integrations
Power Platform Pipelines for Copilot Studio
Introduction to Power Platform Pipelines — no-code ALM for citizen and pro developers
How Pipelines simplify solution promotion across environments
Configuring automated pipelines for Copilot Studio agents
Using deployment profiles to control environment variables and data connections
Monitoring deployment success, rollback procedures, and version tracking
Combining Pipelines, GitHub, and DevOps for hybrid ALM strategies
Module 9 – Analytics & KPIs
This module teaches learners how to measure, analyze, and optimize the performance of Copilot Studio agents using data-driven insights.
Participants will explore conversation analytics, engagement metrics, and key performance indicators (KPIs) that reflect business impact and user satisfaction.
By implementing a structured analytics and optimization strategy, learners will be able to continuously improve their agents’ effectiveness, refine conversation design, and demonstrate ROI to stakeholders.
Topics Covered
Conversation Design and Outcome Tracking
Understanding conversation analytics in Copilot Studio
Measuring conversation flow effectiveness: intent recognition, success paths, and drop-off points
Designing conversations with measurable outcomes (e.g., task completion, satisfaction, resolution rates)
Tracking end-user interactions and intent success using telemetry and built-in analytics
Mapping conversational outcomes to business objectives and performance goals
Using conversation data to refine prompts, topics, and agent logic
Engagement and Outcomes
Defining and measuring engagement metrics:Total users, active sessions, conversation depth, and dwell timeRepeat interactions and user satisfaction trends
Identifying key engagement drivers — tone, context, personalization, and response time
Using data to segment audiences and identify high-value user scenarios
Correlating agent engagement with organizational productivity and ROI
Example KPIs:Resolution rate per topicTime-to-response improvementReduction in support tickets through automationBusiness cost savings from AI adoption
Analytics Strategy
Building a comprehensive analytics strategy for Copilot agentsAligning analytics goals with business priorities and governance policiesDefining measurable KPIs for agent performance and value realizationUsing Microsoft analytics tools:Copilot Studio Analytics DashboardPower BI integration for advanced reportingDataverse telemetry for raw data analysisHow to combine Copilot analytics with Power Platform CoE dashboards
Tracking metrics across environments: Dev, Test, and Production
Data governance considerations in analytics — ensuring accuracy and privacy
Optimization Strategy
Developing an optimization cycle for continuous improvement:Monitor → 2. Analyze → 3. Adjust → 4. Deploy → 5. Measure again
Leveraging A/B testing for topic or prompt improvements
Applying analytics insights to refine:
Using performance data to identify underperforming agents or topics
Creating a feedback loop with stakeholders and users for ongoing tuning
Setting thresholds and alerts for critical KPIs (e.g., low satisfaction, high failure rate
Module 10 – Licensing and capacity
This module provides learners with a deep understanding of how Microsoft Copilot Studio licensing and capacity consumption work within the Power Platform ecosystem.
Participants will learn how to plan, monitor, and manage Copilot Studio resource usage across environments while maintaining cost efficiency and operational scalability.
Topics Covered
Licensing and Capacity Overview
Overview of Copilot Studio licensing modelsLicensing through Microsoft 365, Power Platform, and standalone Copilot subscriptionsKey licensing dependencies: Power Virtual Agents, Power Automate, Dataverse
Capacity components and what they represent:Dataverse storage (database, file, log)Power Platform request limitsAI Builder and Copilot Studio usage entitlements
Aligning licensing strategy with your organization’s scale, user base, and governance zones
How to assign and manage licenses across tenants and environments
Basic Credit Consumption Scenarios
Understanding Copilot capacity credits and how they are consumed
Common usage patterns that drive credit consumption:Agent interactions and conversation sessionsGenerative AI responses and knowledge retrievalTool usage (code interpreter, connectors, RAG queries)
Mapping agent types to credit requirements (simple, task-based, autonomous)
Real-world credit usage examples for typical Copilot deployments
How conversation complexity, orchestration, and integration affect credit burn
Agent Activity and Billing Rates
Understanding Agent Activity metrics and their impact on billing
How billing rates differ based on:Generative AI vs. retrieval-based responsesTool and connector usageFrequency of orchestration or autonomous agent actions
Reading and interpreting usage reports in the Power Platform admin center
Using telemetry data to connect activity metrics to cost drivers
Best practices for minimizing unnecessary agent calls and redundant executions
Understanding Credit Burn Rate
Definition of credit burn rate in Copilot Studio
How to monitor and project credit consumption across environments
Factors influencing burn rate:Agent concurrency and scalingNumber of active users or sessionsSize and complexity of AI prompts and retrieval operations
Strategies for managing and reducing burn rate:Optimizing conversation length and efficiencyReusing knowledge sources and cached responsesScheduling non-critical agents during off-peak hours
Setting up alerts or dashboards to track consumption trends
Copilot Studio Estimator
Introduction to the Copilot Studio Estimator Tool
How to use the estimator to forecast usage, licensing, and costs
Simulating scenarios based on:Number of agentsDaily conversation volumeGenerative AI usage patterns
Interpreting estimator outputs to guide budget and capacity planning
Integrating estimator results into business case and ROI modeling
Capacity Management
Building a capacity management strategy for Copilot Studio
Monitoring capacity in the Power Platform Admin Center
Allocating capacity per environment and adjusting for usage growth
Using governance zones and environment strategy to balance capacity
Managing cross-tenant capacity sharing and reporting
Planning for scale: forecasting enterprise-wide usage
Coordinating with IT operations and finance teams for ongoing monitoring
Module 11 – Testing agents
This module teaches learners how to effectively test, validate, and ensure quality for Copilot Studio agents before deployment.
Participants will explore Copilot Studio Kit testing capabilities, learn how to test agents at scale, and understand the types of tests supported within the Copilot Studio ecosystem.
By applying structured testing practices, learners will develop the skills to identify defects, improve performance, and deliver reliable, production-ready Copilot agents that align with enterprise standards.
Topics Covered
Introduction to Testing in Copilot Studio
The importance of testing and validation in the Copilot agent lifecycle
How testing fits into the Application Lifecycle Management (ALM) and deployment process
Typical challenges in testing AI-driven and conversational systems
Core goals of agent testing:Ensuring accuracy, reliability, and usabilityVerifying data access and securityConfirming proper orchestration and workflow logic
Overview of the Copilot Studio Kit
Introduction to the Copilot Studio Kit and its testing capabilities
Components of the Kit:Test automation frameworkReporting and analytics toolsConfiguration and environment setup utilities
How the Kit integrates with Power Platform, Azure DevOps, or GitHub Actions pipelines
Preparing the testing environment and data sets
Using the Kit for continuous testing in multi-environment deployments
Testing Agents at Scale
Strategies for scaling agent testing across multiple environments and use cases
Simulating large-scale user interactions and load testing scenarios
Managing and tracking test execution across Dev, UAT, and Production environments
Automating tests as part of CI/CD pipelines (DevOps or GitHub Actions)
Monitoring performance and response times under real-world usage conditions
Identifying and resolving issues related to:Latency and orchestration delaysData retrieval and grounding (RAG) errorsTool integration failures or misconfigurations
Ensuring governance compliance during automated test runs
Supported Test Types in the Copilot Studio Kit
Overview of test types supported in Copilot Studio Kit:Unit Tests: Validate individual topics, nodes, and responsesIntegration Tests: Verify that connectors, triggers, and tools function correctly togetherRegression Tests: Ensure existing functionality remains stable after changes or updatesPerformance Tests: Evaluate speed, concurrency, and response timesSecurity Tests: Validate DLP adherence, authentication, and permissionsConversational Flow Tests: Assess natural language understanding, disambiguation, and orchestration accuracy
Best practices for selecting appropriate test types for each phase of development
How to interpret test results and generate actionable reports